[resolved]Zone-DL.Plugin Removal Help Needed

The other day I noticed some advertisements popping up when I opened IE. I narrowed it down to being the Zone-DL.Plugin but I can't find anything to remove it? I've tried all the scanners and it won't delete it. Here's my Hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 5:52:30 PM, on 12/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\Rar$EX01.391\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bcctv.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [scrchin] C:\DOCUME~1\Owner\APPLIC~1\USERSE~1\filmloadcast.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm080YYUS
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8eb9918bc1f44fa99cd9f338612a396
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8eb9918bc1f44fa99cd9f338612a396
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1101847098699
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153748136781
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cherrytap.com/imgs/ImageUploader4.cab
O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2317.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE



*THANK YOU THANK YOU THANK YOU, IN ADVANCE FOR ANY HELP!!!!!!!

Comments

  • edited January 2007
    :( No help huh?
  • edited January 2007
    I was told to come post a new HiJack This log so here goes:

    Logfile of HijackThis v1.99.1
    Scan saved at 12:12:27 PM, on 1/6/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Owner\My Documents\Programs\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bcctv.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
    N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
    N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
    O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
    O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
    O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [scrchin] C:\DOCUME~1\Owner\APPLIC~1\USERSE~1\filmloadcast.exe
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
    O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
    O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm080YYUS
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8eb9918bc1f44fa99cd9f338612a396
    O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8eb9918bc1f44fa99cd9f338612a396
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
    O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1101847098699
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153748136781
    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cherrytap.com/imgs/ImageUploader4.cab
    O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
    O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2317.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
  • jmoney3457jmoney3457 Maine
    edited January 2007
    Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

    Answer Yes, when prompted to install an ActiveX component.
    • The program will then begin downloading the latest definition files.
    • Once the files have been downloaded click on NEXT
    • Locate the Scan Settings button & configure to:
      • Scan using the following Anti-Virus database:
        • Extended
      • Scan Options:
        • Scan Archives
        • Scan Mail Bases
    • Click OK & have it scan My Computer
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
    * Turn off the real time scanner of any existing antivirus program while performing the online scan
  • edited January 2007
    Thanx so much for helping me!!!!!!!!!! Here's the log of what the Kapersky scan found:

    KASPERSKY ONLINE SCANNER REPORT
    Sunday, January 07, 2007 5:12:51 PM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.83.0
    Kaspersky Anti-Virus database last update: 7/01/2007
    Kaspersky Anti-Virus database records: 256703

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    A:\
    C:\
    D:\
    E:\

    Scan Statistics:
    Total number of scanned objects: 102617
    Number of viruses found: 5
    Number of infected objects: 15 / 0
    Number of suspicious objects: 0
    Duration of the scan process: 01:35:35

    Infected Object Name / Virus Name / Last Action
    C:\Documents and Settings\All Users\Application Data\byterealcopyboob\creative pure funk Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-12062006-173029.log Object is locked skipped
    C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\AntiPhishing\07FB382D-AA75-4683-82F4-EAB265A275CB.dat Object is locked skipped
    C:\Documents and Settings\Guest\Local Settings\Temporary Internet Files\AntiPhishing\07FB382D-AA75-4683-82F4-EAB265A275CB.dat Object is locked skipped
    C:\Documents and Settings\Guest\Local Settings\Temporary Internet Files\AntiPhishing\2997C193-A464-4307-88C9-F9C00083CD16.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\Owner\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{CDA612A1-BEB0-4F68-87DD-756EE6F007B4} Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Temp\~DFAF38.tmp Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Temp\~DFAF46.tmp Object is locked skipped
    C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\Owner\My Documents\Programs\Programs + Firewalls\IPhider.zip/ip hider.exe Infected: not-a-virus:NetTool.Win32.Wfips skipped
    C:\Documents and Settings\Owner\My Documents\Programs\Programs + Firewalls\IPhider.zip ZIP: infected - 1 skipped
    C:\Documents and Settings\Owner\My Documents\Programs\Yahoo Tools\yaheek.zip/yaheek.dll Infected: not-a-virus:Monitor.Win32.Dafunk skipped
    C:\Documents and Settings\Owner\My Documents\Programs\Yahoo Tools\yaheek.zip ZIP: infected - 1 skipped
    C:\Documents and Settings\Owner\ntuser.dat Object is locked skipped
    C:\Documents and Settings\Owner\ntuser.dat.LOG Object is locked skipped
    C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
    C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
    C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\BWKDLogs\BWTargetInf.log Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.dat Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chandir.idx Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.dat Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\chn.idx Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\D0000000.FCS Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\inuse.txt Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\L0000009.FCS Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\main.log Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.dat Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs.idx Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.dat Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_die.idx Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.dat Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_dnd.idx Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.dat Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_ext.idx Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.dat Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\prs_rcv.idx Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.dat Object is locked skipped
    C:\Program Files\Kodak\KODAK Software Updater\7288971\Users\Default\Data\storydb.idx Object is locked skipped
    C:\Program Files\Uninstall My Web Search.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.p skipped
    C:\Program Files\Yahoo!\Messenger\logs\billing_Owner.log Object is locked skipped
    C:\Program Files\Yahoo!\Messenger\logs\client_Owner.log Object is locked skipped
    C:\Program Files\Yahoo!\Messenger\logs\network_Owner.log Object is locked skipped
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/WINDOWS/NDNuninstall6_38.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/Program Files/newdotnet/newdotnet6_38.dll Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/Program Files/newdotnet/uninstall6_38.exe Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/Program Files/newdotnet/newdotnet6_38.to_be_deleted Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/Program Files/newdotnet/newdotnet6_38.to_be_deleted_x Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip ZIP: infected - 5 skipped
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930150901.zip/Program Files/newdotnet/newdotnet6_38.to_be_deleted Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930150901.zip/Program Files/newdotnet/newdotnet6_38.to_be_deleted_x Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930150901.zip ZIP: infected - 2 skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{8D91E204-D5C8-4C39-844C-ECE7DE711522}\RP879\A0232610.ocx Infected: not-a-virus:AdWare.Win32.Coupons.h skipped
    C:\System Volume Information\_restore{8D91E204-D5C8-4C39-844C-ECE7DE711522}\RP892\change.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\EventCache\{FF2DDFB5-C8CC-4CFC-9225-74941855EE3C}.bin Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\default Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\software Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\system Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\Temp\Perflib_Perfdata_6d0.dat Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.


    Again, thank you sooooooo much for any help!!!
  • jmoney3457jmoney3457 Maine
    edited January 2007
    no problem please do this..Download ATF Cleaner
    • Double-click ATF-Cleaner.exe to run the program.
    • Click Select All found at the bottom of the list.
    • Click the Empty Selected button.
    If you use Firefox browser, do this also:
    • Click Firefox at the top and choose Select All from the list.
    • Click the Empty Selected button.
    • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser, do this also:
    • Click Opera at the top and choose Select All from the list.
    • Click the Empty Selected button.
    • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.

    then, First download AVG anti-spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program
    1. Once you have downloaded AVG anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Once the setup is complete you will need run AVG and update the definition files.
    3. On the main screen select the icon "Update" then select the "Update now" link.
      • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    6. Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    Close AVG anti-spyware, Do Not run a scan just yet, we will shortly.
    1. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
      IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning proccess:
    2. Lauch AVG-anti-spyware by double-clicking the icon on your desktop.
    3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    4. AVG will now begin the scanning process, be patient this may take a little time.
      Once the scan is complete do the following:
    5. If you have any infections you will prompted, then select "Apply all actions"
    6. Next select the "Reports" icon at the top.
    7. Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    8. Close AVG and reboot your system back into Normal Mode and post the results of the AVG report scan.
  • edited January 2007
    Here's what I got after doing everything you told me to. I'm still getting the pop ups. :(

    AVG Anti-Spyware - Scan Report

    + Created at: 11:30:17 PM 1/7/2007

    + Scan result:



    C:\System Volume Information\_restore{8D91E204-D5C8-4C39-844C-ECE7DE711522}\RP879\A0232610.ocx -> Adware.Coupons : Cleaned with backup (quarantined).
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/Program Files/newdotnet/newdotnet6_38.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/Program Files/newdotnet/newdotnet6_38.to_be_deleted -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/Program Files/newdotnet/newdotnet6_38.to_be_deleted_x -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/Program Files/newdotnet/uninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930082837.zip/WINDOWS/NDNuninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930150901.zip/Program Files/newdotnet/newdotnet6_38.to_be_deleted -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\Program Files\Yahoo!\YPSR\Quarantine\20050930150901.zip/Program Files/newdotnet/newdotnet6_38.to_be_deleted_x -> Adware.NewDotNet : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\FUSIONButtons.ocx -> Backdoor.IRCBot : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\KewlButtonz.ocx -> Backdoor.IRCBot : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{8D91E204-D5C8-4C39-844C-ECE7DE711522}\RP879\A0232609.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined).


    ::Report end
  • jmoney3457jmoney3457 Maine
    edited January 2007
    still more to do :) please go HERE under step 3 perform bitdefender and attach the log it gives you to your next post
  • edited January 2007
    Here are the results of the bitdefender scan:

    <HTML>
    <HEAD>
    <TITLE>BitDefender Online Scanner -Scan Report</TITLE>
    <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
    <meta name="generator" content="Namo WebEditor v5.0(Trial)">
    </HEAD>
    <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >


    <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">
    <tr>
    <td width="458">
    <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender
    Online Scanner</b></span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>
    <tr>
    <td colspan="3" width="912">
    <p><font face="Arial"><span style="font-size:11pt;"><B>Scan report generated
    at: Mon, Jan 08, 2007 - 10:28:00</b></span></font></p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <p><font face="Arial"><span style="font-size:11pt;"><B>Scan
    path: </b></span><span style="font-size:10pt;">A:\;C:\;D:\;E:\;</span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="451" colspan="2" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Statistics</b></font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Time</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">01:34:55</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Files</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">366402</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Folders</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">8564</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Boot Sectors</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">2</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Archives</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">4418</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Packed Files</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">20332</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>



    <tr>
    <td width="458">
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="451" colspan="2" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Results</b></font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Identified Viruses </font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">1</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Infected Files </font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">1</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Suspect Files </font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">0</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Warnings</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">0</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Disinfected</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">0</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Deleted Files</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">1</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="451" colspan="2" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Engines Info</b></font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Virus Definitions</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">368492</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Engine build</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">AVCORE v1.0 (build 2371) (i386) (Dec 13 2006 11:16:42)</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Scan plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">14</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Archive plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">38</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Unpack plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">6</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">E-mail plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">6</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">System plugins</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">1</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="451" colspan="2" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Scan Settings</b></font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">First Action</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Disinfect</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Second Action</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Delete</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Heuristics</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Enable Warnings</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Scanned Extensions</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">*;</font></p>
    </td>
    </tr>

    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Exclude Extensions</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2"> </font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Scan Emails</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Scan Archives</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Scan Packed</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Scan Files</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Yes</font></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">Scan Boot</font></p>
    </td>
    <td width="43%" align="right">
    <p><font face="Arial" size="2">Yes</font></p>
    </td>
    </tr>
    </table>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td colspan=2>  
    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">
    <tr>
    <td width="252" bgcolor="#CCCCCC">
    <p><font face="Arial" size="2"><B>Scanned File</b></font></p>
    </td>
    <td width="195" bgcolor="#CCCCCC" align="right">
    <p align="left"><b><font size="2" face="Arial"> Status</font></b></p>
    </td>
    </tr>
    <tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{8D91E204-D5C8-4C39-844C-ECE7DE711522}\RP876\A0231997.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Infected with: Trojan.Downloader.Agent.XO</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{8D91E204-D5C8-4C39-844C-ECE7DE711522}\RP876\A0231997.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Disinfection failed</font></p>
    </td>
    </tr><tr>
    <td width="57%">
    <p><font face="Arial" size="2">C:\System Volume Information\_restore{8D91E204-D5C8-4C39-844C-ECE7DE711522}\RP876\A0231997.exe</font></p>
    </td>
    <td width="43%" align="left">
    <p><font face="Arial" size="2">Deleted</font></p>
    </td>
    </tr>
    </table>
    </td>

    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    <tr>
    <td width="458">
    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>
    </td>
    <td width="40%">
    <p> </p>
    </td>
    <td width="10%">
    <p> </p>
    </td>
    </tr>

    </table>
    <p> </p>

    </body>
    </html>


    ***Sorry, I'm not sure why it came with all the html code???
  • edited January 2007
    I wanted to add also that when I shut my computer down I get a popup box that says something about filmlo~1.exe. It's only up there for a second or two so I can't see all of it to tell exactly what it's saying to me. And it's only at shutdown.

