Unsolved

This post is more than 5 years old

36 Posts

2862

March 17th, 2007 21:00

HELP! Regedit doesn't work or my task manager and Limewire keeps re-starting

HELP! Regedit doesn't work or my task manager and Limewire keeps re-starting. Norton picks up nothing. Turned off system restore did a reboot, ran a scan and nothing
 
Logfile of HijackThis v1.99.1
Scan saved at 4:01:18 PM, on 3/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\dlcqcoms.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WinRamTurbo XP\WinRamTurboXP.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\limewire\limewire.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Kirk\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Surf Surf Surf
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinRamTurbo] C:\Program Files\WinRamTurbo XP\WinRamTurboXP.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [sitewipelongjump] C:\Documents and Settings\All Users\Application Data\purecoalsitewipe\OnceBook.exe
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ref online] C:\DOCUME~1\Kirk\APPLIC~1\DARTBI~1\AtomSlow.exe
O4 - Global Startup: svchost.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm231YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/MyMailStationeryFWBInitialSetup1.0.0.15.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.media-motor.net/cabs/download.cab
O16 - DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} (ERPageAddin Class) - https://eroom.entergy.com/eRoomSetup/client.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1165292709687
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

10.4K Posts

March 18th, 2007 00:00

kbelmon

Please Download NoLop to your desktop from one of the links below...
Link 1
Link 2
Link 3

  • First close any other programs you have running as this will require a reboot
  • Double click NoLop.exe to run it
  • Now click the button labelled "Search and Destroy" <>
  • When scanning is finished you will be prompted to reboot only if infected, Click OK
  • Now click the "REBOOT" Button.
  • A Message should popup from NoLop. If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log along with a fresh HijackThis log
--If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.--

bamajim   Graduate of MRU

 


Message Edited by bamajim on 03-17-2007 08:42 PM

36 Posts

March 18th, 2007 03:00

2nd part of Hijack log again
 
O18 - Protocol: bw+0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: dlcq_device -   - C:\WINDOWS\system32\dlcqcoms.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

36 Posts

March 18th, 2007 03:00

Trie the NoLop and it didn't find anything...??? What else can I do
 
Logfile of HijackThis v1.99.1
Scan saved at 11:00:50 PM, on 3/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\dlcqcoms.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WinRamTurbo XP\WinRamTurboXP.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\limewire\limewire.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Kirk\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Surf Surf Surf
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinRamTurbo] C:\Program Files\WinRamTurbo XP\WinRamTurboXP.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [sitewipelongjump] C:\Documents and Settings\All Users\Application Data\purecoalsitewipe\OnceBook.exe
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ref online] C:\DOCUME~1\Kirk\APPLIC~1\DARTBI~1\AtomSlow.exe
O4 - Global Startup: svchost.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm231YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/MyMailStationeryFWBInitialSetup1.0.0.15.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.media-motor.net/cabs/download.cab
O16 - DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} (ERPageAddin Class) - https://eroom.entergy.com/eRoomSetup/client.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1165292709687
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

10.4K Posts

March 19th, 2007 00:00

kbelmon

That's o.k. we need to check and fix in sequence

1.
Rerun Hijackthis (scan only) and place checks beside the following entries
  • R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
    O4 - HKLM\..\Run: [sitewipelongjump] C:\Documents and Settings\All Users\Application Data\purecoalsitewipe\OnceBook.exe
    O4 - HKCU\..\Run: [ref online] C:\DOCUME~1\Kirk\APPLIC~1\DARTBI~1\AtomSlow.exe
    O4 - Global Startup: svchost.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.media-motor.net/cabs/download.cab
Close all other open windows except Hijackthis and Select " Fix checked"

2. Using Windows Explorer
  • (Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
Locate and Delete the following folders
  • C:\Documents and Settings\All Users\Application Data\purecoalsitewipe
    C:\DOCUME~1\Kirk\APPLIC~1\DARTBI~1
Close windows explorer->>Reboot your PC->>Rerun Hijackthis and post a fresh Hijackthis log
 
bamajim   Graduate of MRU
 

36 Posts

March 19th, 2007 16:00

Ok this is working, got my task manager back, my ram has increased, Limewire doesn't re-start, regedit is working now!!! WOO HOOO!!!
 
Is there anything else in here that looks suspect?
 
 
Logfile of HijackThis v1.99.1
Scan saved at 12:42:55 PM, on 3/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\dlcqcoms.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\WinRamTurbo XP\WinRamTurboXP.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\LVComsX.exe
C:\Documents and Settings\Kirk\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Surf Surf Surf
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [WinRamTurbo] C:\Program Files\WinRamTurbo XP\WinRamTurboXP.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ref online] C:\DOCUME~1\Kirk\APPLIC~1\DARTBI~1\AtomSlow.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm231YYUS
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/MyMailStationeryFWBInitialSetup1.0.0.15.cab
O16 - DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} (ERPageAddin Class) - https://eroom.entergy.com/eRoomSetup/client.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1165292709687
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab

36 Posts

March 19th, 2007 16:00

Hijack log Part 2
 
Sure do have a lot of these 018s
 
O18 - Protocol: bw+0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {6C7798D4-6E66-46C4-8CC3-6CFF970FFAEC} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: dlcq_device -   - C:\WINDOWS\system32\dlcqcoms.exe
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

10.4K Posts

March 19th, 2007 17:00

kbelmon

Glad to hear it. As far as the 018 lines, they are created by Logitech Desktop Manager. Which is a program most people do not use. If you do not use it, you can go to Add/Remove programs and  uninstall it.
 
