Unsolved

This post is more than 5 years old

13 Posts

2735

April 11th, 2007 16:00

Extreme Pop ups and Computer running slow

This is my work computer so if anyone can help please do! I ran Trend micro on my computer and it found a ddayz.dll, sstqp.dll  as well as WORM_RBOT.ckt that is located in the kernel32.exe.  The last post posted without me saying so. But the system has been running incredibly slow every action takes about 40 seconds to a minute to execute even something as small as opening a folder. I now have an extreme amount of pop ups everytime I view different webpages and on certain pages the start menu will freeze as well as the webpage. Here are the results of the Hijack this scan.
 
 
Logfile of HijackThis v1.99.1
Scan saved at 12:49:59 PM, on 4/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\system32\DllHost.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\FlexiSIGN-PRO 7.6v1\Program\App.exe
C:\Program Files\FlexiSIGN-PRO 7.6v1\Program\App.exe
C:\Dell\RegistryBooster2\RegistryBooster.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Microsoft System Service] taskmgr1.exe
O4 - HKLM\..\Run: [Microsoft Windows System Kernel] kernel32.exe
O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\ejrtfcsw.dll",setvm
O4 - HKLM\..\RunServices: [Microsoft System Service] taskmgr1.exe
O4 - HKLM\..\RunServices: [Microsoft Windows System Kernel] kernel32.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Windows System Kernel] kernel32.exe
O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Dell\RegistryBooster2\RegistryBooster.exe /S
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 

4 Apprentice

 • 

20.5K Posts

April 11th, 2007 17:00

Welcome :)
This will take a few procedures.

Please disable SpySweeper temporarily so it does not interfere with registry changes that we are going to make. You can re-enable it after you're clean.
To disable SpySweeper:
Open it click >Options over to the left then >program options >Uncheck "load at windows startup".
Over to the left click "shields" and uncheck all there.
Uncheck "home page shield".
Uncheck "automatically restore default without notification".
Exit the program.
[After your system is fully cleaned reenable Spysweeper using the same steps but this time reverse them.]

First let's remove NewDotNet using Add/Remove Programs if it is listed there:
Although Newdotnet does not claim to be spyware, it has been associated with computer instability in certain situations. I suggest that you remove it. I'd like to do it now so that some of the other tools we are going to run do not remove the uninstaller, thus making it more diffeicult to remove.
Please open Add/Remove programs and uninstall New.net Application or New.net Domains from there if listed. If it is not listed let me know in your next reply.
REBOOT.

Download AVG Anti-Spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program

  1. Once you have downloaded AVG AS, locate the icon on the desktop and double-click it to launch the set up program.
  2. Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Right click on AVG AS in the system tray and uncheck "Start with Windows".
  3. >
  4. Go to Start > Run and type: services.msc
  5. Press "OK".
  6. In Services, click the "Extended tab" and scroll down the list to find AVG anti-spyware guard.
  7. When you find the guard service, double-click on it.
  8. In the Properties Window > General Tab that opens, click the "Stop" button.
  9. From the drop-down menu next to "Startup Type", click on "Manual".
  10. Now click "Apply", then "OK" and close the Services window
  11. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
  12. On the main screen select the icon "Update". Tthen select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    • If you are having problems with the updater, manually update with the AVG ASnti-spyware Full database installer from here.
    • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    • Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
      • Close AVG Anti-Spyware, Do Not run a scan just yet.
        1. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
        2. IMPORTANT: Do not open any other windows or programs while AVG AS is scanning, it may interfere with the scanning proccess:
        3. Launch AVG Anti-Spyware by double-clicking the icon on your desktop.
        4. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
        5. AVG AS will now begin the scanning process, be patient this may take a little time.
        6. Once the scan is complete do the following:
        7. If you have any infections you will prompted, then select "Apply all actions"
        8. Next select the "Reports" icon at the top.
        9. Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
        10. Close AVG AS and reboot your system back into Normal Mode.


        11. Please download the latest version of
          VundoFix.exe to

          your desktop. (If you have an earlier version, delete it and its old log here: C:\ vundofix.txt.)
          • Double-click VundoFix.exe to run it.
          • Click the Scan for Vundo button.
          • Once it's done scanning, click the Remove Vundo button.
          • You will receive a prompt asking if you want to remove the files,
          • click YES
          • Once you click yes, your desktop will go blank as it starts removing
          • Vundo.
          • When completed, it will prompt that it will shutdown your computer,
          • click OK.
          • Turn your computer back on.

          Note: It is possible that VundoFix encountered a file it could not
          remove.
          In this case, VundoFix will run on reboot, simply follow the above
          instructions starting from "Click the Scan for

          Vundo
          button." when VundoFix appears at reboot. ** If you get a warning in your VundoFix log about updating Java, do not do so until I can give you further instructions.

          Please go to your HijackThis here: C:\Program Files\Hijackthis\HijackThis.exe
          Rename HijackThis.exe analyzer.exe

          Please run analyzer (HijackThis) and save a log to be posted in your next reply.
          * Also open HijackThis and click on the "Open the Misc Tools section" button.
          Click on the "Open Uninstall Manager" button
          Click the "Save List" button.

          After you click the "Save List" button, you will be asked where to save the file.
          Pick a place to save it then the list should open in notepad.
          Copy and paste that list here with the contents of C:\vundofix.txt, your report from AVG Anti-Spyware, and a new analyzer (actually HiJackThis) log.

          You may need several replies in order to get all your logs posted. (Just keep replying to yourself until all your logs are included.)

      13 Posts

      April 12th, 2007 16:00

      New HiJack this Log

      Logfile of HijackThis v1.99.1
      Scan saved at 12:45:08 PM, on 4/12/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5346.0005)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\hphmon06.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\ALCWZRD.EXE
      C:\WINDOWS\ALCMTR.EXE
      C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\kernel32.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      C:\WINDOWS\system32\wuauclt.exe
      c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\WINDOWS\system32\DllHost.exe
      C:\Program Files\InterMute\SpySubtract\SpySub.exe
      C:\Program Files\Hijackthis\analyzer.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\ykugramq.dll (file missing)
      O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O2 - BHO: (no name) - {C953C9C7-A86C-4BB1-BAC2-E565E7B3E318} - C:\WINDOWS\system32\ddayx.dll (file missing)
      O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
      O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
      O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Microsoft System Service] taskmgr1.exe
      O4 - HKLM\..\Run: [Microsoft Windows System Kernel] kernel32.exe
      O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\ejrtfcsw.dll",setvm
      O4 - HKLM\..\RunServices: [Microsoft System Service] taskmgr1.exe
      O4 - HKLM\..\RunServices: [Microsoft Windows System Kernel] kernel32.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Microsoft Windows System Kernel] kernel32.exe
      O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Dell\RegistryBooster2\RegistryBooster.exe /S
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
      O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
      O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet3_88.dll' missing
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
      O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
      O20 - Winlogon Notify: efccyyw - C:\WINDOWS\SYSTEM32\efccyyw.dll
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

      13 Posts

      April 12th, 2007 16:00

      I cannot post the AVG report the website says it has prohibited content and it stops the post everytime.

      13 Posts

      April 12th, 2007 16:00

      Here are the logs from the procedures I haven't had any pop ups so I'm sure its worked for th emost part.
       