    When I go to my Sprint Picture Mail site I can't see any of my pics. :( They're all just little red x's. I'm so unhappy. :(

    Thanks so much for your help though...without you I'd be really up the creek.
  • TroganTrogan London, UK
    edited January 2007
    Sorry to jump in Jmoney!

    tanyatanyam, you have a LOP infection:

    Please Download NoLop to your desktop from one of the links below...
    Link 1
    Link 2
    Link 3
    • First close any other programs you have running as this will require a reboot
    • Double click NoLop.exe to run it
      • Now click the button labelled "Search and Destroy"
        <<your computer will now be scanned for infected files>>
      • When scanning is finished you will be prompted to reboot only if infected, Click OK
      • Now click the "REBOOT" Button.
      • A Message should popup from NoLop. If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log along with a fresh HijackThis log
      --If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.--

      I need to see another log from HijackThis.
      • Run Hijackthis.
      • Click on Open the Misc Tools section.
      • Next click on Open uninstall manager.
      • Press the Save list button.
      • Save the file to your desktop, with the default name of uninstall_list
      • Copy & Paste the entire contents of that file in your in your next post.

      Do you have a Firewall?
    • jmoney3457jmoney3457 Maine
      edited January 2007
      tanya, the reason why it came out like that is because you posted the report in the actual body of your reply, you must attach the report instead and this can be done by clicking on *manage attachments* under misc. options when replying to your thread..trog I don't mind at all..the thread is all yours thanks again;)
    • edited January 2007
      Okay...THANK YOU SO MUCH FOR YOUR HELP TOO! Yes, I have a firewall..the Windows firewall.

      Here are the logs you wanted:

      NoLop! Log by Skate_Punk_21

      Fix running from: C:\Documents and Settings\Owner\My Documents\Programs
      [1/8/2007]
      [4:20:23 PM]

      ---Infection Files Found/Removed---
      C:\WINDOWS\tasks\A7839F6E90B813F6.job

      Beginning Removal...
      Rebooting...

      Beginning Removal...
      Rebooting...
      Removing Lop's Leftover Files/Folders...
      Editing Registry...
      **Fix Complete!**

      ---Listing AppData sub directories---

      C:\Documents and Settings\Administrator\Application Data\Microsoft
      C:\Documents and Settings\Administrator.dellany\Application Data\Microsoft
      C:\Documents and Settings\Administrator.dellany.000\Application Data\Microsoft
      C:\Documents and Settings\Administrator.dellany.001\Application Data\Microsoft
      C:\Documents and Settings\All Users\Application Data\Adobe
      C:\Documents and Settings\All Users\Application Data\Adobe Systems
      C:\Documents and Settings\All Users\Application Data\Aol
      C:\Documents and Settings\All Users\Application Data\Aol Downloads
      C:\Documents and Settings\All Users\Application Data\Aol Ocp
      C:\Documents and Settings\All Users\Application Data\Apple Computer
      C:\Documents and Settings\All Users\Application Data\Arcsoft
      C:\Documents and Settings\All Users\Application Data\Byterealcopyboob
      C:\Documents and Settings\All Users\Application Data\Gtek
      C:\Documents and Settings\All Users\Application Data\Installshield
      C:\Documents and Settings\All Users\Application Data\Kodak
      C:\Documents and Settings\All Users\Application Data\Microsoft
      C:\Documents and Settings\All Users\Application Data\Msn Search Toolbar
      C:\Documents and Settings\All Users\Application Data\Quicktime
      C:\Documents and Settings\All Users\Application Data\Skype
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      C:\Documents and Settings\All Users\Application Data\Symantec
      C:\Documents and Settings\All Users\Application Data\Trymedia
      C:\Documents and Settings\All Users\Application Data\Viewpoint
      C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
      C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
      C:\Documents and Settings\All Users\Application Data\Yahoo!
      C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
      C:\Documents and Settings\Chris\Application Data\Identities
      C:\Documents and Settings\Chris\Application Data\Macromedia
      C:\Documents and Settings\Chris\Application Data\Microsoft
      C:\Documents and Settings\Chris\Application Data\Real
      C:\Documents and Settings\Chris\Application Data\Wholesecurity
      C:\Documents and Settings\Default User\Application Data\Microsoft
      C:\Documents and Settings\Guest\Application Data\Identities
      C:\Documents and Settings\Guest\Application Data\Macromedia
      C:\Documents and Settings\Guest\Application Data\Microsoft
      C:\Documents and Settings\Guest\Application Data\Real
      C:\Documents and Settings\Guest\Application Data\Sun
      C:\Documents and Settings\Guest\Application Data\Wholesecurity
      C:\Documents and Settings\Guest\Application Data\Yahoo!
      C:\Documents and Settings\Localservice\Application Data\Help -- EMPTY Directory
      C:\Documents and Settings\Localservice\Application Data\Macromedia
      C:\Documents and Settings\Localservice\Application Data\Microsoft
      C:\Documents and Settings\Networkservice\Application Data\Microsoft
      C:\Documents and Settings\Networkservice\Application Data\Symantec
      C:\Documents and Settings\Owner\Application Data\Acccore
      C:\Documents and Settings\Owner\Application Data\Adobe
      C:\Documents and Settings\Owner\Application Data\Adobeaum
      C:\Documents and Settings\Owner\Application Data\Adobeum
      C:\Documents and Settings\Owner\Application Data\Aim -- EMPTY Directory
      C:\Documents and Settings\Owner\Application Data\Apple Computer
      C:\Documents and Settings\Owner\Application Data\Arcsoft
      C:\Documents and Settings\Owner\Application Data\Corel
      C:\Documents and Settings\Owner\Application Data\Help
      C:\Documents and Settings\Owner\Application Data\Identities
      C:\Documents and Settings\Owner\Application Data\Jasc
      C:\Documents and Settings\Owner\Application Data\Lavasoft
      C:\Documents and Settings\Owner\Application Data\Leadertech
      C:\Documents and Settings\Owner\Application Data\Macromedia
      C:\Documents and Settings\Owner\Application Data\Microsoft
      C:\Documents and Settings\Owner\Application Data\Mozilla
      C:\Documents and Settings\Owner\Application Data\Msn Search Toolbar
      C:\Documents and Settings\Owner\Application Data\Myspace
      C:\Documents and Settings\Owner\Application Data\Netscape
      C:\Documents and Settings\Owner\Application Data\Opera -- EMPTY Directory
      C:\Documents and Settings\Owner\Application Data\Real
      C:\Documents and Settings\Owner\Application Data\Registry Defender
      C:\Documents and Settings\Owner\Application Data\Sun
      C:\Documents and Settings\Owner\Application Data\Symantec
      C:\Documents and Settings\Owner\Application Data\Syntrillium
      C:\Documents and Settings\Owner\Application Data\Talkback
      C:\Documents and Settings\Owner\Application Data\User Setup Long
      C:\Documents and Settings\Owner\Application Data\Warezghost
      C:\Documents and Settings\Owner\Application Data\Webshots -- EMPTY Directory
      C:\Documents and Settings\Owner\Application Data\Wholesecurity
      C:\Documents and Settings\Owner\Application Data\Yahoo!
      C:\Documents and Settings\Owner\Application Data\Yahoo! Messenger



      HiJack This uninstall_list:
      3-D_Smiley_Guys_Demo Screen Saver
      ABBYY FineReader 5.0 Sprint
      Ad-Aware SE Personal
      Adobe Bridge 1.0
      Adobe Common File Installer
      Adobe Flash Player 9 ActiveX
      Adobe Help Center 1.0
      Adobe Photoshop CS2
      Adobe Reader 7.0.8
      Adobe Stock Photos 1.0
      AIM 6.0
      Allads 1.0
      AOL Uninstaller (Choose which Products to Remove)
      Apple Software Update
      ArcSoft Funhouse
      ArcSoft PhotoImpression
      avast! Antivirus
      AVG Anti-Spyware 7.5
      BitComet 0.79
      Broadcom 440x 10/100 Integrated Controller
      CardRd81
      CCScore
      Conexant SmartHSFi V.9x 56K DF PCI Modem
      Cool Edit Pro 2.0
      CoreVorbis Audio Decoder (remove only)
      CR2
      Dell AIO Printer A920
      Dell Media Experience
      Dell ResourceCD
      DellConnect
      DFX 8 for Winamp
      DivX
      DivX Player
      eBay Toolbar
      ESSBrwr
      ESSCDBK
      ESScore
      ESSCT
      ESSEMAIL
      ESSgui
      ESShelp
      ESSini
      ESSPCD
      ESSPDock
      ESSSONIC
      ESSTOOLS
      essvatgt
      essvcpt
      ESSvpaht
      ESSvpot
      HijackThis 1.99.1
      HLPIndex
      HLPPDOCK
      HLPSFO
      Hotfix for Windows XP (KB896344)
      Hotfix for Windows XP (KB914440)
      Hotfix for Windows XP (KB915865)
      Hotfix for Windows XP (KB926239)
      Intel(R) Extreme Graphics Driver
      iTunes
      J2SE Runtime Environment 5.0 Update 10
      J2SE Runtime Environment 5.0 Update 3
      J2SE Runtime Environment 5.0 Update 6
      J2SE Runtime Environment 5.0 Update 9
      Jasc Paint Shop Pro 9.01 - (9.0.1.1)
      Java 2 Runtime Environment, SE v1.4.1_02
      Kaspersky Online Scanner
      kgcbaby
      kgchday
      kgchlwn
      kgcinvt
      kgckids
      kgcmove
      kgcvday
      Kodak EasyShare software
      KSU
      LimeWire 4.12.6
      Macromedia Shockwave Player
      Microsoft .NET Framework 2.0
      Microsoft Compression Client Pack 1.0 for Windows XP
      Microsoft Encarta Encyclopedia Standard 2003
      Microsoft Internationalized Domain Names Mitigation APIs
      Microsoft Money 2003
      Microsoft Money 2003 System Pack
      Microsoft National Language Support Downlevel APIs
      Microsoft Phishing Filter Add-in for MSN Search Toolbar
      Microsoft Picture It! Photo 7.0
      Microsoft PowerPoint Viewer 97
      Microsoft Streets and Trips 2002
      Microsoft User-Mode Driver Framework Feature Pack 1.0
      Microsoft Windows Journal Viewer
      Microsoft Word 2002
      Microsoft Works 2003 Setup Launcher
      Microsoft Works 7.0
      Microsoft Works Suite Add-in for Microsoft Word
      Mozilla Firefox (2.0.0.1)
      MSN Music Assistant
      MSXML 4.0 SP2 (KB925672)
      MSXML 4.0 SP2 (KB927978)
      Musicmatch for Windows Media Player
      myJAL Apollo Edition
      Notifier
      OfotoXMI
      OTtBP
      OTtBPSDK
      PIXresizer 1.0.9
      PokerStars.net
      QuickTime
      RealPlayer
      Security Update for Microsoft .NET Framework 2.0 (KB917283)
      Security Update for Microsoft .NET Framework 2.0 (KB922770)
      Security Update for Windows Media Player (KB911564)
      Security Update for Windows Media Player 10 (KB911565)
      Security Update for Windows Media Player 10 (KB917734)
      Security Update for Windows Media Player 6.4 (KB925398)
      Security Update for Windows XP (KB883939)
      Security Update for Windows XP (KB890046)
      Security Update for Windows XP (KB893756)
      Security Update for Windows XP (KB896358)
      Security Update for Windows XP (KB896422)
      Security Update for Windows XP (KB896423)
      Security Update for Windows XP (KB896424)
      Security Update for Windows XP (KB896428)
      Security Update for Windows XP (KB896688)
      Security Update for Windows XP (KB899587)
      Security Update for Windows XP (KB899588)
      Security Update for Windows XP (KB899591)
      Security Update for Windows XP (KB900725)
      Security Update for Windows XP (KB901017)
      Security Update for Windows XP (KB901190)
      Security Update for Windows XP (KB901214)
      Security Update for Windows XP (KB902400)
      Security Update for Windows XP (KB903235)
      Security Update for Windows XP (KB904706)
      Security Update for Windows XP (KB905414)
      Security Update for Windows XP (KB905749)
      Security Update for Windows XP (KB905915)
      Security Update for Windows XP (KB908519)
      Security Update for Windows XP (KB908531)
      Security Update for Windows XP (KB911280)
      Security Update for Windows XP (KB911562)
      Security Update for Windows XP (KB911567)
      Security Update for Windows XP (KB911927)
      Security Update for Windows XP (KB912812)
      Security Update for Windows XP (KB912919)
      Security Update for Windows XP (KB913446)
      Security Update for Windows XP (KB913580)
      Security Update for Windows XP (KB914388)
      Security Update for Windows XP (KB914389)
      Security Update for Windows XP (KB916281)
      Security Update for Windows XP (KB917159)
      Security Update for Windows XP (KB917344)
      Security Update for Windows XP (KB917422)
      Security Update for Windows XP (KB917953)
      Security Update for Windows XP (KB918439)
      Security Update for Windows XP (KB919007)
      Security Update for Windows XP (KB920213)
      Security Update for Windows XP (KB920214)
      Security Update for Windows XP (KB920670)
      Security Update for Windows XP (KB920683)
      Security Update for Windows XP (KB920685)
      Security Update for Windows XP (KB921398)
      Security Update for Windows XP (KB921883)
      Security Update for Windows XP (KB922616)
      Security Update for Windows XP (KB922819)
      Security Update for Windows XP (KB923191)
      Security Update for Windows XP (KB923414)
      Security Update for Windows XP (KB923694)
      Security Update for Windows XP (KB923980)
      Security Update for Windows XP (KB924191)
      Security Update for Windows XP (KB924270)
      Security Update for Windows XP (KB924496)
      Security Update for Windows XP (KB926255)
      SFR
      SFR2
      SHASTA
      Shockwave
      SKIN0001
      SKINXSDK
      SoulSeek Client 157 test 8
      SoundMAX
      SP2 Connection Patcher
      Spybot - Search & Destroy 1.4
      The Weather Channel
      Theme Manager
      Trillian
      Update for Windows XP (KB894391)
      Update for Windows XP (KB896727)
      Update for Windows XP (KB898461)
      Update for Windows XP (KB900485)
      Update for Windows XP (KB904942)
      Update for Windows XP (KB910437)
      Update for Windows XP (KB916595)
      Update for Windows XP (KB920872)
      Update for Windows XP (KB922582)
      Viewpoint Media Player
      Vivicam 3340
      VPRINTOL
      Weather Services
      Winamp (remove only)
      Windows Defender
      Windows Defender Signatures
      Windows Genuine Advantage v1.3.0254.0
      Windows Installer 3.1 (KB893803)
      Windows Installer 3.1 (KB893803)
      Windows Internet Explorer 7
      Windows Live Messenger
      Windows Live Sign-in Assistant
      Windows Live Toolbar
      Windows Live Toolbar
      Windows Media Format 11 runtime
      Windows Media Format 11 runtime
      Windows Media Player 11
      Windows Media Player 11
      Windows XP Hotfix - KB834707
      Windows XP Hotfix - KB867282
      Windows XP Hotfix - KB873333
      Windows XP Hotfix - KB873339
      Windows XP Hotfix - KB885250
      Windows XP Hotfix - KB885835
      Windows XP Hotfix - KB885836
      Windows XP Hotfix - KB885884
      Windows XP Hotfix - KB886185
      Windows XP Hotfix - KB887472
      Windows XP Hotfix - KB887742
      Windows XP Hotfix - KB887797
      Windows XP Hotfix - KB888113
      Windows XP Hotfix - KB888240
      Windows XP Hotfix - KB888302
      Windows XP Hotfix - KB890047
      Windows XP Hotfix - KB890175
      Windows XP Hotfix - KB890859
      Windows XP Hotfix - KB890923
      Windows XP Hotfix - KB891781
      Windows XP Hotfix - KB893066
      Windows XP Hotfix - KB893086
      Windows XP Service Pack 2
      WinRAR archiver
      WIRELESS
      Wordware 2002
      X-Cleaner Freeware
      Yahoo! Anti-Spy
      Yahoo! Browser Services
      Yahoo! Mail
      Yahoo! Messenger
      Yahoo! Toolbar
    • TroganTrogan London, UK
      edited January 2007
      Good job! :)