Then Rerun Hijackthis and place checks beside the 018 lines and Select " Fix checked"

Go here and Download AVG Anti-Spyware
( 30 day free trial version) Save it to Your Desktop
 
Double Click AVG Anti-Spyware-setup
(It will create its own folder)
Once the program starts You will be at the Status menu
Under "Your computers Security"
Click Update now (next to last update)
After the update loads
Under Automatic updates Uncheck download and install updates automatically(recommended)
(you can always select maual updates the next day)

At the top toolbar Click Scanner Then the settings tab
  • Under How to act? Set default action for detected malwareTo Quarantine
    Under how to scan All boxes should be checked
    Under Possibly unwanted software All boxes should be checked
    Under reports Select Automatically generate report after every scan
    Uncheck Only if threats were found
    Under what to scan Scan every file should be highlited
Exit AVG (But do not run it yet)
 
Reboot into Safe Mode
This can be done by
  • Restart your PC, and after it starts, but before you see the Windows Splash screen
    Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
    Use your arrow keys and select Safe Mode and then Enter
Run AVG Anti-Spyware
  • Click scanner
    Select Complete system scan
Once the scan finishes
  • Select Apply all actions (The items found will be quarantined)
    Click save report as (Another window will open)
    Save it to your desktop
    (By default It will be saved in the AVG folder as)
    C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports

Exit AVG
 
Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
  • Double click the report-scan txt. you saved to your desktop
    It will open in Notepad
    Copy and paste that report as a reply to this thread
    bamajim   Graduate of Malware Removal University

    36 Posts

    March 29th, 2007 00:00

    part 4
     



    C:\I386\Limeshared\_\MDM Zinc v2.5.0.23.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MDaemon Pro v9.51.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MP3 Producer v2.56.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MP3 To Ringtone Gold 3.50.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MP3 Wav Studio v6.18.61105.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MP3-Tag-Editor 3.11.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MS eMbedded Visual Studio 4.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mac OS X Server 10.3 Panther Visual QuickPro Guide.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Macro Mania v11.1.3.0608200.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MacroMachine v3.1.5.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Magic Audio Converter v8.3.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Magic Audio Converter v8.3.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Magic DVD Ripper v5.0.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Magic Music Factory 7.0.7.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MailBell v2.20.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Maptech Chart Navigator PRO.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mario XP121.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Math Magic Pro.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Max Payne 2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\McAfee Virus-Scan Plus 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\McFunSoft Audio Studio v5.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Media Force Record-Anything v2.95.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MediaKG FotoWorks v9.3.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MediaKG Intelligent Shutdown.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MediaKG Slideshow Pro v9.8.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Medieval II  Total War iSO.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Medieval II Total War.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Meet the Fockers.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mem Optimizer.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Men Behind the Sun DVDRip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MiLoPhoto v2.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Micro-Sys A1 Sitemap Generator v1.4.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Microccd 4.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Microsoft FrontPage 2003.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Microsoft Malicious Software Removal Tool 1.18.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Microsoft Money 2007 16.0.10.705.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Microsoft Office 2006 Enterprise Final.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Microsoft Office 2007 Pro.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Microsoft Private Folder 1.0 [Cracked].exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Microsoft Windows Vista Final 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Midtown Madness 2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mil Shield v4.8.1485.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mimic Sentinel DVDRip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MindMapper v4.5.5044.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MindSoft Utilities XP v9.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mini Key Log v2.6.1.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mobile Nokia 6630 Games.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Modeling and Simulation in Scilab Scicos.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Moleskinsoft Clone Remover 2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Most Popular Solitaire v1.11.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Movie DVD Maker 1.7.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Movie DVD Maker v1.7.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mozilla Firefox 1.5.0.5 RC4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mr. Smith Goes to Washington James Stewart1939.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Multi Messenger Hack v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Multiple File Rename v1.1.0.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Music and Lyrics 2007 CAM Rip - Very Good.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MusicMatch Jukebox v10.0.4033 Plus.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\My Remote Files 1.2.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\MySQL2PostgreSQL PRO 1.2.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Mystery Solitaire Secret Island.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\N-Track Studio 24bit v5.0.2164.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\N-track Studio 5.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\NBA street version3 ps2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\NCH Swift Express Burn Plus v2.00.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\NCH Swift Express Dial.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\NLauncher v1.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\NOD32 Antivirus System 2.70.12 RC1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\NOD32 v2.70.32.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Native American Beadwork Tradi Native American Beadw.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Native Instruments Guitar Rig v2.02 Retail.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Need For Speed Carbon ISO.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Nero 7 Reloaded Plugin Pack 2.0.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Nero 7.5.1.1 Premium.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Nero Burning ROM v7.5.9.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Net Profile Switch 4.72.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\NetLimiter Pro v2.0.9.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Network Magic 4.1.7039.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\New Star Soccer 3.16.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\NewsReactor 1.0 Build 9044.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\NewsReactor v1.0.9052.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Night At The Museum 2006 - TS.XViD VCDUS.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Nikon Capture Nx 1.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\No1 DVD Ripper v2.9.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\No1 Video Converter v4.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Norbit 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Norbyte Downfall v2.6.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Norman Virus Control v5.82.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Norton 360 Home for Windows XP  Vista.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Norton Antivirus 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Norton Internet Security 2007 Final.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Norton Partition Magic 8.05.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Norton Personal Firewall 2006 v.9.0.0.73.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Norton Systemworks 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Office Cleaning 2.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker CD To MP3 v1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker DVDCD Data Burner v1.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker Disk Cleaner v1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker ISO Maker v1.7.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker MP3 Joiner v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker MP3 To CD Burner v1.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker Optimize Expert v1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker Optimize Expert v1.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker Password Manager v1.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker Quick Burner v1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker Shutdown Expert v1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Okoker Sudoku v1.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Old School 2003.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Oneclick Cleanup V10.2 Retail.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Oni ISO.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\OrangeCD Suite 6.0.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Outlook Express Protector 1.82.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Outpost Firewall Pro 4.0.971H.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PC Auto Shutdown v2.8.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PC Booster v5.0.106.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PC Tools Firewall Plus 2.012.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PDF Combine v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PDF Creator Plus v3.0.0.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PDF Decrypt v2.x.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PDF Split v2.x.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PDR Electronic Library 2006 - Physicians Desk Referen.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Panda Antivirus Plus Firewall 2007 6.00.02.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Panorado v3.3.1.67.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\ParticleIllusion 3.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Partition Recovery 1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Pay Roll 2006.v10.3.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PcMedik v6.1.2.2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Personal Chess Trainer v2.00.29.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Personal Mail Server Pro v2.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Personal Mailing List 1.30.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Phone Booth.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Photo Frames 1.73.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Photo Slide Show 3.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PhotoFiltre Studio v7.3.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PhotoLightning v4.52.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PhotoLightning v4.8.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PhotoWatermark Pro v6.1.34.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PhotoZoom Pro 2.1.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Pic Master v4.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Pics Print v3.10.1.412.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Picture Window Pro v4.0.1.8.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Picture to Icon v1.97.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Pinnacle Studio MediaSuite v10.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Plato DVD Ripper v5.52.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Plato DVD To DivX XviD Ripper v4.52.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Plato Video To iPod Converter v3.52.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Plato Video To iPod PSP 3GP 3.31.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Playboys Sexy Ladies - October 1995.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Pool Buddy Yahoo 5.10.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Portable Babylon Pro 6.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Portable Kaspersky AntiVirus v6.0.1.41.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Poster v7.9.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Power Audio Editor v11.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Power Sudoku Fuer Kids.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Power Video Converter v1.5.7.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PowerArchiver 2006 9.63.01.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PowerPoint PPT2PDF v3.x.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Premium Clock v2.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Presenter Pro v5.05.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PrintStudio Pro 2.0 FULL.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\PrintStudio Pro.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Prison Break Season 2 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Privacy Eraser Pro v5.90.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Process Guard 3.200.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Product Key Explorer v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Program Protector Ver.2.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Proxy Finder Enterprise v1.90.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Public PC Desktop 3.32.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\QuickTime Alternative (QT7) 1.72.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).

