Help - Search - Members - Calendar
Full Version: hurl.exe
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
Pages: 1, 2
sagaemia
i have hurl.exe on my desk top and i was not able to remove it. everytime when i try to delete it a window poped up saying that it being used by another user or program. and i need assistance.
~thanks
Mosaic1
Post a hijackthis log please. Download and then extract Hijackthis.exe to a new folder. Do not run it from the zip the desktop or a temp folder.

Here's a link:
http://www.merijn.org/files/hijackthis.zip

Do not remove anything using HijackThis. Save the log and then copy and paste the contents into your next reply here in this same topic. It lists many types of entries. Some are good, and others need to be removed. We will help you sort it out.
sagaemia
Logfile of HijackThis v1.99.1
Scan saved at 下午 05:38:44, on 2006/2/9
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\SAND\qqfacerclient.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O4 - HKLM\..\Run: [?? ?"h'??T3r鑒WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\dhneomt.exe
O4 - HKLM\..\Run: [=NOI] C:\windows\mrjj.exe
O4 - HKLM\..\Run: [F ma] C:\windows\mrjj.exe
O4 - HKLM\..\Run: [Komzsbf] C:\Program Files\Oqxks\Rmhkxpw.exe
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE\Update.exe
O4 - HKLM\..\Run: [res] C:\WINDOWS\system32\res.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O8 - Extra context menu item: 使用KuGoo3下载(&K) - C:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 匯出至 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: Windows Print Controller (Universal Disk Manager) - COMENET TECHNOLOGY - C:\Program Files\Common Files\SAND\qqfacerclient.exe
Mosaic1
Hurl.exe is created by REal Player when you download music. Later you'll be restartikng into safe mode. See if you can delete it when you get there.


Please download, install, and update the free version of Ewido trojan scanner:
http://www.ewido.net/en/download/


When you run ewido for the first time, you might get a warning "Database could not be found!". Click OK.

From the main ewido screen, click on update in the left menu, then click the Start update button.

After the update finishes (the status bar at the bottom will display "Update successful")

Exit Ewido. DO NOT scan yet.


If you are having problems with the updater, you can go to http://www.ewido.net/en/download/updates/ to update manually
-----------------
You will be restarting into Safe mode later. Here's help if you need it.

To use the F8 key to start Windows XP in Safe mode
Restart the computer.
Some computers have a progress bar that refers to the word BIOS. Others may not let you know what is happening.
As soon as the BIOS loads, begin tapping the F8 key on your keyboard. Do so until the Windows Advanced Options menu appears.
If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. If this happens, restart the computer and try again.
Using the arrow keys on the keyboard, select Safe mode and then press Enter.

-------------------
Restart into safe mode.
Run hijackthis. Select the following items and press the fix checked button:



O4 - HKLM\..\Run: [?? ?"h'??T3r鑒WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\dhneomt.exe
O4 - HKLM\..\Run: [=NOI] C:\windows\mrjj.exe
O4 - HKLM\..\Run: [F ma] C:\windows\mrjj.exe
O4 - HKLM\..\Run: [Komzsbf] C:\Program Files\Oqxks\Rmhkxpw.exe

O4 - HKLM\..\Run: [Update] C:\Program Files\Common Files\UPDATE\Update.exe
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab





Delete these files:

C:\windows\mrjj.exe
C:\Program Files\Common Files\UPDATE\Update.exe

-------

Next, run a scan with Ewido.

Click on the Scanner button in the left menu, then click on the Start button. This scan can take quite a while to run, so please be patient

If Ewido finds anything, it will pop up a notification. You can select "remove" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK.

When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.

Copy and paste the results from that scan back here when you return to post again.

*Note: Ewido is a free trial product for 14 days. After that you can purchase it for full features OR you can also keep the free version to use as an on-demand scanner (recommended).
You will still be able to manually update Ewido using the *update* button
---------------


Restart into Regular Windows.

I suspect you have more than what we have seen in just the hijackthis log. We'll have more to do.


Download Autoruns from this page:
http://www.sysinternals.com/Utilities/Autoruns.html

Unzip to a folder and the double click on autoruns.exe

Wait until the program has finished running (the status line will show 'Ready')
Under the 'Options' menu, make sure that 'Include Empty Sections' is checked.
Wait again until ready.

Be sure the 'Everything' tab is selected.
Select 'File -> Save' and save the output file.

Copy the contents of the Autoruns text file and post its contents in your next reply here.


----------------


You may have to reply more than once to fit all the logs into your response. Please be sure the entire contents of all logs is showing in your reponses. Thank you.




Post a startuplist too please. In Hijackthis press the Config Button
Click Misc Tools
Check both boxes next to the Generate StartupList log and then click the generate startuplist log button.

Paste the contents into your next reply here.
sagaemia
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 下午 07:18:54, 2006/2/10
+ Report-Checksum: E784EAA6

+ Scan result:

HKLM\SOFTWARE\Microsoft\Netstat -> Adware.Ezula : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{93CECBB2-6B1B-448D-91B9-72604EF70105} -> Adware.180Solutions : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFF4E223-7019-4CE7-BE03-D7D3C8CCE884} -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-21-3077702801-3347712112-3811928096-1006\Software\DNS -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-21-3077702801-3347712112-3811928096-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0CF098A0-CBAC-4EFB-8451-3AFC201C7222} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-3077702801-3347712112-3811928096-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2296428D-C133-4928-B76A-A200FF409572} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-3077702801-3347712112-3811928096-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4006DCA3-433D-4FC8-AC36-42DA7797DCB7} -> Adware.eZula : Cleaned with backup
HKU\S-1-5-21-3077702801-3347712112-3811928096-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{55BE9F0D-6CAF-4C3E-B125-5A13A8C9D0EC} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-3077702801-3347712112-3811928096-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95C60327-8E17-44D6-98EB-7EB70CC606DD} -> Adware.SafeSurfing : Cleaned with backup
HKU\S-1-5-21-3077702801-3347712112-3811928096-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9ADE0443-2AB2-4B23-A3F8-AC520773DE12} -> Adware.Begin2Search : Cleaned with backup
HKU\S-1-5-21-3077702801-3347712112-3811928096-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FBD2EBD0-E6DF-456E-B300-A4D10A90C683} -> Trojan.VB.aft : Cleaned with backup
HKU\S-1-5-21-3077702801-3347712112-3811928096-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFF4E223-7019-4CE7-BE03-D7D3C8CCE884} -> Adware.Shorty : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{93CECBB2-6B1B-448D-91B9-72604EF70105} -> Adware.180Solutions : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFF4E223-7019-4CE7-BE03-D7D3C8CCE884} -> Adware.Shorty : Cleaned with backup
:mozilla.10:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.11:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.12:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.13:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.14:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.15:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.16:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.17:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.18:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.19:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.23:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.24:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.47:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.48:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.50:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.52:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.53:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.54:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.55:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.56:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.57:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.58:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.64:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.65:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.66:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.67:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.68:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.69:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.70:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.78:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.79:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.85:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.91:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.92:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.93:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.94:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.95:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.96:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.99:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.100:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.101:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.102:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.103:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.104:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.105:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.106:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.123:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.124:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.131:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.132:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.139:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.143:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.144:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.145:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.146:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.181:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.182:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.183:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.194:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.195:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.196:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.197:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.209:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.210:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.211:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.212:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.213:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.214:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.215:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.216:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.217:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.218:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.220:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.221:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.222:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.223:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.224:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.241:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.242:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.245:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.251:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.252:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.253:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.254:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.255:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.256:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.257:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.258:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.279:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.280:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.281:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.282:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.283:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.284:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.286:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.287:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.288:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.289:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.293:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.294:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.295:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.296:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.297:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.298:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.299:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.300:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.301:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.302:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.326:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.336:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.356:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.361:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.362:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.363:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.364:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.389:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.390:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.391:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.392:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.393:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.394:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.395:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.396:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.398:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.399:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.400:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.401:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.402:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.403:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.413:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.414:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.415:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.416:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.424:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.442:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.448:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.449:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.452:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.453:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.457:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.482:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.483:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.484:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.490:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.491:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.496:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.515:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned with backup
:mozilla.516:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned with backup
:mozilla.528:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup
:mozilla.540:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.542:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.546:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Enhance : Cleaned with backup
:mozilla.559:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.560:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.561:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.562:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.569:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup
:mozilla.573:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.575:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.584:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.-- The nicest hobby on Earth ;) --counter : Cleaned with backup
:mozilla.585:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.-- The nicest hobby on Earth ;) --counter : Cleaned with backup
:mozilla.586:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup
:mozilla.594:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned with backup
:mozilla.595:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.596:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.607:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Abcsearch : Cleaned with backup
:mozilla.608:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Abcsearch : Cleaned with backup
:mozilla.614:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.616:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.624:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.647:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.648:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.650:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.651:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.653:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.654:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.655:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.656:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@anat.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@as1.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@c5.zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@data1.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@data2.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\KevinKo\Local Settings\Temp\180sainstallernusac.exe/clientax.dll -> Adware.180Solutions : Cleaned with backup
C:\Documents and Settings\KevinKo\Local Settings\Temp\180sainstallernusac.exe/clientax.dll -> Adware.180Solutions : Cleaned with backup
C:\Documents and Settings\KevinKo\Local Settings\Temp\99_app99.exe -> Dropper.Agent.xw : Cleaned with backup
C:\Documents and Settings\KevinKo\Local Settings\Temp\i8E.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\KevinKo\Local Settings\Temp\ICD2.tmp\UWFX5_0001_N56M0311NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.c : Cleaned with backup
C:\Documents and Settings\KevinKo\Local Settings\Temp\isinst.exe -> Downloader.IstBar.oe : Cleaned with backup
C:\Documents and Settings\KevinKo\Local Settings\Temp\temp.frC69B -> Adware.180Solutions : Cleaned with backup
C:\mstmp\install\Setup.exe -> Adware.Mediaplex : Cleaned with backup
C:\Program Files\Common Files\SAND\qqfacerclient.exe -> Adware.AdHelper : Cleaned with backup
C:\Program Files\Common Files\system32.dll/Catcher.dll -> Adware.Maxifiles : Cleaned with backup
C:\WINDOWS\=NOI.exe/mrjj.exe -> Trojan.LowZones.am : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX5_0001_N57M2811NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWFX6_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWFX5_0001_N57M2811NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWFX6_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\UWFX5_0001_N57M2811NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWFX5_0001_N56M0311NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.c : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWFX5_0001_N57M2811NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWFX6_0001_N57M0912NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\UWFX6_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Cleaned with backup
C:\WINDOWS\mynexus.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\NDNuninstall6_98.exe -> Adware.NewDotNet : Cleaned with backup
C:\WINDOWS\SYSTEM32\2B28282F2F2E323.exe -> Trojan.VB.aft : Cleaned with backup
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\SYSTEM32\Kerzhv.exe -> Adware.DealHelper : Cleaned with backup
C:\WINDOWS\SYSTEM32\magitp.exe -> Logger.VB.eh : Cleaned with backup
C:\WINDOWS\SYSTEM32\res.exe -> Downloader.Small.cdm : Cleaned with backup
C:\WINDOWS\werlqdz.exe -> Downloader.VB.hj : Cleaned with backup