      Please do the following...

      Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

      Updating Java:
      • Download the latest version of Java Runtime Environment (JRE) 6 .
      • Click the "Download" button to the right.
      • Check the box that says: "Accept License Agreement."
      • The page will refresh.
      • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
      • Close any programs you may have running - especially your web browser.
      • Go to Start > Control Panel double-click on Add/Remove programs and remove the following...
        • Java 2 Runtime Environment, SE v1.4.1_02
        • J2SE Runtime Environment 5.0 Update 3
        • J2SE Runtime Environment 5.0 Update 6
        • J2SE Runtime Environment 5.0 Update 9
        • J2SE Runtime Environment 5.0 Update 10
      • Reboot your computer once all Java components are removed.
      • Then from your desktop double-click on jre-6-windows-i586.exe to install the newest version.

      Please post a new HijackThis log. Let me know how things are.
    • edited January 2007
      Thanx. Did all that and here's the latest log:

      Logfile of HijackThis v1.99.1
      Scan saved at 10:39:08 PM, on 1/8/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5730.0011)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      c:\progra~1\intern~1\iexplore.exe
      C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Documents and Settings\Owner\My Documents\Programs\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
      N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
      O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
      O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
      O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [scrchin] C:\DOCUME~1\Owner\APPLIC~1\USERSE~1\filmloadcast.exe
      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
      O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
      O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
      O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
      O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm080YYUS
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
      O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
      O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
      O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8eb9918bc1f44fa99cd9f338612a396
      O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8eb9918bc1f44fa99cd9f338612a396
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1101847098699
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153748136781
      O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cherrytap.com/imgs/ImageUploader4.cab
      O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
      O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2317.cab
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE


      *Wanted to add...still have the popup advertisements in IE and still have that filmlo~1.exe popup at shutdown. When I go to my Sprint Picture Mail site it says on the tab 'Player Detection in Browser' before it says Sprint Picture Mail on the tab...and it won't let me see the pictures...just little red x's where the pics should be. I had to go download Mozilla Firefox to view my pics on the site.:banghead:
    • TroganTrogan London, UK
      edited January 2007
      Download this file to your Desktop- combofix.exe
      Double click combofix.exe & follow the prompts.
      When finished, it shall produce a log for you. Post that log in your next reply

      Note:
      Do not mouseclick combofix's window whilst it's running. That may cause it to stall

      Please post the following...

      1) ComboFix log
      2) New HijackThis log
    • edited January 2007
      THANX, YET AGAIN. Here are the logs:

      Owner - 07-01-09 13:38:02.28 Service Pack 2
      ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Owner\Desktop"

      ((((((((((((((((((((((((((((((( Files Created from 2006-12-09 to 2007-01-09 ))))))))))))))))))))))))))))))))))


      2007-01-08 16:23 <DIR> d----c--- C:\NoLopBackups
      2007-01-08 12:24 <DIR> d
      C:\Documents and Settings\Owner\Application Data\Talkback
      2007-01-08 12:23 <DIR> d
      C:\Program Files\Mozilla Firefox
      2007-01-08 01:22 <DIR> d
      C:\WINDOWS\BDOSCAN8
      2007-01-07 21:49 3,968 --a
      C:\WINDOWS\system32\drivers\AvgAsCln.sys
      2007-01-07 21:49 <DIR> d
      C:\Program Files\Grisoft
      2007-01-07 02:13 <DIR> d
      C:\WINDOWS\system32\Kaspersky Lab
      2006-12-27 10:47 <DIR> d
      C:\Program Files\Spybot - Search & Destroy
      2006-12-27 10:47 <DIR> d
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2006-12-27 02:07 <DIR> d
      C:\Program Files\Lavasoft
      2006-12-27 02:07 <DIR> d
      C:\Documents and Settings\Owner\Application Data\Lavasoft
      2006-12-26 22:21 78,488 --a
      C:\WINDOWS\system32\XMD5.dll
      2006-12-26 22:21 101,888 --a
      C:\WINDOWS\system32\vb6stkit.dll
      2006-12-26 14:35 <DIR> d
      C:\Program Files\iTunes
      2006-12-26 14:35 <DIR> d
      C:\Program Files\iPod
      2006-12-26 14:33 <DIR> d
      C:\Program Files\QuickTime
      2006-12-26 14:32 <DIR> d
      C:\Program Files\Apple Software Update
      2006-12-26 14:31 <DIR> d
      C:\Documents and Settings\All Users\Application Data\Apple Computer
      2006-12-25 21:54 <DIR> d
      C:\Program Files\user setup long
      2006-12-25 21:54 <DIR> d
      C:\Documents and Settings\Owner\Application Data\user setup long
      2006-12-25 21:54 <DIR> d
      C:\Documents and Settings\All Users\Application Data\byterealcopyboob
      2006-12-19 18:13 <DIR> d
      C:\Documents and Settings\Owner\Application Data\Opera
      2006-12-18 23:43 <DIR> d
      C:\Documents and Settings\All Users\Application Data\Adobe Systems
      2006-12-18 23:12 <DIR> d
      C:\Program Files\Common Files\Adobe Systems Shared
      2006-12-13 23:04 <DIR> d
      C:\Documents and Settings\All Users\Application Data\AOL OCP
      2006-12-13 22:54 <DIR> d
      C:\Program Files\AIM6
      2006-12-13 13:34 <DIR> d
      C:\Program Files\Windows Media Connect 2
      2006-12-13 13:30 <DIR> d
      C:\WINDOWS\system32\LogFiles
      2006-12-13 13:30 <DIR> d
      C:\WINDOWS\system32\drivers\UMDF


