Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads

User Tag List

Being attacked by adware/spyware...help

This is a discussion on Being attacked by adware/spyware...help within the Resolved HJT Threads forums, part of the Tech Support Forum category. I gave this computer to my daughter and she accidentally infected it with multiple problems. We now have an understanding


 
 
Thread Tools Search this Thread
Old 06-26-2009, 09:53 PM   #1
Registered Member
 
Join Date: Oct 2007
Location: Little Rock, AR
Posts: 67
OS: XP



I gave this computer to my daughter and she accidentally infected it with multiple problems. We now have an understanding as to how to keep these off, but i need help removing them if possible...thanks.


GMER 1.0.15.14972 - https://www.gmer.net
Rootkit scan 2009-06-26 23:25:22
Windows 5.1.2600 Service Pack 3


---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 mouclass.sys (Mouse Class Driver/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\USB_RNDIS \Device\{FCA22336-5931-44E8-93F4-E80B36EF256D} RNDISMP.SYS (Remote NDIS Miniport/Microsoft Corporation)

---- Services - GMER 1.0.15 ----

Service C:\WINDOWS\system32\drivers\UACsmnaxvmp.sys (*** hidden *** ) [SYSTEM] UACd.sys <-- ROOTKIT !!!

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\[email protected] 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\[email protected] \systemroot\system32\drivers\UACsmnaxvmp.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\[email protected] file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\drivers\UACsmnaxvmp.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACfqxotfqr.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACjpumlwuw.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACheexnqcn.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACracbfprb.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACxfpapeil.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACtkowfovw.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACbpasjjpg.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACiiyvmext.log
Reg HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACdujwqbit.dll
Reg HKLM\SYSTEM\ControlSet003\Services\[email protected] 1
Reg HKLM\SYSTEM\ControlSet003\Services\[email protected] 1
Reg HKLM\SYSTEM\ControlSet003\Services\[email protected] \systemroot\system32\drivers\UACsmnaxvmp.sys
Reg HKLM\SYSTEM\ControlSet003\Services\[email protected] file system
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\modules
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\drivers\UACsmnaxvmp.sys
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACfqxotfqr.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACjpumlwuw.dat
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACheexnqcn.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACracbfprb.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACxfpapeil.dll
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACtkowfovw.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACbpasjjpg.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACiiyvmext.log
Reg HKLM\SYSTEM\ControlSet003\Services\UACd.sys\[email protected] \\?\globalroot\systemroot\system32\UACdujwqbit.dll

---- EOF - GMER 1.0.15 ----
Attached Files
File Type: zip ark.zip (926 Bytes, 20 views)
File Type: zip Attach.zip (1.7 KB, 22 views)
alanh is offline  
Sponsored Links
Advertisement
 
Old 06-28-2009, 10:19 AM   #2
Security Team
Analyst
 
Join Date: Jan 2009
Posts: 553
OS: Win98SE, XP Home SP3, Windows 7 64-bit



Hello and welcome to Tech Support Forum.

My name is km2357 and I will be helping you to remove any infection(s) that you may have.

I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.

Please run DDS again. I need to see the main log, DDS.txt in your next post/reply.
km2357 is offline  
Old 06-28-2009, 11:25 AM   #3
Registered Member
 
Join Date: Oct 2007
Location: Little Rock, AR
Posts: 67
OS: XP



DDS (Ver_09-06-26.01) - NTFSx86
Run by Kyrsti at 23:12:40.63 on Fri 06/26/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.143 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\All Users\Application Data\KwinzySearch\kwinzy123.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\RelevantKnowledge\rlvknlg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\KwinzySearch\kwinzy.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Gamevance\gamevance32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\VoloMedia\VoloMedia Service\VoloMediaService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\MSN\Toolbar\3.0.1125.0\msntask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Kyrsti\Local Settings\Temporary Internet Files\Content.IE5\9G087ZS1\dds[1].scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.theprizeday.com/today.php
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*https://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*https://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*https://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*https://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://www.yahoo.com
mSearchAssistant = hxxp://www.crawler.com/search/ie.aspx?tb_id=60315
mCustomizeSearch = hxxp://dnl.crawler.com/support/sa_customize.aspx?TbId=60315
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: NetAssistantBHO Class: {e38fa08e-f56a-4169-abf5-5c71e3c153a1} - c:\program files\my.freeze.com toolbar\NetAssistant.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Gamevance: {0ed403e8-470a-4a8a-85a4-d7688cfe39a3} - c:\program files\gamevance\gamevancelib32.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PCCBHO.CPCCBHO: {22fc6ce8-7d47-479f-b74a-bfbb04adb9af} - c:\program files\winferno\pc confidential\PCCBHO.dll
BHO: Media Access Startup: {25b8d58c-b0cb-46b0-ba64-05b3804e4e86} - c:\program files\media access startup\1.3.0.790\HPIEAddOn.dll
BHO: NP Helper Class: {35b8d58c-b0cb-46b0-ba64-05b3804e4e86} - c:\program files\internet saving optimizer\3.3.0.4160\NPIEAddOn.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: System Search Dispatcher: {cdbfb47b-58a8-4111-bf95-06178dce326d} - c:\program files\system search dispatcher\1.2.0.750\ssd.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: NetAssistantBHO Class: {e38fa08e-f56a-4169-abf5-5c71e3c153a1} - c:\program files\my.freeze.com toolbar\NetAssistant.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Gamevance class: {f02fabcb-92dd-475a-98af-14217bd50746} - c:\program files\gamevance\gvtl.dll
BHO: XBTBPos00 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\my.freeze.com toolbar\freeze_us.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: My.Freeze.com Toolbar: {d0523bb4-21e7-11dd-9ab7-415b56d89593} - c:\program files\my.freeze.com toolbar\freeze_us.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File
TB: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [VibeFireAlerts]
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Gamevance] c:\program files\gamevance\gamevance32.exe a
mRun: [Ajirogis] rundll32.exe "c:\windows\Hlehitulobomagi.dll",e
mRun: [Ybosig] rundll32.exe "c:\windows\ehuqiqej.dll",e
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [VoloMedia Service] "c:\program files\volomedia\volomedia service\VoloMediaService.exe"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: RelevantKnowledge - c:\program files\relevantknowledge\rlls.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R2 KwinzySearch Service;KwinzySearch Service;c:\documents and settings\all users\application data\kwinzysearch\kwinzy123.exe [2009-6-18 54760]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656]
R2 WUSB54GSv2SVC;WUSB54GSv2SVC;c:\program files\linksys wireless-g usb wireless network monitor\WLService.exe [2008-10-18 41025]