    36 Posts

    March 29th, 2007 00:00

    Logfile of HijackThis v1.99.1
    Scan saved at 8:44:02 PM, on 3/28/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\WinRamTurbo XP\WinRamTurboXP.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Dell Photo AIO Printer 966\memcard.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\dlcqcoms.exe
    C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Kirk\Desktop\HijackThis.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/flash/index.cfm
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Surf Surf Surf
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
    O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [WinRamTurbo] C:\Program Files\WinRamTurbo XP\WinRamTurboXP.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [dlcqmon.exe] "C:\Program Files\Dell Photo AIO Printer 966\dlcqmon.exe"
    O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [DLCQCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 966\memcard.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [ref online] C:\DOCUME~1\Kirk\APPLIC~1\DARTBI~1\AtomSlow.exe
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZCxdm231YYUS
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
    O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/MyMailStationeryFWBInitialSetup1.0.0.15.cab
    O16 - DPF: {6E2510E6-BF2D-4C78-9F28-2F5C8760F124} (ERPageAddin Class) - https://eroom.entergy.com/eRoomSetup/client.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1165292709687
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
    O18 - Protocol: AutorunsDisabled - (no CLSID) - (no file)
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
    O23 - Service: dlcq_device -   - C:\WINDOWS\system32\dlcqcoms.exe
    O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\NPROTECT.EXE
    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~3\SPEEDD~1\NOPDB.EXE
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    36 Posts