      (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


      2007-01-08 22:29
      d
      C:\Program Files\SP2 Connection Patcher
      2007-01-08 22:24
      d
      C:\Program Files\Java
      2007-01-08 18:59
      d
      C:\Program Files\PokerStars.NET
      2007-01-08 12:23
      d
      C:\Documents and Settings\Owner\Application Data\Mozilla
      2007-01-08 00:14
      d
      C:\Program Files\YahELite
      2007-01-08 00:13
      d
      C:\Program Files\MyChat
      2007-01-08 00:12
      d
      C:\Program Files\Google
      2006-12-26 11:25
      d
      C:\Program Files\X-Cleaner
      2006-12-19 00:41
      d
      C:\Program Files\Adobe
      2006-12-19 00:37
      d
      C:\Program Files\Common Files\Adobe
      2006-12-18 23:43
      d
      C:\Documents and Settings\Owner\Application Data\Adobe
      2006-12-18 23:12
      d
      C:\Program Files\Common Files
      2006-12-18 18:36
      d
      C:\Program Files\Paint.NET
      2006-12-18 18:34
      d--h
      C:\Program Files\InstallShield Installation Information
      2006-12-18 18:34
      d
      C:\Program Files\IrfanView
      2006-12-18 18:33
      d
      C:\Program Files\dwyco2
      2006-12-15 01:33
      d
      C:\Program Files\Outlook Express
      2006-12-15 01:33
      d
      C:\Program Files\Common Files\System
      2006-12-14 09:36
      d
      C:\Program Files\Common Files\AOL
      2006-12-13 22:58
      d
      C:\Program Files\Common Files\aolshare
      2006-12-13 13:34
      d
      C:\Program Files\Windows Media Player
      2006-12-09 02:05
      d
      C:\Program Files\Trillian
      2006-12-06 17:30
      d
      C:\Program Files\Windows Defender
      2006-12-03 22:58
      d
      C:\Program Files\BitComet
      2006-12-03 22:53 2560 --a
      C:\WINDOWS\system32\BitCometRes.dll
      2006-12-01 14:41
      d
      C:\Program Files\Winamp
      2006-12-01 14:41
      d
      C:\Program Files\DFX
      2006-11-27 22:34
      d
      C:\Program Files\Soulseek-Test
      2006-11-13 14:28
      d---s---- C:\Documents and Settings\Owner\Application Data\Microsoft
      2006-11-13 07:55
      d
      C:\Program Files\Windows Live Toolbar
      2006-11-13 07:55
      d
      C:\Program Files\MSN Toolbar Suite
      2006-11-08 00:06 679424 --a
      C:\WINDOWS\system32\inetcomm.dll
      2006-11-04 14:14 1245696 --a
      C:\WINDOWS\system32\msxml4.dll
      2006-10-19 08:56 713216 --a
      C:\WINDOWS\system32\sxs.dll
      2006-10-18 21:58 8704 --a
      C:\WINDOWS\system32\wdfmgr.exe
      2006-10-18 21:58 8704 --a
      C:\WINDOWS\system32\uwdf.exe
      2006-10-18 21:47 99840 --a
      C:\WINDOWS\system32\wmpshell.dll
      2006-10-18 21:47 991744 --a
      C:\WINDOWS\system32\drmv2clt.dll
      2006-10-18 21:47 937984 --a
      C:\WINDOWS\system32\WMNetMgr.dll
      2006-10-18 21:47 8231936 --a
      C:\WINDOWS\system32\wmploc.dll
      2006-10-18 21:47 767488
      C:\WINDOWS\system32\WMVSENCD.dll
      2006-10-18 21:47 757248 --a
      C:\WINDOWS\system32\WMADMOD.dll
      2006-10-18 21:47 7168 --a
      C:\WINDOWS\system32\asferror.dll
      2006-10-18 21:47 656896
      C:\WINDOWS\system32\WMVXENCD.dll
      2006-10-18 21:47 63488 --a
      C:\WINDOWS\system32\wpdmtpus.dll
      2006-10-18 21:47 629760 --a
      C:\WINDOWS\system32\wpd_ci.dll
      2006-10-18 21:47 613376
      C:\WINDOWS\system32\wmpmde.dll
      2006-10-18 21:47 603648 --a
      C:\WINDOWS\system32\WMSPDMOD.dll
      2006-10-18 21:47 542720 --a
      C:\WINDOWS\system32\blackbox.dll
      2006-10-18 21:47 535040
      C:\WINDOWS\system32\wmdrmsdk.dll
      2006-10-18 21:47 429056 --a
      C:\WINDOWS\system32\wmdrmdev.dll
      2006-10-18 21:47 414208 --a
      C:\WINDOWS\system32\msscp.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wmvdmoe2.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wmvdmod.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\WMVADVE.DLL
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\WMVADVD.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wmsdmoe2.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wmsdmod.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wdfapi.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\MPG4DMOD.dll
      2006-10-18 21:47 4096
      C:\WINDOWS\system32\MP4SDMOD.dll
      2006-10-18 21:47 4096
      C:\WINDOWS\system32\MP43DMOD.dll
      2006-10-18 21:47 38400
      C:\WINDOWS\system32\wpdshextres.dll
      2006-10-18 21:47 37376 --a
      C:\WINDOWS\system32\wmdmps.dll
      2006-10-18 21:47 35840 --a
      C:\WINDOWS\system32\wpdconns.dll
      2006-10-18 21:47 356352 --a
      C:\WINDOWS\system32\wpdsp.dll
      2006-10-18 21:47 348672 --a
      C:\WINDOWS\system32\wmdrmnet.dll
      2006-10-18 21:47 33792 --a
      C:\WINDOWS\system32\wmdmlog.dll
      2006-10-18 21:47 321536 --a
      C:\WINDOWS\system32\mswmdm.dll
      2006-10-18 21:47 317440
      C:\WINDOWS\system32\MP4SDECD.dll
      2006-10-18 21:47 314880 --a
      C:\WINDOWS\system32\wmpdxm.dll
      2006-10-18 21:47 295936
      C:\WINDOWS\system32\wmpeffects.dll
      2006-10-18 21:47 284160
      C:\WINDOWS\system32\PortableDeviceApi.dll
      2006-10-18 21:47 276992 --a
      C:\WINDOWS\system32\audiodev.dll
      2006-10-18 21:47 27136 --a
      C:\WINDOWS\system32\mspmsnsv.dll
      2006-10-18 21:47 2603008
      C:\WINDOWS\system32\WpdShext.dll
      2006-10-18 21:47 259072
      C:\WINDOWS\system32\MPG4DECD.dll
      2006-10-18 21:47 259072
      C:\WINDOWS\system32\MP43DECD.dll
      2006-10-18 21:47 2450944 --a
      C:\WINDOWS\system32\wmvcore.dll
      2006-10-18 21:47 242688 --a
      C:\WINDOWS\system32\wmpasf.dll
      2006-10-18 21:47 229376 --a
      C:\WINDOWS\system32\cewmdm.dll
      2006-10-18 21:47 227328 --a
      C:\WINDOWS\system32\wmerror.dll
      2006-10-18 21:47 222208 --a
      C:\WINDOWS\system32\WMASF.dll
      2006-10-18 21:47 212992
      C:\WINDOWS\system32\MFPLAT.dll
      2006-10-18 21:47 211456 --a
      C:\WINDOWS\system32\qasf.dll
      2006-10-18 21:47 204288 --a
      C:\WINDOWS\system32\wmpsrcwp.dll
      2006-10-18 21:47 199168
      C:\WINDOWS\system32\PortableDeviceWMDRM.dll
      2006-10-18 21:47 179712 --a
      C:\WINDOWS\system32\msnetobj.dll
      2006-10-18 21:47 175616 --a
      C:\WINDOWS\system32\mspmsp.dll
      2006-10-18 21:47 166912
      C:\WINDOWS\system32\PortableDeviceTypes.dll
      2006-10-18 21:47 1661440 --a
      C:\WINDOWS\system32\wmpencen.dll
      2006-10-18 21:47 1574912
      C:\WINDOWS\system32\WMVENCOD.dll
      2006-10-18 21:47 157184 --a
      C:\WINDOWS\system32\wmidx.dll
      2006-10-18 21:47 154624 --a
      C:\WINDOWS\system32\wpdmtp.dll
      2006-10-18 21:47 1543680
      C:\WINDOWS\system32\WMVDECOD.dll
      2006-10-18 21:47 1382912
      C:\WINDOWS\system32\WMVSDECD.dll
      2006-10-18 21:47 133632
      C:\WINDOWS\system32\WPDShServiceObj.dll
      2006-10-18 21:47 1329152 --a
      C:\WINDOWS\system32\WMSPDMOE.dll
      2006-10-18 21:47 132096
      C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
      2006-10-18 21:47 130048
      C:\WINDOWS\system32\wmpps.dll
      2006-10-18 21:47 11264 --a
      C:\WINDOWS\system32\LAPRXY.dll
      2006-10-18 21:47 1117696 --a
      C:\WINDOWS\system32\WMADMOE.dll
      2006-10-18 21:47 101888
      C:\WINDOWS\system32\PortableDeviceClassExtension.dll
      2006-10-18 20:03 100864 --a
      C:\WINDOWS\system32\logagent.exe
      2006-10-18 20:00 249856
      C:\WINDOWS\system32\drmupgds.exe
      2006-10-18 20:00 17408
      C:\WINDOWS\system32\wpdshextautoplay.exe
      2006-10-17 13:33 6049280
      C:\WINDOWS\system32\ieframe.dll
      2006-10-17 13:33 50688
      C:\WINDOWS\system32\msfeedsbs.dll
      2006-10-17 13:33 458752
      C:\WINDOWS\system32\msfeeds.dll
      2006-10-17 13:33 413696 --a
      C:\WINDOWS\system32\vbscript.dll
      2006-10-17 13:33 231424 --a
      C:\WINDOWS\system32\webcheck.dll
      2006-10-17 13:33 180736
      C:\WINDOWS\system32\ieui.dll
      2006-10-17 13:33 156160 --a
      C:\WINDOWS\system32\msls31.dll
      2006-10-17 13:06 78336 --a
      C:\WINDOWS\system32\ieencode.dll
      2006-10-17 13:05 40960 --a
      C:\WINDOWS\system32\licmgr10.dll
      2006-10-17 13:05 206336
      C:\WINDOWS\system32\WinFXDocObj.exe
      2006-10-17 13:05 105984 --a
      C:\WINDOWS\system32\url.dll
      2006-10-17 13:04 101376 --a
      C:\WINDOWS\system32\occache.dll
      2006-10-17 13:03 17408 --a
      C:\WINDOWS\system32\corpol.dll
      2006-10-17 13:01 71680 --a
      C:\WINDOWS\system32\admparse.dll
      2006-10-17 13:01 55296 --a
      C:\WINDOWS\system32\iesetup.dll
      2006-10-17 13:01 382976 --a
      C:\WINDOWS\system32\iedkcs32.dll
      2006-10-17 13:01 229376 --a
      C:\WINDOWS\system32\ieaksie.dll
      2006-10-17 13:01 152064 --a
      C:\WINDOWS\system32\ieakeng.dll
      2006-10-17 13:01 13312 --a
      C:\WINDOWS\system32\ieudinit.exe
      2006-10-17 13:00 54784 --a
      C:\WINDOWS\system32\ie4uinit.exe
      2006-10-17 13:00 43008 --a
      C:\WINDOWS\system32\iernonce.dll
      2006-10-17 13:00 123904 --a
      C:\WINDOWS\system32\advpack.dll
      2006-10-17 12:58 61952
      C:\WINDOWS\system32\icardie.dll
      2006-10-17 12:58 12288
      C:\WINDOWS\system32\msfeedssync.exe
      2006-10-17 12:57 36352 --a
      C:\WINDOWS\system32\imgutil.dll
      2006-10-17 12:57 266752
      C:\WINDOWS\system32\iertutil.dll
      2006-10-17 12:56 45568 --a
      C:\WINDOWS\system32\mshta.exe
      2006-10-17 12:28 48128 --a
      C:\WINDOWS\system32\mshtmler.dll
      2006-10-17 12:27 380928
      C:\WINDOWS\system32\ieapfltr.dll
      2006-10-17 12:23 161792 --a
      C:\WINDOWS\system32\ieakui.dll
      2006-10-13 07:35 142336 --a
      C:\WINDOWS\system32\nwprovau.dll


      (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

      *Note* empty entries are not shown

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
      "SP2 Connection Patcher"="\"C:\\Program Files\\SP2 Connection Patcher\\SP2ConnPatcher.exe\" -n=200"
      "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
      "scrchin"="C:\\DOCUME~1\\Owner\\APPLIC~1\\USERSE~1\\filmloadcast.exe"
      "Aim6"=""

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
      "eBayToolbar"="C:\\Program Files\\eBay\\eBay Toolbar2\\eBayTBDaemon.exe"
      "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
      "IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
      "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
      "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
      "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
      "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
      "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
      "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
      "Installed"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
      "Installed"="1"
      "NoChange"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
      "Installed"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE\Microsoft]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE\Microsoft\Windows]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE\Microsoft\Windows\CurrentVersion]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "WFIPS"="C:\\Documents and Settings\\Owner\\My Documents\\Programs\\IPhider\\ip hider.exe -autoboot"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
      @=&quot;"

      [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
      "DeskHtmlVersion"=dword:00000110
      "DeskHtmlMinorVersion"=dword:00000005
      "Settings"=dword:00000001
      "GeneralFlags"=dword:00000000

      [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
      "Source"="http://www.totse.com/images/t3/bg.jpg&quot;
      "SubscribedURL"="http://www.totse.com/images/t3/bg.jpg&quot;
      "FriendlyName"=""
      "Flags"=dword:00000001
      "Position"=hex:2c,00,00,00,90,01,00,00,2e,01,00,00,70,00,00,00,74,00,00,00,e8,\
      03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
      "CurrentState"=dword:00000001
      "OriginalStateInfo"=hex:18,00,00,00,12,03,00,00,19,01,00,00,70,00,00,00,74,00,\
      00,00,01,00,00,40
      "RestoredStateInfo"=hex:14,6d,37,03,41,c0,b4,74,18,c0,56,04,68,de,37,03,20,6d,\
      37,03,96,15,00,00

      [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My Current Home Page"
      "Flags"=dword:00000002
      "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,ea,\
      03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
      "CurrentState"=dword:40000004
      "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
      ff,ff,04,00,00,00
      "RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
      00,00,01,00,00,00

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
      "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
      "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
      "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
      "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
      "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
      "NoDriveTypeAutoRun"=dword:00000091

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "dontdisplaylastusername"=dword:00000000
      "legalnoticecaption"=""
      "legalnoticetext"=""
      "shutdownwithoutlogon"=dword:00000001
      "undockwithoutlogon"=dword:00000001

