Please could one of you VERY NICE people help?
I've read other posts & remedies for winik but, not being the most computer literate person, I would be hugely grateful for point in the right direction (before I turn my pc into a toaster!!)
Here are the details from my pc:
Logfile of HijackThis v1.99.1
Scan saved at 13:17:15, on 15/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\WINDOWS\system32\atwtusb.exe
C:\Program Files\Trust\250S Series\lwbwheel.exe
C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\Program Files\VoyagerTest\fts.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\vrwuwvvr\bEwCIoBN.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\PROGRA~1\vrwuwvvr\NBoICwEb.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Nova Development\Photo Explosion\CalCheck.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtWLan.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Ace Explorer\Aexplore.exe
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.homechoice.co.uk/customer
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.red.clientapps.yahoo.com/customi...fo/bt_side.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.euro.dell.com/countries/uk/enu/gen/default.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.hotbar.com/dyn/hotbar/3.0/sb_searchPageHome.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.red.clientapps.yahoo.com/customi...www.yahoo.co.uk
O2 - BHO: DownloadRedirect Class - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - C:\Program Files\iMesh\iMesh5\iMeshBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: iMeshBar BHO - {5345A7A1-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\4.bin\IMESHBAR.DLL
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O2 - BHO: PosHelp - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O3 - Toolbar: iMeshBar - {5345A7A9-805A-4923-B505-86B2FEBA3FE0} - C:\Program Files\iMeshBar\bar\4.bin\IMESHBAR.DLL
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [atwtusb] atwtusb.exe beta
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Trust\250S Series\lwbwheel.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [%FP%Friendly fts.exe] "C:\Program Files\VoyagerTest\fts.exe"
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Photo Explosion Calendar Checker.lnk = ?
O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EP...l_v1-0-3-24.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1135369239890
O16 - DPF: {6FDB0065-2787-11D6-B1D8-0001023916FC} (CLOActiveXInstaller Control) - http://www.igl.net/clo/install/grab/CLOAct...tallerProj1.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://media.grab.com/media/fbd793/games/f...outLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://i.grab.com/media/d82c8d/games/files...aploader_v6.cab
O16 - DPF: {E23FABEE-12E3-33DA-DA12-195DAC123984} (GameDesire Mahjong) - http://67.15.101.3/g_bin/eng/mahjong_2_0_0_19.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
Silent runners:
"Silent Runners.vbs", revision 43, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"updateMgr" = "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0" [file not found]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"IgfxTray" = "C:\WINDOWS\System32\igfxtray.exe" ["Intel Corporation"]
"HotKeysCmds" = "C:\WINDOWS\System32\hkcmd.exe" ["Intel Corporation"]
"BCMSMMSG" = "BCMSMMSG.exe" ["Broadcom Corporation"]
"dla" = "C:\WINDOWS\system32\dla\tfswctrl.exe" ["Sonic Solutions"]
"PCMService" = ""C:\Program Files\Dell\Media Experience\PCMService.exe"" ["CyberLink Corp."]
"DVDSentry" = "C:\WINDOWS\System32\DSentry.exe" ["Dell - Advanced Desktop Engineering"]
"AOLDialer" = "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" ["America Online, Inc"]
"Openwares LiveUpdate" = "C:\Program Files\LiveUpdate\LiveUpdate.exe" ["Openwares"]
"atwtusb" = "atwtusb.exe beta" ["Aiptek"]
"UpdateManager" = ""C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r" ["Sonic Solutions"]
"LWBMOUSE" = "C:\Program Files\Trust\250S Series\lwbwheel.exe" [empty string]
"LVCOMS" = "C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE" ["Logitech Inc."]
"DSLSTATEXE" = "C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon" ["GlobespanVirata, Inc."]
"DSLAGENTEXE" = "C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe" [null data]
"%FP%Friendly fts.exe" = ""C:\Program Files\VoyagerTest\fts.exe"" ["Friendly Technologies"]
"MPFExe" = "C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" ["McAfee Security"]
"(Default)" = """ = (data in unrecognized format!)" [file not found]
"AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
"AVG7_EMC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" ["GRISOFT, s.r.o."]
