Wilburg - sudden slow computer, pop-ups, freezing etc. Can anyone help?

Hi all

Very recently (the past week) my laptop has just decided to become VERY slow. I haven't installed or downloaded anything which I can think may have caused this. Furthermore I am now getting pop-ups when I close legitimate windows (including this one).

Another thing I have noticed is that my computer takes AGES to respond. For example, I will type a website address in the Address Bar of IE and it will only then click and start loading the page after about 30 seconds. Furthermore, the page takes ages to load up.

Please could you help? Any advice would be greatly appreciated.

Kind regards

Wilburg

Comments

  • edited May 2007
    Apologies - i've just seen the "sticky" about posting HJT logs. I will follow all the steps and post a HJT a.s.a.p

    Thanks again :D

    Wilburg
  • Rahina-RescueRahina-Rescue Finland
    edited May 2007
    Hello Willburg, Welcome to Short media Virus/Spyware Removal Forums.

    Please do the following:

    Download Deckard's System Scanner (DSS) and save it to your Desktop.
    • Close all other windows before proceeding.
    • Double-click on dss.exe and follow the prompts.
    • When it has finished, DSS will open two Notepads: main.txt and extra.txt
    • Use Save As to save both Notepad files to your Desktop and post them in your next reply.

    Thanks.
  • edited May 2007
    Hi Rahina

    Thank you for taking on my case so quickly. Please find pasted below a copy of the two reports created after running DSS.

    In addition, I don't know whether it's noteworthy, but Ad-aware keeps being unable to pass making a Deep Registry search when I ask it to search for adware, malware etc. I have tried three times and on each occasion it stops at the same place.

    Deckard's System Scanner v20070426.43
    Run by Daniel Wilmot on 2007-05-12 at 18:31:10
    Computer is in Normal Mode.
    -- System Restore
    System Restore is disabled; attempting to re-enable...success.

    -- Last 1 Restore Point(s) --
    1: 2007-05-12 17:31:25 UTC - RP1 - System Checkpoint

    Backed up registry hives.
    Performed disk cleanup.

    -- HijackThis (run as Daniel Wilmot.exe)
    Logfile of HijackThis v1.99.1
    Scan saved at 18:33:31, on 12/05/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Program Files\Cordless USB Phone\Cordless DUALphone Suite.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\explorer.exe
    C:\Documents and Settings\Daniel Wilmot\Desktop\Malware Tools\Deckard's System Scanner.exe
    C:\DOCUME~1\DANIEL~1\Desktop\MALWAR~1\HJT\Daniel Wilmot.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cwgsy.net/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - Global Startup: Cordless DUALphone Startup.lnk = C:\Program Files\Cordless USB Phone\Cordless DUALphone Suite.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=laptop
    O15 - Trusted Zone: *.kpmgcareers.co.uk
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    -- HijackThis Fixed Entries (C:\DOCUME~1\DANIEL~1\Desktop\MALWAR~1\HJT\backups\)
    backup-20070301-201010-367 O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
    backup-20070301-201434-231 O2 - BHO: (no name) - {C47A9554-195A-4769-9B13-04F15B450A39} - C:\WINDOWS\system32\efcdecc.dll
    backup-20070301-201434-490 O20 - Winlogon Notify: awvvu - C:\WINDOWS\system32\awvvu.dll
    backup-20070301-201434-637 O2 - BHO: (no name) - {6077B6AF-384F-4664-9729-87250A7D0D06} - C:\WINDOWS\system32\awvvu.dll
    backup-20070301-201434-772 O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
    backup-20070301-201434-993 O2 - BHO: (no name) - {3F317B05-ADA5-438A-87DF-45D261B380FE} - C:\WINDOWS\system32\awtqo.dll (file missing)
    backup-20070301-201435-549 O20 - Winlogon Notify: efcdecc - C:\WINDOWS\SYSTEM32\efcdecc.dll
    backup-20070305-160544-430 O2 - BHO: (no name) - {E230B6D0-BF60-4E5D-8590-850F648BD347} - C:\WINDOWS\system32\mljgh.dll (file missing)
    backup-20070305-160544-484 O2 - BHO: (no name) - {6077B6AF-384F-4664-9729-87250A7D0D06} - C:\WINDOWS\system32\awvvu.dll (file missing)
    backup-20070305-160544-650 O2 - BHO: (no name) - {C47A9554-195A-4769-9B13-04F15B450A39} - C:\WINDOWS\system32\efcdecc.dll (file missing)
    backup-20070305-160544-825 O20 - Winlogon Notify: efcdecc - efcdecc.dll (file missing)
    backup-20070305-160545-411 O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll (file missing)
    backup-20070312-173756-112 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    backup-20070312-173756-122 O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    backup-20070312-173756-297 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    backup-20070312-173756-326 O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    backup-20070312-173756-525 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    backup-20070312-173756-828 O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    backup-20070312-173756-882 O15 - Trusted Zone: *.kpmgcareers.co.uk
    backup-20070312-173756-902 O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    -- File Associations
    All associations okay.

    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    R3 CLEDX (Team H2O CLEDX service) - c:\windows\system32\drivers\cledx.sys <Not Verified; Team H2O; CLEDX>
    R3 dvd43llh - c:\windows\system32\drivers\dvd43llh.sys <Not Verified; RIF; DVD For Free>
    R3 Iviaspi (IVI ASPI Shell) - c:\windows\system32\drivers\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>
    R3 Pcouffin (Low level access layer for CD devices) - c:\windows\system32\drivers\pcouffin.sys <Not Verified; VSO Software; Patin couffin engine>
    R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
    S3 Amsmpu4p - c:\docume~1\daniel~1\locals~1\temp\amsmpu4p.sys (file missing)

    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
    S3 hpqwmi (HP WMI Interface) - c:\program files\hpq\shared\hpqwmi.exe <Not Verified; Hewlett-Packard Development Company, L.P.; hpqwmi Module>

    -- Files created between 2007-04-12 and 2007-05-12
    2007-05-12 15:37:21 0 d
    C:\WINDOWS\LastGood

    -- Find3M Report
    2007-05-12 16:38:06 0 d
    C:\Program Files\MSN Messenger
    2007-05-12 16:34:25 0 d
    C:\Program Files\Microsoft ActiveSync
    2007-05-12 16:33:14 0 d
    C:\Program Files\iTunes
    2007-05-12 16:29:06 0 d
    C:\Program Files\Google
    2007-05-12 16:28:32 0 d
    C:\Program Files\Cordless USB Phone
    2007-05-12 15:11:55 2008 --a
    C:\WINDOWS\system32\tmp.reg
    2007-05-12 14:24:08 0 d
    C:\Documents and Settings\Daniel Wilmot\Application Data\Skype
    2007-05-11 19:41:32 0 d
    C:\Documents and Settings\Daniel Wilmot\Application Data\uTorrent
    2007-05-01 12:13:17 0 d
    C:\Documents and Settings\Daniel Wilmot\Application Data\AVG7
    2007-04-29 19:54:09 4212 ---h
    C:\WINDOWS\system32\zllictbl.dat
    2007-02-16 23:28:11 356352 --a
    C:\WINDOWS\eSellerateEngine.dll <Not Verified; eSellerate Inc.; eSellerateEngine>

    -- Registry Dump
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    {53707962-6F74-2D53-2644-206D7942484F} C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    {AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar5.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
    "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
    "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
    "eabconfg.cpl"="C:\\Program Files\\HPQ\\Quick Launch Buttons\\EabServr.exe /Start"
    "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
    "SsAAD.exe"="C:\\PROGRA~1\\Sony\\SONICS~1\\SsAAD.exe"
    "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE\""
    "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\Awasu]
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableRegistryTools"=dword:00000000
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
    Authentication Packages REG_MULTI_SZ msv1_0\0\0
    Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
    Notification Packages REG_MULTI_SZ scecli\0\0