    March 29th, 2007 00:00

    part 7
     

    C:\I386\Limeshared\_\TVedia v4.0.0714.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Table Pro v.3.28.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Talisman Desktop 2.98.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\TamoSoft CommView Remote Agent v2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\TamoSoft CommView for WiFi v5.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\TamoSoft CommView v5.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\TamoSoft SmartWhois v4.1.197.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\TaoNotes 3D Pro v2.71.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Teleport Pro 1.41.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Tenacious D The Pick of Destiny 2006 DVDRip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Terminal Studio Challenger Tetris v1.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Terminal Studio Tetris Arena v1.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Terminal Studio Tetris Revolution v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Big Sleep Humphrey Bogart 1946.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Black Dahlia.TS.CAM.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Bloodstained Bride.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Butterfly Effect 2 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The City Of Violance 2006 dts.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Fast And The Furious - Tokyo Drift HDDVD  2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Fog 1980.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Ground of the Image Perspectives in Continental.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Grudge 2 - DVD-Rip XVID.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Grudge DVDRip Xvid.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Invincible Iron Man.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The JukeBoxer v3.8.0.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Lost Tomb of Jesus 2007 DVDRip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Manchurian Candidate DVDRip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Messengers 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Negotiator.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Notorious Bettie Page 2005.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The PC Detective Pro v2.8.125.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Return.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Rock.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Rocket Post 2006 Dvdscr.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Sims 2 Summer Life.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Stepfather.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Three Stooges-Hokus Pokus.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Unit - 1st season.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The War Tapes 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\The Woods 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Throttle v6.1.2.2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Timesheets Express v7.1.0.0271.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Titan Poker.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Tomb Raider Legend.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Tomb Raider The Angel of Darkness.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Top Gun 1986.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Total Audio Converter v2.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Total Commander v6.55 Public Beta 3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Total Commander v7.0pb2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Total Doc Converter v1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Total Excel Converter v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Total HTML Converter v1.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Total Movie Converter v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Tough Enough DVDRip  2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Trend Micro Anti-Spyware v3.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Trojan Guarder Gold Ver.7.06.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Trojan Remover 6.5.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\True Launch Bar v.4.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Try Master 1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Tube Hunter v9.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Tukanas Hits Generator v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\TuneUp Utilities 2006 v5.3.2343.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Tunebite 3.0.1.8.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\TurboFTP 5.00 Build 530.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Turistas UNRATED DVDRip XviD-DiAMOND.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\TwistingPixels ArtStudioPro Bundle v1.25.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Twistpad v.1.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\URLBase v6.0 Professional Retail.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\USB LOCK AP 1.9.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\USB LOCK RP 2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ulead Gif Animator 5.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ulead PhotoImpact 12.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ulead PhotoImpact v12 Retail.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ulead Videostudio V10.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ultimate Defrag 1.29.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\UltimateDefrag v1.29.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ultimatedefrag V1.29 Options.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ultra DVD Creator v1.6.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ultra Quicktime Converter 1.2.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ultra RM Converter 2.2.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Undelete Pro v5.0.114.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Urgent Backup v2.52.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\UrlShop v1.09.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\User Time Control v3.5.5.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\V rally for pc.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VCOM SystemSuite Professional 7.0.2.7.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VIP Organizer v2.4.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VJ Ripper Pro v 1.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VMware VirtualCenter v2.0.27704 Retail.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VSO Convert X to DVD v.2.1.12.214.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VSO PhotoDvd.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Van Wilder 2 UNRATED DVDR-Replica.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Van Wilder 2 Unrated DVDRip  2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Video Enhancer 1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VideoCat v.2.12.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VideoCharge 3.7.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VideoCharge Full version 3.7.6.16.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VideoGet v2.0.2.27.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VideoGet ver. 1.0.0.8.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Virtual DJ Studio v.5.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VirtualMEC v1.5.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Vision Backup Enterprise v10.9.30.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Vista Manager 1.0.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Vista Manager 1.1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Vista Sidebar For XP v2.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Vista Sidebar for XP v.2.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Visual Business Cards 4.15.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Visual Studio 2005 Pro iSO DVD.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VividLyrics v2.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\VueScan Pro v8.3.53.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Vuescan Professional V8.3.78.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WM Recorder v.11.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WMA to MP3 Encoder v5.08.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WWE Raw 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Watchman 7.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WaveLab v5.01b.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Web Translator v8.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Web-PC-Exe Lock 1.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WebZIP v7.0.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Webroot Spy Sweeper 5.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Webzip 7.0.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Wedding Crashers.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Weeds series season 1 and 2 - new ep 6 2005 6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Welcome To Durham 2006 DVDRip XviD-SiNK.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Where Eagles Dare Eastwood  Burton 1968.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Wilderness 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Win Live Mesenger.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WinAMP PRO v5.3.1 Build 979.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WinDesign v7.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WinFtpServer v.2.0.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WinOrganizer v3.1.935.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WinRAR 3.70 BETA 4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WinTasks 5 Professional 5.03.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WinTools.net Professional 7.7.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WinXP Manager v5.0.9.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WinZip Pro Corp v11.0.7313.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Winamp 5.25 Build 787 Beta.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Winamp 5.33.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Winamp Full 5.34.1155 Beta.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Winamp Pro v5.31.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Winclear 1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WindowBlinds Enhanced 5.50.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Windows Media Encoder Studio Edition Beta 1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Windows Vista Activator 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Windows Vista Ultimate 32Bit.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Windows XP 3D Flip Effect.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Windows XP x64 With Service Pack 2 Retail.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Windows Zune Theme + Extra Colours.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Winning Eleven Pro Evolution Soccer 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\WiseDesktop 1.5.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Witcobber Easy DVD Extractor v3.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Witcobber Super Video Converter.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Wivisoft 3GP Video Converter.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\World Championship Snooker 2004.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\World Poker Championship.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\World Snooker Challenge 2007 PSP.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\World Trade Center 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\World of Warcraft The Burning Crusade.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Worms 3D.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).