      [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
      "NoDriveTypeAutoRun"=dword:00000091

      [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
      "NoDriveTypeAutoRun"=dword:00000091

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
      "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
      "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
      "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
      "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
      "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
      "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
      "item"="Adobe Reader Speed Launch"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak EasyShare software.lnk"
      "backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -hx"
      "item"="Kodak EasyShare software"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak software updater.lnk"
      "backup"="C:\\WINDOWS\\pss\\Kodak software updater.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\Kodak\\KODAKS~1\\7288971\\Program\\KODAKS~1.EXE "
      "item"="Kodak software updater"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
      "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\MICROS~4\\Office10\\OSA.EXE -b -l"
      "item"="Microsoft Office"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Windows Desktop Search.lnk"
      "backup"="C:\\WINDOWS\\pss\\Windows Desktop Search.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\MSNTOO~1\\DS\\020500~1.111\\en-us\\bin\\WINDOW~3.EXE /startup"
      "item"="Windows Desktop Search"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Webshots.lnk]
      "path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\Webshots.lnk"
      "backup"="C:\\WINDOWS\\pss\\Webshots.lnkStartup"
      "location"="Startup"
      "command"="C:\\Program Files\\Webshots\\Launcher.exe /t"
      "item"="Webshots"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="apdproxy"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\*********]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="*********"
      "hkey"="HKLM"
      "command"="C:\\Program Files\\*********\\********* Personal Firewall\\*********.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="ashDisp"
      "hkey"="HKLM"
      "command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BestPopUpKiller]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="BestPopupKiller"
      "hkey"="HKCU"
      "command"="C:\\Program Files\\BestPopUpKiller\\BestPopupKiller.exe /startup"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="dlbkbmgr"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Dell AIO Printer A920\\dlbkbmgr.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"=""
      "hkey"="HKCU"
      "command"=""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="gcasServ"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="hkcmd"
      "hkey"="HKLM"
      "command"="C:\\WINDOWS\\system32\\hkcmd.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="igfxtray"
      "hkey"="HKLM"
      "command"="C:\\WINDOWS\\system32\\igfxtray.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="WkUFind"
      "hkey"="HKLM"
      "command"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="mnyexpr"
      "hkey"="HKCU"
      "command"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="NEWDOT~2"
      "hkey"="HKLM"
      "command"="rundll32 C:\\PROGRA~1\\NEWDOT~1\\NEWDOT~2.DLL,NewDotNetStartup -s"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="PCMService"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="qttask"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SP2 Connection Patcher]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="SP2ConnPatcher"
      "hkey"="HKCU"
      "command"="\"C:\\Program Files\\SP2 Connection Patcher\\SP2ConnPatcher.exe\" -n=200"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyKiller]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="spykiller"
      "hkey"="HKCU"
      "command"="C:\\Program Files\\SpyKiller\\spykiller.exe /startup"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Begone]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="freescan"
      "hkey"="HKCU"
      "command"="C:\\freescan\\freescan.exe -FastScan"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="realsched"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Registry Repair Pro]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="RegistryRepairPro"
      "hkey"="HKCU"
      "command"="C:\\Program Files\\3B Software\\Windows Registry Repair Pro\\RegistryRepairPro.exe 4"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\X-Cleaner Freeware]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="XCLEAN~1"
      "hkey"="HKCU"
      "command"="\"C:\\PROGRA~1\\X-CLEA~1\\XCLEAN~1.EXE\" -turbo -autostart -NOREBOOT"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
      "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


      Contents of the 'Scheduled Tasks' folder
      C:\WINDOWS\tasks\AppleSoftwareUpdate.job
      C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
      C:\WINDOWS\tasks\Disk Cleanup.job
      C:\WINDOWS\tasks\MP Scheduled Scan.job

      Completion time: 07-01-09 13:40:32.17
      C:\ComboFix.txt ... 07-01-09 13:40





      Logfile of HijackThis v1.99.1
      Scan saved at 1:44:11 PM, on 1/9/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5730.0011)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      c:\progra~1\intern~1\iexplore.exe
      C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\Documents and Settings\Owner\My Documents\Programs\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
      N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
      O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
      O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
      O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [scrchin] C:\DOCUME~1\Owner\APPLIC~1\USERSE~1\filmloadcast.exe
      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
      O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
      O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
      O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
      O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm080YYUS
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
      O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
      O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
      O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8eb9918bc1f44fa99cd9f338612a396
      O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8eb9918bc1f44fa99cd9f338612a396
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1101847098699
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153748136781
      O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cherrytap.com/imgs/ImageUploader4.cab
      O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
      O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2317.cab
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    • TroganTrogan London, UK
      edited January 2007
      I need to see two more logs and then we can get rid of this mess. :)

      First, I need to see another log from HijackThis.
      • Run Hijackthis.
      • Click on Open the Misc Tools section.
      • Next click on Open uninstall manager.
      • Press the Save list button.
      • Save the file to your desktop, with the default name of uninstall_list
      • Copy & Paste the entire contents of that file in your in your next post.
      Second,
      1. Create a new folder in the C:. To do that, Double-Click My Computer > Double-Click C: or Your Local Disk > Go to File > New > Folder. Name the folder as FindLop
      2. Next, download Findlop by Metallica and save it to your desktop.
      3. Open the zip file on your desktop, and extract the contents to C:\FindLop
      4. Navigate to the C:\FindLop, and Double-Click on Findlop.bat. It will open a notepad file.
      5. Copy and paste the contents in your next reply.
    • edited January 2007
      Well, I hope I did this right. Here's what I got:

      [TRACE] Enumerating jobs and queues
      [TRACE] Activating job 'AppleSoftwareUpdate.job'
      [TRACE] Printing all job properties

      ApplicationName: 'C:\Program Files\Apple Software Update\SoftwareUpdate.exe'
      Parameters: '-Task'
      WorkingDirectory: ''
      Comment: ''
      Creator: 'SYSTEM'
      Priority: NORMAL
      MaxRunTime: 259200000 (3d 0:00:00)
      IdleWait: 10
      IdleDeadline: 60
      MostRecentRun: 12/27/2006 8:57:00
      NextRun: 01/10/2007 8:57:00
      StartError: S_OK
      ExitCode: 0
      Status: SCHED_S_TASK_READY
      ScheduledWorkItem Flags:
      DeleteWhenDone = 0
      Suspend = 0
      StartOnlyIfIdle = 0
      KillOnIdleEnd = 0
      RestartOnIdleResume = 0
      DontStartIfOnBatteries = 0
      KillIfGoingOnBatteries = 0
      RunOnlyIfLoggedOn = 0
      SystemRequired = 0
      Hidden = 0
      TaskFlags: 0

      1 Trigger

      Trigger 0:
      Type: Weekly
      WeeksInterval: 1
      DaysOfTheWeek: ...W...
      StartDate: 12/26/2006
      EndDate: 00/00/0000
      StartTime: 08:57
      MinutesDuration: 0
      MinutesInterval: 0
      Flags:
      HasEndDate = 0
      KillAtDuration = 0
      Disabled = 0


      [TRACE] Activating job 'Check Updates for Windows Live Toolbar.job'
      [TRACE] Printing all job properties

      ApplicationName: 'C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE'
      Parameters: ''
      WorkingDirectory: ''
      Comment: ''
      Creator: 'Owner'
      Priority: NORMAL
      MaxRunTime: 259200000 (3d 0:00:00)
      IdleWait: 10
      IdleDeadline: 60
      MostRecentRun: 01/09/2007 16:15:00
      NextRun: 01/09/2007 17:15:00
      StartError: S_OK
      ExitCode: 0
      Status: SCHED_S_TASK_READY
      ScheduledWorkItem Flags:
      DeleteWhenDone = 0
      Suspend = 0
      StartOnlyIfIdle = 0
      KillOnIdleEnd = 0
      RestartOnIdleResume = 0
      DontStartIfOnBatteries = 0
      KillIfGoingOnBatteries = 0
      RunOnlyIfLoggedOn = 0
      SystemRequired = 0
      Hidden = 0
      TaskFlags: 0

      1 Trigger

      Trigger 0:
      Type: Daily
      DaysInterval: 1
      StartDate: 11/13/2006
      EndDate: 00/00/0000
      StartTime: 01:15
      MinutesDuration: 1440
      MinutesInterval: 60
      Flags:
      HasEndDate = 0
      KillAtDuration = 0
      Disabled = 0


      [TRACE] Activating job 'Disk Cleanup.job'
      [TRACE] Printing all job properties

      ApplicationName: 'C:\WINDOWS\system32\cleanmgr.exe'
      Parameters: ''
      WorkingDirectory: 'C:\WINDOWS\system32'
      Comment: ''
      Creator: 'Owner'
      Priority: NORMAL
      MaxRunTime: 7200000 (0d 2:00:00)
      IdleWait: 10
      IdleDeadline: 60
      MostRecentRun: 00/00/0000 0:00:00
      NextRun: 02/01/2007 9:00:00
      StartError: 0x8007052e
      ExitCode: 0
      Status: SCHED_S_TASK_HAS_NOT_RUN
      ScheduledWorkItem Flags:
      DeleteWhenDone = 0
      Suspend = 0
      StartOnlyIfIdle = 0
      KillOnIdleEnd = 0
      RestartOnIdleResume = 0
      DontStartIfOnBatteries = 1
      KillIfGoingOnBatteries = 1
      RunOnlyIfLoggedOn = 0
      SystemRequired = 1
      Hidden = 0
      TaskFlags: 0

      1 Trigger

      Trigger 0:
      Type: MonthlyDate
      Days: 1
      Months: JanFebMarAprMayJunJulAugSepOctNovDec
      StartDate: 11/01/2004
      EndDate: 00/00/0000
      StartTime: 09:00
      MinutesDuration: 0
      MinutesInterval: 0
      Flags:
      HasEndDate = 0
      KillAtDuration = 0
      Disabled = 0


      [TRACE] Activating job 'MP Scheduled Scan.job'
      [TRACE] Printing all job properties

      ApplicationName: 'C:\Program Files\Windows Defender\MpCmdRun.exe'
      Parameters: 'Scan -RestrictPrivileges'
      WorkingDirectory: ''
      Comment: 'Scheduled Scan'
      Creator: 'SYSTEM'
      Priority: NORMAL
      MaxRunTime: 259200000 (3d 0:00:00)
      IdleWait: 10
      IdleDeadline: 60
      MostRecentRun: 01/09/2007 11:00:00
      NextRun: 01/10/2007 11:00:00
      StartError: S_OK
      ExitCode: 0
      Status: SCHED_S_TASK_READY
      ScheduledWorkItem Flags:
      DeleteWhenDone = 0
      Suspend = 0
      StartOnlyIfIdle = 0
      KillOnIdleEnd = 0
      RestartOnIdleResume = 0
      DontStartIfOnBatteries = 1
      KillIfGoingOnBatteries = 0
      RunOnlyIfLoggedOn = 0
      SystemRequired = 0
      Hidden = 1
      TaskFlags: 0

      1 Trigger

      Trigger 0:
      Type: Daily
      DaysInterval: 1
      StartDate: 01/08/2007
      EndDate: 00/00/0000
      StartTime: 11:00
      MinutesDuration: 0
      MinutesInterval: 0
      Flags:
      HasEndDate = 0
      KillAtDuration = 0
      Disabled = 0


      Logfile of HijackThis v1.99.1
      Scan saved at 4:41:48 PM, on 1/9/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5730.0011)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      c:\progra~1\intern~1\iexplore.exe
      C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Owner\My Documents\Programs\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
      N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
      O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
      O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
      O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [scrchin] C:\DOCUME~1\Owner\APPLIC~1\USERSE~1\filmloadcast.exe
      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
      O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
      O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
      O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
      O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm080YYUS
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
      O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
      O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
      O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8eb9918bc1f44fa99cd9f338612a396
      O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8eb9918bc1f44fa99cd9f338612a396
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1101847098699
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153748136781
      O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cherrytap.com/imgs/ImageUploader4.cab
      O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
      O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2317.cab
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

      Thanx so much. :)
    • TroganTrogan London, UK
      edited January 2007
      You posted the FindLop log, which is correct.