"SM1BG" = "C:\WINDOWS\SM1BG.EXE" ["Cypress Semiconductor"]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
"SPAMfighter Agent" = ""C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60" ["SPAMfighter ApS"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{00000000-6CB0-410C-8C3D-8FA8D2011D0A}\(Default) = "DownloadRedirect Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\iMesh\iMesh5\iMeshBHO.dll" ["iMesh Ltd"]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{5345A7A1-805A-4923-B505-86B2FEBA3FE0}\(Default) = "iMeshBar BHO"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\iMeshBar\bar\4.bin\IMESHBAR.DLL" ["iMesh"]
{5CA3D70E-1895-11CF-8E15-001234567890}\(Default) = "DriveLetterAccess" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\dla\tfswshx.dll" ["Sonic Solutions"]
{9394EDE7-C8B5-483E-8773-474BF36AF6E4}\(Default) = "ST" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll" [MS]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = "MSNToolBandBHO" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll" [MS]
{CDEEC43D-3572-4E95-A2A5-F519D29F00C0}\(Default) = "PosHelp"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL" ["Amazing Software Products"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{DEE12703-6333-4D4E-8F34-738C4DCC2E04}" = "RecordNow! SendToExt"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Sonic\RecordNow!\shlext.dll" ["Sonic Solutions"]
"{5CA3D70E-1895-11CF-8E15-001234567890}" = "DriveLetterAccess"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\dla\tfswshx.dll" ["Sonic Solutions"]
"{5464D816-CF16-4784-B9F3-75C0DB52B499}" = "Yahoo! Mail"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Yahoo!\Common\ymmapi.dll" ["Yahoo! Inc."]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Computer, Inc."]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
"{29e3fb5b-cf62-45b5-b8bf-1ad500385fc7}" = "Shell Context Menu Handler for Application References"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\dfshim.dll" [MS]
"{29e3fb5b-cf62-45b5-b8bf-1ad500385fc6}" = "Shell Context Menu Handler for Application Manifests"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\dfshim.dll" [MS]
"{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}" = "Shell Icon Handler for Application References"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\dfshim.dll" [MS]
"{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{57F02779-3D88-4958-8AD3-83C12D86ADC7}" = "Advanced Searchbar"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll" ["Amazing Software Products"]
"{CDEEC43D-3572-4E95-A2A5-F519D29F00C0}" = "Advanced Searchbar"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL" ["Amazing Software Products"]
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
Yahoo! Mail\(Default) = "{5464D816-CF16-4784-B9F3-75C0DB52B499}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\Yahoo!\Common\ymmapi.dll" ["Yahoo! Inc."]
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\kaz75\My Documents\My Pictures\vamp2.gif.bmp"
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\ss3dfo.scr" [MS]
Startup items in "kaz75" & "All Users" startup folders:
-------------------------------------------------------
C:\Documents and Settings\kaz75\Start Menu\Programs\Startup
INFECTION WARNING! "PowerReg Scheduler V3.exe" ["Leader Technologies"]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"hp psc 1000 series" -> shortcut to: "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe" ["Hewlett-Packard Co."]
"hpoddt01.exe" -> shortcut to: "C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" ["Hewlett-Packard"]
"Photo Explosion Calendar Checker" -> shortcut to: "C:\WINDOWS\Installer\{5BC304B7-84B4-43B3-8A62-EB9BC2051544}\PhotoExplosionCalendarChecker.exe" [null data]
"WG111v2 Smart Wizard Wireless Setting" -> shortcut to: "C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe" [empty string]
Enabled Scheduled Tasks:
------------------------
"Disk Cleanup" -> launches: "C:\WINDOWS\SYSTEM32\CLEANMGR.EXE" [MS]
"FRU Task #Hewlett-Packard#hp psc 1200 series#1091452301" -> launches: "C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe -I "#Hewlett-Packard#hp psc 1200 series#1091452301"" [empty string]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 21
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = "MSN" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll" [MS]
"{5345A7A9-805A-4923-B505-86B2FEBA3FE0}" = "iMeshBar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\iMeshBar\bar\4.bin\IMESHBAR.DLL" ["iMesh"]
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = "MSN" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll" [MS]
"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" = "AOL Toolbar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\AOL Toolbar\toolbar.dll" ["IE Toolbar"]
"{57F02779-3D88-4958-8AD3-83C12D86ADC7}" = "Advanced Searchbar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll" ["Amazing Software Products"]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = "0"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll" [MS]
"{5345A7A9-805A-4923-B505-86B2FEBA3FE0}" = "iMeshBar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\iMeshBar\bar\4.bin\IMESHBAR.DLL" ["iMesh"]