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
    "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\Adobe\\ACROBA~3.0\\Reader\\READER~1.EXE "
    "item"="Adobe Reader Speed Launch"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^broadband medic.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\broadband medic.lnk"
    "backup"="C:\\WINDOWS\\pss\\broadband medic.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\ntl\\BROADB~1\\bin\\matcli.exe -boot"
    "item"="broadband medic"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="CFD"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="CTDetect"
    "hkey"="HKCU"
    "command"="C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe /R"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="dvd43_tray"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\dvd43\\dvd43_tray.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="WCESCOMM"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE\""
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="cledx"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\SyncroSoft\\Pos\\H2O\\cledx.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Home Theater SchSvr]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="SchSvr"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Common Files\\InterVideo\\SchSvr\\SchSvr.exe\""
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="issch"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="iTunesHelper"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="MotiveSB"
    "hkey"="HKLM"
    "command"="C:\\PROGRA~1\\ntl\\BROADB~1\\SMARTB~1\\MotiveSB.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="qttask"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="Skype"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="SsAAD"
    "hkey"="HKLM"
    "command"="C:\\PROGRA~1\\Sony\\SONICS~1\\SsAAD.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="GoogleToolbarNotifier"
    "hkey"="HKCU"
    "command"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Quick-Drop]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="Quick-Drop"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Ulead Systems\\Ulead DVD MovieFactory 5 Plus\\Ulead DVD MovieFactory 5\\Quick-Drop.exe\" WINDOWCALL"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="sgtray"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="winampa"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\Winamp\\winampa.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINREMOTE]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="WinRemote"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\InterVideo\\Common\\Bin\\WinRemote.exe\""
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="ypager"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe\" -quiet"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
    LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ DnsCache\0\0
    DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    termsvcs REG_MULTI_SZ TermService\0\0

    -- End of Deckard's System Scanner: finished at 2007-05-12 at 18:33:59


    Deckard's System Scanner v20070426.43
    Extra logfile - please post this as an attachment with your post.
    -- System Information
    Microsoft Windows XP Home Edition (build 2600) SP 2.0
    Architecture: X86; Language: English
    CPU 0: Intel(R) Pentium(R) M processor 1.60GHz
    Percentage of Memory in Use: 74%
    Physical Memory (total/avail): 478.42 MiB / 120.94 MiB
    Pagefile Memory (total/avail): 1120.55 MiB / 768.9 MiB
    Virtual Memory (total/avail): 2047.88 MiB / 1973.57 MiB
    C: is Fixed (NTFS) - 92.95 GiB total, 9.47 GiB free.
    D: is CDROM (CDFS)

    -- Security Center
    AUOptions is scheduled to auto-install.
    Windows Internal Firewall is disabled.
    FirstRunDisabled is set.
    FW: ZoneAlarm Firewall v7.0.337.000 (Check Point, LTD.)
    AV: AVG 7.5.467 v7.5.467 (GRISOFT)

    -- Environment Variables
    ALLUSERSPROFILE=C:\Documents and Settings\All Users
    APPDATA=C:\Documents and Settings\Daniel Wilmot\Application Data
    audesktop=C:\DOCUME~1\ALLUSE~1\Desktop
    aufavorites=C:\DOCUME~1\ALLUSE~1\FAVORI~1
    austartm=C:\DOCUME~1\ALLUSE~1\STARTM~1
    austartprg=C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs
    austartup=C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup
    ChoixMenu=2
    ChoixRegistre=y
    CLASSPATH=.;C:\Program Files\Java\jre1.5.0_09\lib\ext\QTJava.zip
    CommonProgramFiles=C:\Program Files\Common Files
    COMPUTERNAME=DANSLAPTOP
    ComSpec=C:\WINDOWS\system32\cmd.exe
    CurDir=C:\Documents and Settings\Daniel Wilmot\Desktop\Malware Tools\SmitfraudFix
    desktop=C:\DOCUME~1\DANIEL~1\Desktop
    DoReboot=0
    DoRestart=0
    favorites=C:\DOCUME~1\DANIEL~1\FAVORI~1
    fixname=SmitFraudFix
    fixvers=v2.147
    FP_NO_HOST_CHECK=NO
    FSType=NTFS
    HOMEDRIVE=C:
    HOMEPATH=\Documents and Settings\Daniel Wilmot
    huy32Mess=huy32 detected, use a Rootkit scanner
    KDMess=detected !
    lang=int
    LOGONSERVER=\\DANSLAPTOP
    lzx32Mess=lzx32 detected, use a Rootkit scanner
    msguardMess=msguard detected, use a Rootkit scanner
    NUMBER_OF_PROCESSORS=1
    OS=Windows_NT
    Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Common Files\Ulead Systems\MPEG;C:\Program Files\QuickTime\QTSystem\;;"C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier";"C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier"
    PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    pe386Mess=pe386 detected, use a Rootkit scanner
    PROCESSOR_ARCHITECTURE=x86
    PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 6, GenuineIntel
    PROCESSOR_LEVEL=6
    PROCESSOR_REVISION=0d06
    ProgramFiles=C:\Program Files
    PROMPT=$P$G
    QTJAVA=C:\Program Files\Java\jre1.5.0_09\lib\ext\QTJava.zip
    RKScan=use a Rootkit scanner
    SafeMDisp=Fix run in safe mode
    SafeMWarn=Fix run in normal mode
    sChoice=Enter your choice
    sDel=Deleted
    sEnd=End
    sError=Problem while deleting
    SESSIONNAME=Console
    sFound=FOUND !
    sFSType=The filesystem type is
    sfxname=C:\Documents and Settings\Daniel Wilmot\Desktop\Malware Tools\SmitfraudFix.exe
    sHOSTS=hosts file corrupted !
    sInfect=infected !
    sInfect2=infected !
    sNotFound=not found
    sProcess=Killing process
    sRegClean=Registry Cleaning
    sRegCleanQ=Do you want to clean the registry ? (y/n)
    sRunFrom=Run from
    sScanDate=Scan done at
    sSearch=Scanning
    startm=C:\DOCUME~1\DANIEL~1\STARTM~1
    startprg=C:\DOCUME~1\DANIEL~1\STARTM~1\Programs
    startup=C:\DOCUME~1\DANIEL~1\STARTM~1\Programs\Startup
    sTempFolder=Deleting Temp Files
    sTrustBackUp=Saving BackUp
    sTrustDone=Trusted Zone deleted.
    sTrustError=*** Error : zone.reg not found ***
    sTrustQ=Restore Trusted Zone ? (y/n)
    sWininetQ=Replace infected file ? (y/n)
    sWiniSearch=Scanning wininet.dll backup
    syspath=C:\WINDOWS\system32
    SystemDrive=C:
    SystemRoot=C:\WINDOWS
    TEMP=C:\DOCUME~1\DANIEL~1\LOCALS~1\Temp
    TMP=C:\DOCUME~1\DANIEL~1\LOCALS~1\Temp
    tvdumpflags=8
    USERDOMAIN=DANSLAPTOP
    USERNAME=Daniel Wilmot
    USERPROFILE=C:\Documents and Settings\Daniel Wilmot
    Version=Microsoft Windows XP [Version 5.1.2600]
    windir=C:\WINDOWS

    -- User Profiles
    Daniel Wilmot (admin)