      The Uninstall log:
       
      ABBYY FineReader OCR Engine for Microtek
      Adobe Anchor Service CS3
      Adobe Asset Services CS3
      Adobe Bridge 1.0
      Adobe Bridge CS3
      Adobe Bridge Start Meeting
      Adobe Camera Raw 4.0
      Adobe CMaps
      Adobe Default Language CS3
      Adobe Device Central CS3
      Adobe ExtendScript Toolkit 2
      Adobe Flash Player 9 ActiveX
      Adobe Fonts All
      Adobe Help Viewer 1.1
      Adobe Illustrator CS2
      Adobe Linguistics CS3
      Adobe PDF Library Files
      Adobe Photoshop CS2
      Adobe Photoshop CS3
      Adobe Photoshop CS3
      Adobe Reader 7.0.9
      Adobe Setup
      Adobe Stock Photos CS3
      Adobe SVG Viewer 3.0
      Adobe Type Support
      Adobe Version Cue CS3 Client
      Adobe WinSoft Linguistics Plugin
      Adobe XMP Panels CS3
      Agere Systems PCI Soft Modem
      Alias DirectConnect 2.0
      AVG Anti-Spyware 7.5
      BitTornado 0.3.17
      BitTorrent 4.22.1
      Blackhawk Striker 2 from Hewlett-Packard Desktops (remove only)
      Blasterball 2 from Hewlett-Packard Desktops (remove only)
      Blasterball 2 Remix from Hewlett-Packard Desktops (remove only)
      Bounce Symphony from Hewlett-Packard Desktops (remove only)
      CC_ccProxyExt
      ccCommon
      ccPxyCore
      Corel Painter Essentials 3
      Corel Painter IX
      CoreVorbis Audio Decoder (remove only)
      Crystal Maze from Hewlett-Packard Desktops (remove only)
      Easy Internet Sign-up
      ffdshow
      FlexiSIGN-PRO 7.6v1
      Google Earth
      Help and Support Additions
      High Definition Audio Driver Package - KB835221
      Hijackthis 1.99.1
      HijackThis 1.99.1
      Hotfix for Windows XP (KB915865)
      HP Deskjet Preloaded Printer Drivers
      HP Image Zone 4.5.3
      HP Image Zone Plus 4.5.3
      HP Organize
      HP Photosmart Cameras 4.0
      HP PSC & OfficeJet 4.0
      HP Software Update
      HPIZplus450
      Intel(R) Graphics Media Accelerator Driver
      IntelliMover Data Transfer Demo
      Internet Explorer 7 Beta 2
      InterVideo DiscLabel
      InterVideo WinDVD Creator
      InterVideo WinDVD Player
      IsoBuster 2.0
      iTunes
      J2SE Runtime Environment 5.0 Update 11
      J2SE Runtime Environment 5.0 Update 6
      J2SE Runtime Environment 5.0 Update 9
      Java 2 Runtime Environment, SE v1.4.2_03
      KBD
      LiveReg (Symantec Corporation)
      LiveUpdate 2.5 (Symantec Corporation)
      Microsoft .NET Framework 1.1
      Microsoft Office Access MUI (English) 2007 (Beta)
      Microsoft Office Excel MUI (English) 2007 (Beta)
      Microsoft Office InfoPath MUI (English) 2007 (Beta)
      Microsoft Office Outlook MUI (English) 2007 (Beta)
      Microsoft Office PowerPoint MUI (English) 2007 (Beta)
      Microsoft Office Professional 2007 (Beta)
      Microsoft Office Professional Edition 2003
      Microsoft Office Professional Plus 2007 (Beta)
      Microsoft Office Proof (English) 2007 (Beta)
      Microsoft Office Proof (French) 2007 (Beta)
      Microsoft Office Proof (Spanish) 2007 (Beta)
      Microsoft Office Publisher MUI (English) 2007 (Beta)
      Microsoft Office Shared MUI (English) 2007 (Beta)
      Microsoft Office Standard Edition 2003
      Microsoft Office Word MUI (English) 2007 (Beta)
      Microsoft Plus! Dancer LE
      Microsoft Plus! Digital Media Edition Installer
      Microsoft Plus! Photo Story 2 LE
      Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348)
      Microsoft Works
      MSN
      MSRedist
      muvee autoProducer 3.5 magicMoments - HPD
      NetMos Multi-IO Controller
      Nimo Codecs Pack v5.0 (Remove Only)
      Norton AntiSpam
      Norton AntiVirus 2005
      Norton Internet Security
      Norton Internet Security
      Norton Internet Security
      Norton Internet Security
      Norton Internet Security
      Norton Internet Security
      Norton Internet Security
      Norton Internet Security
      Norton Internet Security
      Norton Internet Security
      Norton Internet Security 2005 (Symantec Corporation)
      Norton Security Center
      Norton WMI Update
      Norton WMI Update
      openCanvas4.06E Plus
      Orbital from Hewlett-Packard Desktops (remove only)
      Overball from Hewlett-Packard Desktops (remove only)
      PC-Doctor for Windows
      Photosmart 320,370,7400,8100,8400 Series
      Polar Bowler from Hewlett-Packard Desktops (remove only)
      Polar Golfer from Hewlett-Packard Desktops (remove only)
      PS2
      Python 2.2 pywin32 extensions (build 203)
      Python 2.2.3
      QuickTime
      RealPlayer
      Road Ready Streetwise from Hewlett-Packard Desktops (remove only)
      ScanWizard 5
      Sentinel System Driver
      Shrek 2 Ogre Bowler from Hewlett-Packard Desktops (remove only)
      Sonic Express Labeler
      Sonic RecordNow!
      SPBBC
      Spy Sweeper for MSN
      SpySubtract
      Super Granny from Hewlett-Packard Desktops (remove only)
      SymNet
      The Logo Creator v5
      Tradewinds from Hewlett-Packard Desktops (remove only)
      Updates from HP
      Windows Media Format 11 runtime
      Windows Media Format 11 runtime
      Windows Media Player 11
      Windows Media Player 11
      Windows XP Hotfix - KB873339
      Windows XP Hotfix - KB883667
      Windows XP Hotfix - KB885835
      Windows XP Hotfix - KB885836
      Windows XP Hotfix - KB887742
      Windows XP Hotfix - KB888239
      Windows XP Hotfix - KB890175
      Yahoo! Anti-Spy
      Yahoo! Browser Services
      Yahoo! Install Manager
      Yahoo! Internet Mail
      Yahoo! Messenger
      Yahoo! Toolbar
       
      Vundofix.txt

      VundoFix V6.3.19

      Checking Java version...

      Java version is 1.4.2.3
      Old versions of java are exploitable and should be removed.

      Java version is 1.5.0.6
      Old versions of java are exploitable and should be removed.

      Java version is 1.5.0.9
      Old versions of java are exploitable and should be removed.

      Java version is 1.5.0.11

      Scan started at 12:26:33 PM 4/12/2007

      Listing files found while scanning....

      C:\WINDOWS\system32\avcfochn.dll
      C:\WINDOWS\system32\awtsqnn.dll
      C:\WINDOWS\system32\clwocnpn.dll
      C:\WINDOWS\system32\ddayx.dll
      C:\WINDOWS\system32\gebawur.dll
      C:\WINDOWS\system32\iedrppnw.dll
      C:\WINDOWS\system32\nnnmkjk.dll
      C:\WINDOWS\system32\pqtss.bak1
      C:\WINDOWS\system32\rqrppmm.dll
      C:\WINDOWS\system32\sstqp.dll
      C:\WINDOWS\system32\xyadd.bak1
      C:\WINDOWS\system32\xyadd.bak2
      C:\WINDOWS\system32\xyadd.ini
      C:\WINDOWS\system32\xyadd.ini2
      C:\WINDOWS\system32\yayaaaw.dll
      C:\WINDOWS\system32\ykugramq.dll

      Beginning removal...

       Attempting to delete C:\WINDOWS\system32\avcfochn.dll
      C:\WINDOWS\system32\avcfochn.dll Has been deleted!

       Attempting to delete C:\WINDOWS\system32\awtsqnn.dll
      C:\WINDOWS\system32\awtsqnn.dll Could not be deleted.