::Report End
sagaemia
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit + C:\WINDOWS\system32\userinit.exe Userinit Logon Application Microsoft Corporation c:\windows\system32\userinit.exe HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell + Explorer.exe Windows Explorer Microsoft Corporation c:\windows\explorer.exe C:\Documents and Settings\KevinKo\Start Menu\Programs\Startup + Trillian.lnk Trillian Cerulean Studios c:\program files\trillian\trillian.exe HKCU\Software\Microsoft\Windows\CurrentVersion\Run + AIM AOL Instant Messenger America Online, Inc. c:\program files\aim\aim.exe + ctfmon.exe CTF Loader Microsoft Corporation c:\windows\system32\ctfmon.exe HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components + Address Book 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe + Browser Customizations Microsoft Internet Explorer Customization DLL Microsoft Corporation c:\windows\system32\iedkcs32.dll + Fax ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll + Internet Explorer Windows NT User Data Migration Tool Microsoft Corporation c:\windows\system32\shmgrate.exe + Internet Explorer Windows Setup API Microsoft Corporation c:\windows\system32\setupapi.dll + Internet Explorer 6 IE 5.0 Per-User Install Utility Microsoft Corporation c:\windows\system32\ie4uinit.exe + Microsoft Outlook Express 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe + Microsoft Windows Media Player Microsoft Windows Media Player Setup Utility Microsoft Corporation c:\windows\inf\unregmp2.exe + Microsoft Windows Media Player ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll + NetMeeting 3.01 ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll + Outlook Express Windows NT User Data Migration Tool Microsoft Corporation c:\windows\system32\shmgrate.exe + Themes Setup Microsoft© Register Server Microsoft Corporation c:\windows\system32\regsvr32.exe + Windows Desktop Update Microsoft© Register Server Microsoft Corporation c:\windows\system32\regsvr32.exe + Windows Messenger 4.7 ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler + Browseui preloader Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Component Categories cache daemon Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad + CDBurn Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll + PostBootReminder Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll + SysTray Systray shell service object Microsoft Corporation c:\windows\system32\stobject.dll + UPnPMonitor UPNP Tray Monitor and Folder Microsoft Corporation c:\windows\system32\upnpui.dll + WebCheck File not found: CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks + ewido shell guard c:\program files\ewido anti-malware\shellhook.dll HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved + %DESC_PublishDropTarget% Photo Printing Wizard Microsoft Corporation c:\windows\system32\photowiz.dll + &Address Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + .CAB file viewer Cabinet File Viewer Shell Extension Microsoft Corporation c:\windows\system32\cabview.dll + Accessible Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + ActiveX Cache Folder Object Control Viewer Microsoft Corporation c:\windows\system32\occache.dll + Address EditBox Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Administrative Tools Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + AlcoholShellEx AXShlEx.dll Alcohol Soft Development Team c:\program files\alcohol soft\alcohol 120\axshlex.dll + Audio Media Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll + Augmented Shell Folder Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Augmented Shell Folder 2 Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Auto Update Property Sheet Extension Automatic Updates Control Panel Microsoft Corporation c:\windows\system32\wuaucpl.cpl + Avi Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll + BandProxy Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Briefcase Windows Briefcase Microsoft Corporation c:\windows\system32\syncui.dll + CDF Extension Copy Hook Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Channel File Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll + Channel Handler Object Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll + Channel Menu Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll + Channel Properties Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll + Channel Shortcut Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll + Code Download Agent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll + Compatibility Page Compatibility Tab Shell Extension DLL Microsoft Corporation c:\windows\system32\slayerxp.dll + Compressed (zipped) Folder Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfldr.dll + Compressed (zipped) Folder Right Drag Handler Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfldr.dll + Compressed (zipped) Folder SendTo Target Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfldr.dll + ConnectionAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll + Crypto PKO Extension Crypto Shell Extensions Microsoft Corporation c:\windows\system32\cryptext.dll + Crypto Sign Extension Crypto Shell Extensions Microsoft Corporation c:\windows\system32\cryptext.dll + Custom MRU AutoCompleted List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Darwin App Publisher Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl + DfsShell Distributed File System shell extension Microsoft Corporation c:\windows\system32\dfsshlex.dll + Directory Context Menu Verbs Directory Service Common UI Microsoft Corporation c:\windows\system32\dsuiext.dll + Directory Object Find Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll + Directory Property UI Directory Service Common UI Microsoft Corporation c:\windows\system32\dsuiext.dll + Directory Query UI Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll + Directory Start/Search Find Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll + Disk Copy Extension Windows DiskCopy Microsoft Corporation c:\windows\system32\diskcopy.dll + Disk Quota UI Windows Shell Disk Quota UI DLL Microsoft Corporation c:\windows\system32\dskquoui.dll + Display Adapter CPL Extension Advanced display adapter properties Microsoft Corporation c:\windows\system32\deskadp.dll + Display Monitor CPL Extension Advanced display monitor properties Microsoft Corporation c:\windows\system32\deskmon.dll + Display Panning CPL Extension File not found: deskpan.dll + Display TroubleShoot CPL Extension Advanced display performance properties Microsoft Corporation c:\windows\system32\deskperf.dll + Download Status Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + DriveLetterAccess Drive Letter Access Component Sonic Solutions c:\windows\system32\dla\tfswshx.dll + DS Security Page Directory Service Security UI Microsoft Corporation c:\windows\system32\dssec.dll + E-mail Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Explorer Band Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Extensions Manager Folder Extensions Manager Microsoft Corporation c:\windows\system32\extmgr.dll + Favorites Band Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Fonts Windows Font Folder Microsoft Corporation c:\windows\system32\fontext.dll + Fonts Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + For &People... Find People Microsoft Corporation c:\program files\outlook express\wabfind.dll + FTP Folders Webview Microsoft Internet Explorer FTP Folder Shell Extension Microsoft Corporation c:\windows\system32\msieftp.dll + Fusion Cache Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscoree.dll + GDI+ file thumbnail extractor Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll + Get a Passport Wizard Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll + Global Folder Settings Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Help and Support Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Help and Support Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + History Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + HTML Thumbnail Extractor Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll + HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\windows\system32\hticons.dll + ICC Profile Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll + ICM Monitor Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll + ICM Printer Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll + ICM Scanner Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll + IE4 Suite Splash Screen Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + In-pane search Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Installed Apps Enumerator Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl + Internet Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Internet Name Space Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + InternetShortcut Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + ISFBand OC Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + iTunes iTunes Mini Player DLL Apple Computer, Inc. c:\program files\itunes\itunesminiplayer.dll + Microsoft Agent Character Property Sheet Handler Microsoft Agent Property Sheet Handler Microsoft Corporation c:\windows\msagent\agentpsh.dll + Microsoft AutoComplete Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Microsoft Browser Architecture Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Microsoft BrowserBand Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Microsoft Data Link Microsoft Data Access - OLE DB Core Services Microsoft Corporation c:\program files\common files\system\ole db\oledb32.dll + Microsoft DocProp Inplace Calendar Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll + Microsoft DocProp Inplace Droplist Combo Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll + Microsoft DocProp Inplace Edit Box Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll + Microsoft DocProp Inplace ML Edit Box Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll + Microsoft DocProp Inplace Time Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll + Microsoft DocProp Shell Ext Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll + Microsoft History AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Microsoft Internet Toolbar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Microsoft Multiple AutoComplete List Container Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Microsoft Shell Folder AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Microsoft Url History Service Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Microsoft Url Search Hook Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Midi Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll + MMC Icon Handler MMC Shell Extension DLL Microsoft Corporation c:\windows\system32\mmcshext.dll + MRU AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Multimedia File Property Sheet Control Panel Drivers Applet Microsoft Corporation c:\windows\system32\mmsys.cpl + MyDocs Copy Hook My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll + MyDocs Drop Target My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll + MyDocs Properties My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll + Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshell.dll + Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshell.dll + NTFS Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32.dll + Offline Files Folder Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll + Offline Files Folder Options Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll + Offline Files Menu Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll + OLE Docfile Property Page OLE DocFile Property Page Microsoft Corporation c:\windows\system32\docprop.dll + PlusPack CPL Extension Windows Theme API Microsoft Corporation c:\windows\system32\themeui.dll + Portable Media Devices Portable Media Devices Shell Extension Microsoft Corporation c:\windows\system32\audiodev.dll + Portable Media Devices Menu Portable Media Devices Shell Extension Microsoft Corporation c:\windows\system32\audiodev.dll + PostAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll + Previous Versions Previous Versions property page Microsoft Corporation c:\windows\system32\twext.dll + Previous Versions Property Page Previous Versions property page Microsoft Corporation c:\windows\system32\twext.dll + Print Ordering via the Web Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll + Printers Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32.dll + RecordNow! SendToExt Shell Extensions c:\program files\sonic\recordnow!\shlext.dll + Registry Tree Options Utility Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Remote Sessions CPL Extension Remote Sessions CPL Extension Microsoft Corporation c:\windows\system32\remotepg.dll + Run... Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll + Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll + Scheduled Tasks Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll + Search Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Search Assistant OC Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Search Band Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendmail.dll + Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendmail.dll + Set Program Access and Defaults Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Shell Application Manager Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl + Shell Automation Inproc Service Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Shell Band Site Menu Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Shell DeskBar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Shell DeskBarApp Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Shell DocObject Viewer Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Shell extensions for Microsoft Windows Network objects Network object shell UI Microsoft Corporation c:\windows\system32\ntlanui2.dll + Shell Extensions for RealOne Player RealPlayer Shell Extensions RealNetworks, Inc. c:\program files\ace mega codecs pack\systems\realmedia\rpshell.dll + Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshrui.dll + Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshrui.dll + Shell extensions for Windows Script Host Microsoft ® Shell Extension for Windows Script Host Microsoft Corporation c:\windows\system32\wshext.dll + Shell Image Data Factory Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll + Shell Image Property Handler Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll + Shell Image Verbs Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll + Shell properties for a DS object Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll + Shell Publishing Wizard Object Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll + Shell Rebar BandSite Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Shell Scrap DataHandler Shell scrap object handler Microsoft Corporation c:\windows\system32\shscrap.dll + Shell Search Band Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Subscription Folder Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll + Subscription Mgr Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll + Summary Info Thumbnail handler (DOCFILES) Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll + Synaptics Control Panel TouchPad Control Panel Extensions Synaptics, Inc. c:\program files\synaptics\syntp\syntpcpl.dll + Taskbar and Start Menu Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll + Tasks Folder Icon Handler Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll + Tasks Folder Shell Extension Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll + Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + The Internet Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll + Track Popup Bar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + TrayAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll + TridentImageExtractor Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Universal Plug and Play Devices UPNP Tray Monitor and Folder Microsoft Corporation c:\windows\system32\upnpui.dll + User Accounts Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll + User Assist Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + Video Media Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll + Video Thumbnail Extractor Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll + Wav Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll + Web Folders Microsoft Web Folders Microsoft Corporation c:\program files\common files\microsoft shared\web folders\mson-- The nicest hobby on Earth ;) --t.dll + Web Printer Shell Extension Print UI DLL Microsoft Corporation c:\windows\system32\printui.dll + Web Publishing Wizard Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll + Web Search Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll + WebCheck SyncMgr Handler Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll + WebCheckChannelAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll + WebCheckWebCrawler Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll + Windows Media Player Add to Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll + Windows Media Player Burn Audio CD Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll + Windows Media Player Play as Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll + WinRAR shell extension c:\program files\winrar\rarext.dll HKLM\Software\Classes\Folder\Shellex\ColumnHandlers + PDF Shell Extension PDF Shell Extension Adobe Systems, Inc. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll + {0D2E74C4-3C34-11d2-A27E-00C04FC30871} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll + {24F14F01-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll + {24F14F02-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll + {66742402-F9B9-11D1-A202-0000F81FEDEE} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks + shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll HKLM\Software\Microsoft\Internet Explorer\Extensions + AIM AOL Instant Messenger America Online, Inc. c:\program files\aim\aim.exe + Uninstall BitDefender Online Scanner v8 c:\windows\bdoscandel.exe Task Scheduler + ISP signup reminder 1.job Windows OOBE Balloon Reminder Microsoft Corporation c:\windows\system32\oobe\oobebaln.exe + McAfee.com Scan for Viruses - My Computer (KEVIN-KevinKo).job File not found: c:\program files\mcafee.com\vso\mcmnhdlr.exe HKLM\System\CurrentControlSet\Services + 6to4 Provides DDNS name registration and automatic IPv6 connectivity over an IPv4 network. If this service is stopped, other computers may not be able to reach it by name and the machine will only have IPv6 connectivity if it is connected to a native IPv6 network. If this service is disabled, any other services that explicitly depend on this service will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + AudioSrv Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + Browser Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + CryptSvc Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + DcomLaunch Provides launch functionality for DCOM services. Microsoft Corporation c:\windows\system32\svchost.exe + Dhcp Manages network configuration by registering and updating IP addresses and DNS names. Microsoft Corporation c:\windows\system32\svchost.exe + Dnscache Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + ERSvc Allows error reporting for services and applictions running in non-standard environments. Microsoft Corporation c:\windows\system32\svchost.exe + Eventlog Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped. Microsoft Corporation c:\windows\system32\services.exe + ewido security suite control ewido control ewido networks c:\program files\ewido anti-malware\ewidoctrl.exe + ewido security suite guard guard ewido networks c:\program files\ewido anti-malware\ewidoguard.exe + Fax Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network. Microsoft Corporation c:\windows\system32\fxssvc.exe + Framework Windows 运行加速器,提供软件的快速运行,恢复,以及加速功能。无法终止此服务。 Microsoft Corporation c:\windows\system32\svchost.exe + helpsvc Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + lanmanserver Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + lanmanworkstation Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + LmHosts Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Microsoft Corporation c:\windows\system32\svchost.exe + PlugPlay Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Microsoft Corporation c:\windows\system32\services.exe + PolicyAgent Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Microsoft Corporation c:\windows\system32\lsass.exe + ProtectedStorage Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Microsoft Corporation c:\windows\system32\lsass.exe + RpcSs Provides the endpoint mapper and other miscellaneous RPC services. Microsoft Corporation c:\windows\system32\svchost.exe + SamSs Stores security information for local user accounts. Microsoft Corporation c:\windows\system32\lsass.exe + Schedule Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + seclogon Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + SENS Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Microsoft Corporation c:\windows\system32\svchost.exe + SharedAccess Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. Microsoft Corporation c:\windows\system32\svchost.exe + ShellHWDetection Provides notifications for AutoPlay hardware events. Microsoft Corporation c:\windows\system32\svchost.exe + Spooler Loads files to memory for later printing. Microsoft Corporation c:\windows\system32\spoolsv.exe + srservice Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties Microsoft Corporation c:\windows\system32\svchost.exe + Themes Provides user experience theme management. Microsoft Corporation c:\windows\system32\svchost.exe + TrkWks Maintains links between NTFS files within a computer or across computers in a network domain. Microsoft Corporation c:\windows\system32\svchost.exe + UMWdf Enables Windows user mode drivers. Microsoft Corporation c:\windows\system32\wdfmgr.exe + Universal Disk Manager Windows μ?′òó?????×ó?μí3£?ìá1?°2è??ì?ùμ?′òó?·t???£ File not found: C:\Program Files\Common Files\SAND\qqfacerclient.exe + w32time Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + WebClient Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + winmgmt Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe + wscsvc Monitors system security settings and configurations. Microsoft Corporation c:\windows\system32\svchost.exe + wuauserv Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Microsoft Corporation c:\windows\system32\svchost.exe + WZCSVC Provides automatic configuration for the 802.11 adapters Microsoft Corporation c:\windows\system32\svchost.exe HKLM\System\CurrentControlSet\Services + abp480n5 AdvanSys SCSI Controller Driver Microsoft Corporation c:\windows\system32\drivers\abp480n5.sys + ACPI ACPI Driver for NT Microsoft Corporation c:\windows\system32\drivers\acpi.sys + adpu160m Adaptec Ultra160 SCSI miniport Microsoft Corporation c:\windows\system32\drivers\adpu160m.sys + aec Microsoft Acoustic Echo Canceller Microsoft Corporation c:\windows\system32\drivers\aec.sys + AFD AFD Networking Support Environment Microsoft Corporation c:\windows\system32\drivers\afd.sys + agp440 440 NT AGP Filter Microsoft Corporation c:\windows\system32\drivers\agp440.sys + agpCPQ CompatNT AGP Filter Microsoft Corporation c:\windows\system32\drivers\agpcpq.sys + Aha154x Adaptec AHA-154x series SCSI miniport Microsoft Corporation c:\windows\system32\drivers\aha154x.sys + aic78u2 Adaptec Ultra2 SCSI miniport Microsoft Corporation c:\windows\system32\drivers\aic78u2.sys + aic78xx Adaptec Ultra SCSI miniport Microsoft Corporation c:\windows\system32\drivers\aic78xx.sys + AliIde ALi mini IDE Driver Acer Laboratories Inc. c:\windows\system32\drivers\aliide.sys + alim1541 ALi M1541 NT AGP Filter Microsoft Corporation c:\windows\system32\drivers\alim1541.sys + amdagp AMD Win2000 AGP Filter Advanced Micro Devices, Inc. c:\windows\system32\drivers\amdagp.sys + amsint AMD SCSI/NET Controller Microsoft Corporation c:\windows\system32\drivers\amsint.sys + APPDRV App Support Driver Dell Inc c:\windows\system32\drivers\appdrv.sys + asc AdvanSys SCSI Controller Driver Advanced System Products, Inc. c:\windows\system32\drivers\asc.sys + asc3350p AdvanSys SCSI Card Driver Microsoft Corporation c:\windows\system32\drivers\asc3350p.sys + asc3550 AdvanSys Ultra-Wide PCI SCSI Driver Advanced System Products, Inc. c:\windows\system32\drivers\asc3550.sys + AsyncMac RAS Asynchronous Media Driver Microsoft Corporation c:\windows\system32\drivers\asyncmac.sys + atapi IDE/ATAPI Port Driver Microsoft Corporation c:\windows\system32\drivers\atapi.sys + Atmarpc ATM ARP Client Protocol Microsoft Corporation c:\windows\system32\drivers\atmarpc.sys + audstub AudStub Driver Microsoft Corporation c:\windows\system32\drivers\audstub.sys + BCM43XX BCM 802.11g Network Adapter wireless driver Broadcom Corporation c:\windows\system32\drivers\bcmwl5.sys + bcm4sbxp Broadcom Corporation NDIS 5.1 ethernet driver Broadcom Corporation c:\windows\system32\drivers\bcm4sbxp.sys + BCMModem Modem Device Driver Broadcom Corporation c:\windows\system32\drivers\bcmsm.sys + bDMusicb c:\documents and settings\kevinko\local settings\temp\bdmusicb.sys + cbidf CardBus/PCMCIA IDE Miniport Driver Microsoft Corporation c:\windows\system32\drivers\cbidf2k.sys + CCDECODE WDM Closed Caption VBI Codec Microsoft Corporation c:\windows\system32\drivers\ccdecode.sys + cd20xrnt IBM Portable CD-ROM Drive Miniport Microsoft Corporation c:\windows\system32\drivers\cd20xrnt.sys + Cdrom SCSI CD-ROM Driver Microsoft Corporation c:\windows\system32\drivers\cdrom.sys + CmBatt Control Method Battery Driver Microsoft Corporation c:\windows\system32\drivers\cmbatt.sys + CmdIde CMD PCI IDE Bus Driver CMD Technology, Inc. c:\windows\system32\drivers\cmdide.sys + Compbatt Composite Battery Driver Microsoft Corporation c:\windows\system32\drivers\compbatt.sys + Cpqarray Compaq Drive Array Controllers SCSI Miniport Driver Microsoft Corporation c:\windows\system32\drivers\cpqarray.sys + dac2w2k Mylex Disk Array Controller Driver Mylex Corporation c:\windows\system32\drivers\dac2w2k.sys + dac960nt Mylex Disk Array Controller Driver Microsoft Corporation c:\windows\system32\drivers\dac960nt.sys + Disk PnP Disk Driver Microsoft Corporation c:\windows\system32\drivers\disk.sys + DMusic Microsoft Kernel DLS Synthesizer Microsoft Corporation c:\windows\system32\drivers\dmusic.sys + dpti2o DPT SmartRAID miniport Microsoft Corporation c:\windows\system32\drivers\dpti2o.sys + drmkaud Microsoft Kernel DRM Audio Descrambler Filter Microsoft Corporation c:\windows\system32\drivers\drmkaud.sys + drvmcdb Device Driver Sonic Solutions c:\windows\system32\drivers\drvmcdb.sys + E100B NDIS 5 driver Intel Corporation c:\windows\system32\drivers\e100b325.sys + ewido security suite driver c:\program files\ewido anti-malware\guard.sys + Fdc Floppy Disk Controller Driver Microsoft Corporation c:\windows\system32\drivers\fdc.sys + Flpydisk Floppy Driver Microsoft Corporation c:\windows\system32\drivers\flpydisk.sys + FsVga Full Screen Video Driver Microsoft Corporation c:\windows\system32\drivers\fsvga.sys + Ftdisk FT Disk Driver Microsoft Corporation c:\windows\system32\drivers\ftdisk.sys + GEARAspiWDM CDRom Class Filter Driver GEAR Software Inc. c:\windows\system32\drivers\gearaspiwdm.sys + Gpc Generic Packet Classifier Microsoft Corporation c:\windows\system32\drivers\msgpc.sys + HidUsb USB Miniport Driver for Input Devices Microsoft Corporation c:\windows\system32\drivers\hidusb.sys + hpn NetRAID-4M Miniport Driver Microsoft Corporation c:\windows\system32\drivers\hpn.sys + HTTP This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\drivers\http.sys + i2omp I2O Miniport Driver Microsoft Corporation c:\windows\system32\drivers\i2omp.sys + i8042prt i8042 Port Driver Microsoft Corporation c:\windows\system32\drivers\i8042prt.sys + ialm Intel Graphics Miniport Driver Intel Corporation c:\windows\system32\drivers\ialmnt5.sys + Imapi IMAPI Kernel Driver Microsoft Corporation c:\windows\system32\drivers\imapi.sys + ini910u INITIO ini910u SCSI miniport Microsoft Corporation c:\windows\system32\drivers\ini910u.sys + IntelIde Intel PCI IDE Driver Microsoft Corporation c:\windows\system32\drivers\intelide.sys + intelppm Processor Device Driver Microsoft Corporation c:\windows\system32\drivers\intelppm.sys + Ip6Fw Provides intrusion prevention service for a home or small office network. Microsoft Corporation c:\windows\system32\drivers\ip6fw.sys + IpFilterDriver IP Traffic Filter Driver Microsoft Corporation c:\windows\system32\drivers\ipfltdrv.sys + IpInIp IP in IP Tunnel Driver Microsoft Corporation c:\windows\system32\drivers\ipinip.sys + IpNat IP Network Address Translator Microsoft Corporation c:\windows\system32\drivers\ipnat.sys + IPSec IPSEC driver Microsoft Corporation c:\windows\system32\drivers\ipsec.sys + IRENUM Infra-Red Bus Enumerator Microsoft Corporation c:\windows\system32\drivers\irenum.sys + isapnp PNP ISA Bus Driver Microsoft Corporation c:\windows\system32\drivers\isapnp.sys + Kbdclass Keyboard Class Driver Microsoft Corporation c:\windows\system32\drivers\kbdclass.sys + kmixer Kernel Mode Audio Mixer Microsoft Corporation c:\windows\system32\drivers\kmixer.sys + MDC8021X AEGIS Protocol (IEEE 802.1x) v2.3.1.7 Meetinghouse Data Communications c:\windows\system32\drivers\mdc8021x.sys + Mouclass Mouse Class Driver Microsoft Corporation c:\windows\system32\drivers\mouclass.sys + mouhid HID Mouse Filter Driver Microsoft Corporation c:\windows\system32\drivers\mouhid.sys + mraid35x MegaRAID RAID Controller Driver for Windows Whistler 32 American Megatrends Inc. c:\windows\system32\drivers\mraid35x.sys + MSKSSRV MS KS Server Microsoft Corporation c:\windows\system32\drivers\mskssrv.sys + MSPCLOCK MS Proxy Clock Microsoft Corporation c:\windows\system32\drivers\mspclock.sys + MSPQM MS Proxy Quality Manager Microsoft Corporation c:\windows\system32\drivers\mspqm.sys + mssmbios System Management BIOS Driver Microsoft Corporation c:\windows\system32\drivers\mssmbios.sys + MSTEE WDM Tee/Communication Transform Filter Microsoft Corporation c:\windows\system32\drivers\mstee.sys + NABTSFEC WDM NABTS/FEC VBI Codec Microsoft Corporation c:\windows\system32\drivers\nabtsfec.sys + NdisIP Microsoft IP Driver Microsoft Corporation c:\windows\system32\drivers\ndisip.sys + NdisTapi Remote Access NDIS TAPI Driver Microsoft Corporation c:\windows\system32\drivers\ndistapi.sys + Ndisuio NDIS Usermode I/O Protocol Microsoft Corporation c:\windows\system32\drivers\ndisuio.sys + NdisWan Remote Access NDIS WAN Driver Microsoft Corporation c:\windows\system32\drivers\ndiswan.sys + NetBT NetBios over Tcpip Microsoft Corporation c:\windows\system32\drivers\netbt.sys + nm Netmon NT Driver Microsoft Corporation c:\windows\system32\drivers\nmnt.sys + npkcrypt File not found: C:\Program Files\Gravity\RO\npkcrypt.sys + NPPTNT2 nProtect NPSC Kernel Mode Driver for NT INCA Internet Co., Ltd. c:\windows\system32\npptnt2.sys + nv NVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 NVIDIA Corporation c:\windows\system32\drivers\nv4_mini.sys + nvport Port Driver NVIDIA Corporation. c:\windows\system32\drivers\nvport.sys + NwlnkFlt IPX Traffic Filter Driver Microsoft Corporation c:\windows\system32\drivers\nwlnkflt.sys + NwlnkFwd IPX Traffic Forwarder Driver Microsoft Corporation c:\windows\system32\drivers\nwlnkfwd.sys + omci OMCI Device Driver Dell Inc c:\windows\system32\drivers\omci.sys + Parport Parallel Port Driver Microsoft Corporation c:\windows\system32\drivers\parport.sys + PCI NT Plug and Play PCI Enumerator Microsoft Corporation c:\windows\system32\drivers\pci.sys + PCIIde Generic PCI IDE Bus Driver Microsoft Corporation c:\windows\system32\drivers\pciide.sys + Pcmcia PCMCIA Bus Driver Microsoft Corporation c:\windows\system32\drivers\pcmcia.sys + perc2 PERC 2 Miniport Driver Microsoft Corporation c:\windows\system32\drivers\perc2.sys + perc2hib PERC 2 Hibernate Driver Microsoft Corporation c:\windows\system32\drivers\perc2hib.sys + pfc Padus® ASPI Shell Padus, Inc. c:\windows\system32\drivers\pfc.sys + PptpMiniport WAN Miniport (PPTP) Microsoft Corporation c:\windows\system32\drivers\raspptp.sys + PSched QoS Packet Scheduler Microsoft Corporation c:\windows\system32\drivers\psched.sys + Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\windows\system32\drivers\ptilink.sys + PxHelp20 Px Engine Device Driver for Windows 2000/XP Sonic Solutions c:\windows\system32\drivers\pxhelp20.sys + ql1080 Miniport Driver for QLogic ISP PCI Adapters QLogic Corporation c:\windows\system32\drivers\ql1080.sys + Ql10wnt Miniport Driver for QLogic ISP PCI Adapters Microsoft Corporation c:\windows\system32\drivers\ql10wnt.sys + ql12160 Miniport Driver for QLogic ISP PCI Adapters QLogic Corporation c:\windows\system32\drivers\ql12160.sys + ql1240 QLogic ISP PCI Adapters Microsoft Corporation c:\windows\system32\drivers\ql1240.sys + ql1280 Miniport Driver for QLogic ISP PCI Adapters QLogic Corporation c:\windows\system32\drivers\ql1280.sys + RasAcd Remote Access Auto Connection Driver Microsoft Corporation c:\windows\system32\drivers\rasacd.sys + Rasl2tp WAN Miniport (L2TP) Microsoft Corporation c:\windows\system32\drivers\rasl2tp.sys + RasPppoe Remote Access PPPOE Driver Microsoft Corporation c:\windows\system32\drivers\raspppoe.sys + Raspti Direct Parallel Microsoft Corporation c:\windows\system32\drivers\raspti.sys + RDPCDD RDP Miniport Microsoft Corporation c:\windows\system32\drivers\rdpcdd.sys + rdpdr Microsoft RDP Device redirector Microsoft Corporation c:\windows\system32\drivers\rdpdr.sys + redbook Redbook Audio Filter Driver Microsoft Corporation c:\windows\system32\drivers\redbook.sys + Secdrv SafeDisc driver Macrovision Europe Ltd c:\windows\system32\drivers\secdrv.sys + serenum Serial Port Enumerator Microsoft Corporation c:\windows\system32\drivers\serenum.sys + Serial Serial Device Driver Microsoft Corporation c:\windows\system32\drivers\serial.sys + Sfloppy SCSI Floppy Driver Microsoft Corporation c:\windows\system32\drivers\sfloppy.sys + sisagp SiS NT AGP Filter Silicon Integrated Systems Corporation c:\windows\system32\drivers\sisagp.sys + SLIP Microsoft Slip Deframing Filter Minidriver Microsoft Corporation c:\windows\system32\drivers\slip.sys + sonypvs1 File not found: system32\DRIVERS\sonypvs1.sys + Sparrow Adaptec AIC-6x60 series SCSI miniport Adaptec, Inc. c:\windows\system32\drivers\sparrow.sys + splitter Microsoft Kernel Audio Splitter Microsoft Corporation c:\windows\system32\drivers\splitter.sys + STAC97 SigmaTel Audio Driver (WDM) SigmaTel, Inc. c:\windows\system32\drivers\stac97.sys + streamip Microsoft IP Test Driver Microsoft Corporation c:\windows\system32\drivers\streamip.sys + StyleXPHelper StyleXP Windows ® 2000 DDK provider c:\program files\tgtsoft\stylexp\stylexphelper.exe + swenum Plug and Play Software Device Enumerator Microsoft Corporation c:\windows\system32\drivers\swenum.sys + swmidi Microsoft GS Wavetable Synthesizer Microsoft Corporation c:\windows\system32\drivers\swmidi.sys + sym_hi Symbios Hi-Perf SCSI Miniport Driver LSI Logic c:\windows\system32\drivers\sym_hi.sys + sym_u3 Symbios Ultra3 SCSI Miniport Driver LSI Logic c:\windows\system32\drivers\sym_u3.sys + symc810 Symbios Logic Inc. SCSI Miniport Driver Symbios Logic Inc. c:\windows\system32\drivers\symc810.sys + symc8xx Symbios 8XX SCSI Miniport Driver LSI Logic c:\windows\system32\drivers\symc8xx.sys + SynTP Synaptics Touchpad Driver Synaptics, Inc. c:\windows\system32\drivers\syntp.sys + sysaudio System Audio WDM Filter Microsoft Corporation c:\windows\system32\drivers\sysaudio.sys + Tcpip TCP/IP Protocol Driver Microsoft Corporation c:\windows\system32\drivers\tcpip.sys + Tcpip6 Microsoft IPv6 Protocol Driver Microsoft Corporation c:\windows\system32\drivers\tcpip6.sys + TermDD Terminal Server Driver Microsoft Corporation c:\windows\system32\drivers\termdd.sys + TosIde Toshiba PCI IDE Controller Microsoft Corporation c:\windows\system32\drivers\toside.sys + tunmp Microsoft Tunnel Interface Driver Microsoft Corporation c:\windows\system32\drivers\tunmp.sys + ultra Promise Ultra66 Miniport Driver Promise Technology, Inc. c:\windows\system32\drivers\ultra.sys + Update Update Driver Microsoft Corporation c:\windows\system32\drivers\update.sys + usbaudio USB Audio Class Driver Microsoft Corporation c:\windows\system32\drivers\usbaudio.sys + usbccgp USB Common Class Generic Parent Driver Microsoft Corporation c:\windows\system32\drivers\usbccgp.sys + usbehci EHCI eUSB Miniport Driver Microsoft Corporation c:\windows\system32\drivers\usbehci.sys + usbhub Default Hub Driver for USB Microsoft Corporation c:\windows\system32\drivers\usbhub.sys + USBSTOR USB Mass Storage Class Driver Microsoft Corporation c:\windows\system32\drivers\usbstor.sys + usbuhci UHCI USB Miniport Driver Microsoft Corporation c:\windows\system32\drivers\usbuhci.sys + VgaSave VGA/Super VGA Video Driver Microsoft Corporation c:\windows\system32\drivers\vga.sys + viaagp VIA NT AGP Filter Microsoft Corporation c:\windows\system32\drivers\viaagp.sys + ViaIde Generic PCI IDE Bus Driver Microsoft Corporation c:\windows\system32\drivers\viaide.sys + Wanarp Remote Access IP ARP Driver Microsoft Corporation c:\windows\system32\drivers\wanarp.sys + wanatw File not found: system32\DRIVERS\wanatw4.sys + wdmaud MMSYSTEM Wave/Midi API mapper Microsoft Corporation c:\windows\system32\drivers\wdmaud.sys + WSTCODEC WDM WST Codec Driver Microsoft Corporation c:\windows\system32\drivers\wstcodec.sys + xmasbus Plug and Play BIOS Extension c:\windows\system32\drivers\xmasbus.sys + xmasscsi SCSI miniport c:\windows\system32\drivers\xmasscsi.sys HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute + autocheck autochk * Auto Check Utility Microsoft Corporation c:\windows\system32\autochk.exe HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options + Your Image File Name Here without a path Symbolic Debugger for Windows 2000 Microsoft Corporation c:\windows\system32\ntsd.exe HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls + advapi32 Advanced Windows 32 Base API Microsoft Corporation c:\windows\system32\advapi32.dll + comdlg32 Common Dialogs DLL Microsoft Corporation c:\windows\system32\comdlg32.dll + gdi32 GDI Client DLL Microsoft Corporation c:\windows\system32\gdi32.dll + imagehlp Windows NT Image Helper Microsoft Corporation c:\windows\system32\imagehlp.dll + kernel32 Windows NT BASE API Client DLL Microsoft Corporation c:\windows\system32\kernel32.dll + lz32 LZ Expand/Compress API DLL Microsoft Corporation c:\windows\system32\lz32.dll + ole32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\ole32.dll + oleaut32 Microsoft Corporation c:\windows\system32\oleaut32.dll + olecli32 Object Linking and Embedding Client Library Microsoft Corporation c:\windows\system32\olecli32.dll + olecnv32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olecnv32.dll + olesvr32 Object Linking and Embedding Server Library Microsoft Corporation c:\windows\system32\olesvr32.dll + olethk32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olethk32.dll + rpcrt4 Remote Procedure Call Runtime Microsoft Corporation c:\windows\system32\rpcrt4.dll + shell32 Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll + url Internet Shortcut Shell Extension DLL Microsoft Corporation c:\windows\system32\url.dll + urlmon OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll + user32 Windows XP USER API Client DLL Microsoft Corporation c:\windows\system32\user32.dll + version Version Checking and File Installation Libraries Microsoft Corporation c:\windows\system32\version.dll + wininet Internet Extensions for Win32 Microsoft Corporation c:\windows\system32\wininet.dll + wldap32 Win32 LDAP API DLL Microsoft Corporation c:\windows\system32\wldap32.dll HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify + crypt32chain Crypto API32 Microsoft Corporation c:\windows\system32\crypt32.dll + cryptnet Crypto Network Related API Microsoft Corporation c:\windows\system32\cryptnet.dll + cscdll Offline Network Agent Microsoft Corporation c:\windows\system32\cscdll.dll + ScCertProp Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll + Schedule Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll + sclgntfy Secondary Logon Service Notification DLL Microsoft Corporation c:\windows\system32\sclgntfy.dll + SensLogn Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll + termsrv Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll + wlballoon Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll HKCU\Control Panel\Desktop\Scrnsave.exe + C:\WINDOWS\MATRIX~1.SCR 32 Bit CineMac Screen Saver Engine MacSourcery c:\windows\matrix code.scr HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9 + MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3209255F-FCE9-4B81-9A6F-1604FE2E9678}] DATAGRAM 5 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3209255F-FCE9-4B81-9A6F-1604FE2E9678}] SEQPACKET 5 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip6_{37E9851C-DA1E-496E-818C-A9CFD9B13122}] DATAGRAM 6 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip6_{37E9851C-DA1E-496E-818C-A9CFD9B13122}] SEQPACKET 6 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip6_{40927BA9-6FF1-4F71-9170-B73B05C5F108}] DATAGRAM 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip6_{40927BA9-6FF1-4F71-9170-B73B05C5F108}] SEQPACKET 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip6_{66B34C7B-415F-44E9-9892-9ECF1324135B}] DATAGRAM 7 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip6_{66B34C7B-415F-44E9-9892-9ECF1324135B}] SEQPACKET 7 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{2810EB22-763D-4D0C-9450-64BBD1758685}] DATAGRAM 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{2810EB22-763D-4D0C-9450-64BBD1758685}] SEQPACKET 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{3209255F-FCE9-4B81-9A6F-1604FE2E9678}] DATAGRAM 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{3209255F-FCE9-4B81-9A6F-1604FE2E9678}] SEQPACKET 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{40927BA9-6FF1-4F71-9170-B73B05C5F108}] DATAGRAM 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{40927BA9-6FF1-4F71-9170-B73B05C5F108}] SEQPACKET 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{531D3D38-B38F-4A40-9052-52EFBA55506B}] DATAGRAM 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{531D3D38-B38F-4A40-9052-52EFBA55506B}] SEQPACKET 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{66B34C7B-415F-44E9-9892-9ECF1324135B}] DATAGRAM 8 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD NetBIOS [\Device\NetBT_Tcpip_{66B34C7B-415F-44E9-9892-9ECF1324135B}] SEQPACKET 8 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD Tcpip [RAW/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD Tcpip [RAW/IPv6] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD Tcpip [TCP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD Tcpip [TCP/IPv6] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD Tcpip [UDP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + MSAFD Tcpip [UDP/IPv6] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll + RSVP TCP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp.dll + RSVP UDP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp.dll HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors + BJ Language Monitor Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation c:\windows\system32\cnbjmon.dll + Local Port Local Spooler DLL Microsoft Corporation c:\windows\system32\localspl.dll + Microsoft Shared Fax Monitor Microsoft Fax Print Monitor Microsoft Corporation c:\windows\system32\fxsmon.dll + PJL Language Monitor PJL Language monitor Microsoft Corporation c:\windows\system32\pjlmon.dll + Standard TCP/IP Port Standard TCP/IP Port Monitor DLL Microsoft Corporation c:\windows\system32\tcpmon.dll + USB Monitor Standard Dynamic Printing Port Monitor DLL Microsoft Corporation c:\windows\system32\usbmon.dll
sagaemia
StartupList report, 2006/2/10, 下午 07:26:06
StartupList version: 1.52.2
Started from : C:\Documents and Settings\KevinKo\Desktop\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\KevinKo\Start Menu\Programs\Startup]
Trillian.lnk = C:\Program Files\Trillian\trillian.exe