    -- Add/Remove Programs
    --> "C:\Program Files\InstallShield Installation Information\{1A91D1FA-B9B3-4556-9878-5C61059A19B2}\setup.exe" REMOVEALL
    --> C:\PROGRA~1\ntl\BROADB~1\Uninstall.exe ntl
    --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
    --> C:\WINDOWS\system32\\MSIEXEC.EXE /I {09DA4F91-2A09-4232-AB8C-6BC740096DE3} REMOVE=UpdateMgrFeature
    --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19}
    --> Dummy
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88E5FCB8-5F25-11D5-B16F-0800460222F0}\setup.exe" -l0x9 UNINSTALL
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{89AD2814-AFA2-46AF-AE53-C27196D9FBE6}\setup.exe" REMOVEALL
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D5DFD1A-5B25-48B7-B4D5-E04778BDC676}\Setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AAA4CCCE-78DB-47B0-A651-68270D838BD4}\setup.exe" REMOVEALL
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D76298C2-E532-4A11-BCFF-76F3F19DA84D}\setup.exe" UNINSTALL
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0B095086-7205-4D48-90DF-DCD16613C6D4}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{103BCDA0-E063-46AC-8028-64E78722ABA7}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2616B36E-38CE-4357-8AB5-8B3EE9B1C117}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2616B36E-38CE-4357-8AB5-8B3EE9B1C117}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{700932B3-A964-4878-82A2-96054622A1F7}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{836612F0-1571-4C65-A4B7-58A39AA578EE}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{836612F0-1571-4C65-A4B7-58A39AA578EE}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9104A09A-EC83-11D8-8469-00D0B726B56E}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9104A09A-EC83-11D8-8469-00D0B726B56E}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9744AE38-1CC6-414F-96CE-0643AEE30A9B}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9744AE38-1CC6-414F-96CE-0643AEE30A9B}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9AB14DF5-3B04-4E3B-9969-695DBA7F2008}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9AB14DF5-3B04-4E3B-9969-695DBA7F2008}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9E54F486-CD4A-44A5-B041-16D4E1E56A53}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A82F10CB-18B5-4EAC-AEF2-FA49CD565626}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CB99E420-8071-48F9-9567-4A53BE7569C4}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D524239C-FD5C-4183-A49C-7930915A9C0A}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D524239C-FD5C-4183-A49C-7930915A9C0A}\setup.exe" -l0x9 /remove
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD2D9012-E5A1-4717-8EE9-8DB3F36E2F8C}\setup.exe" -l0x9
    --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DD2D9012-E5A1-4717-8EE9-8DB3F36E2F8C}\setup.exe" -l0x9 /remove
    --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    µTorrent --> "C:\Program Files\uTorrent\uninstall.exe"
    1Click DVD Copy 5.0.0.15 --> "C:\Program Files\LG Software Innovations\1Click DVD Copy 5\unins000.exe"
    AC3Filter (remove only) --> C:\Program Files\AC3Filter\uninstall.exe
    Ad-Aware SE Personal --> C:\PROGRA~1\Lavasoft\AD-AWA~1\UNWISE.EXE C:\PROGRA~1\Lavasoft\AD-AWA~1\INSTALL.LOG
    Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll"
    Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
    Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002}
    Apple Software Update --> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D}
    ArcSoft Camera Suite 1.3 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AD13BFB0-FDD2-4AFA-A8AF-9F4A950D56B7}\setup.exe" -l0x9
    Audacity 1.2.4 --> "C:\Program Files\Audacity\unins000.exe"
    AVG 7.5 --> C:\Program Files\Grisoft\AVG7\setup.exe /UNINSTALL
    broadband medic --> C:\WINDOWS\Motive\ntl\MCCUninst.exe
    Canon Camera Support Core Library --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{91F1A0D6-23AD-49FE-8D4E-379485652214} /l1033
    Canon Camera Window DS for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{91203BD3-6C3E-472F-ADBD-F60FDC7C4010}
    Canon Camera Window DVC for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{4C96958A-6562-4143-B820-FF4890D3B734}
    Canon Camera Window for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{C7281207-4AA4-425E-B57A-0E9EF8445635}
    Canon Internet Library for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{2F81FBFC-9A37-431F-9050-14B55485DF5A}
    Canon MovieEdit Task for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{8AF1E098-1A5C-4336-BBE2-D047ABB401ED}
    Canon PhotoRecord --> MsiExec.exe /X{0878E100-C0BB-41E8-B4C6-C486B61FDA7B}
    Canon RAW Image Task for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{45EF4EE3-F591-4B74-A477-0CAE12934CE7}
    Canon RemoteCapture Task for ZoomBrowser EX --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{28291BD5-92D2-4685-82DC-CCA925C53CCA}
    Canon Utilities PhotoStitch 3.1 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{218BBBE3-FE63-4BB2-81A8-7435575A84FA}
    Canon ZoomBrowser EX --> MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}
    Citrix Program Neighborhood --> C:\WINDOWS\ISUNINST.EXE -fC:\PROGRA~1\Citrix\ICACLI~1\Uninst.isu -cC:\PROGRA~1\Citrix\ICACLI~1\uninstpn.dll
    Citrix Web Client --> C:\WINDOWS\system32\ctxsetup.exe /uninst C:\PROGRA~1\Citrix\icaweb32\uninst.inf
    Conexant AC-Link Audio --> CIAunwdm.exe
    Cordless DUALphone Suite --> "C:\Program Files\Cordless USB Phone\unins000.exe"
    Creative Jukebox Driver --> C:\Program Files\Creative\Jukebox 3 Drivers\DrvUnins.exe /s
    Creative MediaSource --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E0C1913-886B-4C5C-8DAF-D1E649CE5FCC}\setup.exe" -l0x9 /remove
    Creative Removable Disk Manager --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{57FA4E0F-82C9-417D-87BC-0186D6CB7A44}\setup.exe" -l0x9 /remove
    Creative System Information --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A317D0-60A6-43FC-848A-9FE4A53B29CE}\setup.exe" -l0x9 /remove
    Creative Zen Micro --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D944236D-7992-41D6-8257-930B5832F1CC}\SETUP.EXE" -l0x9 /remove
    CrystalFire Wormhole 2.1.0 --> "C:\Program Files\CrystalFire\Wormhole2\unins000.exe"
    DivX --> C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
    DVD43 v3.9.0 --> "C:\Program Files\dvd43\unins000.exe"
    Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar5.dll"
    Guitar Pro 5.0 --> "C:\Program Files\Guitar Pro 5\unins000.exe"
    HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}
    HijackThis 1.99.1 --> C:\DOCUME~1\DANIEL~1\LOCALS~1\Temp\Rar$EX00.172\HijackThis.exe /uninstall
    HP Help and Support --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\setup.exe" -l0x9
    HP Memories Disc --> MsiExec.exe /X{B376402D-58EA-45EA-BD50-DD924EB67A70}
    HP Photo and Imaging 2.0 - All-in-One --> MsiExec.exe /X{9867A917-5D17-40DE-83BA-BEA5293194B1}
    HP Photo and Imaging 2.0 - All-in-One Drivers --> MsiExec.exe /X{6ECB39BD-73C2-44DD-B1A0-898207C58D8B}
    HP Photo and Imaging 2.0 - hp psc 1200 series --> C:\Program Files\Hewlett-Packard\Digital Imaging\{7C8BB31C-E09E-4c7d-BBF1-45E33B467FE1}\Setup\hpzscr01.exe -datfile hposcr02.dat -forcereboot
    hp psc 1200 series --> MsiExec.exe /X{C900EF06-2E76-49C7-8DB0-41F629B21DC5}
    Intel(R) Extreme Graphics 2 Driver --> RUNDLL32.EXE C:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_3582
    InterActual Player --> C:\Program Files\InterActual\InterActual Player\inuninst.exe
    InterVideo Home Theater --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F7514465-E5F3-48E9-A952-327DAEF33DE6}\setup.exe" REMOVEALL
    InterVideo WinDVD --> "C:\Program Files\InstallShield Installation Information\{91810AFC-A4F8-4EBA-A5AA-B198BBC81144}\setup.exe" REMOVEALL
    iPAQ WebReg --> MsiExec.exe /I{D37C6152-89DF-4D29-83CF-666200D5F398}
    iTunes --> MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4}
    Java(TM) SE Runtime Environment 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
    Kaspersky Online Scanner --> C:\WINDOWS\system32\KASPER~1\KASPER~1\kavuninstall.exe
    Macromedia Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
    Microsoft ActiveSync 3.7 --> "C:\WINDOWS\ISUNINST.EXE" -f"C:\Program Files\Microsoft ActiveSync\DeIsL1.isu" -c"C:\Program Files\Microsoft ActiveSync\ceuninst.dll"
    Microsoft Age of Empires II --> "C:\Program Files\Microsoft Games\Age of Empires II\UNINSTAL.EXE" /runtemp /uninstall
    Microsoft Money 2005 --> C:\Program Files\Microsoft Money 2005\MNYCoreFiles\Setup\uninst.exe /s:120
    Microsoft Office Access 2003 --> MsiExec.exe /I{90150409-6000-11D3-8CFE-0150048383C9}
    Microsoft Office Standard Edition 2003 --> MsiExec.exe /I{91120409-6000-11D3-8CFE-0150048383C9}
    Microsoft Works --> MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}
    MSN Gaming Zone --> C:\PROGRA~1\MSNGAM~1\zsetup.exe /Uninstall
    muvee autoProducer 3.5 - SE --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{37E31FCE-A048-4D8C-B167-31891BCF6585}\setup.exe" -l0x9
    myTunes Redux 1.0 --> "C:\Program Files\myTunes\unins000.exe"
    Ogg for iTunes --> "C:\Program Files\Ogg for iTunes\Uninstall.exe"
    OpenMG Limited Patch 4.4-06-13-19-01 --> C:\Program Files\Common Files\Sony Shared\OpenMG\HotFixes\HotFix4.4-06-13-19-01\HotFixSetup\setup.exe /u
    OpenMG Secure Module 4.4.00 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{CFB17307-B244-4EAD-AE8E-CDAF440477C2} UNINSTALL
    OpenOffice.org 2.1 --> MsiExec.exe /I{43983EB4-43DC-4C3D-9712-1EF592A31CA8}
    Panda ActiveScan --> C:\WINDOWS\system32\ASUninst.exe Panda ActiveScan
    Quick Launch Buttons 5.00 C2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{CEB326EC-8F40-47B2-BA22-BB092565D66F}\setup.exe" -l0x9 -uninst
    QuickTime --> MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A}
    RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
    Security Update for Step By Step Interactive Training (KB898458) --> "C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
    Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
    SimCity 3000 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Maxis\SimCity 3000\Uninst.isu"
    SimCity 4 Deluxe --> C:\Program Files\Maxis\SimCity 4 Deluxe\EAUninstall.exe
    Skype 3.0 --> "C:\Program Files\Skype\Phone\unins000.exe"
    Skype Plugin Manager --> MsiExec.exe /I{3D5E5C0A-5B36-4F98-99A7-287F7DBDCE03}
    SoftV92 Data Fax Modem with SmartCP --> C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_8086&DEV_24C6&SUBSYS_3080103C\HXFSETUP.EXE -U -Ihpm30805.inf
    Sonic RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19}
    Sonic Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3}
    SonicStage 3.4 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A0EB195B-5876-48E6-879D-33D4B2102610}\setup.exe" -l0x9 UNINSTALL -removeonly
    Spybot - Search & Destroy 1.4 --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    SpywareBlaster v3.5.1 --> "C:\Program Files\SpywareBlaster\unins000.exe"
    Steinberg Cubase SX v3.1.1.944 --> C:\PROGRA~1\STEINB~1\CUBASE~1\UNWISE.EXE C:\PROGRA~1\STEINB~1\CUBASE~1\INSTALL.LOG
    Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
    Syncrosoft's License Control --> C:\PROGRA~1\SYNCRO~1\UNWISE.EXE C:\PROGRA~1\SYNCRO~1\INSTALL.LOG
    SyncroSoft Emu (Remove only) --> C:\Program Files\SyncroSoft\Pos\H2O\Uninst.exe
    Texas Instruments PCIxx21/x515 drivers. --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{C569D686-A444-4AF0-A437-15CBB2816E34}
    TRUST 120 [EMAIL="SPACEC@M"]SPACEC@M[/EMAIL] --> C:\WINDOWS\CleanDev.exe C:\WINDOWS\DC2110a.ini
    Ulead DVD MovieFactory 5 Plus --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FF164702-AF8B-4F2F-8038-74A4C536866B}\setup.exe" -l0x9
    WebDialogs Unyte --> C:\Documents and Settings\All Users\Application Data\Skype\Plugins\Plugins\40E74BFD69174D7FB489C85D9E586824\uninstall.exe
    Winamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe"
    Windows Live Messenger --> MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
    WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe
    Yahoo! Address AutoComplete --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\yaddbook.dll
    Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\ymmapi.dll
    ZoneAlarm --> C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe

    -- End of Deckard's System Scanner: finished at 2007-05-12 at 18:33:59
  • Rahina-RescueRahina-Rescue Finland
    edited May 2007
    Looks like you have been using Hijackthis on your own :skeptic:

    We have things to do.

    Step #1

    We Have to move Hijackthis to it's own folder because In it's current location, we'll lose both the program and the backups it creates. These backups are important in case we need to restore any 'fixed' entry(s) later

    Click START>My Computer >right click Local Disk (usually (C:) for most people)>Explore.
    Right click an open area in the main panel.
    Select New > Folder.
    Type in HJT & press Enter

    Now We have Created C:\HJT\ folder. Put your HijackThis.exe there.

    Step #2

    Please download VundoFix.exe to your desktop
    • Double-click VundoFix.exe to run it.
    • Click the Scan for Vundo button.
    • Once it's done scanning, click the Remove Vundo button.
    • You will receive a prompt asking if you want to remove the files, click YES
    • Once you click yes, your desktop will go blank as it starts removing Vundo.
    • When completed, it will prompt that it will reboot your computer, click OK.
    • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
    Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

    Step #3

    Please download Combofix to your desktop.
    • Double click on Combofix.exe & follow the prompts.
    • When finished, it shall produce a log for you. Post that log & a fresh HJT log in your next reply
    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

    Step #4

    In your next reply please post the following logfiles:

    C:\Combofix.txt

    Also add a Fresh Hijackthis Logfile.
  • edited May 2007
    Hi Rahina

    Thank you for your reply and instructions.

    Yes, I have used HJT before, back in March, because I was infected with the Downloader.Zlob infection. On that occasion I also used Short-Media to help me along.

    Please find below a fresh HJT log and the ComboFix log. No VundoFix log was created as it didn't find any infections.

    "Daniel Wilmot" - 2007-05-13 11:45:57 Service Pack 2
    ComboFix 07-05.13.V - Running from: "C:\Documents and Settings\Daniel Wilmot\Desktop\Malware Tools\"

    ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-13 ))))))))))))))))))))))))))))))))))

    2007-05-13 11:34 <DIR> d
    C:\HJT
    2007-05-12 18:30 <DIR> d
    C:\Deckard
    2007-05-12 15:37 <DIR> d
    C:\WINDOWS\LastGood

    (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-05-13 10:35:40
    d
    w C:\DOCUME~1\DANIEL~1\APPLIC~1\Skype
    2007-05-12 15:38:06
    d
    w C:\Program Files\MSN Messenger
    2007-05-12 15:34:25
    d
    w C:\Program Files\Microsoft ActiveSync
    2007-05-12 15:33:14
    d
    w C:\Program Files\iTunes
    2007-05-12 15:29:06
    d
    w C:\Program Files\Google
    2007-05-12 15:28:32
    d
    w C:\Program Files\Cordless USB Phone
    2007-05-12 14:11:55 2,008 ----a-w C:\WINDOWS\system32\tmp.reg
    2007-05-11 18:41:32
    d
    w C:\DOCUME~1\DANIEL~1\APPLIC~1\uTorrent
    2007-04-29 18:54:09 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
    2007-03-17 13:43:01 292,864 ----a-w C:\WINDOWS\system32\winsrv.dll
    2007-03-09 00:02:00 75,512 ----a-w C:\WINDOWS\zllsputility.exe
    2007-03-09 00:01:42 1,087,216 ----a-w C:\WINDOWS\system32\zpeng24.dll
    2007-03-08 15:36:28 577,536 ----a-w C:\WINDOWS\system32\user32.dll
    2007-03-08 15:36:28 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
    2007-03-08 15:36:28 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
    2007-03-08 13:47:48 1,843,584 ----a-w C:\WINDOWS\system32\win32k.sys
    2007-02-16 22:28:11 356,352 ----a-w C:\WINDOWS\eSellerateEngine.dll
    2007-02-05 20:17:02 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll

    (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    {53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 02:04]
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0\bin\ssv.dll [2007-03-07 11:51]
    {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar5.dll [2007-01-20 00:55]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
    "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
    "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
    "eabconfg.cpl"="C:\\Program Files\\HPQ\\Quick Launch Buttons\\EabServr.exe /Start"
    "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
    "SsAAD.exe"="C:\\PROGRA~1\\Sony\\SONICS~1\\SsAAD.exe"
    "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-06-17 21:43]
    "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 19:40]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 19:38]
    "eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-09-18 01:19]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-04-21 08:36]
    "SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 02:36]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 01:02]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 09:00]
    "H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-03 22:42]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-01-26 05:27]
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE\""
    "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\Awasu]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
    Authentication Packages msv1_0\0\0
    Security Packages kerberos\0msv1_0\0schannel\0wdigest\0\0
    Notification Packages scecli\0\0
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^adobe reader speed launch.lnk
    C:\PROGRA~1\Adobe\ACROBA~3.0\Reader\READER~1.EXE
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^broadband medic.lnk
    C:\PROGRA~1\ntl\BROADB~1\bin\matcli.exe -boot
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bjcfd
    C:\Program Files\BroadJump\Client Foundation\CFD.exe
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\creative detector
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43
    C:\Program Files\dvd43\dvd43_tray.exe
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\h/pc connection agent
    "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\h2o
    C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\home theater schsvr
    "C:\Program Files\Common Files\InterVideo\SchSvr\SchSvr.exe"
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\isusscheduler
    "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ituneshelper
    "C:\Program Files\iTunes\iTunesHelper.exe"
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\motive smartbridge
    C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\quicktime task
    "C:\Program Files\QuickTime\qttask.exe" -atboottime
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\skype
    "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ssaad.exe
    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ulead quick-drop
    "C:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5 Plus\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updatemanager
    "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winampagent
    C:\Program Files\Winamp\winampa.exe
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winremote
    "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
    HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\yahoo! pager
    "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
    HTTPFilter HTTPFilter\0\0
    LocalService Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService DnsCache\0\0
    DcomLaunch DcomLaunch\0TermService\0\0
    rpcss RpcSs\0\0
    imgsvc StiSvc\0\0
    termsvcs TermService\0\0
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost

    ~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
    backup-20070312-173756-882
    O15 - Trusted Zone: *.kpmgcareers.co.uk
    backup-20070312-173756-525
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    backup-20070312-173756-112
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    backup-20070312-173756-326
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    backup-20070312-173756-297
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    backup-20070312-173756-122
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    backup-20070312-173756-902
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    backup-20070312-173756-828
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    backup-20070305-160545-411
    O20 - Winlogon Notify: mljgh - C:\WINDOWS\system32\mljgh.dll (file missing)
    backup-20070305-160544-825
    O20 - Winlogon Notify: efcdecc - efcdecc.dll (file missing)
    backup-20070305-160544-484
    O2 - BHO: (no name) - {6077B6AF-384F-4664-9729-87250A7D0D06} - C:\WINDOWS\system32\awvvu.dll (file missing)
    backup-20070305-160544-430
    O2 - BHO: (no name) - {E230B6D0-BF60-4E5D-8590-850F648BD347} - C:\WINDOWS\system32\mljgh.dll (file missing)
    backup-20070305-160544-650
    O2 - BHO: (no name) - {C47A9554-195A-4769-9B13-04F15B450A39} - C:\WINDOWS\system32\efcdecc.dll (file missing)
    backup-20070301-201435-549
    O20 - Winlogon Notify: efcdecc - C:\WINDOWS\SYSTEM32\efcdecc.dll
    backup-20070301-201434-490
    O20 - Winlogon Notify: awvvu - C:\WINDOWS\system32\awvvu.dll
    backup-20070301-201434-231
    O2 - BHO: (no name) - {C47A9554-195A-4769-9B13-04F15B450A39} - C:\WINDOWS\system32\efcdecc.dll
    backup-20070301-201434-637
    O2 - BHO: (no name) - {6077B6AF-384F-4664-9729-87250A7D0D06} - C:\WINDOWS\system32\awvvu.dll
    backup-20070301-201434-772
    O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
    backup-20070301-201434-993
    O2 - BHO: (no name) - {3F317B05-ADA5-438A-87DF-45D261B380FE} - C:\WINDOWS\system32\awtqo.dll (file missing)
    backup-20070301-201010-367
    O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Program Files\VSAdd-in\VSAdd-in.dll (file missing)
    ********************************************************************
    catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-05-13 11:51:10
    Windows 5.1.2600 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden services ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    C:\system.sav\CTO.TXT 4096 bytes
    C:\system.sav\CTOHW.TXT 16 bytes
    C:\system.sav\DAYLGSAV.reg 320 bytes
    C:\system.sav\delink.log 104 bytes
    C:\system.sav\highgost.flg 32 bytes
    C:\system.sav\info.bom 8192 bytes
    C:\system.sav\INFO.US 4096 bytes
    C:\system.sav\ISLOGCHK.LOG 4096 bytes
    C:\system.sav\logoff.bat 112 bytes
    C:\system.sav\logoff.reg 288 bytes
    C:\system.sav\Logs
    C:\system.sav\Logs\Cia.ini 32768 bytes
    C:\system.sav\Logs\Info.bom 8192 bytes
    C:\system.sav\Logs\Install.log 331776 bytes
    C:\system.sav\Logs\Preinchk.log 4096 bytes
    C:\system.sav\Logs\Sysinfo.log 311296 bytes
    C:\system.sav\mszone.log 4096 bytes
    C:\system.sav\PREINCHK.log 4096 bytes
    C:\system.sav\REBOOT.ME 48 bytes
    C:\system.sav\REGDEV.LOG 40 bytes
    C:\system.sav\REGFLUSH.LOG 4096 bytes
    C:\system.sav\RegionCF
    C:\system.sav\RegionCF\euro.reg 216 bytes
    C:\system.sav\RegionCF\SFr.reg 232 bytes
    C:\system.sav\RmDev.log 4096 bytes
    C:\system.sav\SYSINFO.LOG 311296 bytes
    C:\system.sav\util
    C:\system.sav\util\AppEvBk1.old 12288 bytes
    C:\system.sav\util\bcr.cmd 232 bytes
    C:\system.sav\util\bootldr.flg 0 bytes
    C:\system.sav\util\BOOTSEC.NT4 512 bytes
    C:\system.sav\util\brand.exe 184320 bytes
    C:\system.sav\util\BrandIt.Log 4096 bytes
    C:\system.sav\util\BRAND_2.FLG 16 bytes
    C:\system.sav\util\CHKIMAGE.exe 122880 bytes
    C:\system.sav\util\CIA.CDC 28672 bytes
    C:\system.sav\util\CIA.INI 32768 bytes
    C:\system.sav\util\CLEARTYP.REG 496 bytes
    C:\system.sav\util\CMDOOBE.CMD 72 bytes
    C:\system.sav\util\CMDSWSET.CMD 64 bytes
    C:\system.sav\util\cpqci.dll 122880 bytes
    C:\system.sav\util\cpqsm.exe 53248 bytes
    C:\system.sav\util\cvacompg.exe 118784 bytes
    C:\system.sav\util\cvacompg.tmp 168 bytes
    C:\system.sav\util\delcia.flg 32 bytes
    C:\system.sav\util\DelDir.exe 20480 bytes
    C:\system.sav\util\delmodem.bat 128 bytes
    C:\system.sav\util\delmodem.ini 184 bytes
    C:\system.sav\util\DelWLAN.reg 320 bytes
    C:\system.sav\util\DETECTOS.EXE 65536 bytes
    C:\system.sav\util\DETECTOS.INI 408 bytes
    C:\system.sav\util\dmiuia.cmd 136 bytes
    C:\system.sav\util\DNSP1.LOG 4096 bytes
    C:\system.sav\util\DQM_MRK.exe 323584 bytes
    C:\system.sav\util\EISDTICON.log 32 bytes
    C:\system.sav\util\EISFE.log 32 bytes
    C:\system.sav\util\FB_EIS.log 32 bytes
    C:\system.sav\util\hpqnt.dll 53248 bytes
    C:\system.sav\util\infobomg.exe 172032 bytes
    C:\system.sav\util\INSTALL.LOG 335872 bytes
    C:\system.sav\util\ISLOGCHK.EXE 110592 bytes
    C:\system.sav\util\ISLOGCHK.INI 4096 bytes
    C:\system.sav\util\make_rtr.flg 136 bytes
    C:\system.sav\util\mobproc.flg 136 bytes
    C:\system.sav\util\oobe.min 144 bytes
    C:\system.sav\util\oobe.wpe 4096 bytes
    C:\system.sav\util\osexclude.txt 176 bytes
    C:\system.sav\util\PININST.INI 120 bytes
    C:\system.sav\util\PININST.LOG 176 bytes
    C:\system.sav\util\POSTOOBE.CMD 4096 bytes
    C:\system.sav\util\POSTOOBE.LOG 24 bytes
    C:\system.sav\util\postproc.ini 552 bytes
    C:\system.sav\util\powerset.log 88 bytes
    C:\system.sav\util\PREINCHK.BAT 216 bytes
    C:\system.sav\util\PREINFO.INI 168 bytes
    C:\system.sav\util\PREINFO2.EXE 102400 bytes
    C:\system.sav\util\qlb.log 176 bytes
    C:\system.sav\util\random.ini 40 bytes
    C:\system.sav\util\REGDEV.EXE 106496 bytes
    C:\system.sav\util\REGDEV.INI 560 bytes
    C:\system.sav\util\RMDEV.CMD 512 bytes
    C:\system.sav\util\RMIRDEV.CMD 112 bytes
    C:\system.sav\util\RunCType.REG 392 bytes
    C:\system.sav\util\SecEvBk1.old 24576 bytes
    C:\system.sav\util\sedinst.log 168 bytes
    C:\system.sav\util\SWSETDIR.exe 118784 bytes
    C:\system.sav\util\SWSETUP.BTO 424 bytes
    C:\system.sav\util\SWSETUP.CMD 136 bytes
    C:\system.sav\util\SWSET_B.INI 4096 bytes
    C:\system.sav\util\SysEvBk1.old 12288 bytes
    C:\system.sav\util\touchpad.log 192 bytes
    C:\system.sav\util\uiadump32.exe 16384 bytes
    C:\system.sav\util\uiautil.exe 32768 bytes
    C:\system.sav\util\WINDVD.LOG 168 bytes
    C:\system.sav\util\WMI.BAT 48 bytes
    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 95