       Attempting to delete C:\WINDOWS\system32\clwocnpn.dll
      C:\WINDOWS\system32\clwocnpn.dll Has been deleted!

       Attempting to delete C:\WINDOWS\system32\ddayx.dll
      C:\WINDOWS\system32\ddayx.dll Has been deleted!

       Attempting to delete C:\WINDOWS\system32\gebawur.dll
      C:\WINDOWS\system32\gebawur.dll Has been deleted!

       Attempting to delete C:\WINDOWS\system32\iedrppnw.dll
      C:\WINDOWS\system32\iedrppnw.dll Has been deleted!

       Attempting to delete C:\WINDOWS\system32\nnnmkjk.dll
      C:\WINDOWS\system32\nnnmkjk.dll Has been deleted!

       Attempting to delete C:\WINDOWS\system32\pqtss.bak1
      C:\WINDOWS\system32\pqtss.bak1 Has been deleted!

       Attempting to delete C:\WINDOWS\system32\rqrppmm.dll
      C:\WINDOWS\system32\rqrppmm.dll Has been deleted!

       Attempting to delete C:\WINDOWS\system32\sstqp.dll
      C:\WINDOWS\system32\sstqp.dll Has been deleted!

       Attempting to delete C:\WINDOWS\system32\xyadd.bak1
      C:\WINDOWS\system32\xyadd.bak1 Has been deleted!

       Attempting to delete C:\WINDOWS\system32\xyadd.bak2
      C:\WINDOWS\system32\xyadd.bak2 Has been deleted!

       Attempting to delete C:\WINDOWS\system32\xyadd.ini
      C:\WINDOWS\system32\xyadd.ini Has been deleted!

       Attempting to delete C:\WINDOWS\system32\xyadd.ini2
      C:\WINDOWS\system32\xyadd.ini2 Has been deleted!

       Attempting to delete C:\WINDOWS\system32\yayaaaw.dll
      C:\WINDOWS\system32\yayaaaw.dll Has been deleted!

       Attempting to delete C:\WINDOWS\system32\ykugramq.dll
      C:\WINDOWS\system32\ykugramq.dll Has been deleted!

      Performing Repairs to the registry.
      Done!

      VundoFix V6.3.19

      Checking Java version...

      Java version is 1.4.2.3
      Old versions of java are exploitable and should be removed.

      Java version is 1.5.0.6
      Old versions of java are exploitable and should be removed.

      Java version is 1.5.0.9
      Old versions of java are exploitable and should be removed.

      Java version is 1.5.0.11

      Scan started at 12:34:57 PM 4/12/2007

      Listing files found while scanning....

      C:\WINDOWS\system32\awtsqnn.dll

      Beginning removal...

       Attempting to delete C:\WINDOWS\system32\awtsqnn.dll
      C:\WINDOWS\system32\awtsqnn.dll Has been deleted!

      Performing Repairs to the registry.
      Done!

       


      4 Apprentice

       • 

      20.5K Posts

      April 12th, 2007 23:00

      "Prohibited content". Well...that is not much help. We'll do our best with the forum software here, and if that does not work, we'll move you to another website where you can post your AVG report.
      Please make sure the font size in normal. Yours seems to be oversized.

      Please disable Spysweeper so it does not interfere with our changes.
      Open it click >Options over to the left then >program options >Uncheck "load at windows startup".
      Over to the left click "shields" and uncheck all there.
      Uncheck "home page shield".
      Uncheck "automatically restore default without notification".
      Exit the program.

      * Double-click VundoFix.exe to run it again.
      Click Scan for Vundo button.
      * Once the scan is complete, Right Click inside the listbox (white box) and click add more files

      * Copy&Paste the 2 entries below into the top 2 boxes

      C:\WINDOWS\SYSTEM32\efccyyw.dll

      C:\WINDOWS\system32\wyyccfe.*

      * Click Add Files and Click Close Window
      * Click the Remove Vundo button.
      * You will receive a prompt asking if you want to remove the files, click YES
      * Once you click yes, your desktop will go blank as it starts removing Vundo.
      * When completed, it will prompt that it will shutdown your computer, click OK.
      * Turn your computer back on.

      ** If you get a warning in your VundoFix log about updating Java, do not do so until I can give you further instructions.

      Please make sure SpySweeper is still disabled after the reboot!

      Next, launch analyzer (HijackThis) and place a checkmark next to these if they still exist:
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\ykugramq.dll (file missing)
      O2 - BHO: (no name) - {C953C9C7-A86C-4BB1-BAC2-E565E7B3E318} - C:\WINDOWS\system32\ddayx.dll (file missing)
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [Microsoft System Service] taskmgr1.exe
      O4 - HKLM\..\Run: [Microsoft Windows System Kernel] kernel32.exe
      O4 - HKLM\..\Run: [SoundService] rundll32.exe "C:\WINDOWS\system32\ejrtfcsw.dll",setvm
      O4 - HKLM\..\RunServices: [Microsoft System Service] taskmgr1.exe
      O4 - HKLM\..\RunServices: [Microsoft Windows System Kernel] kernel32.exe
      O4 - HKCU\..\Run: [Microsoft Windows System Kernel] kernel32.exe
      020 - Winlogon Notify: efccyyw - C:\WINDOWS\SYSTEM32\efccyyw.dll

      Close all windows except HijackThis and click "Fix Checked".

      Reboot into Safemode:
      Turn on the computer.
      Immediately begin tapping the F8 key.
      Use the arrow keys to highlight Safe Mode and press the Enter key.

      Configure to show all files/folders:
      Go to Start>Search and at the top select Tools>Folder Options
      Select the View tab
      Display the contents of system folders
      Show hidden files and folders
      Uncheck: Hide protected operating system files
      Click on Apply.
      Next go to the side of the Search box and select All files and folders. Go down to More advanced options.
      Be sure the first three boxes are selected:
      Search System folders
      Search Hidden Files and folders
      Search SubFolders

      Delete the specified files if they still exist:

      C:\WINDOWS\System32\ kernel32.exe --file
      C:\WINDOWS\system32\ ejrtfcsw.dll --file
      C:\WINDOWS\SYSTEM32\ efccyyw.dll --file

      This one you will have to search for. Unless you at one time renamed your task manager, delete this one:
      taskmgr1.exe

      Reboot normally.

      Go back and rehide files:
      Start>Search and at the top select Tools>Folder Options
      Select the View tab
      Display the contents of system folders
      Show hidden files and folders
      Check: Hide protected operating system files
      Click on Apply.

      * Please post the contents of C:\vundofix.txt and a new analyzer (HiJackThis) log.

      13 Posts

      April 13th, 2007 10:00

      AVG Anti-Spyware - Scan Report
      ---------------------------------------------------------
       + Created at: 12:16:26 PM 4/12/2007
       + Scan result: 
       