=============== Created Last 30 ================

2009-06-18 14:35 <DIR> --d----- c:\program files\KwinzySearch
2009-06-18 14:35 <DIR> --d----- c:\docume~1\alluse~1\applic~1\KwinzySearch
2009-06-15 01:16 <DIR> --d----- c:\program files\Media Access Startup
2009-06-15 01:16 <DIR> --d----- c:\program files\Internet Saving Optimizer
2009-06-15 01:16 <DIR> --d----- c:\program files\System Search Dispatcher
2009-06-15 01:15 <DIR> --d----- c:\program files\DoubleD
2009-06-15 00:14 <DIR> --d----- c:\program files\Horse Racing Simulation LLC
2009-06-15 00:14 <DIR> --d----- c:\docume~1\kyrsti\applic~1\Hrsim
2009-06-15 00:12 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}
2009-06-07 12:13 <DIR> --d----- c:\documents and settings\kyrsti\.thumb
2009-06-07 12:07 <DIR> --d----- c:\program files\Xobni
2009-06-07 12:05 <DIR> --d----- c:\docume~1\kyrsti\applic~1\blinkx
2009-06-07 12:05 <DIR> --d----- c:\program files\RelevantKnowledge
2009-06-07 12:04 577,536 a------- c:\windows\system32\VibeFire.dll

==================== Find3M ====================

2009-06-13 03:11 51,200 -------- c:\windows\system32\drivers\UACsmnaxvmp.sys
2009-06-12 23:13 5,746 a------- c:\windows\system32\uacinit.dll
2009-05-07 10:32 345,600 a------- c:\windows\system32\localspl.dll
2009-04-28 23:56 827,392 a------- c:\windows\system32\wininet.dll
2009-04-28 23:55 78,336 a------- c:\windows\system32\ieencode.dll
2009-04-17 07:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 09:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-04-06 11:19 66,560 a------- c:\windows\system32\UACxfpapeil.dll
2009-04-06 11:19 19,456 -------- c:\windows\system32\UACdujwqbit.dll
2009-04-06 11:19 17,408 a------- c:\windows\system32\UACracbfprb.dll
2009-04-06 11:19 20,480 a------- c:\windows\system32\UACheexnqcn.dll
2009-04-06 11:19 24,064 a------- c:\windows\system32\UACfqxotfqr.dll
2008-10-18 14:20 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101820081019\index.dat

============= FINISH: 23:13:15.87 ===============
alanh is offline  
Sponsored Links
Advertisement
 
Old 06-28-2009, 11:10 PM   #4
Security Team
Analyst
 
Join Date: Jan 2009
Posts: 553
OS: Win98SE, XP Home SP3, Windows 7 64-bit



Looking over your log, it seems you don't have any evidence of an anti-virus software.

Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these vendors NOW:

1)Antivir PersonalEdition Classic
2)avast! 4 Home Edition

Download and install only one!



Step # 1: Add/Remove Programs

Go to Start-Settings-Control Panel, click on Add Remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

Gamevance

Internet Saving Optimizer

Kwinzy 1.0 build 123

My.Freeze.com Toolbar

RelevantKnowledge


Reboot your Computer.



Step # 2: Download and Run ComboFix

Download ComboFix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3





--------------------------------------------------------------------

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please include C:\ComboFix.txt in your next reply so we can continue cleaning the system.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall
km2357 is offline  
Old 06-29-2009, 11:55 AM   #5
Registered Member
 
Join Date: Oct 2007
Location: Little Rock, AR
Posts: 67
OS: XP



ComboFix 09-06-29.01 - Kyrsti 06/29/2009 13:45.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.248 [GMT -5:00]
Running from: c:\documents and settings\Kyrsti\My Documents\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kyrsti\Local Settings\Application Data\{F06B3C52-7338-46DC-A3F0-F1A779D7A1BA}
c:\documents and settings\Kyrsti\Local Settings\Application Data\{F06B3C52-7338-46DC-A3F0-F1A779D7A1BA}\chrome.manifest
c:\documents and settings\Kyrsti\Local Settings\Application Data\{F06B3C52-7338-46DC-A3F0-F1A779D7A1BA}\chrome\content\_cfg.js
c:\documents and settings\Kyrsti\Local Settings\Application Data\{F06B3C52-7338-46DC-A3F0-F1A779D7A1BA}\chrome\content\c.js
c:\documents and settings\Kyrsti\Local Settings\Application Data\{F06B3C52-7338-46DC-A3F0-F1A779D7A1BA}\chrome\content\overlay.xul
c:\documents and settings\Kyrsti\Local Settings\Application Data\{F06B3C52-7338-46DC-A3F0-F1A779D7A1BA}\install.rdf
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm2B7.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm2DF.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm2EB.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm2F6.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm306.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm322.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm33D.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm34D.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm363.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm37C.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm3AE.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm3FA.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm419.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\_tm49.tmp
c:\documents and settings\Kyrsti\Local Settings\Temporary Internet Files\stb06759.tmp
c:\documents and settings\Kyrsti\Start Menu\A360
c:\documents and settings\Kyrsti\Start Menu\A360\A360.lnk
c:\documents and settings\Kyrsti\Start Menu\A360\Help.lnk
c:\documents and settings\Kyrsti\Start Menu\A360\Registration.lnk
c:\program files\Common Files\System\Uninstall
c:\program files\Common Files\System\Uninstall\Uninstall A360.lnk
c:\program files\FunWebProducts
c:\program files\FunWebProducts\ScreenSaver\Images\001BA1A5.urr
c:\program files\MyWebSearch
c:\program files\MyWebSearch\bar\History\search3
c:\program files\MyWebSearch\bar\Settings\s_pid.dat
c:\program files\MyWebSearch\bar\Settings\setting2.htm
c:\program files\MyWebSearch\bar\Settings\setting2.htm.bak
c:\program files\MyWebSearch\bar\Settings\settings.dat
c:\program files\MyWebSearch\bar\Settings\settings.dat.bak
c:\windows\akuyoqeviwe.dll
c:\windows\ehuqiqej.dll
c:\windows\ejizixoci.dll
c:\windows\Hlehitulobomagi.dll
c:\windows\okomokekegasudev.dll
c:\windows\okubiquyepiyij.dll
c:\windows\system32\UACdujwqbit.dll
c:\windows\system32\UACfqxotfqr.dll
c:\windows\system32\UACheexnqcn.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjpumlwuw.dat
c:\windows\system32\UACracbfprb.dll
c:\windows\system32\UACtkowfovw.log
c:\windows\system32\UACxfpapeil.dll
c:\windows\Temp\tmp3.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-29 )))))))))))))))))))))))))))))))
.