    ********************************************************************
    Completion time: 2007-05-13 11:51:36
    C:\ComboFix-quarantined-files.txt ... 2007-05-13 11:51


    And a fresh HJT log:

    Logfile of HijackThis v1.99.1
    Scan saved at 12:31:47, on 13/05/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Program Files\Cordless USB Phone\Cordless DUALphone Suite.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Skype\Plugin Manager\SkypePM.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\HJT\Daniel Wilmot.exe
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cwgsy.net/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - Global Startup: Cordless DUALphone Startup.lnk = C:\Program Files\Cordless USB Phone\Cordless DUALphone Suite.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=laptop
    O15 - Trusted Zone: *.kpmgcareers.co.uk
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    Thanks again for your help.

    Wilburg
  • Rahina-RescueRahina-Rescue Finland
    edited May 2007
    Hi there.

    Please Run Vundofix, and post the logfile which is located here:

    C:\Vundofix.txt
  • edited May 2007
    Apologies Rahina.

    Because VundoFix said it hadn't found any infections, I didn't think it would produce a logfile. My mistake. Here it is:

    VundoFix V6.3.12
    Checking Java version...
    Java version is 1.4.2.5
    Old versions of java are exploitable and should be removed.
    Java version is 1.4.2.6
    Old versions of java are exploitable and should be removed.
    Java version is 1.5.0.2
    Old versions of java are exploitable and should be removed.
    Java version is 1.5.0.6
    Old versions of java are exploitable and should be removed.
    Java version is 1.5.0.9
    Old versions of java are exploitable and should be removed.
    Scan started at 21:26:36 04/03/2007
    Listing files found while scanning....
    C:\Documents and settings\Daniel Wilmot\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
    C:\Documents and settings\Daniel Wilmot\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
    C:\Program Files\VSAdd-in\VSAdd-in.dll
    C:\WINDOWS\system32\hgjlm.bak1
    C:\WINDOWS\system32\hgjlm.bak2
    C:\WINDOWS\system32\hgjlm.ini
    C:\WINDOWS\system32\mljgh.dll
    C:\WINDOWS\system32\vftpskpv.ini
    C:\WINDOWS\system32\vpksptfv.dll
    Beginning removal...
    Attempting to delete C:\Documents and settings\Daniel Wilmot\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt
    C:\Documents and settings\Daniel Wilmot\Application Data\SearchToolbarCorp\Toolbar Vision\PageHistory.txt Has been deleted!
    Attempting to delete C:\Documents and settings\Daniel Wilmot\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt
    C:\Documents and settings\Daniel Wilmot\Application Data\SearchToolbarCorp\Toolbar Vision\WebHistory.txt Has been deleted!
    Attempting to delete C:\WINDOWS\system32\hgjlm.bak1
    C:\WINDOWS\system32\hgjlm.bak1 Has been deleted!
    Attempting to delete C:\WINDOWS\system32\hgjlm.bak2
    C:\WINDOWS\system32\hgjlm.bak2 Has been deleted!
    Attempting to delete C:\WINDOWS\system32\hgjlm.ini
    C:\WINDOWS\system32\hgjlm.ini Has been deleted!
    Attempting to delete C:\WINDOWS\system32\vftpskpv.ini
    C:\WINDOWS\system32\vftpskpv.ini Has been deleted!
    Attempting to delete C:\WINDOWS\system32\vpksptfv.dll
    C:\WINDOWS\system32\vpksptfv.dll Has been deleted!
    Performing Repairs to the registry.
    Done!
    VundoFix V6.3.12
    Checking Java version...
    Java version is 1.5.0.9
    Old versions of java are exploitable and should be removed.
    Scan started at 15:13:01 12/05/2007
    Listing files found while scanning....
    No infected files were found.

    VundoFix V6.3.12
    Checking Java version...
    Java version is 1.5.0.9
    Old versions of java are exploitable and should be removed.
    Scan started at 11:35:12 13/05/2007
    Listing files found while scanning....
    No infected files were found.
  • Rahina-RescueRahina-Rescue Finland
    edited May 2007
    Now Please post a Fresh Main.txt Logfile.

    Thanks.
  • edited May 2007
    Hi Rahina

    Sorry for my incredibly tardy reply; I was never informed by e-mail that you had replied to my post.

    In any case, please find below a fresh Main.txt log:

    Deckard's System Scanner v20070426.43
    Run by Daniel Wilmot on 2007-05-21 at 23:00:20
    Computer is in Normal Mode.

    -- HijackThis (run as Daniel Wilmot.exe)
    Logfile of HijackThis v1.99.1
    Scan saved at 23:00:54, on 21/05/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\WINDOWS\system32\CTsvcCDA.EXE
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Program Files\Cordless USB Phone\Cordless DUALphone Suite.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Skype\Plugin Manager\SkypePM.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
    C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
    C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Daniel Wilmot\Desktop\Malware Tools\Deckard's System Scanner.exe
    C:\HJT\DANIEL~1.EXE
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cwgsy.net/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - Global Startup: Cordless DUALphone Startup.lnk = C:\Program Files\Cordless USB Phone\Cordless DUALphone Suite.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=laptop
    O15 - Trusted Zone: *.kpmgcareers.co.uk
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    -- Files created between 2007-04-21 and 2007-05-21
    2007-05-13 11:34:03 0 d
    C:\HJT
    2007-05-12 15:37:21 0 d
    C:\WINDOWS\LastGood

    -- Find3M Report
    2007-05-21 22:57:39 0 d
    C:\Documents and Settings\Daniel Wilmot\Application Data\Skype
    2007-05-12 16:38:06 0 d
    C:\Program Files\MSN Messenger
    2007-05-12 16:34:25 0 d
    C:\Program Files\Microsoft ActiveSync
    2007-05-12 16:33:14 0 d
    C:\Program Files\iTunes
    2007-05-12 16:29:06 0 d
    C:\Program Files\Google
    2007-05-12 16:28:32 0 d
    C:\Program Files\Cordless USB Phone
    2007-05-12 15:11:55 2008 --a
    C:\WINDOWS\system32\tmp.reg
    2007-05-11 19:41:32 0 d
    C:\Documents and Settings\Daniel Wilmot\Application Data\uTorrent
    2007-05-01 12:13:17 0 d
    C:\Documents and Settings\Daniel Wilmot\Application Data\AVG7
    2007-04-29 19:54:09 4212 ---h
    C:\WINDOWS\system32\zllictbl.dat