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
*No files*

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

(Default) =
?? ?"h'??T3r鑒WC:\Program Files\ISTsvc\istsvc.exe = C:\WINDOWS\dhneomt.exe
YLive.exe = C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
HostManager = C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
AIM = C:\Program Files\AIM\aim.exe -cnetwait.odl

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

[{8b15971b-5355-4c82-8c07-7e181ea07608}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\MATRIX~1.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

(no name) - C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX - {A9930D97-9CF0-42A0-A10D-4F28836579D5}

--------------------------------------------------

Enumerating Task Scheduler jobs:

ISP signup reminder 1.job
McAfee.com Scan for Viruses - My Computer (KEVIN-KevinKo).job

--------------------------------------------------

Enumerating Download Program Files:

[{00000055-9980-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/fhg.CAB

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM32\Macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock...director/sw.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[BDSCANONLINE Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\oscan8.ocx
CODEBASE = http://download.bitdefender.com/resources/scan8/oscan8.cab

[Housecall ActiveX 6.5]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll
CODEBASE = http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab

[Java Plug-in 1.5.0_04]
InProcServer32 = C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

[Java Plug-in 1.5.0_03]
InProcServer32 = C:\Program Files\Java\jre1.5.0_03\bin\npjpi150_03.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

[Java Plug-in 1.5.0_04]
InProcServer32 = C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll
Protocol #22: C:\WINDOWS\system32\mswsock.dll
Protocol #23: C:\WINDOWS\system32\mswsock.dll
Protocol #24: C:\WINDOWS\system32\mswsock.dll
Protocol #25: C:\WINDOWS\system32\mswsock.dll
Protocol #26: C:\WINDOWS\system32\mswsock.dll

--------------------------------------------------

Enumerating Windows NT/2000/XP services

IPv6 Helper Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
abp480n5: system32\DRIVERS\ABP480N5.SYS (system)
Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
adpu160m: system32\DRIVERS\adpu160m.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD: \SystemRoot\System32\drivers\afd.sys (system)
Intel AGP Bus Filter: system32\DRIVERS\agp440.sys (system)
Compaq AGP Bus Filter: system32\DRIVERS\agpCPQ.sys (system)
Aha154x: system32\DRIVERS\aha154x.sys (system)
aic78u2: system32\DRIVERS\aic78u2.sys (system)
aic78xx: system32\DRIVERS\aic78xx.sys (system)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AliIde: system32\DRIVERS\aliide.sys (system)
ALI AGP Bus Filter: system32\DRIVERS\alim1541.sys (system)
AMD AGP Bus Filter Driver: system32\DRIVERS\amdagp.sys (system)
amsint: system32\DRIVERS\amsint.sys (system)
APPDRV: \SystemRoot\SYSTEM32\DRIVERS\APPDRV.SYS (system)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
asc: system32\DRIVERS\asc.sys (system)
asc3350p: system32\DRIVERS\asc3350p.sys (system)
asc3550: system32\DRIVERS\asc3550.sys (system)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
Dell Wireless WLAN Card Driver: system32\DRIVERS\bcmwl5.sys (manual start)
Broadcom 440x 10/100 Integrated Controller XP Driver: system32\DRIVERS\bcm4sbxp.sys (manual start)
BCM V.92 56K Modem: system32\DRIVERS\BCMSM.sys (manual start)
bDMusicb: \??\C:\DOCUME~1\KevinKo\LOCALS~1\Temp\bDMusicb.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
cbidf: system32\DRIVERS\cbidf2k.sys (system)
Closed Caption Decoder: system32\DRIVERS\CCDECODE.sys (manual start)
cd20xrnt: system32\DRIVERS\cd20xrnt.sys (system)
CD-ROM Driver: system32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
Microsoft ACPI Control Method Battery Driver: system32\DRIVERS\CmBatt.sys (manual start)
CmdIde: system32\DRIVERS\cmdide.sys (system)
Microsoft Composite Battery Driver: system32\DRIVERS\compbatt.sys (system)
COM+ System Application: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cpqarray: system32\DRIVERS\cpqarray.sys (system)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
dac2w2k: system32\DRIVERS\dac2w2k.sys (system)
dac960nt: system32\DRIVERS\dac960nt.sys (system)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
dpti2o: system32\DRIVERS\dpti2o.sys (system)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
drvmcdb: system32\drivers\drvmcdb.sys (system)
drvnddm: system32\drivers\drvnddm.sys (autostart)
Intel® PRO Adapter Driver: system32\DRIVERS\e100b325.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start)
ewido security suite control: C:\Program Files\ewido anti-malware\ewidoctrl.exe (autostart)
ewido security suite driver: \??\C:\Program Files\ewido anti-malware\guard.sys (system)
ewido security suite guard: C:\Program Files\ewido anti-malware\ewidoguard.exe (autostart)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Fax: %systemroot%\system32\fxssvc.exe (autostart)
Floppy Disk Controller Driver: system32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: system32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\DRIVERS\fltMgr.sys (system)
Application Accelerator: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
FsVga: system32\DRIVERS\fsvga.sys (system)
Volume Manager Driver: system32\DRIVERS\ftdisk.sys (system)
GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)
Generic Packet Classifier: system32\DRIVERS\msgpc.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Microsoft HID Class Driver: system32\DRIVERS\hidusb.sys (manual start)
hpn: system32\DRIVERS\hpn.sys (system)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i2omp: system32\DRIVERS\i2omp.sys (system)
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system)
ialm: system32\DRIVERS\ialmnt5.sys (manual start)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\system32\imapi.exe (manual start)
ini910u: system32\DRIVERS\ini910u.sys (system)
IntelIde: system32\DRIVERS\intelide.sys (system)
Intel Processor Driver: system32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys (manual start)
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
iPodService: C:\Program Files\iPod\bin\iPodService.exe (manual start)
IPSEC driver: system32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sys (system)
Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
AEGIS Protocol (IEEE 802.1x) v2.3.1.7: system32\DRIVERS\mdc8021x.sys (autostart)
Messenger: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\system32\mnmsrvc.exe (manual start)
Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: system32\DRIVERS\mouhid.sys (manual start)
mraid35x: system32\DRIVERS\mraid35x.sys (system)
WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start)
Microsoft Streaming Tee/Sink-to-Sink Converter: system32\drivers\MSTEE.sys (manual start)
NABTS/FEC VBI Codec: system32\DRIVERS\NABTSFEC.sys (manual start)
Microsoft TV/Video Connection: system32\DRIVERS\NdisIP.sys (manual start)
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: system32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: system32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\system32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Network Location Awareness (NLA): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Network Monitor Driver: system32\DRIVERS\NMnt.sys (manual start)
npkcrypt: \??\C:\Program Files\Gravity\RO\npkcrypt.sys (manual start)
NPPTNT2: \??\C:\WINDOWS\system32\npptNT2.sys (system)
NT LM Security Support Provider: %SystemRoot%\system32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
nv: system32\DRIVERS\nv4_mini.sys (manual start)
NVIDIA PORT IO Control Driver: \??\C:\WINDOWS\system32\Drivers\nvport.sys (system)
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
OMCI WDM Device Driver: system32\DRIVERS\omci.sys (system)
PACSPTISVR: C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe (manual start)
Parallel port driver: system32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sys (system)
Pcmcia: system32\DRIVERS\pcmcia.sys (system)
perc2: system32\DRIVERS\perc2.sys (system)
perc2hib: system32\DRIVERS\perc2hib.sys (system)
Padus ASPI Shell: system32\drivers\pfc.sys (manual start)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart)
WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: system32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\Drivers\PxHelp20.sys (system)
ql1080: system32\DRIVERS\ql1080.sys (system)
Ql10wnt: system32\DRIVERS\ql10wnt.sys (system)
ql12160: system32\DRIVERS\ql12160.sys (system)
ql1240: system32\DRIVERS\ql1240.sys (system)
ql1280: system32\DRIVERS\ql1280.sys (system)
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: system32\DRIVERS\raspti.sys (manual start)
Rdbss: system32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: system32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: system32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: system32\DRIVERS\serenum.sys (manual start)
Serial port driver: system32\DRIVERS\serial.sys (system)
High-Capacity Floppy Disk Drive: system32\DRIVERS\sfloppy.sys (manual start)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SIS AGP Bus Filter: system32\DRIVERS\sisagp.sys (system)
BDA Slip De-Framer: system32\DRIVERS\SLIP.sys (manual start)
Sony Digital Imaging Video2: system32\DRIVERS\sonypvs1.sys (manual start)
Sparrow: system32\DRIVERS\sparrow.sys (system)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Sony SPTI Service: C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe (manual start)
System Restore Filter Driver: system32\DRIVERS\sr.sys (system)
System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Srv: system32\DRIVERS\srv.sys (manual start)
sscdbhk5: system32\drivers\sscdbhk5.sys (system)
SSDP Discovery Service: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
ssrtln: system32\drivers\ssrtln.sys (system)
Audio Driver (WDM) - SigmaTel CODEC: system32\drivers\stac97.sys (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (manual start)
BDA IPSink: system32\DRIVERS\StreamIP.sys (manual start)
StyleXPHelper: \??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe (system)
StyleXPService: "C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe" (disabled)
Software Bus Driver: system32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhost.exe /Processid:{A445BD1E-49EE-4607-B370-5CCA447377C4} (manual start)
symc810: system32\DRIVERS\symc810.sys (system)
symc8xx: system32\DRIVERS\symc8xx.sys (system)
sym_hi: system32\DRIVERS\sym_hi.sys (system)
sym_u3: system32\DRIVERS\sym_u3.sys (system)
Synaptics TouchPad Driver: system32\DRIVERS\SynTP.sys (manual start)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: system32\DRIVERS\tcpip.sys (system)
Microsoft IPv6 Protocol Driver: system32\DRIVERS\tcpip6.sys (system)
Terminal Device Driver: system32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
tfsnboio: system32\dla\tfsnboio.sys (autostart)
tfsncofs: system32\dla\tfsncofs.sys (autostart)
tfsndrct: system32\dla\tfsndrct.sys (autostart)
tfsndres: system32\dla\tfsndres.sys (autostart)
tfsnifs: system32\dla\tfsnifs.sys (autostart)
tfsnopio: system32\dla\tfsnopio.sys (autostart)
tfsnpool: system32\dla\tfsnpool.sys (autostart)
tfsnudf: system32\dla\tfsnudf.sys (autostart)
tfsnudfa: system32\dla\tfsnudfa.sys (autostart)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
TosIde: system32\DRIVERS\toside.sys (system)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Microsoft Tun Miniport Adapter Driver: system32\DRIVERS\tunmp.sys (manual start)
ultra: system32\DRIVERS\ultra.sys (system)
Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart)
Windows Print Controller: C:\Program Files\Common Files\SAND\qqfacerclient.exe (autostart)
Microcode Update Driver: system32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
USB Audio Driver (WDM): system32\drivers\usbaudio.sys (manual start)
Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
Microsoft USB Standard Hub Driver: system32\DRIVERS\usbhub.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start)
User Privilege Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
VIA AGP Bus Filter: system32\DRIVERS\viaagp.sys (system)
ViaIde: system32\DRIVERS\viaide.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
WAN Miniport (ATW): system32\DRIVERS\wanatw4.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
WLTRYSVC: %SystemRoot%\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe (disabled)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\system32\wbem\wmiapsrv.exe (manual start)
Windows Socket 2.0 Non-IFS Service Provider Support Environment: \SystemRoot\System32\drivers\ws2ifsl.sys (disabled)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
World Standard Teletext Codec: system32\DRIVERS\WSTCODEC.SYS (manual start)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
xmasbus: system32\DRIVERS\xmasbus.sys (system)
xmasscsi: System32\Drivers\xmasscsi.sys (system)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: *Registry key not found*
SysTray: C:\WINDOWS\system32\stobject.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*Registry key not found*