      C:\Program Files\NewDotNet -> Adware.NewDotNet : Cleaned.
      C:\Program Files\NewDotNet\readme.txt -> Adware.NewDotNet : Cleaned.
      C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP234\A0061959.exe -> Adware.NewDotNet : Cleaned.
      C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP242\A0071274.dll -> Adware.NewDotNet : Cleaned.
      C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP234\A0061960.exe -> Not-A-Virus.SpamTool.Win32.Bagle.e : Cleaned.
      C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP234\A0061961.exe -> Not-A-Virus.SpamTool.Win32.Bagle.e : Cleaned.
      C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP234\A0061962.exe -> Not-A-Virus.SpamTool.Win32.Bagle.e : Cleaned.
      C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP234\A0061963.exe -> Not-A-Virus.SpamTool.Win32.Bagle.e : Cleaned.
      C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP234\A0061964.exe -> Not-A-Virus.SpamTool.Win32.Bagle.e : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@buzznet.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@pch.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@eztracks.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@www.abcsearch[1].txt -> TrackingCookie.Abcsearch : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@adbrite[3].txt -> TrackingCookie.Adbrite : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@site.www.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@www.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ad1.clickhype[2].txt -> TrackingCookie.Clickhype : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@mysimon.search.com[1].txt -> TrackingCookie.Com : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wfk4ghczoeo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wfkiejd5kfo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wfkoclcjekp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wfkoqmd5mep.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wfkowoazkdp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wfl4umajaho.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wfl4wldzkep.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wgk4glazcho.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6whkoqgczohq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjk4kpajkbo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjk4qkd5who.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjkogmajigq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjkyekcpsgo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjliencjmgo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjloqnajigq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjlyghaziao.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjny-1jcpwg.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjnycnazodo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjnyokczmgq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjnyqgazmgq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@media.fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@goclick[1].txt -> TrackingCookie.Goclick : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-alt64.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-autodesk.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-digg.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-findlaw.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-foxmovies.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-hollywood.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-hollywoodmedia.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-knightridder.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-legacy.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-maniatv.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-meritsoft.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-oreilly.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-tigerdirect2.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-traderpublishing.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-trilegiant.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-viacom.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-vmixmediainc.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-wacomtechnology.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@komtrack[2].txt -> TrackingCookie.Komtrack : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@linkbuddies[1].txt -> TrackingCookie.Linkbuddies : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@sales.liveperson[3].txt -> TrackingCookie.Liveperson : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@overture[2].txt -> TrackingCookie.Overture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@www.res99[2].txt -> TrackingCookie.Res99 : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@b s.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@anad.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@webstat[2].txt -> TrackingCookie.Web-stat : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.

      ::Report end
      The blocked content were the two letters "b" "s" they go here  "b"s.serving-sys[1].txt

      13 Posts

      April 13th, 2007 13:00

      Here is the latest Vundofix.txt and HiJackThis log
       

      VundoFix V6.3.19
      Checking Java version...
      Java version is 1.4.2.3
      Old versions of java are exploitable and should be removed.
      Java version is 1.5.0.6
      Old versions of java are exploitable and should be removed.
      Java version is 1.5.0.9
      Old versions of java are exploitable and should be removed.
      Java version is 1.5.0.11
      Scan started at 5:04:25 PM 4/12/2007
      Listing files found while scanning....
      C:\WINDOWS\system32\dbibdcjq.dll
      C:\WINDOWS\system32\ijkmp.bak1
      C:\WINDOWS\system32\ijkmp.ini
      C:\WINDOWS\system32\pmkji.dll
      Beginning removal...
       Attempting to delete C:\WINDOWS\system32\dbibdcjq.dll
      C:\WINDOWS\system32\dbibdcjq.dll Has been deleted!
       Attempting to delete C:\WINDOWS\SYSTEM32\efccyyw.dll
      C:\WINDOWS\SYSTEM32\efccyyw.dll Could not be deleted.
       Attempting to delete C:\WINDOWS\system32\ijkmp.bak1
      C:\WINDOWS\system32\ijkmp.bak1 Has been deleted!
       Attempting to delete C:\WINDOWS\system32\ijkmp.ini
      C:\WINDOWS\system32\ijkmp.ini Has been deleted!
       Attempting to delete C:\WINDOWS\system32\pmkji.dll
      C:\WINDOWS\system32\pmkji.dll Has been deleted!
      Performing Repairs to the registry.
      Done!
      VundoFix V6.3.19
      Checking Java version...
      Java version is 1.4.2.3
      Old versions of java are exploitable and should be removed.
      Java version is 1.5.0.6
      Old versions of java are exploitable and should be removed.
      Java version is 1.5.0.9
      Old versions of java are exploitable and should be removed.
      Java version is 1.5.0.11
      Scan started at 8:47:21 AM 4/13/2007
      Listing files found while scanning....
      C:\WINDOWS\system32\nqstv.bak1
      C:\WINDOWS\system32\nqstv.ini
      C:\WINDOWS\system32\vtsqn.dll
      Beginning removal...
       Attempting to delete C:\WINDOWS\SYSTEM32\efccyyw.dll
      C:\WINDOWS\SYSTEM32\efccyyw.dll Has been deleted!
       Attempting to delete C:\WINDOWS\system32\nqstv.bak1
      C:\WINDOWS\system32\nqstv.bak1 Has been deleted!
       Attempting to delete C:\WINDOWS\system32\nqstv.ini
      C:\WINDOWS\system32\nqstv.ini Has been deleted!
       Attempting to delete C:\WINDOWS\system32\vtsqn.dll
      C:\WINDOWS\system32\vtsqn.dll Has been deleted!
      Performing Repairs to the registry.
      Done!

       

      Logfile of HijackThis v1.99.1
      Scan saved at 10:02:02 AM, on 4/13/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5346.0005)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\hphmon06.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\ALCWZRD.EXE
      C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\WINDOWS\system32\DllHost.exe
      C:\Program Files\InterMute\SpySubtract\SpySub.exe
      C:\Program Files\Hijackthis\analyzer.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: (no name) - {856E36A9-A123-418A-A2CC-A05B3BF11AB9} - C:\WINDOWS\system32\ddcyyab.dll
      O2 - BHO: (no name) - {B1EFF46A-CDA6-4CCF-AE56-64AC871BE022} - C:\WINDOWS\system32\pmkji.dll (file missing)
      O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O2 - BHO: (no name) - {C1C450C2-4313-46FD-A830-F28C7BE165E6} - C:\WINDOWS\system32\vtsqn.dll (file missing)
      O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
      O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
      O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
      O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Dell\RegistryBooster2\RegistryBooster.exe /S
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\sslaunch.exe
      O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
      O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
      O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
      O20 - Winlogon Notify: ddcyyab - C:\WINDOWS\SYSTEM32\ddcyyab.dll
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


       
       

      4 Apprentice

       • 

      20.5K Posts

      April 13th, 2007 14:00

      AVG was run at 12:16:26 PM 4/12/2007
      VundoFix was run at 5:04:25 PM 4/12/2007

      Were you connected to the internet between those two scans?

      SpySubtract is now Trendmicro Anti-Spyware. If your copy is outdated and has not been kept updated, uninstall it.
      If you choose to keep it and SpySubtract is running, (It appears to be here.) disable it until we are finished with ALL our fixes and your computer is clean.
      1. Right-click the SpySubtract/Trend Micro Anti-Spyware icon on your taskbar.
      2. Uncheck "Venus Spy Trap: Enable All Monitors".


      In addition, make sure SpySweeper stays disabled until your computer has been fully cleaned. For some reason, it has been enabled again.
      Please repeat the procedure again: Update AVG Anti-Spyware, and run a scan, saving the report. Immediately following the AVG scan, run VundoFix again.


      After that please download Combofix from here: http://download.bleepingcomputer.com/sUBs/combofix.exe
      Or
      http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
      ** Take note that the links are case sensitive

      Save ComboFix to the desktop.

      1. Double click on combo.exe & follow the prompts.

      Note:
      Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
      Do not proceed with the rest of the fix if you fail to run combofix.

      2. When finished, it will produce a logfile located at C:\ComboFix.txt.
      3. Post the contents of that log in your next reply with your report from AVG AS and a new analyzer (HijackThis) log.