      You posted a new HijackThis log but that's not what I want. I need an Uninstall list...check my last post again.
    • edited January 2007
      I'm sooooo sorry. I wasn't even thinking when I posted that. My fault. Here you go:

      3-D_Smiley_Guys_Demo Screen Saver
      ABBYY FineReader 5.0 Sprint
      Ad-Aware SE Personal
      Adobe Bridge 1.0
      Adobe Common File Installer
      Adobe Flash Player 9 ActiveX
      Adobe Help Center 1.0
      Adobe Photoshop CS2
      Adobe Reader 7.0.8
      Adobe Stock Photos 1.0
      AIM 6.0
      Allads 1.0
      AOL Uninstaller (Choose which Products to Remove)
      Apple Software Update
      ArcSoft Funhouse
      ArcSoft PhotoImpression
      avast! Antivirus
      AVG Anti-Spyware 7.5
      BitComet 0.79
      Broadcom 440x 10/100 Integrated Controller
      CardRd81
      CCScore
      Conexant SmartHSFi V.9x 56K DF PCI Modem
      Cool Edit Pro 2.0
      CoreVorbis Audio Decoder (remove only)
      CR2
      Dell AIO Printer A920
      Dell Media Experience
      Dell ResourceCD
      DellConnect
      DFX 8 for Winamp
      DivX
      DivX Player
      eBay Toolbar
      ESSBrwr
      ESSCDBK
      ESScore
      ESSCT
      ESSEMAIL
      ESSgui
      ESShelp
      ESSini
      ESSPCD
      ESSPDock
      ESSSONIC
      ESSTOOLS
      essvatgt
      essvcpt
      ESSvpaht
      ESSvpot
      HijackThis 1.99.1
      HLPIndex
      HLPPDOCK
      HLPSFO
      Hotfix for Windows XP (KB896344)
      Hotfix for Windows XP (KB914440)
      Hotfix for Windows XP (KB915865)
      Hotfix for Windows XP (KB926239)
      Intel(R) Extreme Graphics Driver
      iTunes
      Jasc Paint Shop Pro 9.01 - (9.0.1.1)
      Java 2 Runtime Environment, SE v1.4.1_02
      Java(TM) SE Runtime Environment 6
      Kaspersky Online Scanner
      kgcbaby
      kgchday
      kgchlwn
      kgcinvt
      kgckids
      kgcmove
      kgcvday
      Kodak EasyShare software
      KSU
      LimeWire 4.12.6
      Macromedia Shockwave Player
      Microsoft .NET Framework 2.0
      Microsoft Compression Client Pack 1.0 for Windows XP
      Microsoft Encarta Encyclopedia Standard 2003
      Microsoft Internationalized Domain Names Mitigation APIs
      Microsoft Money 2003
      Microsoft Money 2003 System Pack
      Microsoft National Language Support Downlevel APIs
      Microsoft Phishing Filter Add-in for MSN Search Toolbar
      Microsoft Picture It! Photo 7.0
      Microsoft PowerPoint Viewer 97
      Microsoft Streets and Trips 2002
      Microsoft User-Mode Driver Framework Feature Pack 1.0
      Microsoft Windows Journal Viewer
      Microsoft Word 2002
      Microsoft Works 2003 Setup Launcher
      Microsoft Works 7.0
      Microsoft Works Suite Add-in for Microsoft Word
      Mozilla Firefox (2.0.0.1)
      MSN Music Assistant
      MSXML 4.0 SP2 (KB925672)
      MSXML 4.0 SP2 (KB927978)
      Musicmatch for Windows Media Player
      myJAL Apollo Edition
      Notifier
      OfotoXMI
      OTtBP
      OTtBPSDK
      PIXresizer 1.0.9
      PokerStars.net
      QuickTime
      RealPlayer
      Security Update for Microsoft .NET Framework 2.0 (KB917283)
      Security Update for Microsoft .NET Framework 2.0 (KB922770)
      Security Update for Windows Internet Explorer 7 (KB929969)
      Security Update for Windows Media Player (KB911564)
      Security Update for Windows Media Player 10 (KB911565)
      Security Update for Windows Media Player 10 (KB917734)
      Security Update for Windows Media Player 6.4 (KB925398)
      Security Update for Windows XP (KB883939)
      Security Update for Windows XP (KB890046)
      Security Update for Windows XP (KB893756)
      Security Update for Windows XP (KB896358)
      Security Update for Windows XP (KB896422)
      Security Update for Windows XP (KB896423)
      Security Update for Windows XP (KB896424)
      Security Update for Windows XP (KB896428)
      Security Update for Windows XP (KB896688)
      Security Update for Windows XP (KB899587)
      Security Update for Windows XP (KB899588)
      Security Update for Windows XP (KB899591)
      Security Update for Windows XP (KB900725)
      Security Update for Windows XP (KB901017)
      Security Update for Windows XP (KB901190)
      Security Update for Windows XP (KB901214)
      Security Update for Windows XP (KB902400)
      Security Update for Windows XP (KB903235)
      Security Update for Windows XP (KB904706)
      Security Update for Windows XP (KB905414)
      Security Update for Windows XP (KB905749)
      Security Update for Windows XP (KB905915)
      Security Update for Windows XP (KB908519)
      Security Update for Windows XP (KB908531)
      Security Update for Windows XP (KB911280)
      Security Update for Windows XP (KB911562)
      Security Update for Windows XP (KB911567)
      Security Update for Windows XP (KB911927)
      Security Update for Windows XP (KB912812)
      Security Update for Windows XP (KB912919)
      Security Update for Windows XP (KB913446)
      Security Update for Windows XP (KB913580)
      Security Update for Windows XP (KB914388)
      Security Update for Windows XP (KB914389)
      Security Update for Windows XP (KB916281)
      Security Update for Windows XP (KB917159)
      Security Update for Windows XP (KB917344)
      Security Update for Windows XP (KB917422)
      Security Update for Windows XP (KB917953)
      Security Update for Windows XP (KB918439)
      Security Update for Windows XP (KB919007)
      Security Update for Windows XP (KB920213)
      Security Update for Windows XP (KB920214)
      Security Update for Windows XP (KB920670)
      Security Update for Windows XP (KB920683)
      Security Update for Windows XP (KB920685)
      Security Update for Windows XP (KB921398)
      Security Update for Windows XP (KB921883)
      Security Update for Windows XP (KB922616)
      Security Update for Windows XP (KB922819)
      Security Update for Windows XP (KB923191)
      Security Update for Windows XP (KB923414)
      Security Update for Windows XP (KB923694)
      Security Update for Windows XP (KB923980)
      Security Update for Windows XP (KB924191)
      Security Update for Windows XP (KB924270)
      Security Update for Windows XP (KB924496)
      Security Update for Windows XP (KB926255)
      SFR
      SFR2
      SHASTA
      Shockwave
      SKIN0001
      SKINXSDK
      SoulSeek Client 157 test 8
      SoundMAX
      SP2 Connection Patcher
      Spybot - Search & Destroy 1.4
      The Weather Channel
      Theme Manager
      Trillian
      Update for Windows XP (KB894391)
      Update for Windows XP (KB896727)
      Update for Windows XP (KB898461)
      Update for Windows XP (KB900485)
      Update for Windows XP (KB904942)
      Update for Windows XP (KB910437)
      Update for Windows XP (KB916595)
      Update for Windows XP (KB920872)
      Update for Windows XP (KB922582)
      Viewpoint Media Player
      Vivicam 3340
      VPRINTOL
      Weather Services
      Winamp (remove only)
      Windows Defender
      Windows Defender Signatures
      Windows Genuine Advantage v1.3.0254.0
      Windows Installer 3.1 (KB893803)
      Windows Installer 3.1 (KB893803)
      Windows Internet Explorer 7
      Windows Live Messenger
      Windows Live Sign-in Assistant
      Windows Live Toolbar
      Windows Live Toolbar
      Windows Media Format 11 runtime
      Windows Media Format 11 runtime
      Windows Media Player 11
      Windows Media Player 11
      Windows XP Hotfix - KB834707
      Windows XP Hotfix - KB867282
      Windows XP Hotfix - KB873333
      Windows XP Hotfix - KB873339
      Windows XP Hotfix - KB885250
      Windows XP Hotfix - KB885835
      Windows XP Hotfix - KB885836
      Windows XP Hotfix - KB885884
      Windows XP Hotfix - KB886185
      Windows XP Hotfix - KB887472
      Windows XP Hotfix - KB887742
      Windows XP Hotfix - KB887797
      Windows XP Hotfix - KB888113
      Windows XP Hotfix - KB888240
      Windows XP Hotfix - KB888302
      Windows XP Hotfix - KB890047
      Windows XP Hotfix - KB890175
      Windows XP Hotfix - KB890859
      Windows XP Hotfix - KB890923
      Windows XP Hotfix - KB891781
      Windows XP Hotfix - KB893066
      Windows XP Hotfix - KB893086
      Windows XP Service Pack 2
      WinRAR archiver
      WIRELESS
      Wordware 2002
      X-Cleaner Freeware
      Yahoo! Anti-Spy
      Yahoo! Browser Services
      Yahoo! Mail
      Yahoo! Messenger
      Yahoo! Toolbar
    • TroganTrogan London, UK
      edited January 2007
      Please do the following...

      1. Follow the instructions on PROCEDURE 4 at this site.

      2. Open HijackThis
      - Click the Do a system scan only button
      - Check the following entries (below)

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/cust.../www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

      O4 - HKCU\..\Run: [scrchin] C:\DOCUME~1\Owner\APPLIC~1\USERSE~1\filmloadcast.e xe


      - Close ALL open windows (especially Internet Explorer!)
      - Click Fix Checked
      Close HiajckThis

      3. Find and delete the following Folders:

      C:\Documents and Settings\Owner\Application Data\User Setup Long <-- This folder
      C:\Program Files\user setup long <-- This Folder

      4. Reboot the computer and run ComboFix once more. Post the new log along with a new HijackThis log.
    • edited January 2007
      THANK YOU THANK YOU THANK YOU. Here's the scans:

      Owner - 07-01-09 22:52:51.29 Service Pack 2
      ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Owner\My Documents\Programs"

      ((((((((((((((((((((((((((((((( Files Created from 2006-12-09 to 2007-01-09 ))))))))))))))))))))))))))))))))))


      2007-01-09 17:49 <DIR> d
      C:\WINDOWS\ie7updates
      2007-01-09 16:43 <DIR> d----c--- C:\FindLop
      2007-01-08 16:23 <DIR> d----c--- C:\NoLopBackups
      2007-01-08 12:24 <DIR> d
      C:\Documents and Settings\Owner\Application Data\Talkback
      2007-01-08 12:23 <DIR> d
      C:\Program Files\Mozilla Firefox
      2007-01-08 01:22 <DIR> d
      C:\WINDOWS\BDOSCAN8
      2007-01-07 21:49 3,968 --a
      C:\WINDOWS\system32\drivers\AvgAsCln.sys
      2007-01-07 21:49 <DIR> d
      C:\Program Files\Grisoft
      2007-01-07 02:13 <DIR> d
      C:\WINDOWS\system32\Kaspersky Lab
      2006-12-27 10:47 <DIR> d
      C:\Program Files\Spybot - Search & Destroy
      2006-12-27 10:47 <DIR> d
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2006-12-27 02:07 <DIR> d
      C:\Program Files\Lavasoft
      2006-12-27 02:07 <DIR> d
      C:\Documents and Settings\Owner\Application Data\Lavasoft
      2006-12-26 22:21 78,488 --a
      C:\WINDOWS\system32\XMD5.dll
      2006-12-26 22:21 101,888 --a
      C:\WINDOWS\system32\vb6stkit.dll
      2006-12-26 14:35 <DIR> d
      C:\Program Files\iTunes
      2006-12-26 14:35 <DIR> d
      C:\Program Files\iPod
      2006-12-26 14:33 <DIR> d
      C:\Program Files\QuickTime
      2006-12-26 14:32 <DIR> d
      C:\Program Files\Apple Software Update
      2006-12-26 14:31 <DIR> d
      C:\Documents and Settings\All Users\Application Data\Apple Computer
      2006-12-25 21:54 <DIR> d
      C:\Documents and Settings\All Users\Application Data\byterealcopyboob
      2006-12-19 18:13 <DIR> d
      C:\Documents and Settings\Owner\Application Data\Opera
      2006-12-18 23:43 <DIR> d
      C:\Documents and Settings\All Users\Application Data\Adobe Systems
      2006-12-18 23:12 <DIR> d
      C:\Program Files\Common Files\Adobe Systems Shared
      2006-12-13 23:04 <DIR> d
      C:\Documents and Settings\All Users\Application Data\AOL OCP
      2006-12-13 22:54 <DIR> d
      C:\Program Files\AIM6
      2006-12-13 13:34 <DIR> d
      C:\Program Files\Windows Media Connect 2
      2006-12-13 13:30 <DIR> d
      C:\WINDOWS\system32\LogFiles
      2006-12-13 13:30 <DIR> d
      C:\WINDOWS\system32\drivers\UMDF