--------------------------------------------------

End of report, 37,542 bytes
Report generated in 0.371 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Mosaic1
Your autoruns log is unreadable. Please go back and post it again. Turn word wrap on. In notepad before you do.
Mosaic1
Please edit your previous post. I can't read that autoruns log as it is. Run autoruns again. Do not save in Wordpad if that's what you did. I am leaving shortly. Thank you.
sagaemia
HKCU\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup

HKLM\SOFTWARE\Policies\Microsoft\Windows\System\Scripts\Startup

HKCU\Software\Policies\Microsoft\Windows\System\Scripts\Logon

HKLM\Software\Policies\Microsoft\Windows\System\Scripts\Logon

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit

+ C:\WINDOWS\system32\userinit.exe Userinit Logon Application Microsoft Corporation c:\windows\system32\userinit.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell

HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\Shell

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

+ Explorer.exe Windows Explorer Microsoft Corporation c:\windows\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce

C:\Documents and Settings\All Users\Start Menu\Programs\Startup

C:\Documents and Settings\KevinKo\Start Menu\Programs\Startup

+ Trillian.lnk Trillian Cerulean Studios c:\program files\trillian\trillian.exe

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Load

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\Run

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

+ AIM AOL Instant Messenger America Online, Inc. c:\program files\aim\aim.exe

+ ctfmon.exe CTF Loader Microsoft Corporation c:\windows\system32\ctfmon.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components

+ Address Book 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

+ Browser Customizations Microsoft Internet Explorer Customization DLL Microsoft Corporation c:\windows\system32\iedkcs32.dll

+ Fax ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll

+ Internet Explorer Windows NT User Data Migration Tool Microsoft Corporation c:\windows\system32\shmgrate.exe

+ Internet Explorer Windows Setup API Microsoft Corporation c:\windows\system32\setupapi.dll

+ Internet Explorer 6 IE 5.0 Per-User Install Utility Microsoft Corporation c:\windows\system32\ie4uinit.exe

+ Microsoft Outlook Express 6 Outlook Express Setup Library Microsoft Corporation c:\program files\outlook express\setup50.exe

+ Microsoft Windows Media Player Microsoft Windows Media Player Setup Utility Microsoft Corporation c:\windows\inf\unregmp2.exe

+ Microsoft Windows Media Player ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll

+ NetMeeting 3.01 ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll

+ Outlook Express Windows NT User Data Migration Tool Microsoft Corporation c:\windows\system32\shmgrate.exe

+ Themes Setup Microsoft© Register Server Microsoft Corporation c:\windows\system32\regsvr32.exe

+ Windows Desktop Update Microsoft© Register Server Microsoft Corporation c:\windows\system32\regsvr32.exe

+ Windows Messenger 4.7 ADVPACK Microsoft Corporation c:\windows\system32\advpack.dll

HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler

+ Browseui preloader Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Component Categories cache daemon Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

+ CDBurn Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ PostBootReminder Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ SysTray Systray shell service object Microsoft Corporation c:\windows\system32\stobject.dll

+ UPnPMonitor UPNP Tray Monitor and Folder Microsoft Corporation c:\windows\system32\upnpui.dll

+ WebCheck File not found: CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InprocServer32

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

+ ewido shell guard c:\program files\ewido anti-malware\shellhook.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

+ %DESC_PublishDropTarget% Photo Printing Wizard Microsoft Corporation c:\windows\system32\photowiz.dll

+ &Address Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ .CAB file viewer Cabinet File Viewer Shell Extension Microsoft Corporation c:\windows\system32\cabview.dll

+ Accessible Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ ActiveX Cache Folder Object Control Viewer Microsoft Corporation c:\windows\system32\occache.dll

+ Address EditBox Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Administrative Tools Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ AlcoholShellEx AXShlEx.dll Alcohol Soft Development Team c:\program files\alcohol soft\alcohol 120\axshlex.dll

+ Audio Media Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ Augmented Shell Folder Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Augmented Shell Folder 2 Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Auto Update Property Sheet Extension Automatic Updates Control Panel Microsoft Corporation c:\windows\system32\wuaucpl.cpl

+ Avi Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ BandProxy Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Briefcase Windows Briefcase Microsoft Corporation c:\windows\system32\syncui.dll

+ CDF Extension Copy Hook Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Channel File Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll

+ Channel Handler Object Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll

+ Channel Menu Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll

+ Channel Properties Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll

+ Channel Shortcut Channel Definition File Viewer Microsoft Corporation c:\windows\system32\cdfview.dll

+ Code Download Agent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Compatibility Page Compatibility Tab Shell Extension DLL Microsoft Corporation c:\windows\system32\slayerxp.dll

+ Compressed (zipped) Folder Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfldr.dll

+ Compressed (zipped) Folder Right Drag Handler Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfldr.dll

+ Compressed (zipped) Folder SendTo Target Compressed (zipped) Folders Microsoft Corporation c:\windows\system32\zipfldr.dll

+ ConnectionAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Crypto PKO Extension Crypto Shell Extensions Microsoft Corporation c:\windows\system32\cryptext.dll

+ Crypto Sign Extension Crypto Shell Extensions Microsoft Corporation c:\windows\system32\cryptext.dll

+ Custom MRU AutoCompleted List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Darwin App Publisher Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl

+ DfsShell Distributed File System shell extension Microsoft Corporation c:\windows\system32\dfsshlex.dll

+ Directory Context Menu Verbs Directory Service Common UI Microsoft Corporation c:\windows\system32\dsuiext.dll

+ Directory Object Find Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll

+ Directory Property UI Directory Service Common UI Microsoft Corporation c:\windows\system32\dsuiext.dll

+ Directory Query UI Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll

+ Directory Start/Search Find Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll

+ Disk Copy Extension Windows DiskCopy Microsoft Corporation c:\windows\system32\diskcopy.dll

+ Disk Quota UI Windows Shell Disk Quota UI DLL Microsoft Corporation c:\windows\system32\dskquoui.dll

+ Display Adapter CPL Extension Advanced display adapter properties Microsoft Corporation c:\windows\system32\deskadp.dll

+ Display Monitor CPL Extension Advanced display monitor properties Microsoft Corporation c:\windows\system32\deskmon.dll

+ Display Panning CPL Extension File not found: deskpan.dll

+ Display TroubleShoot CPL Extension Advanced display performance properties Microsoft Corporation c:\windows\system32\deskperf.dll

+ Download Status Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ DriveLetterAccess Drive Letter Access Component Sonic Solutions c:\windows\system32\dla\tfswshx.dll

+ DS Security Page Directory Service Security UI Microsoft Corporation c:\windows\system32\dssec.dll

+ E-mail Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Explorer Band Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Extensions Manager Folder Extensions Manager Microsoft Corporation c:\windows\system32\extmgr.dll

+ Favorites Band Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Fonts Windows Font Folder Microsoft Corporation c:\windows\system32\fontext.dll

+ Fonts Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ For &People... Find People Microsoft Corporation c:\program files\outlook express\wabfind.dll

+ FTP Folders Webview Microsoft Internet Explorer FTP Folder Shell Extension Microsoft Corporation c:\windows\system32\msieftp.dll

+ Fusion Cache Microsoft .NET Runtime Execution Engine Microsoft Corporation c:\windows\system32\mscoree.dll

+ GDI+ file thumbnail extractor Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Get a Passport Wizard Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ Global Folder Settings Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Help and Support Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Help and Support Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ History Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ HTML Thumbnail Extractor Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ HyperTerminal Icon Ext HyperTerminal Applet Library Hilgraeve, Inc. c:\windows\system32\hticons.dll

+ ICC Profile Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll

+ ICM Monitor Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll

+ ICM Printer Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll

+ ICM Scanner Management Microsoft Color Matching System User Interface DLL Microsoft Corporation c:\windows\system32\icmui.dll

+ IE4 Suite Splash Screen Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ In-pane search Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Installed Apps Enumerator Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl

+ Internet Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Internet Name Space Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ InternetShortcut Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ ISFBand OC Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ iTunes iTunes Mini Player DLL Apple Computer, Inc. c:\program files\itunes\itunesminiplayer.dll

+ Microsoft Agent Character Property Sheet Handler Microsoft Agent Property Sheet Handler Microsoft Corporation c:\windows\msagent\agentpsh.dll

+ Microsoft AutoComplete Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Browser Architecture Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Microsoft BrowserBand Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Data Link Microsoft Data Access - OLE DB Core Services Microsoft Corporation c:\program files\common files\system\ole db\oledb32.dll

+ Microsoft DocProp Inplace Calendar Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Droplist Combo Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Edit Box Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace ML Edit Box Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Inplace Time Control Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft DocProp Shell Ext Microsoft DocProp Shell Ext Microsoft Corporation c:\windows\system32\docprop2.dll

+ Microsoft History AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Internet Toolbar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Multiple AutoComplete List Container Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Shell Folder AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Microsoft Url History Service Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Microsoft Url Search Hook Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Midi Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ MMC Icon Handler MMC Shell Extension DLL Microsoft Corporation c:\windows\system32\mmcshext.dll

+ MRU AutoComplete List Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Multimedia File Property Sheet Control Panel Drivers Applet Microsoft Corporation c:\windows\system32\mmsys.cpl

+ MyDocs Copy Hook My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll

+ MyDocs Drop Target My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll

+ MyDocs Properties My Documents Folder UI Microsoft Corporation c:\windows\system32\mydocs.dll

+ Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshell.dll

+ Network Connections Network Connections Shell Microsoft Corporation c:\windows\system32\netshell.dll

+ NTFS Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32.dll

+ Offline Files Folder Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

+ Offline Files Folder Options Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

+ Offline Files Menu Client Side Caching UI Microsoft Corporation c:\windows\system32\cscui.dll

+ OLE Docfile Property Page OLE DocFile Property Page Microsoft Corporation c:\windows\system32\docprop.dll

+ PlusPack CPL Extension Windows Theme API Microsoft Corporation c:\windows\system32\themeui.dll

+ Portable Media Devices Portable Media Devices Shell Extension Microsoft Corporation c:\windows\system32\audiodev.dll

+ Portable Media Devices Menu Portable Media Devices Shell Extension Microsoft Corporation c:\windows\system32\audiodev.dll

+ PostAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Previous Versions Previous Versions property page Microsoft Corporation c:\windows\system32\twext.dll

+ Previous Versions Property Page Previous Versions property page Microsoft Corporation c:\windows\system32\twext.dll

+ Print Ordering via the Web Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ Printers Security Page Security Shell Extension Microsoft Corporation c:\windows\system32\rshx32.dll

+ RecordNow! SendToExt Shell Extensions c:\program files\sonic\recordnow!\shlext.dll

+ Registry Tree Options Utility Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Remote Sessions CPL Extension Remote Sessions CPL Extension Microsoft Corporation c:\windows\system32\remotepg.dll

+ Run... Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scanners & Cameras Imaging Devices Shell Folder UI Microsoft Corporation c:\windows\system32\wiashext.dll

+ Scheduled Tasks Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll

+ Search Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Search Assistant OC Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Search Band Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendmail.dll

+ Sendmail service Send Mail Microsoft Corporation c:\windows\system32\sendmail.dll

+ Set Program Access and Defaults Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Shell Application Manager Shell Application Manager Microsoft Corporation c:\windows\system32\appwiz.cpl

+ Shell Automation Inproc Service Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Shell Band Site Menu Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Shell DeskBar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Shell DeskBarApp Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Shell DocObject Viewer Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Shell extensions for Microsoft Windows Network objects Network object shell UI Microsoft Corporation c:\windows\system32\ntlanui2.dll

+ Shell Extensions for RealOne Player RealPlayer Shell Extensions RealNetworks, Inc. c:\program files\ace mega codecs pack\systems\realmedia\rpshell.dll

+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshrui.dll

+ Shell extensions for sharing Shell extensions for sharing Microsoft Corporation c:\windows\system32\ntshrui.dll

+ Shell extensions for Windows Script Host Microsoft ® Shell Extension for Windows Script Host Microsoft Corporation c:\windows\system32\wshext.dll

+ Shell Image Data Factory Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Shell Image Property Handler Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Shell Image Verbs Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Shell properties for a DS object Directory Service Find Microsoft Corporation c:\windows\system32\dsquery.dll

+ Shell Publishing Wizard Object Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ Shell Rebar BandSite Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Shell Scrap DataHandler Shell scrap object handler Microsoft Corporation c:\windows\system32\shscrap.dll

+ Shell Search Band Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Subscription Folder Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Subscription Mgr Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Summary Info Thumbnail handler (DOCFILES) Windows Picture and Fax Viewer Microsoft Corporation c:\windows\system32\shimgvw.dll

+ Synaptics Control Panel TouchPad Control Panel Extensions Synaptics, Inc. c:\program files\synaptics\syntp\syntpcpl.dll

+ Taskbar and Start Menu Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ Tasks Folder Icon Handler Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll

+ Tasks Folder Shell Extension Task Scheduler interface DLL Microsoft Corporation c:\windows\system32\mstask.dll

+ Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Temporary Internet Files Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ The Internet Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

+ Track Popup Bar Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ TrayAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ TridentImageExtractor Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Universal Plug and Play Devices UPNP Tray Monitor and Folder Microsoft Corporation c:\windows\system32\upnpui.dll

+ User Accounts Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ User Assist Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ Video Media Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ Video Thumbnail Extractor Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ Wav Properties Handler Media File Property Extractor Shell Extension Microsoft Corporation c:\windows\system32\shmedia.dll

+ Web Folders Microsoft Web Folders Microsoft Corporation c:\program files\common files\microsoft shared\web folders\mson-- The nicest hobby on Earth ;) --t.dll

+ Web Printer Shell Extension Print UI DLL Microsoft Corporation c:\windows\system32\printui.dll

+ Web Publishing Wizard Map Network Drives/Network Places Wizard Microsoft Corporation c:\windows\system32\netplwiz.dll

+ Web Search Shell Browser UI Library Microsoft Corporation c:\windows\system32\browseui.dll

+ WebCheck SyncMgr Handler Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ WebCheckChannelAgent Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ WebCheckWebCrawler Web Site Monitor Microsoft Corporation c:\windows\system32\webcheck.dll

+ Windows Media Player Add to Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll

+ Windows Media Player Burn Audio CD Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll

+ Windows Media Player Play as Playlist Context Menu Handler Windows Media Player Launcher Microsoft Corporation c:\windows\system32\wmpshell.dll

+ WinRAR shell extension c:\program files\winrar\rarext.dll

HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved

HKLM\Software\Classes\Folder\Shellex\ColumnHandlers

+ PDF Shell Extension PDF Shell Extension Adobe Systems, Inc. c:\program files\adobe\acrobat 7.0\activex\pdfshell.dll

+ {0D2E74C4-3C34-11d2-A27E-00C04FC30871} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ {24F14F01-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ {24F14F02-7B1C-11d1-838f-0000F80461CF} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ {66742402-F9B9-11D1-A202-0000F81FEDEE} Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

HKCU\Software\Microsoft\Internet Explorer\UrlSearchHooks

+ shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation c:\windows\system32\shdocvw.dll

HKLM\Software\Microsoft\Internet Explorer\Toolbar

HKLM\Software\Microsoft\Internet Explorer\Extensions

+ AIM AOL Instant Messenger America Online, Inc. c:\program files\aim\aim.exe

+ Uninstall BitDefender Online Scanner v8 c:\windows\bdoscandel.exe

Task Scheduler

+ ISP signup reminder 1.job Windows OOBE Balloon Reminder Microsoft Corporation c:\windows\system32\oobe\oobebaln.exe

+ McAfee.com Scan for Viruses - My Computer (KEVIN-KevinKo).job File not found: c:\program files\mcafee.com\vso\mcmnhdlr.exe

HKLM\System\CurrentControlSet\Services

+ 6to4 Provides DDNS name registration and automatic IPv6 connectivity over an IPv4 network. If this service is stopped, other computers may not be able to reach it by name and the machine will only have IPv6 connectivity if it is connected to a native IPv6 network. If this service is disabled, any other services that explicitly depend on this service will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ AudioSrv Manages audio devices for Windows-based programs. If this service is stopped, audio devices and effects will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ Browser Maintains an updated list of computers on the network and supplies this list to computers designated as browsers. If this service is stopped, this list will not be updated or maintained. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ CryptSvc Provides three management services: Catalog Database Service, which confirms the signatures of Windows files; Protected Root Service, which adds and removes Trusted Root Certification Authority certificates from this computer; and Key Service, which helps enroll this computer for certificates. If this service is stopped, these management services will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ DcomLaunch Provides launch functionality for DCOM services. Microsoft Corporation c:\windows\system32\svchost.exe

+ Dhcp Manages network configuration by registering and updating IP addresses and DNS names. Microsoft Corporation c:\windows\system32\svchost.exe

+ Dnscache Resolves and caches Domain Name System (DNS) names for this computer. If this service is stopped, this computer will not be able to resolve DNS names and locate Active Directory domain controllers. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ ERSvc Allows error reporting for services and applictions running in non-standard environments. Microsoft Corporation c:\windows\system32\svchost.exe

+ Eventlog Enables event log messages issued by Windows-based programs and components to be viewed in Event Viewer. This service cannot be stopped. Microsoft Corporation c:\windows\system32\services.exe

+ ewido security suite control ewido control ewido networks c:\program files\ewido anti-malware\ewidoctrl.exe

+ ewido security suite guard guard ewido networks c:\program files\ewido anti-malware\ewidoguard.exe

+ Fax Enables you to send and receive faxes, utilizing fax resources available on this computer or on the network. Microsoft Corporation c:\windows\system32\fxssvc.exe

+ Framework Windows 运行加速器,提供软件的快速运行,恢复,以及加速功能。无法终止此服务。 Microsoft Corporation c:\windows\system32\svchost.exe

+ helpsvc Enables Help and Support Center to run on this computer. If this service is stopped, Help and Support Center will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ lanmanserver Supports file, print, and named-pipe sharing over the network for this computer. If this service is stopped, these functions will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ lanmanworkstation Creates and maintains client network connections to remote servers. If this service is stopped, these connections will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ LmHosts Enables support for NetBIOS over TCP/IP (NetBT) service and NetBIOS name resolution. Microsoft Corporation c:\windows\system32\svchost.exe

+ PlugPlay Enables a computer to recognize and adapt to hardware changes with little or no user input. Stopping or disabling this service will result in system instability. Microsoft Corporation c:\windows\system32\services.exe

+ PolicyAgent Manages IP security policy and starts the ISAKMP/Oakley (IKE) and the IP security driver. Microsoft Corporation c:\windows\system32\lsass.exe

+ ProtectedStorage Provides protected storage for sensitive data, such as private keys, to prevent access by unauthorized services, processes, or users. Microsoft Corporation c:\windows\system32\lsass.exe

+ RpcSs Provides the endpoint mapper and other miscellaneous RPC services. Microsoft Corporation c:\windows\system32\svchost.exe

+ SamSs Stores security information for local user accounts. Microsoft Corporation c:\windows\system32\lsass.exe

+ Schedule Enables a user to configure and schedule automated tasks on this computer. If this service is stopped, these tasks will not be run at their scheduled times. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ seclogon Enables starting processes under alternate credentials. If this service is stopped, this type of logon access will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ SENS Tracks system events such as Windows logon, network, and power events. Notifies COM+ Event System subscribers of these events. Microsoft Corporation c:\windows\system32\svchost.exe

+ SharedAccess Provides network address translation, addressing, name resolution and/or intrusion prevention services for a home or small office network. Microsoft Corporation c:\windows\system32\svchost.exe

+ ShellHWDetection Provides notifications for AutoPlay hardware events. Microsoft Corporation c:\windows\system32\svchost.exe

+ Spooler Loads files to memory for later printing. Microsoft Corporation c:\windows\system32\spoolsv.exe

+ srservice Performs system restore functions. To stop service, turn off System Restore from the System Restore tab in My Computer->Properties Microsoft Corporation c:\windows\system32\svchost.exe

+ Themes Provides user experience theme management. Microsoft Corporation c:\windows\system32\svchost.exe

+ TrkWks Maintains links between NTFS files within a computer or across computers in a network domain. Microsoft Corporation c:\windows\system32\svchost.exe

+ UMWdf Enables Windows user mode drivers. Microsoft Corporation c:\windows\system32\wdfmgr.exe

+ Universal Disk Manager Windows μ?′òó?????×ó?μí3£?ìá1?°2è??ì?ùμ?′òó?·t???£ File not found: C:\Program Files\Common Files\SAND\qqfacerclient.exe

+ w32time Maintains date and time synchronization on all clients and servers in the network. If this service is stopped, date and time synchronization will be unavailable. If this service is disabled, any services that explicitly depend on it will fail to start.