      13 Posts

      April 13th, 2007 18:00

      Logfile of HijackThis v1.99.1
      Scan saved at 3:27:58 PM, on 4/13/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5346.0005)
      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\hphmon06.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\ALCWZRD.EXE
      C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\WINDOWS\system32\DllHost.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
      C:\Program Files\FlexiSIGN-PRO 7.6v1\Program\App.exe
      C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Windows Media Player\wmplayer.exe
      C:\Program Files\FlexiSIGN-PRO 7.6v1\Program\App2.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
      C:\Program Files\Microsoft Office\Office12\WINWORD.EXE
      C:\Program Files\Hijackthis\analyzer.exe
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: (no name) - {67C55A8D-E808-4caa-9EA7-F77102DE0BB6} - C:\WINDOWS\system32\ftcckysb.dll
      O2 - BHO: (no name) - {856E36A9-A123-418A-A2CC-A05B3BF11AB9} - C:\WINDOWS\system32\ddcyyab.dll
      O2 - BHO: (no name) - {B1EFF46A-CDA6-4CCF-AE56-64AC871BE022} - C:\WINDOWS\system32\pmkji.dll (file missing)
      O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O2 - BHO: (no name) - {C1C450C2-4313-46FD-A830-F28C7BE165E6} - C:\WINDOWS\system32\vtsqn.dll (file missing)
      O2 - BHO: (no name) - {D0EDFC4A-C8B7-47BE-BF1E-B43ECCB09DA0} - C:\WINDOWS\system32\vtutr.dll
      O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
      O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
      O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
      O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Dell\RegistryBooster2\RegistryBooster.exe /S
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
      O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
      O20 - Winlogon Notify: ddcyyab - C:\WINDOWS\SYSTEM32\ddcyyab.dll
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: vtutr - C:\WINDOWS\system32\vtutr.dll
      O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
       

      13 Posts

      April 13th, 2007 18:00

      I have DSL so i'd assume I was connected to the internet. The Spysweeper should be disabled I've unchecked everything in it and turned it off. Here are the reports of the newest procedures.
       
      Combofix.txt
       
      "HP_Owner" - 06-04-13 13:27:27    Service Pack 2
      ComboFix 07-04-05 - Running from: "C:\Documents and Settings\HP_Owner\Desktop"

      (((((((((((((((((((((((((((((((   Files Created from 2006-03-13 to 2006-04-13  ))))))))))))))))))))))))))))))))))

      2006-04-27 11:57 6,192 --a--c--- C:\WINDOWS\system\msemx32R.dll
      2006-04-25 20:41 32,528 --a--c--- C:\WINDOWS\system32\FM20ENU.DLL
      2006-04-25 20:41 1,190,152 --a--c--- C:\WINDOWS\system32\FM20.DLL
      2006-04-14 08:23   d-------- C:\DOCUME~1\HP_Owner\APPLIC~1\Newsbin
      2006-04-13 16:12   d--hs---- C:\WINDOWS\ftpcache
      2006-04-13 12:32 123,972 --a------ C:\WINDOWS\system32\osonidrx.dll
      2006-04-11 14:30 93,752 -----c--- C:\WINDOWS\system32\WUDFCoinstaller.dll
      2006-04-11 14:29 87,808 -----c--- C:\WINDOWS\system32\drivers\WudfRd.sys
      2006-04-11 14:27 304,640 -----c--- C:\WINDOWS\system32\WUDFx.dll
      2006-04-11 14:27 130,048 -----c--- C:\WINDOWS\system32\WudfHost.exe
      2006-04-11 14:26 82,944 -----c--- C:\WINDOWS\system32\drivers\WudfPf.sys
      2006-04-11 14:26 54,272 --------- C:\WINDOWS\system32\WudfSvc.dll
      2006-04-11 14:26 158,208 --------- C:\WINDOWS\system32\WudfPlatform.dll
      2006-03-20 01:06 23,552 -----c--- C:\WINDOWS\system32\idndl.dll
      2006-03-20 01:06 20,480 --------- C:\WINDOWS\system32\normaliz.dll
      2006-03-15 18:00   d-------- C:\temp
       
       
      ((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))

      2007-03-27 10:35 76560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
      2006-09-05 12:03 3968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
      2006-05-09 20:58 40704 --a------ C:\WINDOWS\system32\drivers\wpdusb.sys
      2006-04-28 01:51 29968 --a------ C:\WINDOWS\system32\mdimon.dll
      2006-04-13 23:29 156160 --a------ C:\WINDOWS\system32\msls31.dll
      2006-04-13 23:21 78336 --a--c--- C:\WINDOWS\system32\ieencode.dll
      2006-04-13 23:20 32256 --a--c--- C:\WINDOWS\system32\licmgr10.dll
      2006-04-13 23:19 16384 --a--c--- C:\WINDOWS\system32\corpol.dll
      2006-04-13 23:17 73728 --a--c--- C:\WINDOWS\system32\admparse.dll
      2006-04-13 23:16 46080 --a--c--- C:\WINDOWS\system32\iesetup.dll
      2006-04-13 23:16 406016 --a------ C:\WINDOWS\system32\vbscript.dll
      2006-04-13 23:14 34816 --a------ C:\WINDOWS\system32\imgutil.dll
      2006-04-13 23:10 41472 --a------ C:\WINDOWS\system32\mshta.exe
      2006-04-13 22:45 48640 --a--c--- C:\WINDOWS\system32\mshtmler.dll
      2006-04-13 12:32 1370674 ---hs---- C:\WINDOWS\system32\rtutv.bak1
      2006-03-24 16:57 -------- d-------- C:\Program Files\easy internet signup
      2006-03-20 01:06 22752 --a--c--- C:\WINDOWS\system32\spupdsvc.exe
      2006-03-20 01:03 65536 --a--c--- C:\WINDOWS\system32\jgsh400.dll
      2006-03-20 01:03 45568 --a--c--- C:\WINDOWS\system32\jgsd400.dll
      2006-03-20 01:03 44544 --a--c--- C:\WINDOWS\system32\jgaw400.dll
      2006-03-20 01:03 35840 --a--c--- C:\WINDOWS\system32\jgmd400.dll
      2006-03-07 10:16 -------- d-------- C:\Program Files\webroot
      2006-03-07 09:44 -------- d-------- C:\Program Files\ffdshow
      2006-03-07 09:33 -------- d-------- C:\Program Files\nimocodec pack
      2006-03-03 09:29 -------- d-------- C:\Program Files\flexlm
      2006-03-02 08:38 191488 --a--c--- C:\WINDOWS\system32\hlvdd.dll
      2006-02-28 13:41 61440 --a------ C:\WINDOWS\system32\dns-sd.exe
      2006-02-28 13:41 53248 --a------ C:\WINDOWS\system32\dnssd.dll
      2006-02-26 10:20 5120 --a------ C:\WINDOWS\system32\ff_vfw.dll
      2006-02-23 10:48 78336 --a--c--- C:\WINDOWS\system32\drivers\ssi.sys
      2006-01-23 16:57 6656 --a--c--- C:\WINDOWS\system32\haspvdd.dll
      2006-01-23 16:57 383 --a--c--- C:\WINDOWS\system32\haspdos.sys
      2006-01-23 16:42 3645 --a--c--- C:\WINDOWS\viassary-hp.reg
       