"{4982D40A-C53B-4615-B15B-B5B5E98D167C}" = "AOL Toolbar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\AOL Toolbar\toolbar.dll" ["IE Toolbar"]
"{57F02779-3D88-4958-8AD3-83C12D86ADC7}" = "Advanced Searchbar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll" ["Amazing Software Products"]
Explorer Bars
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
{FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\ = "Real.com" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\Shdocvw.dll" [MS]
Dormant Explorer Bars in "View, Explorer Bar" menu
HKLM\Software\Classes\CLSID\{5345A7AE-805A-4923-B505-86B2FEBA3FE0}\ = "iMeshBar Quick View"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\WINDOWS\system32\shdocvw.dll" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-00401C608501}"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\System32\msjava.dll" [file not found]
{4982D40A-C53B-4615-B15B-B5B5E98D167C}\
"ButtonText" = "AOL Toolbar"
"MenuText" = "AOL Toolbar"
{57F02779-3D88-4958-8AD3-83C12D86ADC7}\
"ButtonText" = "Advanced Searchbar"
"MenuText" = "Advanced Searchbar"
"CLSIDExtension" = "{57F02779-3D88-4958-8AD3-83C12D86ADC7}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\AdvancedSearchbar\advancedsearchbar.dll" ["Amazing Software Products"]
{CD67F990-D8E9-11D2-98FE-00C0F0318AFE}\
"ButtonText" = "Real.com"
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]
Miscellaneous IE Hijack Points
------------------------------
C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")
Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Missing lines (compared with English-language version):
[Strings]: 1 line
Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------
AOL Connectivity Service, AOL ACS, ""C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe"" ["America Online, Inc."]
AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe" ["GRISOFT, s.r.o."]
AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe" ["GRISOFT, s.r.o."]
Fax, Fax, "C:\WINDOWS\system32\fxssvc.exe" [MS]
iPod Service, iPodService, ""C:\Program Files\iPod\bin\iPodService.exe"" ["Apple Computer, Inc."]
McAfee Personal Firewall Service, MpfService, "C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe" ["McAfee Corporation"]
Pml Driver HPZ12, Pml Driver HPZ12, "C:\WINDOWS\System32\HPZipm12.exe" ["HP"]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]
Print Monitors:
---------------
HKLM\System\CurrentControlSet\Control\Print\Monitors\
hpzsnt07\Driver = "hpzsnt07.dll" ["HP"]
Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS]
----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 14 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 17 seconds.
---------- (total run time: 58 seconds)
REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "winik" 14/01/2006 17:30:23
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINIK]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINIK\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINIK\0000]
"Service"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINIK\0000]
"DeviceDesc"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINIK\0000\Control]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WINIK\0000\Control]
"ActiveService"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinIK]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinIK]
"DisplayName"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinIK\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinIK\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WinIK\Enum]
"0"="Root\\LEGACY_WINIK\\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINIK]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINIK\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINIK\0000]
"Service"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_WINIK\0000]
"DeviceDesc"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WinIK]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WinIK]
"DisplayName"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\WinIK\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINIK]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINIK\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINIK\0000]
"Service"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINIK\0000]
"DeviceDesc"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINIK\0000\Control]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINIK\0000\Control]
"ActiveService"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinIK]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinIK]
"DisplayName"="WinIK"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinIK\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinIK\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinIK\Enum]
"0"="Root\\LEGACY_WINIK\\0000"
Rootkitreveal:
HKLM\SOFTWARE\Classes\webcal\URL Protocol 23/03/2004 14:15 13 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\YgVJYwox 14/01/2006 15:44 68 bytes Hidden from Windows API.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher\TracesProcessed 14/01/2006 17:04 4 bytes Data mismatch between Windows API and raw hive data.
HKLM\SOFTWARE\RtlWake\LinkedSSID 14/01/2006 17:04 200 bytes Data mismatch between Windows API and raw hive data.