2009-06-29 01:02 . 2009-06-29 01:02 1548 ----a-w- c:\windows\Klupakusadiyur.dat
2009-06-15 06:21 . 2009-06-15 06:21 -------- d-----w- c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer
2009-06-15 06:16 . 2009-06-15 06:16 -------- d-----w- c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup
2009-06-15 06:16 . 2009-06-15 06:16 -------- d-----w- c:\program files\Media Access Startup
2009-06-15 06:16 . 2009-06-15 06:16 -------- d-----w- c:\program files\Internet Saving Optimizer
2009-06-15 06:16 . 2009-06-15 06:16 -------- d-----w- c:\program files\System Search Dispatcher
2009-06-15 06:15 . 2009-06-15 06:15 -------- d-----w- c:\program files\DoubleD
2009-06-15 06:14 . 2009-06-15 06:14 -------- d-----w- c:\documents and settings\Kyrsti\Local Settings\Application Data\DoubleD
2009-06-15 05:15 . 2009-04-24 13:59 2472608 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\setupHRF10_90_SP1.exe
2009-06-15 05:14 . 2009-06-15 05:14 -------- d-----w- c:\program files\Horse Racing Simulation LLC
2009-06-15 05:14 . 2009-06-15 05:14 -------- d-----w- c:\documents and settings\Kyrsti\Application Data\Hrsim
2009-06-15 05:12 . 2009-06-15 05:15 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}
2009-06-15 05:12 . 2009-01-26 15:21 307200 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\3B02A30E\8A52B4FB\HRFviewer.dll
2009-06-15 05:12 . 2008-03-19 23:29 348160 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\F05AD411\9CD9520D\MSVCR71.dll
2009-06-15 05:12 . 2008-02-21 18:11 2117632 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\8B346739\9CD9520D\python25.dll
2009-06-15 05:12 . 2008-01-21 18:21 212992 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\F788288E\4C18FEA5\imagetools.dll
2009-06-15 05:12 . 2009-04-23 13:13 1634304 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\DB7BDDA5\F06B4927\Hrace.exe
2009-06-15 05:12 . 2009-04-21 09:30 3002368 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\B65A4737\F06B4927\Hrfanwin.exe
2009-06-15 05:12 . 2009-02-04 03:44 39936 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\5D6606E9\258FB427\HRGcomm.exe
2009-06-15 05:12 . 2009-01-21 08:59 16896 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\E430A951\9CD9520D\web.exe
2009-06-15 05:12 . 2009-01-17 04:07 28672 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\669E12EA\4C18FEA5\SilksApp.exe
2009-06-15 05:12 . 2008-04-16 13:15 1077248 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\DFBB026D\4C18FEA5\HorseRaceAtl.exe
2009-06-15 05:12 . 2007-11-08 04:43 73728 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\6831DB05\4C18FEA5\FileChecker.exe
2009-06-07 17:13 . 2009-06-07 17:13 -------- d-----w- c:\documents and settings\Kyrsti\.thumb
2009-06-07 17:07 . 2009-06-27 03:17 -------- d-----w- c:\program files\Xobni
2009-06-07 17:05 . 2009-06-07 17:05 -------- d-----w- c:\documents and settings\Kyrsti\Application Data\blinkx
2009-06-07 17:04 . 2009-02-18 22:38 577536 ----a-w- c:\windows\system32\VibeFire.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-27 03:14 . 2009-04-27 01:55 -------- d-----w- c:\program files\Winferno
2009-06-15 06:16 . 2008-10-18 18:18 43336 ----a-w- c:\documents and settings\Kyrsti\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-13 08:11 . 2009-02-25 22:24 51200 ------w- c:\windows\system32\drivers\UACsmnaxvmp.sys
2009-06-07 17:07 . 2009-04-27 01:57 -------- d-----w- c:\program files\Free Offers from Freeze.com
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-04 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-23 13:13 . 2009-04-23 13:13 1634304 ----a-w- c:\documents and settings\Kyrsti\Application Data\Hrsim\Hrfan\Hrace.exe
2009-04-21 09:30 . 2009-04-21 09:30 3002368 ----a-w- c:\documents and settings\Kyrsti\Application Data\Hrsim\Hrfan\Hrfanwin.exe
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 12:19 . 2009-04-17 12:19 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}]
2008-11-27 00:40 253048 ----a-w- c:\program files\My.Freeze.com Toolbar\NetAssistant.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-02-11 801904]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-02-07 344064]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-06-24 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-06-24 561152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-23 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"VoloMedia Service"="c:\program files\VoloMedia\VoloMedia Service\VoloMediaService.exe" [2009-04-01 3965648]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-06-27 88363]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"&#37;windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\WolfQuest\\WolfQuest.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 WUSB54GSv2SVC;WUSB54GSv2SVC;c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [10/18/2008 1:02 PM 41025]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - GTNDIS5
.
Contents of the 'Scheduled Tasks' folder

2009-06-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-06-29 c:\windows\Tasks\PCConfidential.job
- c:\program files\Winferno\PC Confidential\PCConfidential.exe [2009-04-27 19:10]

2009-06-29 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-12 03:18]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-VibeFireAlerts - (no file)
HKLM-Run-Ajirogis - c:\windows\Hlehitulobomagi.dll
HKLM-Run-Ybosig - c:\windows\ehuqiqej.dll


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.theprizeday.com/today.php
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*https://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2009-06-29 13:51
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(844)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1704)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\S24EvMon.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\RegSrvc.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
c:\windows\system32\ati2evxx.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2009-06-29 13:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-29 18:53

Pre-Run: 24,911,687,680 bytes free
Post-Run: 26,914,095,104 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

216 --- E O F --- 2009-06-13 08:11
alanh is offline  
Old 06-29-2009, 12:40 PM   #6
Security Team
Analyst
 
Join Date: Jan 2009
Posts: 553
OS: Win98SE, XP Home SP3, Windows 7 64-bit



If you haven't already you need to install an Anti-Virus program ASAP on the computer. The longer the computer goes without an AV, the better its chances of being infected/reinfected.


Step # 1: Add/Remove Programs

Go to Start-Settings-Control Panel, click on Add Remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

Media Access Startup

PC Confidential 2008

System Search Dispatcher


Reboot your Computer.


Step # 2: Run CFScript

Please Note:

When ComboFix finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the script below, ComboFix will capture a file to submit for analysis.

Ensure you are connected to the internet and click OK on the message box.


  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    Code:
    https://www.techsupportforum.com/2214139-post5.html
    
    KILLALL::
    
    Collect::
    
    c:\windows\system32\drivers\UACsmnaxvmp.sys
    
    File::
    
    c:\windows\Klupakusadiyur.dat
    
    Folder::
    
    c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer
    c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup
    c:\program files\Media Access Startup
    c:\program files\Internet Saving Optimizer
    c:\program files\System Search Dispatcher
    c:\program files\DoubleD
    c:\program files\Winferno
    c:\program files\Free Offers from Freeze.com
    
    Registry::
    
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E38FA08E-F56A-4169-ABF5-5C71E3C153A1}]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.







    Note: This CFScript is for use on alanh's computer only! Do not use it on your computer.