    36 Posts

    March 29th, 2007 00:00

    Part 3

    C:\I386\Limeshared\_\Ella Enchanted DVDRip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Elythril The Elf Treasure 1.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Email Questionnaire v4.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Email Spider Gold 9.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Encrypt Folder v1.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Energy Spy 1.71.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\EssentialPIM PPC Edition 1.81.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Eternal Sunshine of the Spotless Mind.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Europa Universalis III PL.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Evidence Eliminator v5.0.58.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Evil Invasion 1.23.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Evolution GT.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\ExamXML 4.10.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\ExamXML 4.16.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Excel XLS2PDF v3.x.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\EximiousSoft Cool Image v2.08.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\EximiousSoft GIF Creator v3.08.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FBI Forensic Field Kit AIO.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FIFA 07.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FTP Commander PRO v7.90.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FTP Commander Pro.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FTPGetter v2.6.0.29.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FTPRush 1.0.0588 ANSI.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Fake Webcam 2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Fast Cleaner 4.70.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FastContent v1.9.1.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Feast dvdrip - BY BESTSHARE.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Feed Mix RSS Editor 4.62.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\File Lock v6.1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\File Security Manager 1.8.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\File Security Manager v1.7.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Filestream InstallConstruct v6.8.216.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Final Destination.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Final Fantasy 7.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Final Fantasy VII - The Dirge of Cerberus.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Final Fantasy VII PC.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Find Me Guilty Vin Diesel 2006 DVDRip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Firefox 2.0 Beta 1 Released [Official].exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Firefox Portable 2.0.0.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Flash Effect Maker Pro v.3.2560.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FlashGet 1.81.1002.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Flatout 2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Folder Guard Professional v7.91.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Folder Lock 4.25.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FolderSizes 3.3.0.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Font Fitting Room Deluxe V2.8.1.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FontDoctor for Windows v2.5.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Football Manager 2007 v7.0.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Forge Of Freedom.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Form Pilot Office v2.10.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Form Pilot Professional v2.10.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Foxit PDF Reader 2.0 Build 1516.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Foxit PDF Reader Pro 2.0 Build 1516.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Foxy 1.6.7.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Fraps v2.8.1 Build 6403.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Frauenknast Teufelsbrut hinter Gittern.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Fresh Download v7.52.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Fresh Download.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Frontline Fields Of Thunder.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\FullShot Enterprise.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Fussball Manager 07.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\G.I. Combat.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\GAEA WinFence v2.16.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\GT Legends.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\GTA San Andreas, PC Game.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\GTA Vice City German.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Game Gain v2.1.2.2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Game Jackal v2.7.11.320.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Game-Cloner 1.25.0.1 beta.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\GameBoost v1.1.2.2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Gcode2000 v29.020.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\General Invoice 1.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Genesis DVDRip XviD.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Genie Backup Manager 7.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Genie Backup Manager Pro 7.0.179.349.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Geometry Wars Retro Evolved.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\GetDataBack for FAT v3.03.011 Multilingual.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Glyph 1.0.76 Retail.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Good Night Nurse  Fatty Arbuckle Buster Keaton 1918.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Good Sync Pro v4.6.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Google Video Ripper v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Goyas Ghosts DVDRip  2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\GraphNow Math Calculator v2.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\GraphNow Visual Data v2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Graphics Converter Pro v6.68.61105.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Grid Wars 2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Gridiron Gang.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Grim Reaper DVDRip  2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\HDL Companion v2.0 R2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\HTML to Image v2.0.2007.308.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\HTMLPack 2.5.0630.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\HTTP Analyzer IE Addon Edition 2.2.2.109.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hackers 2 Operation Takedown 2000.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hackers 3 Antitrust 2001.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hackman Suite Pro v9.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Half Light 2006 DVDRip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Handy Password 3.9.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\HaneWin LLDP Service v1.2.9.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hangman Pro v1.0.8.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hattrick Manager v2.47.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Helle in the Pacific Lee Marvin 1968.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Heroes Season 1 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hexdataedit v1.20.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\HiDownload Pro 6.92 FULL.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hidden Camera v2.18.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hide And Protect Any Drives.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\His Girl Friday Cary Grant 1940.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hitman 3 Contracts.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Holigans DVDRip XviD-WT.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hollywood FX Pro For Adobe Premier 7.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hollywood Fx Pro.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Honestech VHS to DVD 2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hootech MP3 to SWF Converter 2.4 build 779.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Horoscope Explorer v3.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hot Cpu Tester Pro 4.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hot Fuzz  2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Hunting unlimited 4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\HylaFSP v3.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\IDM UltraSentry v3.00.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\IDpack Pro 7.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\ISO Commander v.1.6.042.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Icon Seizer v1.90.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Iconcool Studio 3.30.70116.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ideal Administration 2007 v7.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Idpack Pro 7.5.59.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\ImTOO MP4 Video Converter v3.1.8.0828b.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Image Analyzer v1.27.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Image Grabber II.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Images WebScan v2.2b.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Inbit Messenger v2.70.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Instant Photo Effects v2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Intel Desktop Control Center 2.1.0003.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\IntelliAdmin LAN Edition v2.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\IntelliJ IDEA v5.1.2.4267.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Internet Download Accelerator v5.1.1.1045.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Internet Download Manager v5.02.9.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Intervideo WinDVD Platinum 8.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Intervideo Windvd Platinum V8.0 B06.072.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Intocartoon Professional Edition v.2.1.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\IntroCreator v2.40.024000.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Iradio Lite Ver.1.0.0.18.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\IsoBuster Pro v2.0.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\JAWS v7.10.500.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Jackss 2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Jackss Number Two 2006 Cam.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Jet Li Fist Of A Legend DVD RIP.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\John Tucker Must Die 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\K-Lite Codec Pack Full 2.86 Beta.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\KLS Backup 2006 Professional v2.1.0.1 Keygen.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kaspersky 6 Emergency CD.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kaspersky Anti-Hacker 1.94.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kaspersky Anti-Hacker v1.9.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kaspersky AntiVirus v.6.0.2.614 Final.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kaspersky Internet Security 6.0.1.411.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kaspersky v6.0.0.303.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kawasaki Jet Ski.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kerio Mailserver V6.30.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kerio WinRoute Firewall v6.2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\King Kong.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kls Backup 2006 Professional2.1.5.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\KoolMoves 5.6.3 Retail.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kundali Pro 4.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Kylix Ringtone Maker 2.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ladder 49 - 2006 DVD-RIP XVID.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Lady In The Water.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Lan2net NAT Firewall v1.9.00.0173 Multilingual.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\LanTalk XP 2.93.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Land of the Dead Directors Cut.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\LaoWei Inc WinVMD v1.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Laurel  Hardy Sailors Beware 1927.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\LightArtist 1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\LimeWire Pro v4.13.2.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\LinkLines v1.2.9.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\LivePIM Conduit Buddy v3.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Lock My PC 4.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Lord Of War 2006 Nicolas Cage DVDRip XviD.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Lord of War.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Lost Season 1 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Lost Season 3 Episode 12 Hdtv 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Lost Season 3 Episode 8 HDTV XviD.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Loving Annabelle.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).