Microsoft Corporation c:\windows\system32\svchost.exe

+ WebClient Enables Windows-based programs to create, access, and modify Internet-based files. If this service is stopped, these functions will not be available. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ winmgmt Provides a common interface and object model to access management information about operating system, devices, applications and services. If this service is stopped, most Windows-based software will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\svchost.exe

+ wscsvc Monitors system security settings and configurations. Microsoft Corporation c:\windows\system32\svchost.exe

+ wuauserv Enables the download and installation of Windows updates. If this service is disabled, this computer will not be able to use the Automatic Updates feature or the Windows Update Web site. Microsoft Corporation c:\windows\system32\svchost.exe

+ WZCSVC Provides automatic configuration for the 802.11 adapters Microsoft Corporation c:\windows\system32\svchost.exe

HKLM\System\CurrentControlSet\Services

+ abp480n5 AdvanSys SCSI Controller Driver Microsoft Corporation c:\windows\system32\drivers\abp480n5.sys

+ ACPI ACPI Driver for NT Microsoft Corporation c:\windows\system32\drivers\acpi.sys

+ adpu160m Adaptec Ultra160 SCSI miniport Microsoft Corporation c:\windows\system32\drivers\adpu160m.sys

+ aec Microsoft Acoustic Echo Canceller Microsoft Corporation c:\windows\system32\drivers\aec.sys

+ AFD AFD Networking Support Environment Microsoft Corporation c:\windows\system32\drivers\afd.sys

+ agp440 440 NT AGP Filter Microsoft Corporation c:\windows\system32\drivers\agp440.sys

+ agpCPQ CompatNT AGP Filter Microsoft Corporation c:\windows\system32\drivers\agpcpq.sys

+ Aha154x Adaptec AHA-154x series SCSI miniport Microsoft Corporation c:\windows\system32\drivers\aha154x.sys

+ aic78u2 Adaptec Ultra2 SCSI miniport Microsoft Corporation c:\windows\system32\drivers\aic78u2.sys

+ aic78xx Adaptec Ultra SCSI miniport Microsoft Corporation c:\windows\system32\drivers\aic78xx.sys

+ AliIde ALi mini IDE Driver Acer Laboratories Inc. c:\windows\system32\drivers\aliide.sys

+ alim1541 ALi M1541 NT AGP Filter Microsoft Corporation c:\windows\system32\drivers\alim1541.sys

+ amdagp AMD Win2000 AGP Filter Advanced Micro Devices, Inc. c:\windows\system32\drivers\amdagp.sys

+ amsint AMD SCSI/NET Controller Microsoft Corporation c:\windows\system32\drivers\amsint.sys

+ APPDRV App Support Driver Dell Inc c:\windows\system32\drivers\appdrv.sys

+ asc AdvanSys SCSI Controller Driver Advanced System Products, Inc. c:\windows\system32\drivers\asc.sys

+ asc3350p AdvanSys SCSI Card Driver Microsoft Corporation c:\windows\system32\drivers\asc3350p.sys

+ asc3550 AdvanSys Ultra-Wide PCI SCSI Driver Advanced System Products, Inc. c:\windows\system32\drivers\asc3550.sys

+ AsyncMac RAS Asynchronous Media Driver Microsoft Corporation c:\windows\system32\drivers\asyncmac.sys

+ atapi IDE/ATAPI Port Driver Microsoft Corporation c:\windows\system32\drivers\atapi.sys

+ Atmarpc ATM ARP Client Protocol Microsoft Corporation c:\windows\system32\drivers\atmarpc.sys

+ audstub AudStub Driver Microsoft Corporation c:\windows\system32\drivers\audstub.sys

+ BCM43XX BCM 802.11g Network Adapter wireless driver Broadcom Corporation c:\windows\system32\drivers\bcmwl5.sys

+ bcm4sbxp Broadcom Corporation NDIS 5.1 ethernet driver Broadcom Corporation c:\windows\system32\drivers\bcm4sbxp.sys

+ BCMModem Modem Device Driver Broadcom Corporation c:\windows\system32\drivers\bcmsm.sys

+ bDMusicb c:\documents and settings\kevinko\local settings\temp\bdmusicb.sys

+ cbidf CardBus/PCMCIA IDE Miniport Driver Microsoft Corporation c:\windows\system32\drivers\cbidf2k.sys

+ CCDECODE WDM Closed Caption VBI Codec Microsoft Corporation c:\windows\system32\drivers\ccdecode.sys

+ cd20xrnt IBM Portable CD-ROM Drive Miniport Microsoft Corporation c:\windows\system32\drivers\cd20xrnt.sys

+ Cdrom SCSI CD-ROM Driver Microsoft Corporation c:\windows\system32\drivers\cdrom.sys

+ CmBatt Control Method Battery Driver Microsoft Corporation c:\windows\system32\drivers\cmbatt.sys

+ CmdIde CMD PCI IDE Bus Driver CMD Technology, Inc. c:\windows\system32\drivers\cmdide.sys

+ Compbatt Composite Battery Driver Microsoft Corporation c:\windows\system32\drivers\compbatt.sys

+ Cpqarray Compaq Drive Array Controllers SCSI Miniport Driver Microsoft Corporation c:\windows\system32\drivers\cpqarray.sys

+ dac2w2k Mylex Disk Array Controller Driver Mylex Corporation c:\windows\system32\drivers\dac2w2k.sys

+ dac960nt Mylex Disk Array Controller Driver Microsoft Corporation c:\windows\system32\drivers\dac960nt.sys

+ Disk PnP Disk Driver Microsoft Corporation c:\windows\system32\drivers\disk.sys

+ DMusic Microsoft Kernel DLS Synthesizer Microsoft Corporation c:\windows\system32\drivers\dmusic.sys

+ dpti2o DPT SmartRAID miniport Microsoft Corporation c:\windows\system32\drivers\dpti2o.sys

+ drmkaud Microsoft Kernel DRM Audio Descrambler Filter Microsoft Corporation c:\windows\system32\drivers\drmkaud.sys

+ drvmcdb Device Driver Sonic Solutions c:\windows\system32\drivers\drvmcdb.sys

+ E100B NDIS 5 driver Intel Corporation c:\windows\system32\drivers\e100b325.sys

+ ewido security suite driver c:\program files\ewido anti-malware\guard.sys

+ Fdc Floppy Disk Controller Driver Microsoft Corporation c:\windows\system32\drivers\fdc.sys

+ Flpydisk Floppy Driver Microsoft Corporation c:\windows\system32\drivers\flpydisk.sys

+ FsVga Full Screen Video Driver Microsoft Corporation c:\windows\system32\drivers\fsvga.sys

+ Ftdisk FT Disk Driver Microsoft Corporation c:\windows\system32\drivers\ftdisk.sys

+ GEARAspiWDM CDRom Class Filter Driver GEAR Software Inc. c:\windows\system32\drivers\gearaspiwdm.sys

+ Gpc Generic Packet Classifier Microsoft Corporation c:\windows\system32\drivers\msgpc.sys

+ HidUsb USB Miniport Driver for Input Devices Microsoft Corporation c:\windows\system32\drivers\hidusb.sys

+ hpn NetRAID-4M Miniport Driver Microsoft Corporation c:\windows\system32\drivers\hpn.sys

+ HTTP This service implements the hypertext transfer protocol (HTTP). If this service is disabled, any services that explicitly depend on it will fail to start. Microsoft Corporation c:\windows\system32\drivers\http.sys

+ i2omp I2O Miniport Driver Microsoft Corporation c:\windows\system32\drivers\i2omp.sys

+ i8042prt i8042 Port Driver Microsoft Corporation c:\windows\system32\drivers\i8042prt.sys

+ ialm Intel Graphics Miniport Driver Intel Corporation c:\windows\system32\drivers\ialmnt5.sys

+ Imapi IMAPI Kernel Driver Microsoft Corporation c:\windows\system32\drivers\imapi.sys

+ ini910u INITIO ini910u SCSI miniport Microsoft Corporation c:\windows\system32\drivers\ini910u.sys

+ IntelIde Intel PCI IDE Driver Microsoft Corporation c:\windows\system32\drivers\intelide.sys

+ intelppm Processor Device Driver Microsoft Corporation c:\windows\system32\drivers\intelppm.sys

+ Ip6Fw Provides intrusion prevention service for a home or small office network. Microsoft Corporation c:\windows\system32\drivers\ip6fw.sys

+ IpFilterDriver IP Traffic Filter Driver Microsoft Corporation c:\windows\system32\drivers\ipfltdrv.sys

+ IpInIp IP in IP Tunnel Driver Microsoft Corporation c:\windows\system32\drivers\ipinip.sys

+ IpNat IP Network Address Translator Microsoft Corporation c:\windows\system32\drivers\ipnat.sys

+ IPSec IPSEC driver Microsoft Corporation c:\windows\system32\drivers\ipsec.sys

+ IRENUM Infra-Red Bus Enumerator Microsoft Corporation c:\windows\system32\drivers\irenum.sys

+ isapnp PNP ISA Bus Driver Microsoft Corporation c:\windows\system32\drivers\isapnp.sys

+ Kbdclass Keyboard Class Driver Microsoft Corporation c:\windows\system32\drivers\kbdclass.sys

+ kmixer Kernel Mode Audio Mixer Microsoft Corporation c:\windows\system32\drivers\kmixer.sys

+ MDC8021X AEGIS Protocol (IEEE 802.1x) v2.3.1.7 Meetinghouse Data Communications c:\windows\system32\drivers\mdc8021x.sys

+ Mouclass Mouse Class Driver Microsoft Corporation c:\windows\system32\drivers\mouclass.sys

+ mouhid HID Mouse Filter Driver Microsoft Corporation c:\windows\system32\drivers\mouhid.sys

+ mraid35x MegaRAID RAID Controller Driver for Windows Whistler 32 American Megatrends Inc. c:\windows\system32\drivers\mraid35x.sys

+ MSKSSRV MS KS Server Microsoft Corporation c:\windows\system32\drivers\mskssrv.sys

+ MSPCLOCK MS Proxy Clock Microsoft Corporation c:\windows\system32\drivers\mspclock.sys

+ MSPQM MS Proxy Quality Manager Microsoft Corporation c:\windows\system32\drivers\mspqm.sys

+ mssmbios System Management BIOS Driver Microsoft Corporation c:\windows\system32\drivers\mssmbios.sys

+ MSTEE WDM Tee/Communication Transform Filter Microsoft Corporation c:\windows\system32\drivers\mstee.sys

+ NABTSFEC WDM NABTS/FEC VBI Codec Microsoft Corporation c:\windows\system32\drivers\nabtsfec.sys

+ NdisIP Microsoft IP Driver Microsoft Corporation c:\windows\system32\drivers\ndisip.sys

+ NdisTapi Remote Access NDIS TAPI Driver Microsoft Corporation c:\windows\system32\drivers\ndistapi.sys

+ Ndisuio NDIS Usermode I/O Protocol Microsoft Corporation c:\windows\system32\drivers\ndisuio.sys

+ NdisWan Remote Access NDIS WAN Driver Microsoft Corporation c:\windows\system32\drivers\ndiswan.sys

+ NetBT NetBios over Tcpip Microsoft Corporation c:\windows\system32\drivers\netbt.sys

+ nm Netmon NT Driver Microsoft Corporation c:\windows\system32\drivers\nmnt.sys

+ npkcrypt File not found: C:\Program Files\Gravity\RO\npkcrypt.sys

+ NPPTNT2 nProtect NPSC Kernel Mode Driver for NT INCA Internet Co., Ltd. c:\windows\system32\npptnt2.sys

+ nv NVIDIA Compatible Windows 2000 Miniport Driver, Version 56.73 NVIDIA Corporation c:\windows\system32\drivers\nv4_mini.sys

+ nvport Port Driver NVIDIA Corporation. c:\windows\system32\drivers\nvport.sys

+ NwlnkFlt IPX Traffic Filter Driver Microsoft Corporation c:\windows\system32\drivers\nwlnkflt.sys

+ NwlnkFwd IPX Traffic Forwarder Driver Microsoft Corporation c:\windows\system32\drivers\nwlnkfwd.sys

+ omci OMCI Device Driver Dell Inc c:\windows\system32\drivers\omci.sys

+ Parport Parallel Port Driver Microsoft Corporation c:\windows\system32\drivers\parport.sys

+ PCI NT Plug and Play PCI Enumerator Microsoft Corporation c:\windows\system32\drivers\pci.sys

+ PCIIde Generic PCI IDE Bus Driver Microsoft Corporation c:\windows\system32\drivers\pciide.sys

+ Pcmcia PCMCIA Bus Driver Microsoft Corporation c:\windows\system32\drivers\pcmcia.sys

+ perc2 PERC 2 Miniport Driver Microsoft Corporation c:\windows\system32\drivers\perc2.sys

+ perc2hib PERC 2 Hibernate Driver Microsoft Corporation c:\windows\system32\drivers\perc2hib.sys

+ pfc Padus® ASPI Shell Padus, Inc. c:\windows\system32\drivers\pfc.sys

+ PptpMiniport WAN Miniport (PPTP) Microsoft Corporation c:\windows\system32\drivers\raspptp.sys

+ PSched QoS Packet Scheduler Microsoft Corporation c:\windows\system32\drivers\psched.sys

+ Ptilink Direct Parallel Link Driver Parallel Technologies, Inc. c:\windows\system32\drivers\ptilink.sys

+ PxHelp20 Px Engine Device Driver for Windows 2000/XP Sonic Solutions c:\windows\system32\drivers\pxhelp20.sys

+ ql1080 Miniport Driver for QLogic ISP PCI Adapters QLogic Corporation c:\windows\system32\drivers\ql1080.sys

+ Ql10wnt Miniport Driver for QLogic ISP PCI Adapters Microsoft Corporation c:\windows\system32\drivers\ql10wnt.sys

+ ql12160 Miniport Driver for QLogic ISP PCI Adapters QLogic Corporation c:\windows\system32\drivers\ql12160.sys

+ ql1240 QLogic ISP PCI Adapters Microsoft Corporation c:\windows\system32\drivers\ql1240.sys

+ ql1280 Miniport Driver for QLogic ISP PCI Adapters QLogic Corporation c:\windows\system32\drivers\ql1280.sys

+ RasAcd Remote Access Auto Connection Driver Microsoft Corporation c:\windows\system32\drivers\rasacd.sys

+ Rasl2tp WAN Miniport (L2TP) Microsoft Corporation c:\windows\system32\drivers\rasl2tp.sys

+ RasPppoe Remote Access PPPOE Driver Microsoft Corporation c:\windows\system32\drivers\raspppoe.sys

+ Raspti Direct Parallel Microsoft Corporation c:\windows\system32\drivers\raspti.sys

+ RDPCDD RDP Miniport Microsoft Corporation c:\windows\system32\drivers\rdpcdd.sys

+ rdpdr Microsoft RDP Device redirector Microsoft Corporation c:\windows\system32\drivers\rdpdr.sys

+ redbook Redbook Audio Filter Driver Microsoft Corporation c:\windows\system32\drivers\redbook.sys

+ Secdrv SafeDisc driver Macrovision Europe Ltd c:\windows\system32\drivers\secdrv.sys

+ serenum Serial Port Enumerator Microsoft Corporation c:\windows\system32\drivers\serenum.sys

+ Serial Serial Device Driver Microsoft Corporation c:\windows\system32\drivers\serial.sys

+ Sfloppy SCSI Floppy Driver Microsoft Corporation c:\windows\system32\drivers\sfloppy.sys

+ sisagp SiS NT AGP Filter Silicon Integrated Systems Corporation c:\windows\system32\drivers\sisagp.sys

+ SLIP Microsoft Slip Deframing Filter Minidriver Microsoft Corporation c:\windows\system32\drivers\slip.sys

+ sonypvs1 File not found: system32\DRIVERS\sonypvs1.sys

+ Sparrow Adaptec AIC-6x60 series SCSI miniport Adaptec, Inc. c:\windows\system32\drivers\sparrow.sys

+ splitter Microsoft Kernel Audio Splitter Microsoft Corporation c:\windows\system32\drivers\splitter.sys

+ STAC97 SigmaTel Audio Driver (WDM) SigmaTel, Inc. c:\windows\system32\drivers\stac97.sys

+ streamip Microsoft IP Test Driver Microsoft Corporation c:\windows\system32\drivers\streamip.sys

+ StyleXPHelper StyleXP Windows ® 2000 DDK provider c:\program files\tgtsoft\stylexp\stylexphelper.exe

+ swenum Plug and Play Software Device Enumerator Microsoft Corporation c:\windows\system32\drivers\swenum.sys

+ swmidi Microsoft GS Wavetable Synthesizer Microsoft Corporation c:\windows\system32\drivers\swmidi.sys

+ sym_hi Symbios Hi-Perf SCSI Miniport Driver LSI Logic c:\windows\system32\drivers\sym_hi.sys

+ sym_u3 Symbios Ultra3 SCSI Miniport Driver LSI Logic c:\windows\system32\drivers\sym_u3.sys

+ symc810 Symbios Logic Inc. SCSI Miniport Driver Symbios Logic Inc. c:\windows\system32\drivers\symc810.sys

+ symc8xx Symbios 8XX SCSI Miniport Driver LSI Logic c:\windows\system32\drivers\symc8xx.sys

+ SynTP Synaptics Touchpad Driver Synaptics, Inc. c:\windows\system32\drivers\syntp.sys

+ sysaudio System Audio WDM Filter Microsoft Corporation c:\windows\system32\drivers\sysaudio.sys

+ Tcpip TCP/IP Protocol Driver Microsoft Corporation c:\windows\system32\drivers\tcpip.sys

+ Tcpip6 Microsoft IPv6 Protocol Driver Microsoft Corporation c:\windows\system32\drivers\tcpip6.sys

+ TermDD Terminal Server Driver Microsoft Corporation c:\windows\system32\drivers\termdd.sys

+ TosIde Toshiba PCI IDE Controller Microsoft Corporation c:\windows\system32\drivers\toside.sys

+ tunmp Microsoft Tunnel Interface Driver Microsoft Corporation c:\windows\system32\drivers\tunmp.sys

+ ultra Promise Ultra66 Miniport Driver Promise Technology, Inc. c:\windows\system32\drivers\ultra.sys

+ Update Update Driver Microsoft Corporation c:\windows\system32\drivers\update.sys

+ usbaudio USB Audio Class Driver Microsoft Corporation c:\windows\system32\drivers\usbaudio.sys

+ usbccgp USB Common Class Generic Parent Driver Microsoft Corporation c:\windows\system32\drivers\usbccgp.sys

+ usbehci EHCI eUSB Miniport Driver Microsoft Corporation c:\windows\system32\drivers\usbehci.sys

+ usbhub Default Hub Driver for USB Microsoft Corporation c:\windows\system32\drivers\usbhub.sys

+ USBSTOR USB Mass Storage Class Driver Microsoft Corporation c:\windows\system32\drivers\usbstor.sys

+ usbuhci UHCI USB Miniport Driver Microsoft Corporation c:\windows\system32\drivers\usbuhci.sys

+ VgaSave VGA/Super VGA Video Driver Microsoft Corporation c:\windows\system32\drivers\vga.sys

+ viaagp VIA NT AGP Filter Microsoft Corporation c:\windows\system32\drivers\viaagp.sys

+ ViaIde Generic PCI IDE Bus Driver Microsoft Corporation c:\windows\system32\drivers\viaide.sys

+ Wanarp Remote Access IP ARP Driver Microsoft Corporation c:\windows\system32\drivers\wanarp.sys

+ wanatw File not found: system32\DRIVERS\wanatw4.sys

+ wdmaud MMSYSTEM Wave/Midi API mapper Microsoft Corporation c:\windows\system32\drivers\wdmaud.sys

+ WSTCODEC WDM WST Codec Driver Microsoft Corporation c:\windows\system32\drivers\wstcodec.sys

+ xmasbus Plug and Play BIOS Extension c:\windows\system32\drivers\xmasbus.sys

+ xmasscsi SCSI miniport c:\windows\system32\drivers\xmasscsi.sys

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute

+ autocheck autochk * Auto Check Utility Microsoft Corporation c:\windows\system32\autochk.exe

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

+ Your Image File Name Here without a path Symbolic Debugger for Windows 2000 Microsoft Corporation c:\windows\system32\ntsd.exe

HKLM\SOFTWARE\Microsoft\Command Processor\Autorun

HKCU\SOFTWARE\Microsoft\Command Processor\Autorun

HKLM\SOFTWARE\Classes\Exefile\Shell\Open\Command\(Default)

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Appinit_Dlls

HKLM\System\CurrentControlSet\Control\Session Manager\KnownDlls

+ advapi32 Advanced Windows 32 Base API Microsoft Corporation c:\windows\system32\advapi32.dll

+ comdlg32 Common Dialogs DLL Microsoft Corporation c:\windows\system32\comdlg32.dll

+ gdi32 GDI Client DLL Microsoft Corporation c:\windows\system32\gdi32.dll

+ imagehlp Windows NT Image Helper Microsoft Corporation c:\windows\system32\imagehlp.dll

+ kernel32 Windows NT BASE API Client DLL Microsoft Corporation c:\windows\system32\kernel32.dll

+ lz32 LZ Expand/Compress API DLL Microsoft Corporation c:\windows\system32\lz32.dll

+ ole32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\ole32.dll

+ oleaut32 Microsoft Corporation c:\windows\system32\oleaut32.dll

+ olecli32 Object Linking and Embedding Client Library Microsoft Corporation c:\windows\system32\olecli32.dll

+ olecnv32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olecnv32.dll

+ olesvr32 Object Linking and Embedding Server Library Microsoft Corporation c:\windows\system32\olesvr32.dll

+ olethk32 Microsoft OLE for Windows Microsoft Corporation c:\windows\system32\olethk32.dll

+ rpcrt4 Remote Procedure Call Runtime Microsoft Corporation c:\windows\system32\rpcrt4.dll

+ shell32 Windows Shell Common Dll Microsoft Corporation c:\windows\system32\shell32.dll

+ url Internet Shortcut Shell Extension DLL Microsoft Corporation c:\windows\system32\url.dll

+ urlmon OLE32 Extensions for Win32 Microsoft Corporation c:\windows\system32\urlmon.dll

+ user32 Windows XP USER API Client DLL Microsoft Corporation c:\windows\system32\user32.dll

+ version Version Che
Mosaic1
The autoruns log got cut off. Could youplease go back to the log and post just the last part which is missing? Don't try to post the entire log again, thanks. It's too long for one reply.
Mosaic1
Go to Start >Run and paste in this next command. Then press enter.
regsvr32 /i webcheck.dll

Wait for the success message.