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


In your next post/reply, I need to see the following:

1. The ComboFix Log that appears after Step 2 has been completed.
km2357 is offline  
Old 06-30-2009, 05:15 PM   #7
Registered Member
 
Join Date: Oct 2007
Location: Little Rock, AR
Posts: 67
OS: XP



ComboFix 09-06-29.07 - Kyrsti 06/30/2009 18:43.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.263 [GMT -5:00]
Running from: c:\documents and settings\Kyrsti\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Kyrsti\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

FILE ::
"c:\windows\Klupakusadiyur.dat"

file zipped: c:\windows\system32\drivers\UACsmnaxvmp.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\config.md
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\ipdata.md
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090615-012108.225.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090615-015821.787.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090615-173426.556.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090615-203434.394.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-004627.945.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-005345.104.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-005540.791.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-011553.777.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-121725.654.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-131554.900.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-153752.324.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-185942.685.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-194820.731.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-211808.959.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090616-222419.060.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090618-092348.907.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090618-133659.577.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090618-163655.077.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090618-163839.697.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090618-182026.423.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090618-182306.295.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090618-203429.023.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-112231.378.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-122719.810.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-131621.439.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-131958.088.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-132148.572.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-132322.167.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-132728.061.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-132927.523.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-133134.105.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090619-133237.095.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090620-163321.183.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090620-163332.750.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090620-202949.507.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090620-203215.859.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090620-223453.606.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090620-232923.656.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090621-003046.257.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090621-221418.431.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090621-221702.084.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090621-221810.726.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090621-221821.635.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090621-225001.315.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090622-181321.204.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090622-181326.141.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090622-235037.374.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090622-235517.005.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090622-235705.009.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090622-235711.780.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-101949.188.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-102121.189.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-102138.737.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-102211.080.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-104307.307.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-104427.534.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-104916.469.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-104950.874.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-113000.106.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-123106.757.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-135451.348.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-135541.359.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-135938.663.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-140117.620.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-140205.631.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-140740.470.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-140956.652.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-141010.933.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-142013.717.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-142756.842.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-143639.719.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-144824.777.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-162615.702.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-162907.669.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-163656.183.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-165111.303.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-165123.430.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-210847.299.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-211101.822.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-224400.915.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090623-225359.485.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090624-181336.786.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090624-183456.186.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090624-184138.895.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090624-185135.173.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090624-185452.707.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090624-185828.247.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090624-190853.486.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090624-191352.155.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090624-192114.341.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-003321.646.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-003357.859.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-003403.559.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-004357.871.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-004406.446.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-010007.032.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-010024.131.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-010846.243.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-011256.791.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-011725.167.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-012602.044.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-012957.709.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-015741.976.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-020227.170.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-020346.697.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-020709.291.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-021502.837.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-022004.318.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-022103.019.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-024025.783.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-031244.699.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090625-044402.819.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-221247.415.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-221803.440.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-230404.060.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-230535.111.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-230759.910.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-231046.229.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233029.080.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233148.434.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233205.638.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233359.853.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233606.395.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233702.075.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233738.707.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233759.297.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233825.204.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-233835.179.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-234156.660.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-234714.980.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090626-235735.552.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-000004.867.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-023820.231.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-024411.566.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-024700.819.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-025144.257.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-031800.781.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-031902.810.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-133133.359.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-133143.203.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-133459.606.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-133939.338.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-133953.859.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-135816.846.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-135856.623.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-140802.018.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-160825.880.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-165349.747.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-173126.460.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-173148.081.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-192643.348.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-193733.352.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-201325.603.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-203724.302.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-203915.526.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-204121.517.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-205720.756.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-205749.707.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090627-220606.663.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-010057.729.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-012850.444.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-013307.223.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-014937.533.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-015141.081.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-015537.030.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-132710.364.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-142626.948.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-142655.950.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-153405.684.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-154306.041.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-155455.501.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-160255.792.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-165023.286.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-173908.773.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-174008.279.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-174042.528.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-174254.628.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-174310.901.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-183713.053.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-192350.543.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-204314.393.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-213402.423.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-225533.536.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090628-232515.418.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-011228.358.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-030140.139.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-030851.730.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-033101.152.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-033149.782.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-114829.246.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-120707.925.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-120940.264.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-121901.481.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-122825.021.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-123018.634.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-133035.657.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-133156.934.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-133735.675.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-134156.119.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\NP_20090629-134509.427.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Internet Saving Optimizer\3.3.0.4160\rstatus.md
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\config.md
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090615-011639.659.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090615-012107.614.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090615-015821.557.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090615-173425.865.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090615-203434.233.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-004627.584.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-005344.382.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-005540.640.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-011553.517.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-121725.474.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-131554.520.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-153752.114.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-185942.425.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-194820.521.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-211808.819.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090616-222417.948.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090618-092348.706.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090618-133659.467.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090618-163654.866.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090618-163839.376.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090618-182025.331.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090618-182305.364.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090618-203428.673.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-112231.028.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-122719.609.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-131620.618.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-131954.432.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-132148.302.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-132321.986.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-132727.870.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-132927.503.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-133134.075.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090619-133237.075.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090620-163321.163.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090620-163332.730.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090620-202948.886.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090620-203215.688.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090620-223452.815.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090620-232923.626.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090621-003046.187.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090621-221418.410.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090621-221701.352.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090621-221810.676.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090621-221821.585.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090621-225001.155.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090622-181321.114.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090622-181326.091.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090622-235037.314.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090622-235516.023.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090622-235704.939.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090622-235711.750.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-101948.897.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-102121.128.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-102138.697.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-102209.938.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-104307.257.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-104427.494.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-104915.768.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-104950.854.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-112959.605.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-123106.517.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-135451.298.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-135541.339.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-135938.513.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-140117.550.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-140205.151.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-140740.419.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-140956.632.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-141010.913.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-142013.697.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-142756.792.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-143639.689.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-144824.757.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-162615.682.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-162907.639.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-163656.163.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-165111.223.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-165123.410.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-210846.758.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-211101.792.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-224400.694.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090623-225359.455.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090624-181336.766.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090624-183455.906.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090624-184138.815.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090624-185134.842.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090624-185452.687.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090624-185828.226.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090624-190853.456.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090624-191352.115.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090624-192114.281.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-003320.645.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-003357.829.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-003403.529.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-004357.841.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-004406.426.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-010007.002.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-010024.100.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-010846.153.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-011256.701.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-011725.137.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-012602.014.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-012957.679.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-015741.855.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-020226.219.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-020346.677.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-020708.720.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-021502.757.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-022004.298.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-022102.989.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-024025.673.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-031244.619.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090625-044402.789.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-221247.295.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-221803.420.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-230403.870.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-230534.941.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-230759.890.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-231046.209.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233029.050.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233148.394.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233205.618.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233359.823.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233606.375.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233702.055.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233738.687.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233759.277.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233825.184.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-233835.159.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-234155.709.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-234714.770.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090626-235735.522.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-000004.837.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-023820.181.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-024411.536.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-024700.789.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-025144.227.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-031800.661.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-031902.790.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-133133.339.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-133143.183.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-133459.586.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-133939.318.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-133953.769.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-135816.586.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-135856.593.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-140801.998.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-160825.850.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-165349.597.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-173126.430.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-173148.051.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-192643.328.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-193733.242.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-201325.403.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-203724.282.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-203915.486.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-204121.497.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-205720.656.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-205749.677.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090627-220606.643.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-010057.709.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-012850.394.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-013307.183.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-014937.513.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-015141.061.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-015537.010.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-132710.344.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-142626.928.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-142655.930.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-153405.584.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-154306.021.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-155455.401.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-160255.772.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-165023.266.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-173908.753.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-174008.258.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-174042.508.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-174254.587.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-174310.791.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-183713.023.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-192350.523.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-204314.373.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-213402.383.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-225533.486.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090628-232515.398.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-011228.338.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-030140.119.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-030851.670.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-033101.132.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-033149.761.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-114829.216.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-120707.594.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-120940.214.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-121901.441.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-122825.001.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-123018.614.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-133035.617.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-133156.914.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-133735.655.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-134156.089.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090629-134509.407.log
c:\documents and settings\Kyrsti\Local Settings\Application Data\Media Access Startup\1.3.0.790\HJHP_20090630-141331.561.log
c:\program files\DoubleD
c:\program files\Free Offers from Freeze.com
c:\program files\Free Offers from Freeze.com\101_Free_Songs.ico
c:\program files\Free Offers from Freeze.com\3715.url
c:\program files\Free Offers from Freeze.com\3770.url
c:\program files\Free Offers from Freeze.com\4115.url
c:\program files\Free Offers from Freeze.com\4294.url
c:\program files\Free Offers from Freeze.com\5008.url
c:\program files\Free Offers from Freeze.com\control.txt
c:\program files\Free Offers from Freeze.com\dolphinico.ico
c:\program files\Free Offers from Freeze.com\games_icon2.ico
c:\program files\Free Offers from Freeze.com\help_icon.ico
c:\program files\Free Offers from Freeze.com\wfallsaw.ico
c:\program files\Internet Saving Optimizer
c:\program files\Internet Saving Optimizer\3.3.0.4160\adwpx.exe
c:\program files\Internet Saving Optimizer\3.3.0.4160\Data\config.md
c:\program files\Internet Saving Optimizer\3.3.0.4160\FF\chrome.manifest
c:\program files\Internet Saving Optimizer\3.3.0.4160\FF\chrome\content\NPAddOn.js
c:\program files\Internet Saving Optimizer\3.3.0.4160\FF\chrome\content\NPAddOn.xul
c:\program files\Internet Saving Optimizer\3.3.0.4160\FF\chrome\NPAddOn.jar
c:\program files\Internet Saving Optimizer\3.3.0.4160\FF\components\NPFFAddOn.dll
c:\program files\Internet Saving Optimizer\3.3.0.4160\FF\components\NPFFAddOn.xpt
c:\program files\Internet Saving Optimizer\3.3.0.4160\FF\components\NPFFHelperComponent.js
c:\program files\Internet Saving Optimizer\3.3.0.4160\FF\install.rdf
c:\program files\Internet Saving Optimizer\3.3.0.4160\NPCommon.dll
c:\program files\Internet Saving Optimizer\3.3.0.4160\NPIEAddOn.dll
c:\program files\Internet Saving Optimizer\3.3.0.4160\unins000.dat
c:\program files\Internet Saving Optimizer\3.3.0.4160\unins000.exe
c:\program files\Winferno
c:\windows\Klupakusadiyur.dat
c:\windows\system32\drivers\UACsmnaxvmp.sys