      (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


      2007-01-09 22:50
      d
      C:\Program Files\SP2 Connection Patcher
      2007-01-08 22:24
      d
      C:\Program Files\Java
      2007-01-08 18:59
      d
      C:\Program Files\PokerStars.NET
      2007-01-08 12:23
      d
      C:\Documents and Settings\Owner\Application Data\Mozilla
      2007-01-08 00:14
      d
      C:\Program Files\YahELite
      2007-01-08 00:13
      d
      C:\Program Files\MyChat
      2007-01-08 00:12
      d
      C:\Program Files\Google
      2006-12-26 11:25
      d
      C:\Program Files\X-Cleaner
      2006-12-19 00:41
      d
      C:\Program Files\Adobe
      2006-12-19 00:37
      d
      C:\Program Files\Common Files\Adobe
      2006-12-18 23:43
      d
      C:\Documents and Settings\Owner\Application Data\Adobe
      2006-12-18 23:12
      d
      C:\Program Files\Common Files
      2006-12-18 18:36
      d
      C:\Program Files\Paint.NET
      2006-12-18 18:34
      d--h
      C:\Program Files\InstallShield Installation Information
      2006-12-18 18:34
      d
      C:\Program Files\IrfanView
      2006-12-18 18:33
      d
      C:\Program Files\dwyco2
      2006-12-15 01:33
      d
      C:\Program Files\Outlook Express
      2006-12-15 01:33
      d
      C:\Program Files\Common Files\System
      2006-12-14 09:36
      d
      C:\Program Files\Common Files\AOL
      2006-12-13 22:58
      d
      C:\Program Files\Common Files\aolshare
      2006-12-13 13:34
      d
      C:\Program Files\Windows Media Player
      2006-12-09 02:05
      d
      C:\Program Files\Trillian
      2006-12-06 17:30
      d
      C:\Program Files\Windows Defender
      2006-12-03 22:58
      d
      C:\Program Files\BitComet
      2006-12-03 22:53 2560 --a
      C:\WINDOWS\system32\BitCometRes.dll
      2006-12-01 14:41
      d
      C:\Program Files\Winamp
      2006-12-01 14:41
      d
      C:\Program Files\DFX
      2006-11-27 22:34
      d
      C:\Program Files\Soulseek-Test
      2006-11-13 14:28
      d---s---- C:\Documents and Settings\Owner\Application Data\Microsoft
      2006-11-13 07:55
      d
      C:\Program Files\Windows Live Toolbar
      2006-11-13 07:55
      d
      C:\Program Files\MSN Toolbar Suite
      2006-11-08 00:06 679424 --a
      C:\WINDOWS\system32\inetcomm.dll
      2006-11-04 14:14 1245696 --a
      C:\WINDOWS\system32\msxml4.dll
      2006-10-19 08:56 713216 --a
      C:\WINDOWS\system32\sxs.dll
      2006-10-18 21:58 8704 --a
      C:\WINDOWS\system32\wdfmgr.exe
      2006-10-18 21:58 8704 --a
      C:\WINDOWS\system32\uwdf.exe
      2006-10-18 21:47 99840 --a
      C:\WINDOWS\system32\wmpshell.dll
      2006-10-18 21:47 991744 --a
      C:\WINDOWS\system32\drmv2clt.dll
      2006-10-18 21:47 937984 --a
      C:\WINDOWS\system32\WMNetMgr.dll
      2006-10-18 21:47 8231936 --a
      C:\WINDOWS\system32\wmploc.dll
      2006-10-18 21:47 767488
      C:\WINDOWS\system32\WMVSENCD.dll
      2006-10-18 21:47 757248 --a
      C:\WINDOWS\system32\WMADMOD.dll
      2006-10-18 21:47 7168 --a
      C:\WINDOWS\system32\asferror.dll
      2006-10-18 21:47 656896
      C:\WINDOWS\system32\WMVXENCD.dll
      2006-10-18 21:47 63488 --a
      C:\WINDOWS\system32\wpdmtpus.dll
      2006-10-18 21:47 629760 --a
      C:\WINDOWS\system32\wpd_ci.dll
      2006-10-18 21:47 613376
      C:\WINDOWS\system32\wmpmde.dll
      2006-10-18 21:47 603648 --a
      C:\WINDOWS\system32\WMSPDMOD.dll
      2006-10-18 21:47 542720 --a
      C:\WINDOWS\system32\blackbox.dll
      2006-10-18 21:47 535040
      C:\WINDOWS\system32\wmdrmsdk.dll
      2006-10-18 21:47 429056 --a
      C:\WINDOWS\system32\wmdrmdev.dll
      2006-10-18 21:47 414208 --a
      C:\WINDOWS\system32\msscp.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wmvdmoe2.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wmvdmod.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\WMVADVE.DLL
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\WMVADVD.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wmsdmoe2.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wmsdmod.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\wdfapi.dll
      2006-10-18 21:47 4096 --a
      C:\WINDOWS\system32\MPG4DMOD.dll
      2006-10-18 21:47 4096
      C:\WINDOWS\system32\MP4SDMOD.dll
      2006-10-18 21:47 4096
      C:\WINDOWS\system32\MP43DMOD.dll
      2006-10-18 21:47 38400
      C:\WINDOWS\system32\wpdshextres.dll
      2006-10-18 21:47 37376 --a
      C:\WINDOWS\system32\wmdmps.dll
      2006-10-18 21:47 35840 --a
      C:\WINDOWS\system32\wpdconns.dll
      2006-10-18 21:47 356352 --a
      C:\WINDOWS\system32\wpdsp.dll
      2006-10-18 21:47 348672 --a
      C:\WINDOWS\system32\wmdrmnet.dll
      2006-10-18 21:47 33792 --a
      C:\WINDOWS\system32\wmdmlog.dll
      2006-10-18 21:47 321536 --a
      C:\WINDOWS\system32\mswmdm.dll
      2006-10-18 21:47 317440
      C:\WINDOWS\system32\MP4SDECD.dll
      2006-10-18 21:47 314880 --a
      C:\WINDOWS\system32\wmpdxm.dll
      2006-10-18 21:47 295936
      C:\WINDOWS\system32\wmpeffects.dll
      2006-10-18 21:47 284160
      C:\WINDOWS\system32\PortableDeviceApi.dll
      2006-10-18 21:47 276992 --a
      C:\WINDOWS\system32\audiodev.dll
      2006-10-18 21:47 27136 --a
      C:\WINDOWS\system32\mspmsnsv.dll
      2006-10-18 21:47 2603008
      C:\WINDOWS\system32\WpdShext.dll
      2006-10-18 21:47 259072
      C:\WINDOWS\system32\MPG4DECD.dll
      2006-10-18 21:47 259072
      C:\WINDOWS\system32\MP43DECD.dll
      2006-10-18 21:47 2450944 --a
      C:\WINDOWS\system32\wmvcore.dll
      2006-10-18 21:47 242688 --a
      C:\WINDOWS\system32\wmpasf.dll
      2006-10-18 21:47 229376 --a
      C:\WINDOWS\system32\cewmdm.dll
      2006-10-18 21:47 227328 --a
      C:\WINDOWS\system32\wmerror.dll
      2006-10-18 21:47 222208 --a
      C:\WINDOWS\system32\WMASF.dll
      2006-10-18 21:47 212992
      C:\WINDOWS\system32\MFPLAT.dll
      2006-10-18 21:47 211456 --a
      C:\WINDOWS\system32\qasf.dll
      2006-10-18 21:47 204288 --a
      C:\WINDOWS\system32\wmpsrcwp.dll
      2006-10-18 21:47 199168
      C:\WINDOWS\system32\PortableDeviceWMDRM.dll
      2006-10-18 21:47 179712 --a
      C:\WINDOWS\system32\msnetobj.dll
      2006-10-18 21:47 175616 --a
      C:\WINDOWS\system32\mspmsp.dll
      2006-10-18 21:47 166912
      C:\WINDOWS\system32\PortableDeviceTypes.dll
      2006-10-18 21:47 1661440 --a
      C:\WINDOWS\system32\wmpencen.dll
      2006-10-18 21:47 1574912
      C:\WINDOWS\system32\WMVENCOD.dll
      2006-10-18 21:47 157184 --a
      C:\WINDOWS\system32\wmidx.dll
      2006-10-18 21:47 154624 --a
      C:\WINDOWS\system32\wpdmtp.dll
      2006-10-18 21:47 1543680
      C:\WINDOWS\system32\WMVDECOD.dll
      2006-10-18 21:47 1382912
      C:\WINDOWS\system32\WMVSDECD.dll
      2006-10-18 21:47 133632
      C:\WINDOWS\system32\WPDShServiceObj.dll
      2006-10-18 21:47 1329152 --a
      C:\WINDOWS\system32\WMSPDMOE.dll
      2006-10-18 21:47 132096
      C:\WINDOWS\system32\PortableDeviceWiaCompat.dll
      2006-10-18 21:47 130048
      C:\WINDOWS\system32\wmpps.dll
      2006-10-18 21:47 11264 --a
      C:\WINDOWS\system32\LAPRXY.dll
      2006-10-18 21:47 1117696 --a
      C:\WINDOWS\system32\WMADMOE.dll
      2006-10-18 21:47 101888
      C:\WINDOWS\system32\PortableDeviceClassExtension.dll
      2006-10-18 20:03 100864 --a
      C:\WINDOWS\system32\logagent.exe
      2006-10-18 20:00 249856
      C:\WINDOWS\system32\drmupgds.exe
      2006-10-18 20:00 17408
      C:\WINDOWS\system32\wpdshextautoplay.exe
      2006-10-17 13:33 6049280
      C:\WINDOWS\system32\ieframe.dll
      2006-10-17 13:33 50688
      C:\WINDOWS\system32\msfeedsbs.dll
      2006-10-17 13:33 458752
      C:\WINDOWS\system32\msfeeds.dll
      2006-10-17 13:33 413696 --a
      C:\WINDOWS\system32\vbscript.dll
      2006-10-17 13:33 231424 --a
      C:\WINDOWS\system32\webcheck.dll
      2006-10-17 13:33 180736
      C:\WINDOWS\system32\ieui.dll
      2006-10-17 13:33 156160 --a
      C:\WINDOWS\system32\msls31.dll
      2006-10-17 13:06 78336 --a
      C:\WINDOWS\system32\ieencode.dll
      2006-10-17 13:05 40960 --a
      C:\WINDOWS\system32\licmgr10.dll
      2006-10-17 13:05 206336
      C:\WINDOWS\system32\WinFXDocObj.exe
      2006-10-17 13:05 105984 --a
      C:\WINDOWS\system32\url.dll
      2006-10-17 13:04 101376 --a
      C:\WINDOWS\system32\occache.dll
      2006-10-17 13:03 17408 --a
      C:\WINDOWS\system32\corpol.dll
      2006-10-17 13:01 71680 --a
      C:\WINDOWS\system32\admparse.dll
      2006-10-17 13:01 55296 --a
      C:\WINDOWS\system32\iesetup.dll
      2006-10-17 13:01 382976 --a
      C:\WINDOWS\system32\iedkcs32.dll
      2006-10-17 13:01 229376 --a
      C:\WINDOWS\system32\ieaksie.dll
      2006-10-17 13:01 152064 --a
      C:\WINDOWS\system32\ieakeng.dll
      2006-10-17 13:01 13312 --a
      C:\WINDOWS\system32\ieudinit.exe
      2006-10-17 13:00 54784 --a
      C:\WINDOWS\system32\ie4uinit.exe
      2006-10-17 13:00 43008 --a
      C:\WINDOWS\system32\iernonce.dll
      2006-10-17 13:00 123904 --a
      C:\WINDOWS\system32\advpack.dll
      2006-10-17 12:58 61952
      C:\WINDOWS\system32\icardie.dll
      2006-10-17 12:58 12288
      C:\WINDOWS\system32\msfeedssync.exe
      2006-10-17 12:57 36352 --a
      C:\WINDOWS\system32\imgutil.dll
      2006-10-17 12:57 266752
      C:\WINDOWS\system32\iertutil.dll
      2006-10-17 12:56 45568 --a
      C:\WINDOWS\system32\mshta.exe
      2006-10-17 12:28 48128 --a
      C:\WINDOWS\system32\mshtmler.dll
      2006-10-17 12:27 380928
      C:\WINDOWS\system32\ieapfltr.dll
      2006-10-17 12:23 161792 --a
      C:\WINDOWS\system32\ieakui.dll
      2006-10-13 07:35 142336 --a
      C:\WINDOWS\system32\nwprovau.dll