    -- Registry Dump
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    {53707962-6F74-2D53-2644-206D7942484F} C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    {AA58ED58-01DD-4d91-8333-CF10577473F7} c:\program files\google\googletoolbar5.dll
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
    "HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
    "SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
    "SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
    "eabconfg.cpl"="C:\\Program Files\\HPQ\\Quick Launch Buttons\\EabServr.exe /Start"
    "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
    "SsAAD.exe"="C:\\PROGRA~1\\Sony\\SONICS~1\\SsAAD.exe"
    "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
    "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
    "H/PC Connection Agent"="\"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE\""
    "swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\Awasu]
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"
    HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
    Authentication Packages REG_MULTI_SZ msv1_0\0\0
    Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
    Notification Packages REG_MULTI_SZ scecli\0\0

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "Skype"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
    "backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\Adobe\\ACROBA~3.0\\Reader\\READER~1.EXE "
    "item"="Adobe Reader Speed Launch"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^broadband medic.lnk]
    "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\broadband medic.lnk"
    "backup"="C:\\WINDOWS\\pss\\broadband medic.lnkCommon Startup"
    "location"="Common Startup"
    "command"="C:\\PROGRA~1\\ntl\\BROADB~1\\bin\\matcli.exe -boot"
    "item"="broadband medic"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BJCFD]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="CFD"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\BroadJump\\Client Foundation\\CFD.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="CTDetect"
    "hkey"="HKCU"
    "command"="C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe /R"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="dvd43_tray"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\dvd43\\dvd43_tray.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="WCESCOMM"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE\""
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="cledx"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\SyncroSoft\\Pos\\H2O\\cledx.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Home Theater SchSvr]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="SchSvr"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Common Files\\InterVideo\\SchSvr\\SchSvr.exe\""
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="issch"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="iTunesHelper"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Motive SmartBridge]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="MotiveSB"
    "hkey"="HKLM"
    "command"="C:\\PROGRA~1\\ntl\\BROADB~1\\SMARTB~1\\MotiveSB.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="qttask"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="Skype"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="SsAAD"
    "hkey"="HKLM"
    "command"="C:\\PROGRA~1\\Sony\\SONICS~1\\SsAAD.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="GoogleToolbarNotifier"
    "hkey"="HKCU"
    "command"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead Quick-Drop]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="Quick-Drop"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Ulead Systems\\Ulead DVD MovieFactory 5 Plus\\Ulead DVD MovieFactory 5\\Quick-Drop.exe\" WINDOWCALL"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateManager]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="sgtray"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="winampa"
    "hkey"="HKLM"
    "command"="C:\\Program Files\\Winamp\\winampa.exe"
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINREMOTE]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="WinRemote"
    "hkey"="HKLM"
    "command"="\"C:\\Program Files\\InterVideo\\Common\\Bin\\WinRemote.exe\""
    "inimapping"="0"
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
    "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
    "item"="ypager"
    "hkey"="HKCU"
    "command"="\"C:\\Program Files\\Yahoo!\\Messenger\\ypager.exe\" -quiet"
    "inimapping"="0"

    [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
    HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
    LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
    NetworkService REG_MULTI_SZ DnsCache\0\0
    DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
    rpcss REG_MULTI_SZ RpcSs\0\0
    imgsvc REG_MULTI_SZ StiSvc\0\0
    termsvcs REG_MULTI_SZ TermService\0\0

    -- End of Deckard's System Scanner: finished at 2007-05-21 at 23:01:30
  • Rahina-RescueRahina-Rescue Finland
    edited May 2007
    Things Happen, don't worry about it.

    Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be promted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)
      • Scan Options:
        Scan Archives
        Scan Mail Bases


        [*]Click OK
        [*]Now under select a target to scan:
          Select
        My Computer

        [*]This will program will start and scan your system.
        [*]The scan will take a while so be patient and let it run.
        [*]Once the scan is complete it will display if your system has been infected.
        • Now click on the Save as Text button:
        [*]Save the file to your desktop.
        [*]Copy and paste that information in your next post.

        How are things running?
      • edited May 2007
        Hi Rahina

        Thank you for your quick reply. I believe the pop-ups have slowed down. In fact I don't think i've seen one today, so that's a positive. However my laptop is still very slow and sluggish.

        I have a question actually. Ever since I deinstalled Norton AV and replaced it with AVG, Zone Alarm and Ad-aware I have been attacked 3 times (including this occasion) by viruses, whereas before I was rarely (if ever) troubled. I'm starting to question the efficacy of AVG. Could you recommend better anti-virus software?

        Please find below the results of a Kapersky Online Scan:

        KASPERSKY ONLINE SCANNER REPORTKASPERSKY ONLINE SCANNER REPORT
        Tuesday, May 22, 2007 11:26:47 AM
        Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build
        2600)
        Kaspersky Online Scanner version: 5.0.83.0
        Kaspersky Anti-Virus database last update: 22/05/2007
        Kaspersky Anti-Virus database records: 325800

        Scan Settings
        Scan using the following antivirus databaseextended
        Scan Archivestrue
        Scan Mail Basestrue
        Scan TargetMy Computer
        C:\
        D:\
        Scan Statistics
        Total number of scanned objects98366
        Number of viruses found5
        Number of infected objects13 / 0
        Number of suspicious objects0
        Duration of the scan process02:14:08
        Infected Object NameVirus NameLast Action
        C:\Documents and Settings\All Users\Application
        Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
        C:\Documents and Settings\All Users\Application
        Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
        C:\Documents and Settings\All Users\Application Data\muvee
        Technologies\030625\0102\0106\values Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Adobe\Acrobat\7.0\Updater\udlog.txt Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Microsoft\Outlook\Outlook.NK2 Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Microsoft\Outlook\Outlook.srs Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Microsoft\Templates\Normal.dot Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\call256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\callmember256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chat256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chat512.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chat8192.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chatmember256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chatmsg1024.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chatmsg2048.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chatmsg256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chatmsg4096.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chatmsg512.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\chatsync\bd\bd26819ad424facd.dat Object is locked
        skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\contactgroup256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\dyncontent\bundle.dat Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\index2.dat Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\message256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\profile256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\sms1024.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\sms256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\sms512.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\transfer256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\transfer512.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\user1024.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\user16384.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\user256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\user4096.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Application
        Data\Skype\danielwilmot\voicemail256.dbb Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Cookies\index.dat Object is locked
        skipped
        C:\Documents and Settings\Daniel Wilmot\Desktop\Malware
        Tools\SmitfraudFix\Reboot.exe Infected:
        not-a-virus:RiskTool.Win32.Reboot.f skipped
        C:\Documents and Settings\Daniel Wilmot\Desktop\Malware
        Tools\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected:
        not-a-virus:RiskTool.Win32.Reboot.f skipped
        C:\Documents and Settings\Daniel Wilmot\Desktop\Malware
        Tools\SmitfraudFix.exe/data.rar Infected:
        not-a-virus:RiskTool.Win32.Reboot.f skipped
        C:\Documents and Settings\Daniel Wilmot\Desktop\Malware
        Tools\SmitfraudFix.exe RarSFX: infected - 2 skipped
        C:\Documents and Settings\Daniel Wilmot\Desktop\Malware
        Tools\SmitfraudFix.exe PE_Patch.UPX: infected - 2 skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Application
        Data\Microsoft\Outlook\archive.pst Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Application
        Data\Microsoft\Outlook\Outlook.pst Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Application
        Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Application
        Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local
        Settings\History\History.IE5\index.dat Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local
        Settings\History\History.IE5\MSHist012007052220070523\index.dat Object is
        locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Temp\~DF8CA3.tmp
        Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Temp\~DFAF79.tmp
        Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Temp\~WRD0002.doc
        Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Temp\~WRF0001.tmp
        Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Temp\~WRS0000.tmp
        Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Temporary Internet
        Files\Content.IE5\index.dat Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Temporary Internet
        Files\MULE8N27\2N25GZ3M\Offline\0x00000001_R Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Temporary Internet
        Files\MULE8N27\2N25GZ3M\Offline\0x00000003_R Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\Local Settings\Temporary Internet
        Files\MULE8N27\2N25GZ3M\Offline\HashFile.dat Object is locked skipped
        C:\Documents and Settings\Daniel Wilmot\My Documents\My Downloaded
        Programs\KeyFinder\keyfinder.exe/data.rar/officekey.exe Infected:
        not-a-virus:PSWTool.Win32.RAS.a skipped
        C:\Documents and Settings\Daniel Wilmot\My Documents\My Downloaded
        Programs\KeyFinder\keyfinder.exe/data.rar Infected:
        not-a-virus:PSWTool.Win32.RAS.a skipped
        C:\Documents and Settings\Daniel Wilmot\My Documents\My Downloaded
        Programs\KeyFinder\keyfinder.exe RarSFX: infected - 2 skipped
        C:\Documents and Settings\Daniel Wilmot\My Documents\My Downloaded
        Programs\Purity Scan Uninstaller\OiUninstaller.exe/data0002 Infected:
        not-a-virus:AdWare.Win32.PurityScan.fk skipped
        C:\Documents and Settings\Daniel Wilmot\My Documents\My Downloaded
        Programs\Purity Scan Uninstaller\OiUninstaller.exe/data0003 Infected:
        not-a-virus:AdWare.Win32.PurityScan.bu skipped
        C:\Documents and Settings\Daniel Wilmot\My Documents\My Downloaded
        Programs\Purity Scan Uninstaller\OiUninstaller.exe NSIS: infected - 2
        skipped
        C:\Documents and Settings\Daniel Wilmot\My Documents\My Downloaded
        Programs\SmitFraud Fix\SmitfraudFix\Reboot.exe Infected:
        not-a-virus:RiskTool.Win32.Reboot.f skipped
        C:\Documents and Settings\Daniel Wilmot\NTUSER.DAT Object is locked
        skipped
        C:\Documents and Settings\Daniel Wilmot\ntuser.dat.LOG Object is locked
        skipped
        C:\Documents and Settings\Daniel Wilmot\UserData\index.dat Object is
        locked skipped
        C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked
        skipped
        C:\Documents and Settings\LocalService\Local Settings\Application
        Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
        C:\Documents and Settings\LocalService\Local Settings\Application
        Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
        C:\Documents and Settings\LocalService\Local
        Settings\History\History.IE5\index.dat Object is locked skipped
        C:\Documents and Settings\LocalService\Local Settings\Temporary Internet
        Files\Content.IE5\index.dat Object is locked skipped
        C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