Let me know if you get an error or if it was successful.

----------

Check to see if this file is present and let me know.

C:\windows\system32\DRIVERS\wanatw4.sys

-----------------

Reset the Internet Security Zone Settings
Start Microsoft Internet Explorer.

Click Tools > Internet Options.

Click on the Security tab.
Click on the Internet Icon on upper pane of the window.
Click on Default Level on lower right corner of the window.
Click on the Local Internet Icon on upper pane of the window.
Click on Default Level on lower right corner of the window.
Click on the Trusted sites Icon on upper pane of the window.
Click on Default Level on lower right corner of the window.
Click on the Restricted sites Icon on upper pane of the window.
Click on Default Level on lower right corner of the window.
Click OK on lower right corner of the window.

--------------------

Run hijackthis and psot the new log .

How is everything running now?
sagaemia
+ user32 Windows XP USER API Client DLL Microsoft Corporation c:\windows\system32\user32.dll

+ version Version Checking and File Installation Libraries Microsoft Corporation c:\windows\system32\version.dll

+ wininet Internet Extensions for Win32 Microsoft Corporation c:\windows\system32\wininet.dll

+ wldap32 Win32 LDAP API DLL Microsoft Corporation c:\windows\system32\wldap32.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\System

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

+ crypt32chain Crypto API32 Microsoft Corporation c:\windows\system32\crypt32.dll

+ cryptnet Crypto Network Related API Microsoft Corporation c:\windows\system32\cryptnet.dll

+ cscdll Offline Network Agent Microsoft Corporation c:\windows\system32\cscdll.dll

+ ScCertProp Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

+ Schedule Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

+ sclgntfy Secondary Logon Service Notification DLL Microsoft Corporation c:\windows\system32\sclgntfy.dll

+ SensLogn Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

+ termsrv Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

+ wlballoon Common DLL to receive Winlogon notifications Microsoft Corporation c:\windows\system32\wlnotify.dll

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GinaDLL

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Taskman

HKCU\Control Panel\Desktop\Scrnsave.exe

+ C:\WINDOWS\MATRIX~1.SCR 32 Bit CineMac Screen Saver Engine MacSourcery c:\windows\matrix code.scr

HKLM\System\CurrentControlSet\Control\BootVerificationProgram\ImageName

HKLM\System\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9

+ MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3209255F-FCE9-4B81-9A6F-1604FE2E9678}] DATAGRAM 5 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip6_{3209255F-FCE9-4B81-9A6F-1604FE2E9678}] SEQPACKET 5 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip6_{37E9851C-DA1E-496E-818C-A9CFD9B13122}] DATAGRAM 6 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip6_{37E9851C-DA1E-496E-818C-A9CFD9B13122}] SEQPACKET 6 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip6_{40927BA9-6FF1-4F71-9170-B73B05C5F108}] DATAGRAM 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip6_{40927BA9-6FF1-4F71-9170-B73B05C5F108}] SEQPACKET 4 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip6_{66B34C7B-415F-44E9-9892-9ECF1324135B}] DATAGRAM 7 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip6_{66B34C7B-415F-44E9-9892-9ECF1324135B}] SEQPACKET 7 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{2810EB22-763D-4D0C-9450-64BBD1758685}] DATAGRAM 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{2810EB22-763D-4D0C-9450-64BBD1758685}] SEQPACKET 1 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{3209255F-FCE9-4B81-9A6F-1604FE2E9678}] DATAGRAM 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{3209255F-FCE9-4B81-9A6F-1604FE2E9678}] SEQPACKET 3 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{40927BA9-6FF1-4F71-9170-B73B05C5F108}] DATAGRAM 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{40927BA9-6FF1-4F71-9170-B73B05C5F108}] SEQPACKET 0 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{531D3D38-B38F-4A40-9052-52EFBA55506B}] DATAGRAM 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{531D3D38-B38F-4A40-9052-52EFBA55506B}] SEQPACKET 2 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{66B34C7B-415F-44E9-9892-9ECF1324135B}] DATAGRAM 8 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD NetBIOS [\Device\NetBT_Tcpip_{66B34C7B-415F-44E9-9892-9ECF1324135B}] SEQPACKET 8 Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD Tcpip [RAW/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD Tcpip [RAW/IPv6] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD Tcpip [TCP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD Tcpip [TCP/IPv6] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD Tcpip [UDP/IP] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ MSAFD Tcpip [UDP/IPv6] Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation c:\windows\system32\mswsock.dll

+ RSVP TCP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp.dll

+ RSVP UDP Service Provider Microsoft Windows Rsvp 1.0 Service Provider Microsoft Corporation c:\windows\system32\rsvpsp.dll

HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors

+ BJ Language Monitor Langage Monitor for Canon Bubble-Jet Printer Microsoft Corporation c:\windows\system32\cnbjmon.dll

+ Local Port Local Spooler DLL Microsoft Corporation c:\windows\system32\localspl.dll

+ Microsoft Shared Fax Monitor Microsoft Fax Print Monitor Microsoft Corporation c:\windows\system32\fxsmon.dll

+ PJL Language Monitor PJL Language monitor Microsoft Corporation c:\windows\system32\pjlmon.dll

+ Standard TCP/IP Port Standard TCP/IP Port Monitor DLL Microsoft Corporation c:\windows\system32\tcpmon.dll

+ USB Monitor Standard Dynamic Printing Port Monitor DLL Microsoft Corporation c:\windows\system32\usbmon.dll
sagaemia
regsvr32 /i webcheck.dll

run success.
-------------------------------
no such file is present.

C:\windows\system32\DRIVERS\wanatw4.sys
----------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 上午 11:13:52, on 2006/2/12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WordPerfect Office 12\Programs\wpwin12.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O4 - HKLM\..\Run: [?? ?"h'??T3r鑒WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\dhneomt.exe
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O8 - Extra context menu item: 使用KuGoo3下载(&K) - C:\Program Files\KuGoo3\KuGoo3DownX.htm
O8 - Extra context menu item: 匯出至 Microsoft Office Excel(&X) - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: Windows Print Controller (Universal Disk Manager) - Unknown owner - C:\Program Files\Common Files\SAND\qqfacerclient.exe (file missing)
Mosaic1
The logs are looking good.

See if there is a copy of
wanatw4.sys in this folder please.


C:\windows\system32\dllcache

----------------------
There has been an issue found recently with Sun Java.

When newer versions are installed, the older versions are left behind and malware can call these older versions to exploit flaws. Some malware has been found to install this way.

First update to the very latest version of Sun Java, which is 1.5.0_06

Then go into Add Remove programs and uninstall any older versions you find listed there.

You have a leftover in your run entries which is not doing anything. But Hijackthis cannot clean it out because of the odd characters.


I'll get to that shortly.
sagaemia
i cant find a copy of C:\windows\system32\dllcache
Mosaic1
Do you mean you can't find See if there is a copy of
wanatw4.sys in the dllcache folder?

Or do you mean you can't find this folder?
C:\windows\system32\dllcache
sagaemia
i cant find the folder: C:\windows\system32\dllcache
LoPhatPhuud
Make sure you have Hidden folders set to display.

how Hidden and System files and folders: http://www.xtra.co.nz/help/0,,4155-1916458,00.html


Check again and adivse.
sagaemia
the folder is set on un-hidden and still i cant find it.
----
also now there is these weird windows poping out.
http://img.photobucket.com/albums/v371/n3rd5b0y/untitled.jpg
please help me with these windows
LoPhatPhuud
You can get a copy of webcheck.dll from here: http://www.driverskit.com/dll/link/3872.html

Put it in C:\Windows\System32\

Then run the following command:
regsvr32 /i webcheck.dll

FInally, run HiJackTHis again, and post a new log in this thread.
sagaemia
Logfile of HijackThis v1.99.1
Scan saved at 7:58:07 PM, on 2/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {A9930D97-9CF0-42A0-A10D-4F28836579D5} - C:\PROGRA~1\KuGoo3\KUGOO3~1.OCX
O4 - HKLM\..\Run: [?? ?"h'??T3r?WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\dhneomt.exe
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O8 - Extra context menu item: ·¢Ë͵½ÊÖ»ú - C:\Program Files\xBar\xBar.htm
O8 - Extra context menu item: ʹÓÃKuGoo3ÏÂÔØ(&K) - C:\Program Files\KuGoo3\KuGoo3DownX.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O20 - Winlogon Notify: winkcj32 - C:\WINDOWS\SYSTEM32\winkcj32.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: Windows Print Controller (Universal Disk Manager) - Unknown owner - C:\Program Files\Common Files\SAND\qqfacerclient.exe (file missing)
LoPhatPhuud
First:
Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task.
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button.
  • You will receive a Done Scanning message, click OK.
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If Look2Me-Destroyer does not reopen automatically, reboot and try again.

If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX


Second:
Open a Command Prompt Window (Start -> Run -> cmd)
Enter the following commands: (then press 'Enter')
sc stop "Universal Disk Manager" <-- ok if this command fails
sc delete "Universal Disk Manager"
exit


Third:
Reboot in Safe Mode* and run HiJackThis. <-- IMPORTANT

Check the following items in HijackThis.
(note: If any R* items mark for deletion, do not appear in Safe Mode, re-run HiJackThis in Normal Mode and remove them after you finish removing these items.)
O4 - HKLM\..\Run: [?? ?"h'??T3r?WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\dhneomt.exe

O20 - Winlogon Notify: winkcj32 - C:\WINDOWS\SYSTEM32\winkcj32.dll


Close all windows except HijackThis and click Fix checked.


While still in Safe Mode*, delete the following: (you may need to show hidden files**)
(Files specified without a full path will be located in C:\Windows\ or C:\Windows\System32\)
C:\Program Files\ISTsvc\ <--delete entire folder
C:\WINDOWS\dhneomt.exe
C:\WINDOWS\SYSTEM32\winkcj32.dll

*How to Boot into Safe mode: http://service1.symantec.com/SUPPORT/tsgen...001052409420406
**Show Hidden and System files and folders: http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Also, uncheck the boxes for hiding known file extensions and hiding protected operating system files. We want to see it all. When we finish here, it would be a good idea to rehide the protected operating system files but leave the rest to be shown.

Reboot in normal mode

Run HiJackThis again and post a new log in this thread.


Last:
Would you please use HiJackThis to produce a startup list and post it here:
1. From HJT main screen, click 'Config' button
2. Click 'Misc Tools' button
3. Check both boxes to the right of 'Generate StartupList Log' button
4. Click 'Generate StartupList Log' button
5. Click 'Yes' in the next dialog
6. Save the log and post a copy in this thread.
sagaemia
Logfile of HijackThis v1.99.1
Scan saved at 5:48:09 PM, on 3/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\PPATCH~1\ping.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\TEMP\win3B.tmp.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com.tw/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O4 - HKLM\..\Run: [?? ?"h'??T3r?WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\dhneomt.exe
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Sen] "C:\WINDOWS\PPATCH~1\ping.exe" -vt yax
O4 - HKCU\..\Run: [Ybpoe] C:\WINDOWS\?ppPatch\s?anregw.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O8 - Extra context menu item: ·¢Ë͵½ÊÖ»ú - C:\Program Files\xBar\xBar.htm
O8 - Extra context menu item: ʹÓÃKuGoo3ÏÂÔØ(&K) - C:\Program Files\KuGoo3\KuGoo3DownX.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: winfyl32 - C:\WINDOWS\SYSTEM32\winfyl32.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
sagaemia
StartupList report, 3/11/2006, 5:51:20 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\KevinKo\Desktop\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\PPATCH~1\ping.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\TEMP\win3B.tmp.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\KevinKo\Start Menu\Programs\Startup]
Trillian.lnk = C:\Program Files\Trillian\trillian.exe

Shell folders AltStartup:
*Folder not found*

User shell folders Startup:
*Folder not found*

User shell folders AltStartup:
*Folder not found*

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
*No files*

Shell folders Common AltStartup:
*Folder not found*

User shell folders Common Startup:
*Folder not found*

User shell folders Alternate Common Startup:
*Folder not found*

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*

[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

(Default) =
?? ?"h'??T3r?WC:\Program Files\ISTsvc\istsvc.exe = C:\WINDOWS\dhneomt.exe
YLive.exe = C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
iTunesHelper = "C:\Program Files\iTunes\iTunesHelper.exe"
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
HostManager = C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
LVCOMSX = C:\WINDOWS\system32\LVCOMSX.EXE
LogitechVideoRepair = C:\Program Files\Logitech\Video\ISStart.exe
LogitechVideoTray = C:\Program Files\Logitech\Video\LogiTray.exe
Daily Weather Forecast = C:\Program Files\Daily Weather Forecast\weather.exe

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
AIM = C:\Program Files\AIM\aim.exe -cnetwait.odl
LogitechSoftwareUpdate = "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
Sen = "C:\WINDOWS\PPATCH~1\ping.exe" -vt yax
Ybpoe = C:\WINDOWS\?ppPatch\s?anregw.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run

*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*

--------------------------------------------------

File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command

(Default) = "%1" %*

--------------------------------------------------

File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command

(Default) = "%1" /S

--------------------------------------------------

File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command

(Default) = C:\WINDOWS\system32\mshta.exe "%1" %*

--------------------------------------------------

File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command

(Default) = %SystemRoot%\system32\NOTEPAD.EXE %1

--------------------------------------------------

Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)

[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP

[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE

[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP

[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE

[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll

[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install

[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT

[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf

[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser

[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub

[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install

[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll

[{89820200-ECBD-11cf-8B85-00AA005B4383}] *
StubPath = %SystemRoot%\system32\ie4uinit.exe

[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\mscories.dll,Install

[{8b15971b-5355-4c82-8c07-7e181ea07608}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser

--------------------------------------------------

Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps

*Registry key not found*

--------------------------------------------------

Load/Run keys from C:\WINDOWS\WIN.INI:

load=*INI section not found*
run=*INI section not found*

Load/Run keys from Registry:

HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\MATRIX~1.SCR
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Checking for EXPLORER.EXE instances:

C:\WINDOWS\Explorer.exe: PRESENT!

C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present

--------------------------------------------------

Checking for superhidden extensions:

.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden

--------------------------------------------------

Verifying REGEDIT.EXE integrity:

- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'

Registry check passed

--------------------------------------------------

Enumerating Browser Helper Objects:

*No BHO's found*

--------------------------------------------------

Enumerating Task Scheduler jobs:

ISP signup reminder 1.job
McAfee.com Scan for Viruses - My Computer (KEVIN-KevinKo).job

--------------------------------------------------

Enumerating Download Program Files:

[{00000055-9980-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/fhg.CAB

[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\SYSTEM32\Macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock...director/sw.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\LegitCheckControl.DLL
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[BDSCANONLINE Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\oscan8.ocx
CODEBASE = http://download.bitdefender.com/resources/scan8/oscan8.cab

[Housecall ActiveX 6.5]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll
CODEBASE = http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab

[{74CD40EA-EF77-4BAD-808A-B5982DA73F20}]
CODEBASE = http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123

[Java Plug-in 1.5.0_04]
InProcServer32 = C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\asinst.dll
CODEBASE = http://acs.pandasoftware.com/activescan/as5free/asinst.cab

[Java Plug-in 1.5.0_04]
InProcServer32 = C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-...indows-i586.cab

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa...ash/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll
Protocol #22: C:\WINDOWS\system32\mswsock.dll
Protocol #23: C:\WINDOWS\system32\mswsock.dll
Protocol #24: C:\WINDOWS\system32\mswsock.dll
Protocol #25: C:\WINDOWS\system32\mswsock.dll
Protocol #26: C:\WINDOWS\system32\mswsock.dll