C:\Documents and Settings\kaz75\Local Settings\Temp\BC.exe 14/01/2006 17:28 95.00 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temp\BC.exe:Zone.Identifier 14/01/2006 17:28 26 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\asap_chrome[1].jpg 14/01/2006 17:20 14.23 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\back[1].gif 14/01/2006 17:20 45 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\ctasp-server[1].htm 14/01/2006 17:19 20 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\ctasp-server[2].htm 14/01/2006 17:19 215 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\ipb_topic[1].js 14/01/2006 17:20 3.40 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\nav_m[1].gif 14/01/2006 17:20 53 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\p_card[1].gif 14/01/2006 17:20 1.52 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\p_quote[1].gif 14/01/2006 17:20 1.48 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\t_poll[1].gif 14/01/2006 17:20 1.85 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\4DSF8BCV\tt[1].gif 14/01/2006 16:55 42 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\365x100_be_at_2[1].jpg 14/01/2006 17:19 12.53 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\asap[1].gif 14/01/2006 17:20 11.02 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\css_img_code[1].gif 14/01/2006 17:20 408 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\ctasp-server[1].htm 14/01/2006 16:55 20 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\index[1].htm 14/01/2006 17:20 97.27 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\nav[1].gif 14/01/2006 17:20 87 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\p_mq_add[1].gif 14/01/2006 17:20 1.59 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\p_offline[1].gif 14/01/2006 17:20 815 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\title1[1].jpg 14/01/2006 17:20 20.60 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\E5CJID2T\to_post_off[1].gif 14/01/2006 17:20 64 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\IR2JADUB\av-2879[1].gif 14/01/2006 17:20 4.51 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\IR2JADUB\gavadmin[1].gif 14/01/2006 17:20 2.20 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\IR2JADUB\ipb_global[1].js 14/01/2006 17:20 8.79 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\IR2JADUB\member[1].gif 14/01/2006 17:20 2.32 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\IR2JADUB\p_pm[1].gif 14/01/2006 17:20 1.19 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\IR2JADUB\tile_cat[1].gif 14/01/2006 17:20 2.70 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\IR2JADUB\tile_sub[1].gif 14/01/2006 17:20 1.54 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\ctasp-server[2].htm 14/01/2006 16:55 20 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\favicon[2].ico 14/01/2006 17:20 902 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\fchz_125sw[1].gif 14/01/2006 17:20 6.48 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\p_up[1].gif 14/01/2006 17:20 1.37 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\spacer[1].gif 14/01/2006 17:20 43 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\t_new[1].gif 14/01/2006 17:20 1.90 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\t_options[1].gif 14/01/2006 17:20 1.89 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\t_reply[1].gif 14/01/2006 17:20 1.91 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\title_strip[1].jpg 14/01/2006 17:20 401 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Local Settings\Temporary Internet Files\Content.IE5\O58LENWX\tt[1].gif 14/01/2006 17:19 42 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus 14/01/2006 17:28 0 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\regsrch 14/01/2006 17:08 0 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\regsrch\RegSrch.vbs 14/01/2006 17:08 3.18 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\regsrch\RegSrch.vbs:Zone.Identifier 14/01/2006 17:08 26 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\rootkitrevealer 14/01/2006 17:28 0 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\rootkitrevealer\README.TXT 14/01/2006 17:28 825 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\rootkitrevealer\README.TXT:Zone.Identifier 14/01/2006 17:28 26 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\rootkitrevealer\RootkitRevealer.chm 14/01/2006 17:08 99.77 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\rootkitrevealer\RootkitRevealer.chm:Zone.Identifier 14/01/2006 17:08 26 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\rootkitrevealer\RootkitRevealer.exe 14/01/2006 17:28 95.00 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\rootkitrevealer\RootkitRevealer.exe:Zone.Identifier 14/01/2006 17:28 26 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\Silent Runners.vbs 14/01/2006 17:09 278.93 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\Silent Runners.vbs:Zone.Identifier 14/01/2006 17:09 26 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\fix virus\Startup Programs (KAZ1) 2006-01-14 16.51.46.txt 14/01/2006 17:09 14.90 KB Hidden from Windows API.