    36 Posts

    March 29th, 2007 00:00

    part 6
     


    C:\I386\Limeshared\_\R-Wipe and Clean v6.5.1241.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RAR Repair Tool 3.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RAR Repair Tool v3.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RAR Repair Tools v.3.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\REAPER 0.999 Beta.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RMBSoft AudioConvert v3.1.126.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Ram Saver Pro v5.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RamDisk Desktop Plus v.8.0.4.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RamSmash v1.11.6.2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Rapid PDF Count v1.12.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RapidKill Pro v5.9 Final.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Rapidshare Premium Link Maker With Rs Accountz.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RealPlayer Premium v10.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RealPlayer for Windows ver. 10.5 (6.0.12.1698).exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Rear Window James Stewart Grace Kelly 1954.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Recover My Files v.3.98.5061.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Red faction II.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Registry Easy v1.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Registry Help Pro v1.31.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Registry Mechanic v6.0.0.750.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Registry Repair Wizard 2007 v4.52.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\RegistryFix 5.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Repentance 2006 DVDRIP XVID.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Resident Evil 4 PC.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Restorator 2007 v.3.70.1729.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Restorator 2007 v3.70.1729.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Return To Mysterious Island.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Rikki and Mikki To The Rescue v1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Robin Hoods Quest.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Rocky Balboa XViD SiNA DvD.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Roller Coaster Tycoon 3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Rometv Season 1  2 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Room 6 - DVDRip Xvid 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Runviewer V1.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SAM Broadcaster v3.5.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SAM Broadcaster v3.5.0_Inc_Patch.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SBMAV Disk Cleaner Ver 3.0 Beta 8.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SC Keylogger Pro.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SQLyog Enterprise v5.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SUPERAntiSpyware Professional v3.6.0.1000.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SWF Max v1.5.785.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SWFKit 3.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SageTV Client v5.0.4.92.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Sam Broadcaster v4.2.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Scarface RIP.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Scramby v.1.5.0.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Scramby v1.5.0.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Scrat No Time For Nuts STV DVDRip XviD - SiSO.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Screen Protractor 3.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Secret Eyes v.1.2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Security Administrator 10.52.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Seed of Chucky Unrated.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Shadow Of The Sword DVDRip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\ShellToys XP v5.2.2.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Shes The Man 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SilverFast DCPro Studio v6.4.4r6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Simple CD DVD Menu 1.3.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Site Translator 2.41.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Skymatter Mudbox Professional v1.04 Rev1760 Network lic.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Skype 2.5.0.130 for Windows.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Slide Show to Go v8.3.1.63.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SlySoft AnyDVD 6.0.8.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SlySoft AnyDVD 6.1.3.0 Final.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Smallville Season 6 Episode 16 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Smart Cd Ripper.3.1.7.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SmartCode VNC Manager Enterprise v3.5.25.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Snappy Invoice System v4.44.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Snoop Dogs Hood of Horror  2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SoftX HTTP Debugger v3.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Software Technology VAZ Modular VSTi DXi v3.04.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SoftwareTime ComputerTime v2.0.0.47.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SolSuite 2006 v6.7.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Solid Converter PDF v3.1 Build 437.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Sonic Scenarist for WinXP v4.20.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Sony ACID Pro v.6.0c.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Sony DVD Architect.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Sony Vegas 7.0b Build 151.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Sound Forge 8.0d.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\South Park Season 11 Episode 02 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Space Station v1.9.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Speed DVD Creator v4.0.4.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Splinter Cell Chaos Theory.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Spy Emergency 2006 3.0.305.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Spy Sniper v3.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SpyCleaner Platinum 9.8.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SpyRemover v2.65.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SpySweeper v5.0.7.1608(Full).exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Spyware Doctor 4.0.0.2621.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Stalag 17 William Holden 1953.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Stardock WindowBlinds Enhanced 5.50.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Starry Night Pro v5.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Stay Alive 2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Steganos Password Manager 2006 v8.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Steganos Safe 2007 v9.0.2 FULL.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Steganos Security Suite 2006 v8.0.6.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Steinberg Nuendo 3.2.0.1128.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Step Up DVDrip.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Stoik Deformer 2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Street fighter 2 turbo for snes.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\StudyMinder Homework System v2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Suburban Mayhem 2006 DVDrip XviD-KuDoS.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Sudoku Pro v1.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Sunbelt Kerio Personal Firewall v4.3.635.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Super DVD Creator v.9.30.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Super Mp3 Recorder Pro 6.2.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Super Video Converter v3.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Super Video to Audio Converter 4.2.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SuperRam v5.1.2.2006.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\SuperWin Speed Startup v.1.01.04.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Supreme Commander 2007 ISO.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Supreme Commander.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Surprise Maker 3.4.0.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Symantec Ghost Corporate 11 Bootable.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Symantec Norton Ghost 11.0.0.1502.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Sync Folder v3.32.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).