       
      ((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
      *Note* empty entries & legit default entries are not shown
      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
      "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
      "Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
      "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
      "Uniblue Registry Booster2"="C:\\Dell\\RegistryBooster2\\RegistryBooster.exe /S"
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
      "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
      "hpsysdrv"="c:\\windows\\system\\hpsysdrv.exe"
      "High Definition Audio Property Page Shortcut"="HDAudPropShortcut.exe"
      "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
      "AGRSMMSG"="AGRSMMSG.exe"
      "HPHUPD06"="c:\\Program Files\\HP\\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\\hphupd06.exe"
      "HPHmon06"="C:\\WINDOWS\\system32\\hphmon06.exe"
      "KBD"="C:\\HP\\KBD\\KBD.EXE"
      "TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\"  -osboot"
      "Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
      "ccApp"="\"c:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
      "IS CfgWiz"="c:\\Program Files\\Norton Internet Security\\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE \"REBOOT\""
      "SSC_UserPrompt"="c:\\Program Files\\Common Files\\Symantec Shared\\Security Center\\UsrPrmpt.exe"
      "PS2"="C:\\WINDOWS\\system32\\ps2.exe"
      "SoundMan"="SOUNDMAN.EXE"
      "AlcWzrd"="ALCWZRD.EXE"
      "LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
      "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
      "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
      "Installed"="1"
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
      "NoChange"="1"
      "Installed"="1"
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
      "Installed"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
      "{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache daemon"
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
      "{182B90A3-F372-438A-800C-6814B4DE417B}"=""
      "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
      "{856E36A9-A123-418A-A2CC-A05B3BF11AB9}"=""
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
      "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
      HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcyyab
      HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtutr
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
      "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
      HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
         Authentication Packages REG_MULTI_SZ    msv1_0\0\0
         Security Packages REG_MULTI_SZ    kerberos\0msv1_0\0schannel\0wdigest\0\0
         Notification Packages REG_MULTI_SZ    scecli\0\0
      [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
      HTTPFilter REG_MULTI_SZ    HTTPFilter\0\0
      LocalService REG_MULTI_SZ    Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
      NetworkService REG_MULTI_SZ    DnsCache\0\0
      DcomLaunch REG_MULTI_SZ    DcomLaunch\0TermService\0\0
      rpcss REG_MULTI_SZ    RpcSs\0\0
      imgsvc REG_MULTI_SZ    StiSvc\0\0
      termsvcs REG_MULTI_SZ    TermService\0\0
      WudfServiceGroup REG_MULTI_SZ    WUDFSvc\0\0

      [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K]
      Shell\AutoRun\command K:\LaunchU3.exe -a
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{946850c5-1e27-11d9-baf0-806d6172696f}]
      Shell\AutoRun\command D:\setup.exe
      [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c26f9522-8c4e-11da-b438-806d6172696f}]
      Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

      Contents of the 'Scheduled Tasks' folder
      C:\WINDOWS\tasks\Symantec NetDetect.job

      ********************************************************************
      catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
      http://www.gmer.net
      scanning hidden processes ...
      scanning hidden services ...
      scanning hidden autostart entries ...
      scanning hidden files ...
      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0
      ********************************************************************
      Completion time: 06-04-13 13:32:31
      C:\ComboFix-quarantined-files.txt ... 06-04-13 13:32
       
       

      VundoFix V6.3.19
      Checking Java version...
      Java version is 1.4.2.3
      Old versions of java are exploitable and should be removed.
      Java version is 1.5.0.6
      Old versions of java are exploitable and should be removed.
      Java version is 1.5.0.9
      Old versions of java are exploitable and should be removed.
      Java version is 1.5.0.11
      Scan started at 1:16:32 PM 4/13/2006
      Listing files found while scanning....
      C:\WINDOWS\system32\darbmoev.dll
      C:\WINDOWS\system32\ftcckysb.dll
      C:\WINDOWS\system32\osonidrx.dll
      C:\WINDOWS\system32\rtutv.bak1
      C:\WINDOWS\system32\rtutv.ini
      C:\WINDOWS\system32\vtutr.dll
       
      ---------------------------------------------------------
      AVG Anti-Spyware - Scan Report
      ---------------------------------------------------------
       + Created at: 1:15:49 PM 4/13/2006
       + Scan result: 
       
      HKU\S-1-5-21-113728092-2515961002-1613950074-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined).
      C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP242\A0071421.exe -> Backdoor.VanBot.cd : Cleaned with backup (quarantined).
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@buzznet.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@www.adobe[1].txt -> TrackingCookie.Adobe : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ads.cnn[1].txt -> TrackingCookie.Cnn : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@dealtime[2].txt -> TrackingCookie.Dealtime : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@stat.dealtime[2].txt -> TrackingCookie.Dealtime : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@e-2dj6wjlyajcpcao.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@hit.gemius[1].txt -> TrackingCookie.Gemius : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ehg-maniatv.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@beta.search.live[1].txt -> TrackingCookie.Live : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@search.live[2].txt -> TrackingCookie.Live : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ssl-hints.netflame[3].txt -> TrackingCookie.Netflame : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
      C:\Documents and Settings\HP_Owner\Cookies\hp_owner@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
      C:\photoshop_cs3_keygen.zip/photoshop_cs3_keygen/photoshop_cs3_keygen.exe/1.exe -> Trojan.Agent : Cleaned with backup (quarantined).
      C:\System Volume Information\_restore{DDE3EB95-4B24-44D8-AD38-1F974B96C2F0}\RP234\A0061822.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
      C:\Documents and Settings\HP_Owner\My Documents\AdobeStockPhotos\Previous Searches\FOLER\Corel Painter Essentials 3&Corel Painter 9.5.rar/Corel Painter Essentials 3&Corel Painter 9.5\Corel Painter 9.5.zip/Cracked/Patch.exe -> Trojan.Crack.b : Cleaned with backup (quarantined).
      C:\Program Files\Corel\Corel Painter IX\Patch.exe -> Trojan.Crack.b : Cleaned with backup (quarantined).

      ::Report end

      4 Apprentice

       • 

      20.5K Posts

      April 13th, 2007 23:00

      Please print these instructions. It is very important that you follow them exactly.

      Did you not completely copy all of the VundoFix report, or did it not finish?

      This appears in your Running processes:
      C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
      If Spysweeper cannot be disabled, you may have to uninstall SpySweeper for now in order to clean this infection.

      Regarding this one also in your Running Process:
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

      QUOTE:
      # In Services, click the "Extended tab" and scroll down the list to find AVG anti-spyware guard.
      # When you find the guard service, double-click on it.
      # In the Properties Window > General Tab that opens, click the "Stop" button.
      # From the drop-down menu next to "Startup Type", click on "Manual".
      # Now click "Apply", then "OK" and close the Services window


      Now let's try this:
      1. Please download The Avenger by Swandog46 from here:

      http://swandog46.geekstogo.com/avenger.zip

      Download it to your Desktop.

      * Click on Avenger.zip to open the file
      * Extract avenger.exe to your desktop


      2. Copy ALL the text in bold contained between the dotted lines below to your Clipboard using and Ctrl + c (or Edit, Copy):
      Do NOT copy the dotted lines.

      --------------------------

      Registry keys to delete:

      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67C55A8D-E808-4caa-9EA7-F77102DE0BB6}
      HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67C55A8D-E808-4caa-9EA7-F77102DE0BB6}
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{856E36A9-A123-418A-A2CC-A05B3BF11AB9}
      HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{856E36A9-A123-418A-A2CC-A05B3BF11AB9}
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcyyab
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BD6CD737-34E1-4864-8697-83EC081F1989}
      HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD6CD737-34E1-4864-8697-83EC081F1989}
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtutr


      Files to Delete:

      C:\WINDOWS\system32\ftcckysb.dll
      C:\Windows\System32\ftcckysb.bak
      C:\Windows\System32\ftcckysb.ini
      C:\Windows\System32\bsykcctf.bak
      C:\Windows\System32\bsykcctf.bak1
      C:\Windows\System32\bsykcctf.bak2
      C:\Windows\System32\bsykcctf.ini
      C:\Windows\System32\bsykcctf.ini2
      C:\Windows\System32\bsykcctf.tmp
      C:\Windows\System32\bsykcctf.tmp1
      C:\Windows\System32\bsykcctf.tmp2
      C:\Windows\System32\ddcyyab.dll
      C:\Windows\System32\ddcyyab.bak
      C:\Windows\System32\ddcyyab.ini
      C:\Windows\System32\bayycdd.bak
      C:\Windows\System32\bayycdd.bak1
      C:\Windows\System32\bayycdd.bak2
      C:\Windows\System32\bayycdd.ini
      C:\Windows\System32\bayycdd.ini2
      C:\Windows\System32\bayycdd.tmp
      C:\Windows\System32\bayycdd.tmp1
      C:\Windows\System32\bayycdd.tmp2
      C:\WINDOWS\system32\vtutr.dll
      C:\Windows\System32\vtutr.bak
      C:\Windows\System32\vtutr.ini
      C:\Windows\System32\rtutv.bak
      C:\Windows\System32\rtutv.bak1
      C:\Windows\System32\rtutv.bak2
      C:\Windows\System32\rtutv.ini
      C:\Windows\System32\rtutv.ini2
      C:\Windows\System32\rtutv.tmp
      C:\Windows\System32\rtutv.tmp1
      C:\Windows\System32\rtutv.tmp2


      ------------------


      Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

      3. Now, start The Avenger program by clicking on its icon on your desktop.

      * Under "Script file to execute" choose "Input Script Manually".
      * Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
      * Paste the text copied to clipboard into this window
      * Click Done
      * Now click on the Green Light to begin execution of the script
      * Answer "Yes" twice when prompted.