.
((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-30 )))))))))))))))))))))))))))))))
.

2009-06-30 23:31 . 2009-03-30 15:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-30 23:31 . 2009-03-24 21:08 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-30 23:31 . 2009-02-13 17:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-30 23:31 . 2009-02-13 17:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-30 23:31 . 2009-06-30 23:31 -------- d-----w- c:\program files\Avira
2009-06-30 23:31 . 2009-06-30 23:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-15 06:14 . 2009-06-15 06:14 -------- d-----w- c:\documents and settings\Kyrsti\Local Settings\Application Data\DoubleD
2009-06-15 05:15 . 2009-04-24 13:59 2472608 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\setupHRF10_90_SP1.exe
2009-06-15 05:14 . 2009-06-15 05:14 -------- d-----w- c:\program files\Horse Racing Simulation LLC
2009-06-15 05:14 . 2009-06-15 05:14 -------- d-----w- c:\documents and settings\Kyrsti\Application Data\Hrsim
2009-06-15 05:12 . 2009-06-15 05:15 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}
2009-06-15 05:12 . 2009-01-26 15:21 307200 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\3B02A30E\8A52B4FB\HRFviewer.dll
2009-06-15 05:12 . 2008-03-19 23:29 348160 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\F05AD411\9CD9520D\MSVCR71.dll
2009-06-15 05:12 . 2008-02-21 18:11 2117632 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\8B346739\9CD9520D\python25.dll
2009-06-15 05:12 . 2008-01-21 18:21 212992 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\F788288E\4C18FEA5\imagetools.dll
2009-06-15 05:12 . 2009-04-23 13:13 1634304 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\DB7BDDA5\F06B4927\Hrace.exe
2009-06-15 05:12 . 2009-04-21 09:30 3002368 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\B65A4737\F06B4927\Hrfanwin.exe
2009-06-15 05:12 . 2009-02-04 03:44 39936 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\5D6606E9\258FB427\HRGcomm.exe
2009-06-15 05:12 . 2009-01-21 08:59 16896 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\E430A951\9CD9520D\web.exe
2009-06-15 05:12 . 2009-01-17 04:07 28672 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\669E12EA\4C18FEA5\SilksApp.exe
2009-06-15 05:12 . 2008-04-16 13:15 1077248 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\DFBB026D\4C18FEA5\HorseRaceAtl.exe
2009-06-15 05:12 . 2007-11-08 04:43 73728 -c--a-w- c:\documents and settings\All Users\Application Data\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}\OFFLINE\6831DB05\4C18FEA5\FileChecker.exe
2009-06-07 17:13 . 2009-06-07 17:13 -------- d-----w- c:\documents and settings\Kyrsti\.thumb
2009-06-07 17:07 . 2009-06-27 03:17 -------- d-----w- c:\program files\Xobni
2009-06-07 17:05 . 2009-06-07 17:05 -------- d-----w- c:\documents and settings\Kyrsti\Application Data\blinkx
2009-06-07 17:04 . 2009-02-18 22:38 577536 ----a-w- c:\windows\system32\VibeFire.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-30 23:08 . 2009-04-17 12:40 -------- d-----w- c:\program files\iTunes
2009-06-15 06:16 . 2008-10-18 18:18 43336 ----a-w- c:\documents and settings\Kyrsti\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-07 15:32 . 2004-08-04 12:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-29 04:56 . 2004-08-04 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-23 13:13 . 2009-04-23 13:13 1634304 ----a-w- c:\documents and settings\Kyrsti\Application Data\Hrsim\Hrfan\Hrace.exe
2009-04-21 09:30 . 2009-04-21 09:30 3002368 ----a-w- c:\documents and settings\Kyrsti\Application Data\Hrsim\Hrfan\Hrfanwin.exe
2009-04-17 12:26 . 2004-08-04 12:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-17 12:19 . 2009-04-17 12:19 75048 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-15 14:51 . 2004-08-04 12:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.