C:\Documents and Settings\kaz75\My Documents\Downloads\New Folder 14/01/2006 17:08 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\regsrch 14/01/2006 16:58 0 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\regsrch.zip 14/01/2006 16:57 1.35 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\regsrch\RegSrch.vbs 14/01/2006 16:58 3.18 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\regsrch\RegSrch.vbs:Zone.Identifier 14/01/2006 16:58 26 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\rootkitrevealer.zip 14/01/2006 17:02 183.01 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\rootkitrevealer\README.TXT 14/01/2006 17:04 825 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\rootkitrevealer\README.TXT:Zone.Identifier 14/01/2006 17:04 26 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\rootkitrevealer\RootkitRevealer.chm 14/01/2006 17:04 99.77 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\rootkitrevealer\RootkitRevealer.chm:Zone.Identifier 14/01/2006 17:04 26 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\rootkitrevealer\RootkitRevealer.exe 14/01/2006 17:04 95.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\rootkitrevealer\RootkitRevealer.exe:Zone.Identifier 14/01/2006 17:04 26 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\Silent Runners.vbs 14/01/2006 16:45 278.93 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\Silent Runners.vbs:Zone.Identifier 14/01/2006 16:45 26 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\sOutTmp165855.tmp 14/01/2006 17:01 2.68 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\My Documents\Downloads\Startup Programs (KAZ1) 2006-01-14 16.51.46.txt 14/01/2006 16:52 14.90 KB Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\Recent\Art Dabbler 2.1.lnk 11/01/2006 12:55 624 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\Recent\fix virus.lnk 14/01/2006 17:17 531 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Recent\FWREADAL.lnk 22/08/2005 18:02 544 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\Recent\Mr.Bones.lnk 20/08/2005 01:09 544 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\Recent\Pictures Downloaded from AOL.lnk 11/01/2006 12:48 658 bytes Visible in Windows API, but not in MFT or directory index.
C:\Documents and Settings\kaz75\Recent\README.lnk 14/01/2006 17:28 922 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Recent\rootkitrevealer (2).lnk 14/01/2006 17:28 657 bytes Hidden from Windows API.
C:\Documents and Settings\kaz75\Recent\RootkitRevealer (3).lnk 14/01/2006 17:29 969 bytes Visible in directory index, but not Windows API or MFT.
C:\Documents and Settings\kaz75\winik.txt 14/01/2006 17:25 70 bytes Hidden from Windows API.
C:\Program Files\IncrediMail\bin\ ssce5432.dll 25/09/1619 09:47 208.00 KB Visible in Windows API, but not in MFT or directory index.
C:\Program Files\IncrediMail\bin\ssce5432.dll 23/01/29092 07:27 208.00 KB Hidden from Windows API.
C:\RECYCLER\S-1-5-21-4138060673-3628925640-3930988211-1006\Dc182.zip 14/01/2006 16:57 1.35 KB Hidden from Windows API.
C:\RECYCLER\S-1-5-21-4138060673-3628925640-3930988211-1006\Dc183.zip 14/01/2006 17:02 183.01 KB Hidden from Windows API.
C:\RECYCLER\S-1-5-21-4138060673-3628925640-3930988211-1006\Dc184.tmp 14/01/2006 17:28 2.68 KB Hidden from Windows API.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP349\A0056353.lnk 20/08/2005 01:09 544 bytes Hidden from Windows API.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP349\A0056354.lnk 11/01/2006 12:48 658 bytes Hidden from Windows API.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP349\A0056355.lnk 14/01/2006 17:28 544 bytes Hidden from Windows API.
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP349\A0056356.lnk 14/01/2006 17:28 624 bytes Hidden from Windows API.
C:\System Volume Information\catalog.wci\00010001.ci 14/01/2006 17:19 60.00 KB Hidden from Windows API.
C:\System Volume Information\catalog.wci\00010001.dir 14/01/2006 17:19 688 bytes Hidden from Windows API.
C:\System Volume Information\catalog.wci\00010003.ci 14/01/2006 17:13 588.00 KB Hidden from Windows API.
C:\System Volume Information\catalog.wci\00010003.dir 14/01/2006 17:13 3.65 KB Hidden from Windows API.
C:\System Volume Information\catalog.wci\CiFLfffc.000 14/01/2006 17:13 240 bytes Visible in Windows API, but not in MFT or directory index.
C:\System Volume Information\catalog.wci\CiFLfffc.001 14/01/2006 17:13 64.00 KB Visible in Windows API, but not in MFT or directory index.
C:\System Volume Information\catalog.wci\CiFLfffc.002 14/01/2006 17:13 64.00 KB Visible in Windows API, but not in MFT or directory index.
C:\System Volume Information\catalog.wci\CiFLfffd.000 14/01/2006 17:19 240 bytes Hidden from Windows API.
C:\System Volume Information\catalog.wci\CiFLfffd.001 14/01/2006 17:19 64.00 KB Hidden from Windows API.
C:\System Volume Information\catalog.wci\CiFLfffd.002 14/01/2006 17:19 64.00 KB Hidden from Windows API.
& finally, contents of winik.txt:
volume in drive C: has no lable
volume serial number is 1001-3AF
Where should I go from here?