      4. The Avenger will automatically do the following:

      * Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
      * On reboot, briefly open a black command window on your desktop, this is normal.
      * After the restart, create a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
      * The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.


      Please launch HijackThis and place a checkmark next to these IF they still exist:

      O2 - BHO: (no name) - {B1EFF46A-CDA6-4CCF-AE56-64AC871BE022} - C:\WINDOWS\system32\pmkji.dll (file missing)
      O2 - BHO: (no name) - {C1C450C2-4313-46FD-A830-F28C7BE165E6} - C:\WINDOWS\system32\vtsqn.dll (file missing)


      Close all windows except HijackThis and click "Fix Checked".
      Reboot.

      Please copy/paste the content of avenger.txt into your reply along with a fresh HJT log by using Add/Reply and Submit Post.

      Message Edited by Bugbatter on 04-13-2007 08:04 PM

      13 Posts

      April 16th, 2007 10:00

      I uninstalled the Spysweeper so it shouldn't be an issue this time.
       
      However I was alittle confused about the Avenger the instructions said it would reboot the comp. twice, it only rebooted once.
       
      Logfile of The Avenger version 1, by Swandog46
      Running from registry key:
      \Registry\Machine\System\CurrentControlSet\Services\yprysqcy
      *******************
      Script file located at: \??\C:\WINDOWS\gegqbnhl.txt
      Script file opened successfully.
      Script file read successfully
      Backups directory opened successfully at C:\Avenger
      *******************
      Beginning to process script file:
      File C:\WINDOWS\system32\ftcckysb.dll deleted successfully.

      File C:\Windows\System32\ftcckysb.bak not found!
      Deletion of file C:\Windows\System32\ftcckysb.bak failed!
      Could not process line:
      C:\Windows\System32\ftcckysb.bak
      Status: 0xc0000034
       
      File C:\Windows\System32\ftcckysb.ini not found!
      Deletion of file C:\Windows\System32\ftcckysb.ini failed!
      Could not process line:
      C:\Windows\System32\ftcckysb.ini
      Status: 0xc0000034
       
      File C:\Windows\System32\bsykcctf.bak not found!
      Deletion of file C:\Windows\System32\bsykcctf.bak failed!
      Could not process line:
      C:\Windows\System32\bsykcctf.bak
      Status: 0xc0000034
       
      File C:\Windows\System32\bsykcctf.bak1 not found!
      Deletion of file C:\Windows\System32\bsykcctf.bak1 failed!
      Could not process line:
      C:\Windows\System32\bsykcctf.bak1
      Status: 0xc0000034
       
      File C:\Windows\System32\bsykcctf.bak2 not found!
      Deletion of file C:\Windows\System32\bsykcctf.bak2 failed!
      Could not process line:
      C:\Windows\System32\bsykcctf.bak2
      Status: 0xc0000034
       
      File C:\Windows\System32\bsykcctf.ini not found!
      Deletion of file C:\Windows\System32\bsykcctf.ini failed!
      Could not process line:
      C:\Windows\System32\bsykcctf.ini
      Status: 0xc0000034
       
      File C:\Windows\System32\bsykcctf.ini2 not found!
      Deletion of file C:\Windows\System32\bsykcctf.ini2 failed!
      Could not process line:
      C:\Windows\System32\bsykcctf.ini2
      Status: 0xc0000034
       
      File C:\Windows\System32\bsykcctf.tmp not found!
      Deletion of file C:\Windows\System32\bsykcctf.tmp failed!
      Could not process line:
      C:\Windows\System32\bsykcctf.tmp
      Status: 0xc0000034
       
      File C:\Windows\System32\bsykcctf.tmp1 not found!
      Deletion of file C:\Windows\System32\bsykcctf.tmp1 failed!
      Could not process line:
      C:\Windows\System32\bsykcctf.tmp1
      Status: 0xc0000034
       
      File C:\Windows\System32\bsykcctf.tmp2 not found!
      Deletion of file C:\Windows\System32\bsykcctf.tmp2 failed!
      Could not process line:
      C:\Windows\System32\bsykcctf.tmp2
      Status: 0xc0000034
      File C:\Windows\System32\ddcyyab.dll deleted successfully.

      File C:\Windows\System32\ddcyyab.bak not found!
      Deletion of file C:\Windows\System32\ddcyyab.bak failed!
      Could not process line:
      C:\Windows\System32\ddcyyab.bak
      Status: 0xc0000034
       
      File C:\Windows\System32\ddcyyab.ini not found!
      Deletion of file C:\Windows\System32\ddcyyab.ini failed!
      Could not process line:
      C:\Windows\System32\ddcyyab.ini
      Status: 0xc0000034
       
      File C:\Windows\System32\bayycdd.bak not found!
      Deletion of file C:\Windows\System32\bayycdd.bak failed!
      Could not process line:
      C:\Windows\System32\bayycdd.bak
      Status: 0xc0000034
       
      File C:\Windows\System32\bayycdd.bak1 not found!
      Deletion of file C:\Windows\System32\bayycdd.bak1 failed!
      Could not process line:
      C:\Windows\System32\bayycdd.bak1
      Status: 0xc0000034
       
      File C:\Windows\System32\bayycdd.bak2 not found!
      Deletion of file C:\Windows\System32\bayycdd.bak2 failed!
      Could not process line:
      C:\Windows\System32\bayycdd.bak2
      Status: 0xc0000034
       
      File C:\Windows\System32\bayycdd.ini not found!
      Deletion of file C:\Windows\System32\bayycdd.ini failed!
      Could not process line:
      C:\Windows\System32\bayycdd.ini
      Status: 0xc0000034
       
      File C:\Windows\System32\bayycdd.ini2 not found!
      Deletion of file C:\Windows\System32\bayycdd.ini2 failed!
      Could not process line:
      C:\Windows\System32\bayycdd.ini2
      Status: 0xc0000034
       
      File C:\Windows\System32\bayycdd.tmp not found!
      Deletion of file C:\Windows\System32\bayycdd.tmp failed!
      Could not process line:
      C:\Windows\System32\bayycdd.tmp
      Status: 0xc0000034
       
      File C:\Windows\System32\bayycdd.tmp1 not found!
      Deletion of file C:\Windows\System32\bayycdd.tmp1 failed!
      Could not process line:
      C:\Windows\System32\bayycdd.tmp1
      Status: 0xc0000034
       
      File C:\Windows\System32\bayycdd.tmp2 not found!
      Deletion of file C:\Windows\System32\bayycdd.tmp2 failed!
      Could not process line:
      C:\Windows\System32\bayycdd.tmp2
      Status: 0xc0000034
      File C:\WINDOWS\system32\vtutr.dll deleted successfully.