((((((((((((((((((((((((((((( [email protected]_18.51.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 07:19 . 2007-11-07 07:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 11:07 . 2008-07-29 11:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 11:07 . 2008-07-29 11:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2009-06-30 23:49 . 2009-06-30 23:49 16384 c:\windows\temp\Perflib_Perfdata_8c.dat
+ 2009-06-30 23:50 . 2009-06-30 23:50 16384 c:\windows\temp\Perflib_Perfdata_278.dat
+ 2009-06-30 23:31 . 2009-05-11 15:12 28520 c:\windows\system32\drivers\ssmdrv.sys
+ 2008-07-29 13:05 . 2008-07-29 13:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 08:54 . 2008-07-29 08:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 13:05 . 2008-07-29 13:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-02-11 801904]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-02-20 4363504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2007-02-07 344064]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-06-24 126976]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-06-24 561152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-23 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2003-06-27 88363]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"&#37;windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\WolfQuest\\WolfQuest.exe"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/30/2009 6:31 PM 108289]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - GTNDIS5
*NewlyCreated* - SSMDRV
.
Contents of the 'Scheduled Tasks' folder

2009-06-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-06-30 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-12 03:18]
.
- - - - ORPHANS REMOVED - - - -

BHO-{E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.theprizeday.com/today.php
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*https://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, https://www.gmer.net
Rootkit scan 2009-06-30 18:50
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(852)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3184)
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\S24EvMon.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\RegSrvc.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
c:\windows\system32\ati2evxx.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-06-30 18:53 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-30 23:53
ComboFix2.txt 2009-06-30 19:25
ComboFix3.txt 2009-06-29 18:53

Pre-Run: 26,708,307,968 bytes free
Post-Run: 26,739,027,968 bytes free

621 --- E O F --- 2009-06-13 08:11
alanh is offline  
Old 06-30-2009, 10:35 PM   #8
Security Team
Analyst
 
Join Date: Jan 2009
Posts: 553
OS: Win98SE, XP Home SP3, Windows 7 64-bit



Step # 1 Update Java

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.

Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u14.
  • Click on the link to download Windows Offline Installation and save to your desktop. Do NOT use the Sun Download Manager.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Remove the following old versions of Java:

  • Java(TM) 6 Update 12

  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • From your desktop double-click on the download to install the newest version.


Step # 2: Download and Run ATF Cleaner
Download ATF (Atribune Temp File) Cleanerę by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it.

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Step # 3 Download and Run Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
km2357 is offline  
Old 07-02-2009, 10:20 PM   #9
Registered Member
 
Join Date: Oct 2007
Location: Little Rock, AR
Posts: 67
OS: XP



Malwarebytes' Anti-Malware 1.38
Database version: 2366
Windows 5.1.2600 Service Pack 3

7/3/2009 12:18:41 AM
mbam-log-2009-07-03 (00-18-41).txt

Scan type: Quick Scan
Objects scanned: 83972
Time elapsed: 8 minute(s), 49 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 18
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
alanh is offline  
Old 07-03-2009, 12:14 PM   #10
Security Team
Analyst
 
Join Date: Jan 2009
Posts: 553
OS: Win98SE, XP Home SP3, Windows 7 64-bit



Step # 1 Update Adobe Acrobat Reader

There is a newer version of Adobe Acrobat Reader available. (See Note below)
  • First, go to Add/Remove Programs and uninstall all previous versions.
  • Please go to this link Adobe Acrobat Reader Download Link
  • On the right Untick Adobe Phototshop Album Starter Edition if you do not wish to include this in the installation.
  • Click the Continue button
  • Click Run, and click Run again
  • Next click the Install Now button and follow the on screen prompts

Note: Adobe 9.1.2 is a large program and if you prefer a smaller program you can get Foxit 3.0 instead from https://www.foxitsoftware.com/pdf/rd_intro.php

If you decide to install Foxit 3.0 instead of Adobe, do the following during Foxit's Setup/Installation process:

Uncheck the following boxes:

I accept the License Terms and want to install Foxit Toolbar

Make Ask.com my default search

Create desktop, quick launch and start menu icon to eBay



Step # 2: Run Kaspersky Online Scan

Please go to Kaspersky website and perform an online antivirus scan.
  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  5. Click on My Computer under Scan.
  6. Once the scan is complete, it will display the results. Click on View Scan Report.
  7. You will see a list of infected items there. Click on Save Report As....
  8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  9. Please post this log in your next reply.


In your next post/reply, I need to see the following:

1. Kaspersky Log
2. A fresh DDS Log
3. How is your computer doing, any problems?
km2357 is offline  
Old 07-03-2009, 11:27 PM   #11
Registered Member
 
Join Date: Oct 2007
Location: Little Rock, AR
Posts: 67
OS: XP



--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
Saturday, July 4, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Saturday, July 04, 2009 04:00:07
Records in database: 2424556
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 38068
Threat name: 10
Infected objects: 22
Suspicious objects: 0
Duration of the scan: 00:57:21


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\Hlehitulobomagi.dll.vir Infected: Trojan-Downloader.Win32.Agent.bpel 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACdujwqbit.dll.vir Infected: Packed.Win32.Tdss.h 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACfqxotfqr.dll.vir Infected: Packed.Win32.Tdss.h 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACheexnqcn.dll.vir Infected: Packed.Win32.Tdss.h 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACracbfprb.dll.vir Infected: Packed.Win32.Tdss.h 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACxfpapeil.dll.vir Infected: Packed.Win32.Tdss.h 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP45\A0094064.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.et 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP45\A0094066.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ew 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP45\A0094079.DLL Infected: not-a-virus:Monitor.Win32.Agent.c 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP45\A0094083.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ax 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP45\A0094092.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.cl 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP45\A0094094.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ff 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP46\A0094969.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.eu 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP53\A0117250.exe Infected: Trojan-GameThief.Win32.OnLineGames.blui 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP53\A0117258.dll Infected: Trojan-GameThief.Win32.OnLineGames.blui 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP53\A0117259.dll Infected: Trojan-GameThief.Win32.OnLineGames.blui 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP53\A0117302.dll Infected: Trojan-Downloader.Win32.Agent.bpel 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP53\A0117305.dll Infected: Packed.Win32.Tdss.h 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP53\A0117306.dll Infected: Packed.Win32.Tdss.h 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP53\A0117307.dll Infected: Packed.Win32.Tdss.h 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP53\A0117309.dll Infected: Packed.Win32.Tdss.h 1
C:\System Volume Information\_restore{FE06B6A5-B760-47E0-B254-72BAA8153EFC}\RP53\A0117310.dll Infected: Packed.Win32.Tdss.h 1

The selected area was scanned.



DDS (Ver_09-06-26.01) - NTFSx86
Run by Kyrsti at 23:12:40.63 on Fri 06/26/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.143 [GMT -5:00]