--------------------------------------------------

Enumerating Windows NT/2000/XP services

IPv6 Helper Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
abp480n5: system32\DRIVERS\ABP480N5.SYS (system)
Microsoft ACPI Driver: system32\DRIVERS\ACPI.sys (system)
adpu160m: system32\DRIVERS\adpu160m.sys (system)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD: \SystemRoot\System32\drivers\afd.sys (system)
Intel AGP Bus Filter: system32\DRIVERS\agp440.sys (system)
Compaq AGP Bus Filter: system32\DRIVERS\agpCPQ.sys (system)
Aha154x: system32\DRIVERS\aha154x.sys (system)
aic78u2: system32\DRIVERS\aic78u2.sys (system)
aic78xx: system32\DRIVERS\aic78xx.sys (system)
Alerter: %SystemRoot%\system32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AliIde: system32\DRIVERS\aliide.sys (system)
ALI AGP Bus Filter: system32\DRIVERS\alim1541.sys (system)
AMD AGP Bus Filter Driver: system32\DRIVERS\amdagp.sys (system)
amsint: system32\DRIVERS\amsint.sys (system)
APPDRV: \SystemRoot\SYSTEM32\DRIVERS\APPDRV.SYS (system)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
asc: system32\DRIVERS\asc.sys (system)
asc3350p: system32\DRIVERS\asc3350p.sys (system)
asc3550: system32\DRIVERS\asc3550.sys (system)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: system32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: system32\DRIVERS\atapi.sys (system)
ATM ARP Client Protocol: system32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: system32\DRIVERS\audstub.sys (manual start)
Dell Wireless WLAN Card Driver: system32\DRIVERS\bcmwl5.sys (manual start)
Broadcom 440x 10/100 Integrated Controller XP Driver: system32\DRIVERS\bcm4sbxp.sys (manual start)
BCM V.92 56K Modem: system32\DRIVERS\BCMSM.sys (manual start)
bDMusicb: \??\C:\DOCUME~1\KevinKo\LOCALS~1\Temp\bDMusicb.sys (manual start)
Background Intelligent Transfer Service: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Computer Browser: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
cbidf: system32\DRIVERS\cbidf2k.sys (system)
Closed Caption Decoder: system32\DRIVERS\CCDECODE.sys (manual start)
cd20xrnt: system32\DRIVERS\cd20xrnt.sys (system)
CD-ROM Driver: system32\DRIVERS\cdrom.sys (system)
Indexing Service: %SystemRoot%\system32\cisvc.exe (manual start)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
Microsoft ACPI Control Method Battery Driver: system32\DRIVERS\CmBatt.sys (manual start)
CmdIde: system32\DRIVERS\cmdide.sys (system)
Microsoft Composite Battery Driver: system32\DRIVERS\compbatt.sys (system)
COM+ System Application: C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cpqarray: system32\DRIVERS\cpqarray.sys (system)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
dac2w2k: system32\DRIVERS\dac2w2k.sys (system)
dac960nt: system32\DRIVERS\dac960nt.sys (system)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Disk Driver: system32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
dmio: System32\drivers\dmio.sys (disabled)
dmload: System32\drivers\dmload.sys (disabled)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\system32\svchost.exe -k NetworkService (autostart)
dpti2o: system32\DRIVERS\dpti2o.sys (system)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
DrvFltIp: \??\C:\Program Files\Internet Lock For LAN (Win-NT or higher)\DrvFltIp.sys (manual start)
drvmcdb: system32\drivers\drvmcdb.sys (system)
drvnddm: system32\drivers\drvnddm.sys (autostart)
Intel® PRO Adapter Driver: system32\DRIVERS\e100b325.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\system32\svchost.exe -k netsvcs (manual start)
ewido security suite control: C:\Program Files\ewido anti-malware\ewidoctrl.exe (autostart)
ewido security suite driver: \??\C:\Program Files\ewido anti-malware\guard.sys (system)
ewido security suite guard: C:\Program Files\ewido anti-malware\ewidoguard.exe (disabled)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Fax: %systemroot%\system32\fxssvc.exe (autostart)
Floppy Disk Controller Driver: system32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: system32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\DRIVERS\fltMgr.sys (system)
Application Accelerator: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
FsVga: system32\DRIVERS\fsvga.sys (system)
Volume Manager Driver: system32\DRIVERS\ftdisk.sys (system)
GEAR CDRom Filter: SYSTEM32\DRIVERS\GEARAspiWDM.sys (manual start)
Generic Packet Classifier: system32\DRIVERS\msgpc.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Microsoft HID Class Driver: system32\DRIVERS\hidusb.sys (manual start)
hpn: system32\DRIVERS\hpn.sys (system)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i2omp: system32\DRIVERS\i2omp.sys (system)
i8042 Keyboard and PS/2 Mouse Port Driver: system32\DRIVERS\i8042prt.sys (system)
ialm: system32\DRIVERS\ialmnt5.sys (manual start)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
CD-Burning Filter Driver: system32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\system32\imapi.exe (manual start)
ini910u: system32\DRIVERS\ini910u.sys (system)
IntelIde: system32\DRIVERS\intelide.sys (system)
Intel Processor Driver: system32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\DRIVERS\Ip6Fw.sys (manual start)
IP Traffic Filter Driver: system32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: system32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: system32\DRIVERS\ipnat.sys (manual start)
iPodService: C:\Program Files\iPod\bin\iPodService.exe (manual start)
IPSEC driver: system32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: system32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: system32\DRIVERS\isapnp.sys (system)
Keyboard Class Driver: system32\DRIVERS\kbdclass.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Server: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
TCP/IP NetBIOS Helper: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Logitech USB Monitor Filter: system32\drivers\lvusbsta.sys (manual start)
AEGIS Protocol (IEEE 802.1x) v2.3.1.7: system32\DRIVERS\mdc8021x.sys (autostart)
Messenger: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\system32\mnmsrvc.exe (manual start)
Mouse Class Driver: system32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: system32\DRIVERS\mouhid.sys (manual start)
mraid35x: system32\DRIVERS\mraid35x.sys (system)
WebDav Client Redirector: system32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: system32\DRIVERS\mrxsmb.sys (system)
Distributed Transaction Coordinator: C:\WINDOWS\system32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: system32\DRIVERS\mssmbios.sys (manual start)
Microsoft Streaming Tee/Sink-to-Sink Converter: system32\drivers\MSTEE.sys (manual start)
NABTS/FEC VBI Codec: system32\DRIVERS\NABTSFEC.sys (manual start)
Microsoft TV/Video Connection: system32\DRIVERS\NdisIP.sys (manual start)
Remote Access NDIS TAPI Driver: system32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: system32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: system32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: system32\DRIVERS\netbios.sys (system)
NetBios over Tcpip: system32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\system32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Network Location Awareness (NLA): %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Network Monitor Driver: system32\DRIVERS\NMnt.sys (manual start)
npkcrypt: \??\C:\Program Files\Gravity\RO\npkcrypt.sys (manual start)
NPPTNT2: \??\C:\WINDOWS\system32\npptNT2.sys (system)
NT LM Security Support Provider: %SystemRoot%\system32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
nv: system32\DRIVERS\nv4_mini.sys (manual start)
NVIDIA PORT IO Control Driver: \??\C:\WINDOWS\system32\Drivers\nvport.sys (system)
IPX Traffic Filter Driver: system32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: system32\DRIVERS\nwlnkfwd.sys (manual start)
OMCI WDM Device Driver: system32\DRIVERS\omci.sys (system)
PACSPTISVR: C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe (manual start)
Parallel port driver: system32\DRIVERS\parport.sys (manual start)
PCI Bus Driver: system32\DRIVERS\pci.sys (system)
PCIIde: system32\DRIVERS\pciide.sys (system)
Pcmcia: system32\DRIVERS\pcmcia.sys (system)
perc2: system32\DRIVERS\perc2.sys (system)
perc2hib: system32\DRIVERS\perc2hib.sys (system)
Padus ASPI Shell: system32\drivers\pfc.sys (manual start)
Logitech QuickCam Express(PID_0928): system32\DRIVERS\LV561AV.SYS (manual start)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\system32\lsass.exe (autostart)
WAN Miniport (PPTP): system32\DRIVERS\raspptp.sys (manual start)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: system32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: system32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\Drivers\PxHelp20.sys (system)
ql1080: system32\DRIVERS\ql1080.sys (system)
Ql10wnt: system32\DRIVERS\ql10wnt.sys (system)
ql12160: system32\DRIVERS\ql12160.sys (system)
ql1240: system32\DRIVERS\ql1240.sys (system)
ql1280: system32\DRIVERS\ql1280.sys (system)
Remote Access Auto Connection Driver: system32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): system32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: system32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: system32\DRIVERS\raspti.sys (manual start)
Rdbss: system32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: system32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: system32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\system32\svchost.exe -k netsvcs (disabled)
Remote Procedure Call (RPC) Locator: %SystemRoot%\system32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\system32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Secdrv: system32\DRIVERS\secdrv.sys (autostart)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: system32\DRIVERS\serenum.sys (manual start)
Serial port driver: system32\DRIVERS\serial.sys (system)
High-Capacity Floppy Disk Drive: system32\DRIVERS\sfloppy.sys (manual start)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SIS AGP Bus Filter: system32\DRIVERS\sisagp.sys (system)
BDA Slip De-Framer: system32\DRIVERS\SLIP.sys (manual start)
Sony Digital Imaging Video2: system32\DRIVERS\sonypvs1.sys (manual start)
Sparrow: system32\DRIVERS\sparrow.sys (system)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Sony SPTI Service: C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe (manual start)
System Restore Filter Driver: system32\DRIVERS\sr.sys (system)
System Restore Service: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Srv: system32\DRIVERS\srv.sys (manual start)
sscdbhk5: system32\drivers\sscdbhk5.sys (system)
SSDP Discovery Service: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
ssrtln: system32\drivers\ssrtln.sys (system)
Audio Driver (WDM) - SigmaTel CODEC: system32\drivers\stac97.sys (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\system32\svchost.exe -k imgsvc (autostart)
BDA IPSink: system32\DRIVERS\StreamIP.sys (manual start)
StyleXPHelper: \??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe (system)
StyleXPService: "C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe" (autostart)
Software Bus Driver: system32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\system32\dllhost.exe /Processid:{A445BD1E-49EE-4607-B370-5CCA447377C4} (manual start)
symc810: system32\DRIVERS\symc810.sys (system)
symc8xx: system32\DRIVERS\symc8xx.sys (system)
sym_hi: system32\DRIVERS\sym_hi.sys (system)
sym_u3: system32\DRIVERS\sym_u3.sys (system)
Synaptics TouchPad Driver: system32\DRIVERS\SynTP.sys (manual start)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: system32\DRIVERS\tcpip.sys (system)
Microsoft IPv6 Protocol Driver: system32\DRIVERS\tcpip6.sys (system)
Terminal Device Driver: system32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
tfsnboio: system32\dla\tfsnboio.sys (autostart)
tfsncofs: system32\dla\tfsncofs.sys (autostart)
tfsndrct: system32\dla\tfsndrct.sys (autostart)
tfsndres: system32\dla\tfsndres.sys (autostart)
tfsnifs: system32\dla\tfsnifs.sys (autostart)
tfsnopio: system32\dla\tfsnopio.sys (autostart)
tfsnpool: system32\dla\tfsnpool.sys (autostart)
tfsnudf: system32\dla\tfsnudf.sys (autostart)
tfsnudfa: system32\dla\tfsnudfa.sys (autostart)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
TosIde: system32\DRIVERS\toside.sys (system)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Microsoft Tun Miniport Adapter Driver: system32\DRIVERS\tunmp.sys (manual start)
ultra: system32\DRIVERS\ultra.sys (system)
Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart)
Microcode Update Driver: system32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\system32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
USB Audio Driver (WDM): system32\drivers\usbaudio.sys (manual start)
Microsoft USB Generic Parent Driver: system32\DRIVERS\usbccgp.sys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: system32\DRIVERS\usbehci.sys (manual start)
Microsoft USB Standard Hub Driver: system32\DRIVERS\usbhub.sys (manual start)
USB Mass Storage Driver: system32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: system32\DRIVERS\usbuhci.sys (manual start)
User Privilege Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
VgaSave: \SystemRoot\System32\drivers\vga.sys (system)
VIA AGP Bus Filter: system32\DRIVERS\viaagp.sys (system)
ViaIde: system32\DRIVERS\viaide.sys (system)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Remote Access IP ARP Driver: system32\DRIVERS\wanarp.sys (manual start)
WAN Miniport (ATW): system32\DRIVERS\wanatw4.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
WLTRYSVC: %SystemRoot%\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe (disabled)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\system32\wbem\wmiapsrv.exe (manual start)
Windows Socket 2.0 Non-IFS Service Provider Support Environment: \SystemRoot\System32\drivers\ws2ifsl.sys (disabled)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
World Standard Teletext Codec: system32\DRIVERS\WSTCODEC.SYS (manual start)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
xmasbus: system32\DRIVERS\xmasbus.sys (system)
xmasscsi: System32\Drivers\xmasscsi.sys (system)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)


--------------------------------------------------

Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*

Windows NT checkdisk command:
BootExecute = autocheck autochk *

Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\DOCUME~1\KevinKo\LOCALS~1\Temp\StyleXPServicenssi0.exe||C:\DOCUME~1\KevinKo\LOCALS~1\Temp\StyleXPnssi0.exe|||e

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
UPnPMonitor: C:\WINDOWS\system32\upnpui.dll

--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

*No values found*

--------------------------------------------------

End of report, 38,408 bytes
Report generated in 0.390 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
LoPhatPhuud
Look2ME Destroyer has a log file. As requested in my prior post, please post the log file in this thread.

I need to see that log before I do anything else.
sagaemia
Look2Me-Destroyer V1.0.10

Scanning for infected files.....
Scan started at 2006/3/12 ?? 07:40:03


Attempting to delete infected files...

Making registry repairs.


Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded
LoPhatPhuud
First:
Launch Notepad.
Copy/paste the text in the box below into a new text file.
Save it as fixme.reg on your Desktop

CODE
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winfyl32]



Locate fixme.reg on your Desktop and double-click on it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".

Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".


Second:
Reboot in Safe Mode* and run HiJackThis. <-- IMPORTANT

Check the following items in HijackThis.
(note: If any R* items mark for deletion, do not appear in Safe Mode, re-run HiJackThis in Normal Mode and remove them after you finish removing these items.)
O4 - HKLM\..\Run: [?? ?"h'??T3r?WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\dhneomt.exe
O4 - HKCU\..\Run: [Sen] "C:\WINDOWS\PPATCH~1\ping.exe" -vt yax
O4 - HKCU\..\Run: [Ybpoe] C:\WINDOWS\?ppPatch\s?anregw.exe

O8 - Extra context menu item: ·¢Ë͵½ÊÖ»ú - C:\Program Files\xBar\xBar.htm
O8 - Extra context menu item: ʹÓÃKuGoo3ÏÂÔØ(&K) - C:\Program Files\KuGoo3\KuGoo3DownX.htm

O20 - Winlogon Notify: winfyl32 - C:\WINDOWS\SYSTEM32\winfyl32.dll

Close all windows except HijackThis and click Fix checked.


While still in Safe Mode*, delete the following: (you may need to show hidden files**)
(Files specified without a full path will be located in C:\Windows\ or C:\Windows\System32\)
C:\WINDOWS\dhneomt.exe
C:\WINDOWS\PPATCH~1\ <--delete entire folder
C:\WINDOWS\?ppPatch\ <--delete entire folder
C:\Program Files\xBar\ <--delete entire folder
C:\Program Files\KuGoo3\ <--delete entire folder
C:\WINDOWS\SYSTEM32\winfyl32.dll

*How to Boot into Safe mode: http://service1.symantec.com/SUPPORT/tsgen...001052409420406
**Show Hidden and System files and folders: http://www.xtra.co.nz/help/0,,4155-1916458,00.html

Also, uncheck the boxes for hiding known file extensions and hiding protected operating system files. We want to see it all. When we finish here, it would be a good idea to rehide the protected operating system files but leave the rest to be shown.

Reboot in normal mode

Run HiJackThis again and post a new log in this thread.
sagaemia
cannot find the following, even with show hidden files:
-C:\WINDOWS\dhneomt.exe
-C:\WINDOWS\PPATCH~1\
-C:\WINDOWS\?ppPatch\
-C:\Program Files\xBar\
sagaemia
Logfile of HijackThis v1.99.1
Scan saved at 11:26:57 PM, on 3/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Program Files\AIM\aim.exe
C:\winstall.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com.tw/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {172A43F5-A961-8BEC-4FE2-A9BFA8F6DE9E} - C:\WINDOWS\system32\jrkxo.dll
O4 - HKLM\..\Run: [?? ?"h'??T3r?WC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\dhneomt.exe
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
sagaemia
please help me, my computer has ben acting weird latly, it kept on poping out this message windows saying that my computer is infected. and ads kept on poping up.
LoPhatPhuud
I am almost at the point of suggesting you reformat and re-install. Backup up any data you need saved in the event this becomes a necessity. It is possible that your system is so severely compromised that nothing we can do will clean it. Some entries refuse to remove yet there is no reason for this behavior. I want to check for startup entries that may be hiding in unusual locations. Then it may be necessary to do some manual registry editing to remove certain entries.

First is the startup list:

Please download SilentRunners from here:
http://www.silentrunners.org/Silent%20Runners.zip

Unzip it to the desktop and double-click on it.
Silent Runners will ask if you want to skip the supplementary search.
Please select 'No' to include them. The program will take longer to run, but wil lgive us more information.

If you get any kind of warning message about scripts, please choose to allow the script to run.

When the scan is finished, a message will pop up and a logfile will have been created on the desktop.
The logfile is named 'Startup Programs' by default and will be located where the program is.

Please post the entire contents of this logfile for me to see.
sagaemia
"Silent Runners.vbs", revision 44, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"AIM" = "C:\Program Files\AIM\aim.exe -cnetwait.odl" ["America Online, Inc."]
"LogitechSoftwareUpdate" = ""C:\Program Files\Logitech\Video\ManifestEngine.exe" boot" ["Logitech Inc."]
"Windows installer" = "C:\winstall.exe" [null data]
"Sen" = ""C:\WINDOWS\PPATCH~1\ping.exe" -vt yax" [null data]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"(Default)" = (empty string)
"??**"h'??T3r*WC:\Program Files\ISTsvc\istsvc.exe" (unwritable string) = "C:\WINDOWS\dhneomt.exe" [file not found]
"YLive.exe" = "C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe" [file not found]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"HostManager" = "C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe" [file not found]
"LVCOMSX" = "C:\WINDOWS\system32\LVCOMSX.EXE" ["Logitech Inc."]
"LogitechVideoRepair" = "C:\Program Files\Logitech\Video\ISStart.exe " ["Logitech Inc."]
"LogitechVideoTray" = "C:\Program Files\Logitech\Video\LogiTray.exe" ["Logitech Inc."]
"Daily Weather Forecast" = "C:\Program Files\Daily Weather Forecast\weather.exe" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{172A43F5-A961-8BEC-4FE2-A9BFA8F6DE9E}\(Default) = (no title provided)
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\jrkxo.dll" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"
-> {HKLM...CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
\InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\shellhook.dll" ["TODO: <Firmenname>"]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]
LoPhatPhuud
That is not a complete SIlent Runners log. It will need to be run again, but wait until I ask for it in these instructions.


First:
Start -> Run -> regedit

When regedit is open, navigate to this key:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Look for the following: ??**"h'??T3r*WC:\Program Files\ISTsvc\istsvc.exe
(the asterisks are place holders only and the actual value will be different)
Right Click on the value, then select 'Delete'
Acknowledge the delete and close regedit.


Second:
Launch Notepad, and copy/paste in the box below to a new text file.
Save it on your Desktop as fixme.reg

CODE
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows installer"=-
"Sen"=-

Locate fixme.reg on your Desktop and double-click on it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".


Third:
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.



Fourth:
Check the following items in HijackThis.

O2 - BHO: (no name) - {172A43F5-A961-8BEC-4FE2-A9BFA8F6DE9E} - C:\WINDOWS\system32\jrkxo.dll

Close all windows except HijackThis and click Fix checked.

Reboot in normal mode

Delete the following file:
C:\winstall.exe


Run HiJackThis again and post a new log in this thread.


Last:
Run Silent Runners again, according to my previous instructions and post the log in this t hread. Be sure to post the whole log.
sagaemia
"Silent Runners.vbs", revision 44, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ctfmon.exe" = "C:\WINDOWS\system32\ctfmon.exe" [MS]
"AIM" = "C:\Program Files\AIM\aim.exe -cnetwait.odl" ["America Online, Inc."]
"LogitechSoftwareUpdate" = ""C:\Program Files\Logitech\Video\ManifestEngine.exe" boot" ["Logitech Inc."]
"Windows installer" = "C:\winstall.exe" [null data]
"Sen" = ""C:\WINDOWS\PPATCH~1\ping.exe" -vt yax" [null data]
"Zhvdny" = "C:\Program Files\Common Files\W*nSxS\c*rss.exe" (unwritable string) [null data]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"(Default)" = (empty string)
"YLive.exe" = "C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe" [file not found]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"HostManager" = "C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe" [file not found]
"LVCOMSX" = "C:\WINDOWS\system32\LVCOMSX.EXE" ["Logitech Inc."]
"LogitechVideoRepair" = "C:\Program Files\Logitech\Video\ISStart.exe " ["Logitech Inc."]
"LogitechVideoTray" = "C:\Program Files\Logitech\Video\LogiTray.exe" ["Logitech Inc."]
"Daily Weather Forecast" = "C:\Program Files\Daily Weather Forecast\weather.exe" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{412C11AE-AC3E-DEEF-4FE2-A9BFA8F6D193}\(Default) = (no title provided)
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\gdkxorjc.dll" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}" = "UnlockerShellExtension"
-> {HKLM...CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
\InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\shellhook.dll" ["TODO: <Firmenname>"]

HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
{F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
-> {HKLM...CLSID} = "PDF Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {HKLM...CLSID} = "Ctest Object"
\InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\context.dll" ["ewido networks"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {HKLM...CLSID} = "Ctest Object"
\InProcServer32\(Default) = "C:\Program Files\ewido anti-malware\context.dll" ["ewido networks"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
UnlockerShellExtension\(Default) = "{DDE4BEEB-DDE6-48fd-8EB5-035C09923F83}"
-> {HKLM...CLSID} = "UnlockerShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Unlocker\UnlockerCOM.dll" [null data]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Group Policies [Description]:
-----------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
HIJACK WARNING! "ForceActiveDesktopOn"=dword:00000001
[enables Active Desktop and prevents disabling it]

"Wallpaper" = (value not set)
[disables the Display Properties|Desktop (tab) (except the "Customize
Desktop..." button); selects wallpaper if Active Desktop is enabled]


Active Desktop and Wallpaper:
-----------------------------

Active Desktop enabled via Group Policy.

Wallpaper selected via Group Policy.