    36 Posts

    March 29th, 2007 01:00

    part 8
     

    C:\I386\Limeshared\_\X-Setup Pro v8.1.110.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\XM Easy Personal Ftp Server 4.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\XP Smoker Pro v5.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\XP Smoker Professional 5.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\XP Tools v5.92.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\XYPlorer Pro v5.00.0045.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\XYplorer v5.20.0026.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\XYplorer v5.80.0000.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Xara 3D v6.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Xara Xtreme Pro v3.0.1.692.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Xilisoft DVD Copy Express v.1.1.1.1026.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Xilisoft DVD Ripper Platinum 4.0.51.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\XnView v.1.90.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\YouTube Video Downloader 2007.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Your Uninstaller PRO 2006 5.0.0.338.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Your Uninstaller PRO 2006 5.0.0.343.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\Zan Image Printer v4.0.10.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\ZoneAlarm 7.0.334.000 Pro  with Antivirus  Internet Sec.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\dlife Pro V2.9.107.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\eCallerID v1.3.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\ePAB Converter 1.0.1.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\eTrust Personal Firewall 5.5.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\iFinance v1.5.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\iPod Flash Cards 1.0.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\x1 Enterprise Client V5.6 Build 3377.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\xzxzxzxzxzxz.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\I386\Limeshared\_\zMapper 1.30.beta.exe -> Dropper.VB.lu : Cleaned with backup (quarantined).
    C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined).
    C:\Documents and Settings\Guest\Cookies\guest@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
    C:\Documents and Settings\Guest\Cookies\guest@ad.admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
    C:\Documents and Settings\Guest\Cookies\guest@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Guest\Cookies\guest@servedby.advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Kirk\Cookies\kirk@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Guest\Cookies\guest@adviva[2].txt -> TrackingCookie.Adviva : Cleaned.
    C:\Documents and Settings\Kirk\Cookies\kirk@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Guest\Cookies\guest@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
    C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Kirk\Cookies\kirk@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Guest\Cookies\guest@webpdp.gator[1].txt -> TrackingCookie.Gator : Cleaned.
    C:\Documents and Settings\Kirk\Cookies\kirk@ehg-comcast.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Kirk\Cookies\kirk@ehg-foxmovies.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Kirk\Cookies\kirk@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Kirk\Cookies\kirk@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\Guest\Cookies\guest@overture[1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Kirk\Cookies\kirk@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
    C:\Documents and Settings\Guest\Cookies\guest@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned.

    ::Report end
     

    10.4K Posts

    March 29th, 2007 01:00


    kbelmon

    As you can see from the results of the AVG log, this is the reason that most of us in the anti-malware community do not like P2P share programs like LimeWire.
    If you decide to keep the program, at the very least turn it off until we are done cleaning your PC. And if you do decide to keep it I will recommend some safeguards when we are finished.

    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

    bamajim   Graduate of MRU
    CastleCops  Instructor

    36 Posts

    March 29th, 2007 20:00

    Thanks!!!
     
     
    "Kirk" - 07-03-29 15:51:19    Service Pack 2
    ComboFix 07-03-27.4.2 - Running from: "C:\Documents and Settings\Kirk\My Documents"

    ((((((((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

    C:\WINDOWS\DOWNLO~1.\Quarantine\ppqdb.dat
    C:\WINDOWS\DOWNLO~1.\Quarantine\ppqsdb.dat
    C:\WINDOWS\system32\svcp.csv
    C:\WINDOWS\system32\zlbw.dll
    C:\WINDOWS\system32\winsub.xml
    C:\WINDOWS\DOWNLO~1.\Quarantine

    (((((((((((((((((((((((((((((((   Files Created from 2007-02-28 to 2007-03-29  ))))))))))))))))))))))))))))))))))

    2007-03-23 23:30 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
    2007-03-23 22:29   d-------- C:\Limeshared
    2007-03-23 22:28   d-------- C:\Incomplete
    2007-03-19 13:58   d-------- C:\Temp
    2007-03-19 00:19   d-------- C:\DOCUME~1\Kirk\APPLIC~1\Dartbikereal
    2007-03-17 22:38 212 --a------ C:\delete.bat
    2007-03-17 22:08   d-------- C:\Program Files\Kudosoft
    2007-03-02 22:22 2,555,904 --ahs---- C:\gobackio.bin
    2007-03-02 08:42   d-------- C:\Program Files\LimeWire
    2007-03-02 08:29   d-------- C:\Program Files\O3
    2007-03-02 00:06 79 --a------ C:\WINDOWS\delay.reg
    2007-03-01 23:28   d-------- C:\Program Files\Norton Internet Security
     