============== Running Processes ===============

C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\All Users\Application Data\KwinzySearch\kwinzy123.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\RelevantKnowledge\rlvknlg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\KwinzySearch\kwinzy.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Gamevance\gamevance32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\VoloMedia\VoloMedia Service\VoloMediaService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\The Weather Channel FW\Desktop\DesktopWeather.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\MSN\Toolbar\3.0.1125.0\msntask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Kyrsti\Local Settings\Temporary Internet Files\Content.IE5\9G087ZS1\dds[1].scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.theprizeday.com/today.php
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*https://www.yahoo.com
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*https://www.yahoo.com/ext/search/search.html
mDefault_Page_URL = hxxp://www.yahoo.com/
mDefault_Search_URL = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://www.yahoo.com
mSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*https://www.yahoo.com
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*https://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://www.yahoo.com
mSearchAssistant = hxxp://www.crawler.com/search/ie.aspx?tb_id=60315
mCustomizeSearch = hxxp://dnl.crawler.com/support/sa_customize.aspx?TbId=60315
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uURLSearchHooks: NetAssistantBHO Class: {e38fa08e-f56a-4169-abf5-5c71e3c153a1} - c:\program files\my.freeze.com toolbar\NetAssistant.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Gamevance: {0ed403e8-470a-4a8a-85a4-d7688cfe39a3} - c:\program files\gamevance\gamevancelib32.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: PCCBHO.CPCCBHO: {22fc6ce8-7d47-479f-b74a-bfbb04adb9af} - c:\program files\winferno\pc confidential\PCCBHO.dll
BHO: Media Access Startup: {25b8d58c-b0cb-46b0-ba64-05b3804e4e86} - c:\program files\media access startup\1.3.0.790\HPIEAddOn.dll
BHO: NP Helper Class: {35b8d58c-b0cb-46b0-ba64-05b3804e4e86} - c:\program files\internet saving optimizer\3.3.0.4160\NPIEAddOn.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: System Search Dispatcher: {cdbfb47b-58a8-4111-bf95-06178dce326d} - c:\program files\system search dispatcher\1.2.0.750\ssd.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: NetAssistantBHO Class: {e38fa08e-f56a-4169-abf5-5c71e3c153a1} - c:\program files\my.freeze.com toolbar\NetAssistant.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: Gamevance class: {f02fabcb-92dd-475a-98af-14217bd50746} - c:\program files\gamevance\gvtl.dll
BHO: XBTBPos00 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\my.freeze.com toolbar\freeze_us.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1125.0\msneshellx.dll
TB: My.Freeze.com Toolbar: {d0523bb4-21e7-11dd-9ab7-415b56d89593} - c:\program files\my.freeze.com toolbar\freeze_us.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {98279C38-DE4B-4BCF-93C9-8EC26069D6F4} - No File
TB: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [VibeFireAlerts]
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Gamevance] c:\program files\gamevance\gamevance32.exe a
mRun: [Ajirogis] rundll32.exe "c:\windows\Hlehitulobomagi.dll",e
mRun: [Ybosig] rundll32.exe "c:\windows\ehuqiqej.dll",e
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [VoloMedia Service] "c:\program files\volomedia\volomedia service\VoloMediaService.exe"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA} - c:\program files\winferno\pc confidential\PCConfidential.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_12-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
Notify: RelevantKnowledge - c:\program files\relevantknowledge\rlls.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R2 KwinzySearch Service;KwinzySearch Service;c:\documents and settings\all users\application data\kwinzysearch\kwinzy123.exe [2009-6-18 54760]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-1-14 226656]
R2 WUSB54GSv2SVC;WUSB54GSv2SVC;c:\program files\linksys wireless-g usb wireless network monitor\WLService.exe [2008-10-18 41025]

=============== Created Last 30 ================

2009-06-18 14:35 <DIR> --d----- c:\program files\KwinzySearch
2009-06-18 14:35 <DIR> --d----- c:\docume~1\alluse~1\applic~1\KwinzySearch
2009-06-15 01:16 <DIR> --d----- c:\program files\Media Access Startup
2009-06-15 01:16 <DIR> --d----- c:\program files\Internet Saving Optimizer
2009-06-15 01:16 <DIR> --d----- c:\program files\System Search Dispatcher
2009-06-15 01:15 <DIR> --d----- c:\program files\DoubleD
2009-06-15 00:14 <DIR> --d----- c:\program files\Horse Racing Simulation LLC
2009-06-15 00:14 <DIR> --d----- c:\docume~1\kyrsti\applic~1\Hrsim
2009-06-15 00:12 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}
2009-06-07 12:13 <DIR> --d----- c:\documents and settings\kyrsti\.thumb
2009-06-07 12:07 <DIR> --d----- c:\program files\Xobni
2009-06-07 12:05 <DIR> --d----- c:\docume~1\kyrsti\applic~1\blinkx
2009-06-07 12:05 <DIR> --d----- c:\program files\RelevantKnowledge
2009-06-07 12:04 577,536 a------- c:\windows\system32\VibeFire.dll

==================== Find3M ====================

2009-06-13 03:11 51,200 -------- c:\windows\system32\drivers\UACsmnaxvmp.sys
2009-06-12 23:13 5,746 a------- c:\windows\system32\uacinit.dll
2009-05-07 10:32 345,600 a------- c:\windows\system32\localspl.dll
2009-04-28 23:56 827,392 a------- c:\windows\system32\wininet.dll
2009-04-28 23:55 78,336 a------- c:\windows\system32\ieencode.dll
2009-04-17 07:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 09:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2009-04-06 11:19 66,560 a------- c:\windows\system32\UACxfpapeil.dll
2009-04-06 11:19 19,456 -------- c:\windows\system32\UACdujwqbit.dll
2009-04-06 11:19 17,408 a------- c:\windows\system32\UACracbfprb.dll
2009-04-06 11:19 20,480 a------- c:\windows\system32\UACheexnqcn.dll
2009-04-06 11:19 24,064 a------- c:\windows\system32\UACfqxotfqr.dll
2008-10-18 14:20 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101820081019\index.dat

============= FINISH: 23:13:15.87 ===============




The pop-ups have pretty much stopped but the internet crashes a lot more. It's a wireless internet connected to the desktop we have and its always crashed a lot but its started crashing more that usual lately.
alanh is offline  
Old 07-04-2009, 10:54 AM   #12
Security Team
Analyst
 
Join Date: Jan 2009
Posts: 553
OS: Win98SE, XP Home SP3, Windows 7 64-bit



Kaspersky found files in the Qoobox folder which is where ComboFix keeps its quarantined files. I'll show you how to remove those in an upcoming post. Kaspersky also found some infected System Restore points. They are harmless where they are. I'll show you how to remove them and set up a new, clean one in an upcoming post.

The DDS log you posted is an old one (from Fri 06/26/2009). Please run DDS again and post a new log.

Regarding the internet crashing, when did it start? Did it start before the computer got infected? Before you came to Tech Support Forum looking for help?
km2357 is offline  
Old 07-04-2009, 06:32 PM   #13
Registered Member
 
Join Date: Oct 2007
Location: Little Rock, AR
Posts: 67
OS: XP



DDS (Ver_09-06-26.01) - NTFSx86
Run by Kyrsti at 20:29:37.24 on Sat 07/04/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.511.230 [GMT -5:00]

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\S24EvMon.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\RegSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GSv2.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Kyrsti\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*https://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*https://www.yahoo.com
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - No File
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: XBTBPos00 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files\my.freeze.com toolbar\freeze_us.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: My.Freeze.com Toolbar: {d0523bb4-21e7-11dd-9ab7-415b56d89593} - c:\program files\my.freeze.com toolbar\freeze_us.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [DW6] "c:\program files\the weather channel fw\desktop\DesktopWeather.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [AROReminder] c:\program files\advanced registry optimizer\ARO.exe -rem
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {53F6FCCD-9E22-4d71-86EA-6E43136192AB}
IE: {925DAB62-F9AC-4221-806A-057BFB1014AA}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-6-30 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-6-30 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-6-30 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-6-30 55640]
R2 WUSB54GSv2SVC;WUSB54GSv2SVC;c:\program files\linksys wireless-g usb wireless network monitor\WLService.exe [2008-10-18 41025]