      (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

      *Note* empty entries are not shown

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
      "SP2 Connection Patcher"="\"C:\\Program Files\\SP2 Connection Patcher\\SP2ConnPatcher.exe\" -n=200"
      "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
      "Aim6"=""

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
      "eBayToolbar"="C:\\Program Files\\eBay\\eBay Toolbar2\\eBayTBDaemon.exe"
      "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
      "IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
      "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
      "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
      "Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
      "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
      "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
      "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
      "Installed"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
      "Installed"="1"
      "NoChange"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
      "Installed"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE\Microsoft]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE\Microsoft\Windows]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE\Microsoft\Windows\CurrentVersion]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "WFIPS"="C:\\Documents and Settings\\Owner\\My Documents\\Programs\\IPhider\\ip hider.exe -autoboot"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
      @=&quot;"

      [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
      "DeskHtmlVersion"=dword:00000110
      "DeskHtmlMinorVersion"=dword:00000005
      "Settings"=dword:00000001
      "GeneralFlags"=dword:00000001

      [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
      "Source"="http://www.totse.com/images/t3/bg.jpg&quot;
      "SubscribedURL"="http://www.totse.com/images/t3/bg.jpg&quot;
      "FriendlyName"=""
      "Flags"=dword:00000001
      "Position"=hex:2c,00,00,00,90,01,00,00,2e,01,00,00,70,00,00,00,74,00,00,00,e8,\
      03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
      "CurrentState"=hex:01,00,00,00
      "OriginalStateInfo"=hex:18,00,00,00,12,03,00,00,19,01,00,00,70,00,00,00,74,00,\
      00,00,01,00,00,40
      "RestoredStateInfo"=hex:14,6d,37,03,41,c0,b4,74,18,c0,56,04,68,de,37,03,20,6d,\
      37,03,96,15,00,00

      [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My Current Home Page"
      "Flags"=dword:00000002
      "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
      00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
      "CurrentState"=hex:04,00,00,40
      "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
      ff,ff,04,00,00,00
      "RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
      00,00,01,00,00,00

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
      "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
      "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
      "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
      "{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
      "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
      "NoDriveTypeAutoRun"=dword:00000091

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "dontdisplaylastusername"=dword:00000000
      "legalnoticecaption"=""
      "legalnoticetext"=""
      "shutdownwithoutlogon"=dword:00000001
      "undockwithoutlogon"=dword:00000001

      [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
      "NoDriveTypeAutoRun"=dword:00000091

      [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
      "NoDriveTypeAutoRun"=dword:00000091

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
      "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
      "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
      "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
      "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
      "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
      "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
      "item"="Adobe Reader Speed Launch"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak EasyShare software.lnk"
      "backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -hx"
      "item"="Kodak EasyShare software"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak software updater.lnk"
      "backup"="C:\\WINDOWS\\pss\\Kodak software updater.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\Kodak\\KODAKS~1\\7288971\\Program\\KODAKS~1.EXE "
      "item"="Kodak software updater"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
      "backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\MICROS~4\\Office10\\OSA.EXE -b -l"
      "item"="Microsoft Office"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
      "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Windows Desktop Search.lnk"
      "backup"="C:\\WINDOWS\\pss\\Windows Desktop Search.lnkCommon Startup"
      "location"="Common Startup"
      "command"="C:\\PROGRA~1\\MSNTOO~1\\DS\\020500~1.111\\en-us\\bin\\WINDOW~3.EXE /startup"
      "item"="Windows Desktop Search"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Webshots.lnk]
      "path"="C:\\Documents and Settings\\Owner\\Start Menu\\Programs\\Startup\\Webshots.lnk"
      "backup"="C:\\WINDOWS\\pss\\Webshots.lnkStartup"
      "location"="Startup"
      "command"="C:\\Program Files\\Webshots\\Launcher.exe /t"
      "item"="Webshots"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="apdproxy"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\*********]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="*********"
      "hkey"="HKLM"
      "command"="C:\\Program Files\\*********\\********* Personal Firewall\\*********.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="ashDisp"
      "hkey"="HKLM"
      "command"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BestPopUpKiller]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="BestPopupKiller"
      "hkey"="HKCU"
      "command"="C:\\Program Files\\BestPopUpKiller\\BestPopupKiller.exe /startup"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell AIO Printer A920]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="dlbkbmgr"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Dell AIO Printer A920\\dlbkbmgr.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DW4]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"=""
      "hkey"="HKCU"
      "command"=""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="gcasServ"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Microsoft AntiSpyware\\gcasServ.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="hkcmd"
      "hkey"="HKLM"
      "command"="C:\\WINDOWS\\system32\\hkcmd.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="igfxtray"
      "hkey"="HKLM"
      "command"="C:\\WINDOWS\\system32\\igfxtray.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="WkUFind"
      "hkey"="HKLM"
      "command"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="mnyexpr"
      "hkey"="HKCU"
      "command"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="NEWDOT~2"
      "hkey"="HKLM"
      "command"="rundll32 C:\\PROGRA~1\\NEWDOT~1\\NEWDOT~2.DLL,NewDotNetStartup -s"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="PCMService"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="qttask"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SP2 Connection Patcher]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="SP2ConnPatcher"
      "hkey"="HKCU"
      "command"="\"C:\\Program Files\\SP2 Connection Patcher\\SP2ConnPatcher.exe\" -n=200"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyKiller]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="spykiller"
      "hkey"="HKCU"
      "command"="C:\\Program Files\\SpyKiller\\spykiller.exe /startup"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Begone]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="freescan"
      "hkey"="HKCU"
      "command"="C:\\freescan\\freescan.exe -FastScan"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="realsched"
      "hkey"="HKLM"
      "command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Registry Repair Pro]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="RegistryRepairPro"
      "hkey"="HKCU"
      "command"="C:\\Program Files\\3B Software\\Windows Registry Repair Pro\\RegistryRepairPro.exe 4"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\X-Cleaner Freeware]
      "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
      "item"="XCLEAN~1"
      "hkey"="HKCU"
      "command"="\"C:\\PROGRA~1\\X-CLEA~1\\XCLEAN~1.EXE\" -turbo -autostart -NOREBOOT"
      "inimapping"="0"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
      "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


      Contents of the 'Scheduled Tasks' folder
      C:\WINDOWS\tasks\AppleSoftwareUpdate.job
      C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
      C:\WINDOWS\tasks\Disk Cleanup.job
      C:\WINDOWS\tasks\MP Scheduled Scan.job

      Completion time: 07-01-09 22:55:21.59
      C:\ComboFix.txt ... 07-01-09 22:55
      C:\ComboFix2.txt ... 07-01-09 13:40


      Logfile of HijackThis v1.99.1
      Scan saved at 10:56:20 PM, on 1/9/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.5730.0011)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\hkcmd.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Java\jre1.6.0\bin\jusched.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Documents and Settings\Owner\My Documents\Programs\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
      N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Owner\Application Data\Mozilla\Profiles\default\ni2nhawo.slt\prefs.js)
      O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
      O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn5\yt.dll
      O3 - Toolbar: eBay Toolbar - {92085AD4-F48A-450D-BD93-B28CC7DF67CE} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
      O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
      O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
      O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
      O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
      O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB\02.05.0001.1119\en-us\msntb.dll/search.htm
      O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm080YYUS
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
      O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
      O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
      O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
      O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/229?8eb9918bc1f44fa99cd9f338612a396
      O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\MSN Toolbar Suite\TAB\02.05.0001.1119\en-us\msntabres.dll/230?8eb9918bc1f44fa99cd9f338612a396
      O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
      O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
      O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
      O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O11 - Options group: [INTERNATIONAL] International*
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1101847098699
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1153748136781
      O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://cherrytap.com/imgs/ImageUploader4.cab
      O16 - DPF: {E991BDE0-9816-4094-853E-6BDB60F0342D} (Get_ActiveX Control) - http://apps.corel.com/nos_dl_manager/plugin/IENetOpPlugin.ocx
      O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2317.cab
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    • TroganTrogan London, UK
      edited January 2007
      A little left to do...

      1. Backup Your Registry with ERUNT
      • Please use the following link and scroll down to ERUNT and download it.
        http://aumha.org/freeware/freeware.php
      • For version with the Installer:
        Use the setup program to install ERUNT on your computer
      • For the zipped version:
        Unzip all the files into a folder of your choice.

      Click Erunt.exe to backup your registry to the folder of your choice.

      Note: to restore your registry, go to the folder and start ERDNT.exe

      2. Open Notepad!
      Copy and Paste everything from the Quote box into Notepad:
      REGEDIT4

      [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup]

      [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyKiller]

      [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Begone]

      Go to File > Save As
      Save File name as Fix.reg
      Change Save as Type to All Files and save the file to your desktop.

      Close Notepad, and double-click Fix.reg on your Desktop. When it asks if you want to merge the info to the registry, hit YES/OK

      3. Find and delete the following Folders in RED, if present:

      C:\Program Files\NewDotNet
      C:\Program Files\SpyKiller
      C:\freescan


      4. Download SmitfraudFix (by S!Ri) to your Desktop.
      http://siri.urz.free.fr/Fix/SmitfraudFix.zip
      Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

      Open the SmitfraudFix folder and double-click smitfraudfix.cmd
      Select option #1 - Search by typing 1 and press Enter
      This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

      IMPORTANT: Do NOT run any other options until you are asked to do so!
    • edited January 2007
      SmitFraudFix v2.132

      Scan done at 15:54:56.00, Wed 01/10/2007
      Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix
      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
      The filesystem type is NTFS
      Fix run in normal mode

      »»»»»»»»»»»»»»»»»»»»»»»» C:\


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data


      »»»»»»»»»»»»»»»»»»»»»»»» Start Menu


      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1


      »»»»»»»»»»»»»»»»»»»»»»»» Desktop


      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


      »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


      »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="http://www.totse.com/images/t3/bg.jpg&quot;
      "SubscribedURL"="http://www.totse.com/images/t3/bg.jpg&quot;
      "FriendlyName"=""

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="My Current Home Page"

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, following keys are not inevitably infected!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll


      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""


      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, following keys are not inevitably infected!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""


      »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


      »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


      »»»»»»»»»»»»»»»»»»»»»»»» End
    • TroganTrogan London, UK
      edited January 2007
      Thanks for the log. Logs are clean. How is the computer?

      Remove this old Java version from Add/Remove programs

      Java 2 Runtime Environment, SE v1.4.1_02

      You can delete the tools we downloaded...

      NoLop
      ComboFix
      FindLop
      SmitfraudFix
    • edited January 2007
      Computer is good! I'm loving it. I still can't view my pics at the Sprint Pic Mail site but I guess that had nothing to do with the virus??? Everything else is great though. No popups or crap when I shut down. I cannot tell you how grateful I am to you for all your help!!!!!!!!!!!!!!!!!!!!
    • jmoney3457jmoney3457 Maine
      edited January 2007
      glad trogan & I could assist you tanya:)The help you received here was free. Please read through some of these Prevention Tips that Short-Media offers.

      This topic is now closed. If you wish it reopened, please send a Private Message (PM) to one of the Spyware Mods with a link to your thread.

      Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required.

      If you are not the user who started this thread, you must start a new Thread instead :)

      Would you also be interested to join Short-Media (Team #93) with the Folding@Home Project? More information available at this link:
      http://www.short-media.com/forum/showthread.php?t=29803
    This discussion has been closed.