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\

HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\0\
"SCRNSAVE.EXE" = "C:\WINDOWS\MATRIX~1.SCR" (Matrix Code.scr) ["MacSourcery"]


Startup items in "KevinKo" & "All Users" startup folders:
---------------------------------------------------------

C:\Documents and Settings\KevinKo\Start Menu\Programs\Startup
"Trillian" -> shortcut to: "C:\Program Files\Trillian\trillian.exe" ["Cerulean Studios"]


Enabled Scheduled Tasks:
------------------------

"ISP signup reminder 1" -> launches: "C:\WINDOWS\system32\OOBE\OOBEBALN.EXE /sys /i /n:1" [MS]
"McAfee.com Scan for Viruses - My Computer (KEVIN-KevinKo)" -> launches: "c:\program files\mcafee.com\vso\mcmnhdlr.exe /runtask:0" [file not found]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 26
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Application Accelerator, Framework, "C:\WINDOWS\System32\svchost.exe -k netsvcs" {"C:\WINDOWS\system\ntstub.dll" [MS]}
ewido security suite control, ewido security suite control, "C:\Program Files\ewido anti-malware\ewidoctrl.exe" ["ewido networks"]
HTTP SSL, HTTPFilter, "C:\WINDOWS\System32\svchost.exe -k HTTPFilter" {"C:\WINDOWS\System32\w3ssl.dll" [MS]}
iPodService, iPodService, "C:\Program Files\iPod\bin\iPodService.exe" ["Apple Computer, Inc."]
IPv6 Helper Service, 6to4, "C:\WINDOWS\system32\svchost.exe -k netsvcs" {"C:\WINDOWS\System32\6to4svc.dll" [MS]}
StyleXPService, StyleXPService, ""C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe"" [empty string]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS]


----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 107 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 33 seconds.
---------- (total run time: 185 seconds)
sagaemia
Logfile of HijackThis v1.99.1
Scan saved at 10:43:44 PM, on 3/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Program Files\AIM\aim.exe
C:\winstall.exe
C:\WINDOWS\PPATCH~1\ping.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\W?nSxS\c?rss.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com.tw/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O2 - BHO: (no name) - {412C11AE-AC3E-DEEF-4FE2-A9BFA8F6D193} - C:\WINDOWS\system32\gdkxorjc.dll
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [Sen] "C:\WINDOWS\PPATCH~1\ping.exe" -vt yax
O4 - HKCU\..\Run: [Zhvdny] C:\Program Files\Common Files\W?nSxS\c?rss.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
LoPhatPhuud
Something seemed strange when that C:\winstal.exe entry would not remove. A little checking left me feeling more than a little embarassed. It's part of SpySheriff which takes a special removal and I should have recognized it. This should do it.


Download smitRem.exe and save the file to your desktop.
If you cannot access that link, here is an alternate link: smitRem.exe
Double click on the file to extract it to its own folder on the desktop.

Place a shortcut to Panda ActiveScan on your desktop.

Please download Ewido Anti-Malware trial version.
  • Install Ewido Anti-Malware
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch Ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates. Do NOT run a scan yet.

If you have not already installed Ad-Aware SE 1.06, follow these download and setup instructions, otherwise, check for updates:
Please download Ad-Aware SE Personal and install it. If you already have Ad-Aware SE, please configure it as indicated below. If you have a previous version of Ad-Aware, please uninstall your current version and install the newest version SE 1.06.
1) Run Ad-Aware, and click Check for updates now.
2) Select Configurations (click the Gear wheel at the top) as follows:
  • General Button > Safety & Settings: Check (Green) all three.
  • Tweak Button > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
Don't run it yet!
Exit Ad-aware.

Next, please reboot your computer in SafeMode by doing the following:
  1. Restart your computer
  2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  3. Instead of Windows loading as normal, a menu should appear
  4. Select the first option, to run Windows in Safe Mode.
==================================================
Run HijackThis, and press "Scan". When the scan is complete place a check mark next to the following entries:

O2 - BHO: (no name) - {412C11AE-AC3E-DEEF-4FE2-A9BFA8F6D193} - C:\WINDOWS\system32\gdkxorjc.dll

O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [Sen] "C:\WINDOWS\PPATCH~1\ping.exe" -vt yax
O4 - HKCU\..\Run: [Zhvdny] C:\Program Files\Common Files\W?nSxS\c?rss.exe



After checking these items CLOSE ALL open windows EXCEPT HijackThis and click "Fix Checked."
===================================================
Close Hijackthis.

Then search for and DELETE the following file(s)/folder(s) IF STILL PRESENT:

C:\winstall.exe
C:\Program Files\Common Files\W?nSxS\c?rss.exe


Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

Open Ad-aware and do a full scan. Remove all it finds.

Run Ewido:
  • Then select "Settings"
  • Under the bottom section "What to Scan?" make sure "Scan every file" is checked.
  • Select "OK" and you will return to scanning options.
  • Click on Complete System Scan and the scan will begin.

    This scan can take quite a while to run, so please be patient .
  • While the scan is in progress, you will be prompted to clean the first infected file it finds.
  • Choose Clean.
  • Then put a check next to 'Perform action on all infections' . Doing this, enables the scan to proceed automatically until its completion. Click OK
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again. The best place to save it would probably be your Desktop.
Close Ewido

Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

Reboot back into Windows and click the Panda ActiveScan shortcut.
- Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, the contents of smitfiles.txt and the Ewido Log by using Post Reply.
Let us know if any problems persist.

** It could be possible, after reboot that the system is using the windows classic theme again.
To restore this and set it back to XP-theme, rightclick on your desktop > properties > tab Appearances and choose Windows XP style again under windows and buttons.
Click apply and OK
sagaemia
Incident Status Location

Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt[]
Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sskcwrd.dll
Adware:Adware/IST.ISTBar Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-35118732.zip[InstallerApplet.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70b9958a-4bc1cd2e.zip[GetAccess.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70b9958a-4bc1cd2e.zip[Installer.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70b9958a-4bc1cd2e.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70b9958a-4bc1cd2e.zip[NewURLClassLoader.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[Beyond.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[NudeBox.class]
Virus:Trj/ClassLoader.P Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[Worker.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[VerifierBug.class]
Adware:Adware/SpySheriff Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[javautil.zip]
Virus:Trj/Downloader.EAA Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[bot.exe]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@888[1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@888[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@ad.yieldmanager[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@adopt.hbmediapro[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@atdmt[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@atwola[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@belnk[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@casalemedia[2].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@cassava[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@dist.belnk[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@doubleclick[1].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@errorsafe[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@fastclick[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@realmedia[1].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@revenue[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@tribalfusion[1].txt
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@valueclick[1].txt
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@winfixer[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@www.errorsafe[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@zedo[2].txt
Virus:Trj/Downloader.MO Not disinfected C:\Documents and Settings\KevinKo\Desktop\backups\backup-20060210-181245-151.inf
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\KevinKo\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\KevinKo\Desktop\smitRem.exe[Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\KevinKo\Local Settings\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\Cache\3EFBEAA3d01[Process.exe]
Adware:Adware/IST.ISTBar Not disinfected C:\Program Files\Daily Weather Forecast\weather.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\Downloaded Program Files\m67m.inf
Potentially unwanted tool:application/winfixer2005 Not disinfected C:\WINDOWS\Downloaded Program Files\UWFX5_0001_N63M2912NetInstaller.exe
Adware:Adware/ConsumerAlertSystem Not disinfected C:\WINDOWS\pf78.exe
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@dist.belnk[2].txt
Spyware:Cookie/empnads Not disinfected C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@empnads[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@rn11[2].txt
Adware:adware program Not disinfected C:\WINDOWS\SYSTEM32\data.~
Adware:adware/iedriver Not disinfected C:\WINDOWS\SYSTEM32\Searchx.htm
sagaemia
Logfile of HijackThis v1.99.1
Scan saved at 11:27:37 PM, on 3/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\KevinKo\LOCALS~1\Temp\16197.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com.tw/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
sagaemia
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 9:57:08 PM, 3/18/2006
+ Report-Checksum: 6C3B933D

+ Scan result:

:mozilla.14:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.15:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.16:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.17:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.18:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.20:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.26:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.27:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.28:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.29:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.30:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.31:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.32:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.34:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.36:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.46:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.47:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.49:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.50:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.52:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.53:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.94:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.105:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.106:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.109:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.110:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.111:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.112:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.113:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.114:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.115:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.116:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.117:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.118:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.119:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.120:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.121:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.132:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.133:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.134:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.135:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.136:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.137:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.152:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.153:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.165:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.166:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.167:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.168:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.170:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.180:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.183:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.184:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.185:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.229:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.231:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.232:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.233:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.236:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.237:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.238:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.239:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.240:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.280:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.281:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.294:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.295:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.296:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.297:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.299:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.300:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.309:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.327:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.328:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.329:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.330:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.331:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.343:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.344:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.345:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.346:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.347:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.353:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.359:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.360:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.361:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.372:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.373:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.374:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.375:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.376:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.381:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.387:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.388:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.389:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.394:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.395:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.396:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.402:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.416:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup
:mozilla.482:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.483:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.486:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.487:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.488:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.489:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.490:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.491:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.513:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.519:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.520:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@ads1.revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\KevinKo\Desktop\backups\backup-20060316-222846-597.dll -> Adware.PurityScan : Cleaned with backup
C:\Documents and Settings\KevinKo\Desktop\backups\backup-20060318-154439-334.dll -> Adware.PurityScan : Cleaned with backup
C:\Program Files\Quiinzip\Cache\000066bb_44137b6f_0009d7f3 -> Downloader.IstBar.j : Cleaned with backup
C:\WINDOWS\SYSTEM32\dfrgsrv.exe -> Downloader.Zlob.in : Cleaned with backup
C:\WINDOWS\SYSTEM32\ginuerep.dll -> Not-A-Virus.Hoax.Win32.Renos.bv : Cleaned with backup
C:\WINDOWS\ΑрpPatch\ping.exe -> Downloader.PurityScan.w : Cleaned with backup


::Report End
sagaemia
smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Sat 03/18/2006
The current time is: 15:47:50.15

Running from
C:\Documents and Settings\KevinKo\Desktop\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~

SpySheriff


~~~ Shortcuts ~~~

Install.dat


~~~ Favorites ~~~



~~~ system32 folder ~~~

logfiles


~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peaco*k@beyondlogic.org
Killing PID 872 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~


~~~ Wininet.dll ~~~

CLEAN! :)
LoPhatPhuud
First:
Download Killbox from here: http://www.downloads.subratam.org/KillBox.zip
or from here: http://www.atribune.org/downloads/KillBox.exe

Reboot in Safe Mode

This will take a little bit to do so keep track and dont miss any files.

Open Killbox, click the option 'Delete on Reboot'

Select the following list of file name(s) and copy to the clipboard (ctrl-c):

C:\DOCUME~1\KevinKo\LOCALS~1\Temp\16197.exe
C:\winstall.exe


From the 'File' menu in KillBox, select 'Paste from Clipboard'
Click the red X, to the far right of the Address Bar
Press 'Yes' to the message box that comes up
Press 'Yes' to the next box asking you to reboot.

If your computer does not automatically reboot, then close Killbox and restart your computer.


Second:
Run HiJackThis again and post a new log in this thread.
sagaemia
Logfile of HijackThis v1.99.1
Scan saved at 4:43:46 PM, on 3/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com.tw/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
LoPhatPhuud
Could you check to see if this file exists? C:\winstall.exe

Also there should be a folder !Killbox or !Submit on C: drive at the root level. Could you zip it and attach to your next post.
sagaemia
i donno if the file C:\winstall.exe still exist.. caz i go to search and i couldnt find any except in the !killbox folder

also it kept on have this message "Upload failed. You are not permitted to upload a file with that file extension."

2 hours after this message was posted C:\winstall.exe came back..
LoPhatPhuud
Lets run the smitRem remover again to see if we can get rid of that c:\winstal.exe for good. Also did you Zip the Killbox folder with XP's native compressor, Winzip, or WinRar? The board should accept *.zip files but may not accept *.rar files.


Download smitRem.exe and save the file to your desktop.
If you cannot access that link, here is an alternate link: smitRem.exe
Double click on the file to extract it to its own folder on the desktop.

Place a shortcut to Panda ActiveScan on your desktop.

Please download Ewido Anti-Malware trial version.
  • Install Ewido Anti-Malware
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch Ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update Ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates. Do NOT run a scan yet.

If you have not already installed Ad-Aware SE 1.06, follow these download and setup instructions, otherwise, check for updates:
Please download Ad-Aware SE Personal and install it. If you already have Ad-Aware SE, please configure it as indicated below. If you have a previous version of Ad-Aware, please uninstall your current version and install the newest version SE 1.06.
1) Run Ad-Aware, and click Check for updates now.
2) Select Configurations (click the Gear wheel at the top) as follows:
  • General Button > Safety & Settings: Check (Green) all three.
  • Tweak Button > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
Don't run it yet!
Exit Ad-aware.

Next, please reboot your computer in SafeMode by doing the following:
  1. Restart your computer
  2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  3. Instead of Windows loading as normal, a menu should appear
  4. Select the first option, to run Windows in Safe Mode.
==================================================
Run HijackThis, and press "Scan". When the scan is complete place a check mark next to the following entries:

----- Insert HijackThis Entries here -----

After checking these items CLOSE ALL open windows EXCEPT HijackThis and click "Fix Checked."
===================================================
Close Hijackthis.

Then search for and DELETE the following file(s)/folder(s) IF STILL PRESENT:

------ insert any other malware files here ----

Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

Open Ad-aware and do a full scan. Remove all it finds.

Run Ewido:
  • Then select "Settings"
  • Under the bottom section "What to Scan?" make sure "Scan every file" is checked.
  • Select "OK" and you will return to scanning options.
  • Click on Complete System Scan and the scan will begin.

    This scan can take quite a while to run, so please be patient .
  • While the scan is in progress, you will be prompted to clean the first infected file it finds.
  • Choose Clean.
  • Then put a check next to 'Perform action on all infections' . Doing this, enables the scan to proceed automatically until its completion. Click OK
  • When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again. The best place to save it would probably be your Desktop.
Close Ewido

Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

Reboot back into Windows and click the Panda ActiveScan shortcut.
- Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, the contents of smitfiles.txt and the Ewido Log by using Post Reply.
Let us know if any problems persist.

** It could be possible, after reboot that the system is using the windows classic theme again.
To restore this and set it back to XP-theme, rightclick on your desktop > properties > tab Appearances and choose Windows XP style again under windows and buttons.
Click apply and OK
sagaemia
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 8:01:50 PM, 4/4/2006
+ Report-Checksum: D032AF1E

+ Scan result:

C:\!KillBox\16197.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Cleaned with backup
C:\!KillBox\winstall.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Cleaned with backup
C:\!KillBox.zip/!KillBox/16197.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Cleaned with backup
C:\!KillBox.zip/!KillBox/winstall.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Cleaned with backup
:mozilla.10:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.16:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.20:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.35:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.53:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.54:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.55:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.56:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.57:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.58:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.59:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.60:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.61:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.62:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.63:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.64:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.65:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.66:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.67:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.68:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.69:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.70:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.71:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.72:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.74:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.75:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.76:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.77:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.78:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.80:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.81:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.82:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.83:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.85:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.86:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.87:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.88:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.89:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.91:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.92:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.93:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.94:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.95:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.96:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.97:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.98:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.99:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.100:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.107:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.108:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.109:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.110:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.111:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.112:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.113:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.114:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.122:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.148:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.150:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.183:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.184:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.185:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.186:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.187:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.188:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.189:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.190:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.191:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.192:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.193:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.194:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.195:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.196:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.197:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.198:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.199:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.201:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.202:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.203:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.208:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.209:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.210:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.211:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.212:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.265:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.266:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.269:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.270:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.274:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.287:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.306:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.313:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.314:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.354:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.368:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.369:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.404:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.412:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.414:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.423:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.424:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.425:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.426:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.432:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.433:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.434:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.435:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.452:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.453:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.454:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.455:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.456:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.457:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.458:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.467:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.468:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.469:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.470:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.471:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.472:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.488:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.489:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.490:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.491:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.492:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.503:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup
:mozilla.504:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.505:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.506:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.511:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.512:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.513:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.514:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.515:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.527:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adition : Cleaned with backup
:mozilla.528:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adition : Cleaned with backup
:mozilla.536:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup
:mozilla.549:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.556:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.588:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.589:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.596:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.608:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.609:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.610:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.611:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.612:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.613:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.614:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.-- The nicest hobby on Earth ;) --counter : Cleaned with backup
:mozilla.615:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.-- The nicest hobby on Earth ;) --counter : Cleaned with backup
:mozilla.633:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.634:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.635:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.637:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.656:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.657:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.665:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.666:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.667:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.668:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.669:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.670:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.676:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.692:C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@ads1.revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@as1.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@e-2dj6wgl4wocjahq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@install.bestoffersnetworks[2].txt -> TrackingCookie.Bestoffersnetworks : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\KevinKo\Cookies\kevinko@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\AUTO_4289_N.exe -> Trojan.Dialer.hh : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\AUTO_4289_N.exe -> Trojan.Dialer.hh : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\AUTO_4289_N.exe -> Trojan.Dialer.hh : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\AUTO_4289_N.exe -> Trojan.Dialer.hh : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\AUTO_4289_N.exe -> Trojan.Dialer.hh : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.5\AUTO_4289_N.exe -> Trojan.Dialer.hh : Cleaned with backup
C:\WINDOWS\SYSTEM\setup4.exe -> Adware.AdHelper : Cleaned with backup
C:\WINDOWS\SYSTEM32\WBEM\IRJIT.DLL -> Adware.AdHelper : Cleaned with backup


::Report End
sagaemia
Incident Status Location

Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\KevinKo\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\cookies.txt[]
Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sskcwrd.dll
Adware:Adware/IST.ISTBar Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-5aa0b436-35118732.zip[InstallerApplet.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70b9958a-4bc1cd2e.zip[GetAccess.class]
Adware:Adware/CWS.Searchmeup Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70b9958a-4bc1cd2e.zip[Installer.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70b9958a-4bc1cd2e.zip[NewSecurityClassLoader.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jrl.jar-70b9958a-4bc1cd2e.zip[NewURLClassLoader.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[Beyond.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[NudeBox.class]
Virus:Trj/ClassLoader.P Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[Worker.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[VerifierBug.class]
Adware:Adware/SpySheriff Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[javautil.zip]
Virus:Trj/Downloader.EAA Not disinfected C:\Documents and Settings\KevinKo\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\menu.jr-16042425-6316994a.zip[bot.exe]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@888[1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@888[2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@adopt.hbmediapro[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@atwola[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@belnk[1].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@cassava[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@dist.belnk[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@errorsafe[2].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@i.screensavers[1].txt
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@winfixer[2].txt
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\KevinKo\Cookies\kevinko@www.errorsafe[2].txt
Virus:Trj/Downloader.MO Not disinfected C:\Documents and Settings\KevinKo\Desktop\backups\backup-20060210-181245-151.inf
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\KevinKo\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\KevinKo\Desktop\smitRem(2).exe[Process.exe]
Dialer:dialer.cos Not disinfected C:\Documents and Settings\KevinKo\Favorites\exsplorer.lnk
Dialer:dialer.akd Not disinfected C:\Documents and Settings\KevinKo\Favorites\WinMoviePlugin.lnk
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\KevinKo\Local Settings\Application Data\Mozilla\Firefox\Profiles\bwhou3z0.default\Cache\3EFBEAA3d01[Process.exe]
Adware:Adware/IST.ISTBar Not disinfected C:\Program Files\Daily Weather Forecast\weather.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\Downloaded Program Files\m67m.inf
Potentially unwanted tool:application/winfixer2005 Not disinfected C:\WINDOWS\Downloaded Program Files\UWFX5_0001_N63M2912NetInstaller.exe
Adware:Adware/ConsumerAlertSystem Not disinfected C:\WINDOWS\pf78.exe
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@dist.belnk[2].txt
Spyware:Cookie/empnads Not disinfected C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@empnads[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\system@rn11[2].txt
Adware:adware program Not disinfected C:\WINDOWS\SYSTEM32\data.~
Adware:adware/iedriver Not disinfected C:\WINDOWS\SYSTEM32\Searchx.htm
sagaemia
Logfile of HijackThis v1.99.1
Scan saved at 9:31:03 PM, on 4/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Daily Weather Forecast\weather.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\KevinKo\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.skymasters.biz?4289
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [YLive.exe] C:\PROGRA~1\Yahoo!\ASSIST~1\YLive.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138168184\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [Daily Weather Forecast] C:\Program Files\Daily Weather Forecast\weather.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: ???? - res://C:\PROGRA~1\Yahoo!\ASSIST~1\Assist\yasbar.dll/246
O15 - Trusted Zone: www.archivio-- The nicest hobby on Earth ;) --.net
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: www.skymasters.biz
O16 - DPF: {072039AB-2117-4ED5-A85F-9B9EB903E021} (NowStarter Control) - http://www.clubbox.co.kr/neo.fld/NowStarter.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
sagaemia
smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Tue 04/04/2006
The current time is: 18:46:14.61

Running from
C:\Documents and Settings\KevinKo\Desktop\smitRem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\system32\browseui.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~

SpySheriff


~~~ Shortcuts ~~~

Install.dat


~~~ Favorites ~~~



~~~ system32 folder ~~~

logfiles


~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 Craig.Peaco*k@beyondlogic.org
Killing PID 800 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]