        C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked
        skipped
        C:\Documents and Settings\NetworkService\Local Settings\Application
        Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
        C:\Documents and Settings\NetworkService\Local Settings\Application
        Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
        C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked
        skipped
        C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked
        skipped
        C:\System Volume Information\MountPointManagerRemoteDatabase Object is
        locked skipped
        C:\System Volume
        Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP8\change.log
        Object is locked skipped
        C:\VundoFix Backups\vpksptfv.dll.bad Infected:
        not-a-virus:AdWare.Win32.Virtumonde.gf skipped
        C:\WINDOWS\$_hpcst$.hpc Object is locked skipped
        C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
        C:\WINDOWS\Internet Logs\DANSLAPTOP.ldb Object is locked skipped
        C:\WINDOWS\Internet Logs\fwdbglog.txt Object is locked skipped
        C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
        C:\WINDOWS\Internet Logs\IAMDB.RDB Object is locked skipped
        C:\WINDOWS\Internet Logs\tvDebug.log Object is locked skipped
        C:\WINDOWS\SchedLgU.Txt Object is locked skipped
        C:\WINDOWS\SoftwareDistribution\EventCache\{F0ED3D98-18E0-4CC1-9046-8D292084EC61}.bin
        Object is locked skipped
        C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked
        skipped
        C:\WINDOWS\Sti_Trace.log Object is locked skipped
        C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
        C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
        C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
        C:\WINDOWS\system32\config\default Object is locked skipped
        C:\WINDOWS\system32\config\default.LOG Object is locked skipped
        C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
        C:\WINDOWS\system32\config\SAM Object is locked skipped
        C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
        C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
        C:\WINDOWS\system32\config\SECURITY Object is locked skipped
        C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
        C:\WINDOWS\system32\config\software Object is locked skipped
        C:\WINDOWS\system32\config\software.LOG Object is locked skipped
        C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
        C:\WINDOWS\system32\config\system Object is locked skipped
        C:\WINDOWS\system32\config\system.LOG Object is locked skipped
        C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
        C:\WINDOWS\system32\h323log.txt Object is locked skipped
        C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
        C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked
        skipped
        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked
        skipped
        C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked
        skipped
        C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked
        skipped
        C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked
        skipped
        C:\WINDOWS\Temp\ZLT054ec.TMP Object is locked skipped
        C:\WINDOWS\Temp\ZLT054ef.TMP Object is locked skipped
        C:\WINDOWS\wiadebug.log Object is locked skipped
        C:\WINDOWS\wiaservc.log Object is locked skipped
        C:\WINDOWS\WindowsUpdate.log Object is locked skipped
        Scan process completed.
      • Rahina-RescueRahina-Rescue Finland
        edited May 2007
        Do you recognize the following folder, and the files it contain inside.

        C:\Documents and Settings\Daniel Wilmot\My Documents\My Downloaded\Programs\KeyFinder

        If Not, Remove That Folder.

        Next Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete this folder (if present):

        C:\Documents and Settings\Daniel Wilmot\My Documents\My Downloaded\Programs\Purity Scan Uninstaller

        Also Locate VUndofix Backups Folder, Remove everythign inside of it.

        C:\VundoFix\Backups

        How Are things Running now?
      • edited May 2007
        Hi Rahina

        Yes, I recognise the Keyfinder folder, so i've kept that.
        I have however deleted the other two folders and their contents as per your request.

        My laptop does seem to be going a little better. Maybe I will just sit and watch and see if anything happens over the next few days.

        Apart from that, did you have any opinions on my question regarding better anti-virus software?

        Kind regards

        Wilburg
      • Rahina-RescueRahina-Rescue Finland
        edited May 2007
        AVG Should Be just fine, Have you been thinking on changing the Firewall Instead?

        I had problems With My ZA When i used it a long time a ago but that's probably just my fault :)

        I Suggest Comodo, i currently use it :)

        There are some usefull links above in my signature if you are interested.
      • edited May 2007
        Hi Rahina

        I had only thought of changing my AV because this is the third time I have had problems with my laptop whereas before with NAV I never had any problems like this. I was just questioning how good AVG was.

        I might take you up on Comodo. I shall definitely check it out.

        In any case, regards the performance of my laptop, so far so good it seems :)
      • Rahina-RescueRahina-Rescue Finland
        edited May 2007
        Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
        • Disable and Enable System Restore.
        If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

        You can find instructions on how to enable and reenable system restore here:

        Managing Windows Millenium System Restore
          Windows XP System Restore Guide

          Reenable system restore with instructions from tutorial above

          [*]Make your Internet Explorer more secure - This can be done by following these simple instructions:
          [*]From within Internet Explorer click on the Tools menu and then click on Options.
          [*]Click once on the Security tab
          [*]Click once on the Internet icon so it becomes highlighted.
          [*]Click once on the Custom Level button.
          1. Change the Download signed ActiveX controls to Prompt
          2. Change the Download unsigned ActiveX controls to Disable
          3. Change the Initialize and script ActiveX controls not marked as safe to Disable
          4. Change the Installation of desktop items to Prompt
          5. Change the Launching programs and files in an IFRAME to Prompt
          6. Change the Navigate sub-frames across different domains to Prompt
          7. When all these settings have been made, click on the OK button.
          8. If it prompts you as to whether or not you want to save the settings, press the Yes button.
          [*]Next press the Apply button and then the OK to exit the Internet Properties page.
          • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

            See this link for a listing of some online & their stand-alone antivirus programs:

            Virus, Spyware, and Malware Protection and Removal Resources
          • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
          • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

            For a tutorial on Firewalls and a listing of some available ones see the link below:

            Understanding and Using Firewalls
          • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
          • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

            A tutorial on installing & using this product can be found here:

            Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
          • Install AVG Anti-Spyware - Install and download AVG Anti-Spyware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

            A tutorial on installing & using this product can be found here:

            Using AVG Anti-Spyware to remove Spyware, Malware, & Hijackers from Your Computer
          • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

            A tutorial on installing & using this product can be found here:

            Using SpywareBlaster to protect your computer from Spyware and Malware
          • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
          Follow this list and your potential for being infected again will reduce dramatically.

          here are some additional utilities that will enhance your safety
          • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
          • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
          • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
          • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
            Using Winpatrol to protect your computer from malicious software
          Let me know if you still receive problems :)
        Sign In or Register to comment.