      File C:\Windows\System32\vtutr.bak not found!
      Deletion of file C:\Windows\System32\vtutr.bak failed!
      Could not process line:
      C:\Windows\System32\vtutr.bak
      Status: 0xc0000034
       
      File C:\Windows\System32\vtutr.ini not found!
      Deletion of file C:\Windows\System32\vtutr.ini failed!
      Could not process line:
      C:\Windows\System32\vtutr.ini
      Status: 0xc0000034
       
      File C:\Windows\System32\rtutv.bak not found!
      Deletion of file C:\Windows\System32\rtutv.bak failed!
      Could not process line:
      C:\Windows\System32\rtutv.bak
      Status: 0xc0000034
      File C:\Windows\System32\rtutv.bak1 deleted successfully.
      File C:\Windows\System32\rtutv.bak2 deleted successfully.
      File C:\Windows\System32\rtutv.ini deleted successfully.

      File C:\Windows\System32\rtutv.ini2 not found!
      Deletion of file C:\Windows\System32\rtutv.ini2 failed!
      Could not process line:
      C:\Windows\System32\rtutv.ini2
      Status: 0xc0000034
       
      File C:\Windows\System32\rtutv.tmp not found!
      Deletion of file C:\Windows\System32\rtutv.tmp failed!
      Could not process line:
      C:\Windows\System32\rtutv.tmp
      Status: 0xc0000034
       
      File C:\Windows\System32\rtutv.tmp1 not found!
      Deletion of file C:\Windows\System32\rtutv.tmp1 failed!
      Could not process line:
      C:\Windows\System32\rtutv.tmp1
      Status: 0xc0000034
       
      File C:\Windows\System32\rtutv.tmp2 not found!
      Deletion of file C:\Windows\System32\rtutv.tmp2 failed!
      Could not process line:
      C:\Windows\System32\rtutv.tmp2
      Status: 0xc0000034
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67C55A8D-E808-4caa-9EA7-F77102DE0BB6} deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67C55A8D-E808-4caa-9EA7-F77102DE0BB6} deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{856E36A9-A123-418A-A2CC-A05B3BF11AB9} deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{856E36A9-A123-418A-A2CC-A05B3BF11AB9} deleted successfully.
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ddcyyab deleted successfully.

      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BD6CD737-34E1-4864-8697-83EC081F1989} not found!
      Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BD6CD737-34E1-4864-8697-83EC081F1989} failed!
      Status: 0xc0000034
       
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD6CD737-34E1-4864-8697-83EC081F1989} not found!
      Deletion of registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BD6CD737-34E1-4864-8697-83EC081F1989} failed!
      Status: 0xc0000034
      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\vtutr deleted successfully.
      Completed script processing.
      *******************
      Finished!  Terminate.
       
       

      13 Posts

      April 16th, 2007 10:00

      Logfile of HijackThis v1.99.1
      Scan saved at 4:56:26 PM, on 4/13/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5346.0005)
      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\svchost.exe
      c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\hphmon06.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\ALCWZRD.EXE
      C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      C:\WINDOWS\system32\wuauclt.exe
      c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
      C:\Program Files\Hijackthis\analyzer.exe
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53056C53-5720-4DEC-8CE8-23FAE383BB20} - C:\WINDOWS\system32\vtutr.dll (file missing)
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
      O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
      O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
      O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Dell\RegistryBooster2\RegistryBooster.exe /S
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\npjpi150_11.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
      O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
       

      4 Apprentice

       • 

      20.5K Posts

      April 16th, 2007 15:00

      That looks better. :) Hopefully we killed what was regenerating that infection each time you went back online.
      There is just a bit more to do.

      Please launch analyzer (Hijackthis) and place a checkmark next to these:
      O2 - BHO: (no name) - {53056C53-5720-4DEC-8CE8-23FAE383BB20} - C:\WINDOWS\system32\vtutr.dll (file missing)
      O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)


      If you are not using a proxy, you can check this one. If you are using a proxy leave it alone. If you are unsure, leave it alone and please consult your ISP.
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

      This is optional to fix depending on your needs. It does use a small amount of resources. It is the Application Scheduler installed along with RealOne_Player. Once installed, it runs independently of RealOne Player. You can fix this with HJT, but you will also need to set it not to load in RealPlayer itself to keep it from resetting itself.
      To disable "tkbell.exe" in the new version (1) Start RealOne Player (2) Tools -> Preferences (3) Automatic services in the Categories pane (4) Uncheck all options and then OK.
      In HijackThis: O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

      Close all windows except analyzer (HijackThis) and click "Fix Checked".

      Reboot.

      Download and scan each user profile with CCleaner: This is a good utility to keep and user regularly.
      http://www.ccleaner.com/downloadbuilds.asp
      ** Select to download the BASIC version.
      1. Before first use, select Options > Advanced and UNCHECK
      " Only delete files in Windows Temp folder older than 48 hours"
      2. Then select the items you wish to clean up.
      In the Windows Tab:
      • Clean all entries in the "Internet Explorer" section.
      • Clean all the entries in the "Windows Explorer" section.
      • Clean all entries in the "System" section.
      • Clean all entries in the "Advanced" section.
      • Clean any others that you choose.
      In the Applications Tab:
      • Clean all in the Firefox/Mozilla section if you use it.
      • Clean all in the Opera section if you use it.
      • Clean Sun Java in the Internet Section.
      • Clean any others that you choose.
      3. Click the " Run Cleaner" button.
      4. A pop up box will appear advising this process will permanently delete files from your system.
      5. Click " OK" and it will scan and clean your system.
      6. Click " exit" when done.
      REBOOT.

      Now that you are clean, we need to find a more secure version of Java. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version Java components and update.

      Updating Java:
      • Download the latest version of Java Runtime Environment (JRE) 6.
      • Scroll down to where it says "Java Runtime Environment (JRE) 6u1 allows end-users to run Java applications".
      • Click the "Download" button to the right.
      • Check the box that says: "Accept License Agreement".
      • The page will refresh.
      • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
      • Close any programs you may have running - especially your web browser.
      • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
      • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
      • Click the Remove or Change/Remove button.
      • Repeat as many times as necessary to remove each Java versions.

      • Reboot your computer once all Java components are removed.
      • Then from your desktop double-click on jre-6u1-windows-i586-p.exe to install the newest version.

      Official JAVA Installation Instructions if needed.

      After that, please post a fresh analyzer log for final review.

      Thanks. :)

      Message Edited by Bugbatter on 04-16-2007 12:12 PM

      13 Posts

      April 18th, 2007 11:00

      Here is the new analyzer log. I have not had any problems and I want to thank you that stuff was slowing down my work! So thank you, I might expand my IT knowledge after this, this stuff is interesting.
       
      Logfile of HijackThis v1.99.1
      Scan saved at 6:06:59 PM, on 4/18/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5346.0005)
      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\svchost.exe
      c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\system32\hphmon06.exe
      C:\HP\KBD\KBD.EXE
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\ALCWZRD.EXE
      C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\Program Files\Hijackthis\analyzer.exe
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
      O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
      O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Norton Internet Security\cfgwiz.exe /GUID {257BBC47-1B26-432e-9F84-188603799DD3} /MODE CfgWiz /CMDLINE "REBOOT"
      O4 - HKLM\..\Run: [SSC_UserPrompt] c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
      O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Uniblue Registry Booster2] C:\Dell\RegistryBooster2\RegistryBooster.exe /S
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
      O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Add To HP Organize... - C:\PROGRA~1\HEWLET~1\HPORGA~1\bin/module.main/favorites\ie_add_to.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesuite.net/dlmanager/versions/activex/dlm-activex-2.0.5.1.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
      O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IS Service (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
      O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
       
      No Events found!

      Top