     
    ((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-03-29 15:40 -------- d-------- C:\Program Files\dl_cats
    2007-03-26 20:19 -------- d-------- C:\Program Files\Common Files\symantec shared
    2007-03-26 07:04 -------- d-------- C:\Program Files\norton systemworks
    2007-03-26 03:32 -------- d-------- C:\Program Files\online services
    2007-03-23 23:37 -------- d--h----- C:\Program Files\installshield installation information
    2007-03-23 23:26 -------- d-------- C:\Program Files\logitech
    2007-03-06 01:42 -------- d-------- C:\Program Files\steam
    2007-03-02 08:37 -------- d-------- C:\Program Files\serenescreen
    2007-03-02 08:34 -------- d-------- C:\Program Files\java
    2007-03-02 08:27 -------- d-------- C:\Program Files\microsoft activesync
    2007-03-02 00:08 48776 --a------ C:\WINDOWS\SYSTEM32\s32evnt1.dll
    2007-03-02 00:08 115000 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
    2007-03-02 00:08 -------- d-------- C:\Program Files\symantec
    2007-03-01 23:29 10344 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symlcbrd.sys
    2007-03-01 22:51 -------- d-------- C:\DOCUME~1\Kirk\APPLIC~1\symantec
    2007-02-28 21:44 -------- d-------- C:\Program Files\nch swift sound
    2007-02-28 21:44 -------- d-------- C:\DOCUME~1\Kirk\APPLIC~1\nch swift sound
    2007-02-26 22:37 2528 --a------ C:\DOCUME~1\Kirk\APPLIC~1\$_hpcst$.hpc
    2007-02-26 22:32 22768 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\usbsermpt.sys
    2007-02-26 21:34 -------- d-------- C:\Program Files\motorola phone tools
    2007-02-26 21:25 -------- d-------- C:\Program Files\liveupdate
    2007-02-26 21:25 -------- d-------- C:\DOCUME~1\Kirk\APPLIC~1\installshield
    2007-02-24 00:46 -------- d-------- C:\DOCUME~1\Kirk\APPLIC~1\winrar
    2007-02-24 00:41 0 --a------ C:\WINDOWS\SYSTEM32\taskkill.exe
    2007-02-14 15:03 -------- d-------- C:\DOCUME~1\Kirk\APPLIC~1\dellfaxctr
    2007-02-13 23:59 -------- d-------- C:\Program Files\failsafe
    2007-02-13 21:25 -------- d-------- C:\Program Files\corel
    2007-02-13 21:22 56 -r-hs---- C:\WINDOWS\SYSTEM32\f22ecbbc9c.sys
    2007-02-13 21:22 3766 --ahs---- C:\WINDOWS\SYSTEM32\kgygaavl.sys
    2007-02-13 21:21 -------- d-------- C:\DOCUME~1\Kirk\APPLIC~1\corel photo album
    2007-02-13 17:35 -------- d-------- C:\Program Files\dell photo aio printer 966
    2007-02-13 17:33 -------- d-------- C:\Program Files\dell
    2007-02-13 17:32 -------- d-------- C:\Program Files\dell pc fax
    2007-02-12 18:22 538256 --a------ C:\WINDOWS\SYSTEM32\symneti.dll
    2007-02-12 18:22 31888 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symids.sys
    2007-02-12 18:22 28304 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symndis.sys
    2007-02-12 18:22 24720 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symredrv.sys
    2007-02-12 18:22 196752 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symtdi.sys
    2007-02-12 18:22 161424 --a------ C:\WINDOWS\SYSTEM32\symredir.dll
    2007-02-12 18:22 12944 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symdns.sys
    2007-02-12 18:22 110736 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\symfw.sys
    2007-02-12 17:00 -------- d-------- C:\Program Files\dartbikereal
    2007-02-12 16:30 -------- d-------- C:\Program Files\cdburnerxp pro 3
    2007-02-12 16:25 -------- d-------- C:\Program Files\audio converter
    2007-02-12 16:24 -------- d-------- C:\DOCUME~1\Kirk\APPLIC~1\cowon
    2007-02-03 22:21 -------- d-------- C:\Program Files\quicktime
    2007-02-03 22:20 -------- d-------- C:\Program Files\apple software update
    2007-01-26 12:52 73216 --a------ C:\WINDOWS\st6unst.exe
    2007-01-26 12:52 249856 --------- C:\WINDOWS\setup1.exe
    2007-01-08 20:01 17408 --a------ C:\WINDOWS\SYSTEM32\corpol.dll
     
     
    ((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
    *Note* empty entries & legit default entries are not shown
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "Steam"=""
    "ref online"="C:\\DOCUME~1\\Kirk\\APPLIC~1\\DARTBI~1\\AtomSlow.exe"
    "updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_8 -reboot 1"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "WinRamTurbo"="C:\\Program Files\\WinRamTurbo XP\\WinRamTurboXP.exe"
    "IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
    "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
    "dlcqmon.exe"="\"C:\\Program Files\\Dell Photo AIO Printer 966\\dlcqmon.exe\""
    "FaxCenterServer"="\"C:\\Program Files\\Dell PC Fax\\fm3032.exe\" /s"
    "ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
    "DLCQCATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\DLCQtime.dll,_RunDLLEntry@16"
    "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_11\\bin\\jusched.exe\""
    "HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
    "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
    "MemoryCardManager"="\"C:\\Program Files\\Dell Photo AIO Printer 966\\memcard.exe\""
    "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
    "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
    "nwiz"="nwiz.exe /install"
    "REGSHAVE"="C:\\Program Files\\REGSHAVE\\REGSHAVE.EXE /AUTORUN"
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
    "Installed"="1"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
    "Installed"="1"
    "NoChange"="1"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
    "Installed"="1"

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
    "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}"
    "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoCDBurning"=dword:00000000
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoViewOnDrive"=dword:00000000
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    LocalService REG_MULTI_SZ    Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ    DnsCache\0\0
    rpcss REG_MULTI_SZ    RpcSs\0\0
    imgsvc REG_MULTI_SZ    StiSvc\0\0
    termsvcs REG_MULTI_SZ    TermService\0\0
    HTTPFilter REG_MULTI_SZ    HTTPFilter\0\0
    DcomLaunch REG_MULTI_SZ    DcomLaunch\0TermService\0\0
    WudfServiceGroup REG_MULTI_SZ    WUDFSvc\0\0

    [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f0071b9a-424c-11d8-8715-806d6172696f}]
    Shell\AutoRun\command E:\LaunchBF.exe
    *newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_COMHOST

    Contents of the 'Scheduled Tasks' folder
    C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Kirk.job
    C:\WINDOWS\tasks\Norton Windows Tune Up.job

    ********************************************************************
    catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
    http://www.gmer.net
    scanning hidden processes ...
    scanning hidden services ...
    scanning hidden autostart entries ...
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      DLCQCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCQtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0
    ********************************************************************
    Completion time: 07-03-29 15:59:02
    No Events found!

    Top