=============== Created Last 30 ================

2009-07-03 00:07 <DIR> --d----- c:\docume~1\kyrsti\applic~1\Malwarebytes
2009-07-03 00:07 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-03 00:07 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-03 00:07 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-03 00:07 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-02 20:40 <DIR> --d----- c:\docume~1\kyrsti\applic~1\Sammsoft
2009-07-02 20:39 <DIR> --d----- c:\program files\Advanced Registry Optimizer
2009-06-30 18:41 <DIR> --ds---- C:\Combo-Fix
2009-06-30 18:31 55,640 a------- c:\windows\system32\drivers\avgntflt.sys
2009-06-30 18:31 <DIR> --d----- c:\program files\Avira
2009-06-30 18:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Avira
2009-06-30 18:08 <DIR> --d----- c:\windows\system32\appmgmt
2009-06-29 13:52 <DIR> -cd----- c:\windows\system32\dllcache\cache
2009-06-29 13:43 <DIR> a-dshr-- C:\cmdcons
2009-06-29 13:41 161,792 a------- c:\windows\SWREG.exe
2009-06-29 13:41 155,136 a------- c:\windows\PEV.exe
2009-06-29 13:41 98,816 a------- c:\windows\sed.exe
2009-06-15 00:14 <DIR> --d----- c:\program files\Horse Racing Simulation LLC
2009-06-15 00:14 <DIR> --d----- c:\docume~1\kyrsti\applic~1\Hrsim
2009-06-15 00:12 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{BE392D1F-8E1A-4ADC-B870-EE9435B5CC6C}
2009-06-07 12:13 <DIR> --d----- c:\documents and settings\kyrsti\.thumb
2009-06-07 12:07 <DIR> --d----- c:\program files\Xobni
2009-06-07 12:05 <DIR> --d----- c:\docume~1\kyrsti\applic~1\blinkx
2009-06-07 12:04 577,536 a------- c:\windows\system32\VibeFire.dll

==================== Find3M ====================

2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-07 10:32 345,600 a------- c:\windows\system32\localspl.dll
2009-04-28 23:56 827,392 a------- c:\windows\system32\wininet.dll
2009-04-28 23:55 78,336 a------- c:\windows\system32\ieencode.dll
2009-04-17 07:26 1,847,168 a------- c:\windows\system32\win32k.sys
2009-04-15 09:51 585,216 a------- c:\windows\system32\rpcrt4.dll
2008-10-18 14:20 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101820081019\index.dat

============= FINISH: 20:30:06.67 ===============



The internet worked perfectly for a little while then it started crashing. It crashes usually when its moved. It crashed once and we had to install a new wireless internet that doesn't have as good a signal.
alanh is offline  
Old 07-04-2009, 09:59 PM   #14
Security Team
Analyst
 
Join Date: Jan 2009
Posts: 553
OS: Win98SE, XP Home SP3, Windows 7 64-bit



Quote:
It crashes usually when its moved.
By "Its" I assume you mean your internet crashes when your wireless router/modem is physically moved? That sounds more like a hardware problem, then a malware problem. If that is the case, it'd be best to post a thread in the Networking Support section of Tech Support Forum and explain to them why your Internet is crashing. They'd be better equipped than I to help you solve your problem.

Since you reported that the pop-ups have stopped and your problem appears to be non-malware related, I'll go ahead and have you do a final clean up and give you some tips to help keep the computer clean in the future.


To remove ComboFix, do the following:

Go to Start > Run - type in ComboFix /u & click OK


Empty your Recycle Bin.


Please follow these simple steps in order to keep your computer clean and secure:

This is a good time to clear your existing system restore points and establish a new clean restore point
  • Go to Start > All Programs > Accessories > System Tools > System Restore
  • Select Create a restore point, and Ok it.
  • Next, go to Start > Run and type in cleanmgr
  • Make sure the C:\ drive is selected and click OK. If your computer's Hard Drive is not located on C:, change it to the correct drive letter then click OK.
  • Select the More options tab
  • Choose the option to clean up system restore and OK it.
  • This will remove all restore points except the new one you just created.
.

Clearing your restore points is not something you should do on a regular basis. Normally, this process only needs to be done after clearing out an infestation of malware.


Make your Internet Explorer more secure This can be done by following these simple instructions:
  1. From within Internet Explorer click on the Tools menu and then click on Options.
  2. Click once on the Security tab
  3. Click once on the Internet icon so it becomes highlighted.
  4. Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub frames across different domains to Prompt
  5. When all these settings have been made, click on the OK button.
  6. If it asks you if you want to save the settings, press the Yes button.
  7. Next press the Apply button and then the OK to exit the Internet Properties page.
Set correct settings for files that should be hidden in Windows XP
  • Click Start > My Computer > Tools menu (at top of page) > Folder Options > View tab.
  • Under "Hidden files and folders" if necessary select Do not show hidden files and folders.
  • If unchecked please checkHide protected operating system files (Recommended)
  • If necessary check "Display content of system folders"
  • If necessary Uncheck Hide file extensions for known file types.
  • Click OK
  • Use An Antivirus Software and Keep It Updated - It is very important that your computer has an antivirus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperative that you update your antivirus software at least once a day. If you do not update your antivirus software, then it will not be able to catch any of the new variants that may come out.
  • Visit Microsoft's Update Site Frequently It is important that you visit Microsoft Updates regularly. This will ensure your computer has the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install SpywareBlaster SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line Anti Malware
  • Use the hosts file: Every version of windows has a hosts file as part of them. In a very basic sense, they are used to locate web pages. We can customize a hosts file so that it blocks certain web pages. However, it can slow down certain computers. This is why using a hosts file is optional. Download mvps hosts file Make sure you read the instructions on how to install the hosts file. There is a good tutorial HERE If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    1. Click the start button on the task bar at the bottom of your screen
    2. Click run
    3. In the dialog box, type services.msc
    4. hit enter, then locate dns client
    5. Highlight it, then doubleclick it.
    6. On the dropdown box, change the setting from automatic to manual.
    7. Click ok..
  • Use an alternative instant messenger program.Trillian and Miranda IM These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)
  • Please read Tony Klein's excellent article: How I got Infected in the First Place
  • Please read Understanding Spyware, Browser Hijackers, and Dialers
  • Please read Simple and easy ways to keep your computer safe and secure on the Internet
  • If you are using Internet Explorer, please consider using an alternate browser: Mozilla's Firefox or
    Opera.
    If you decide to use either FireFox or Opera, it is very important that you keep them up to date and check frequently for updates of the browser of your choice.
  • Update all these programs regularly Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
  • If your computer was infected by a website, a program, IM, MSN, or p2p, check this site because it is Time To Fight Back.
Follow these steps and your potential for being infected again will reduce dramatically.

Here's a good website to read about Malware prevention:

https://users.telenet.be/bluepatchy/m...revention.html

If your computer is running slow, click here for instructions on how to help speed up your computer.

Good luck!

Please reply one last time so that I know you have read my post and this thread can be closed.
km2357 is offline  
Old 07-05-2009, 03:03 AM   #15
Registered Member
 
Join Date: Oct 2007
Location: Little Rock, AR
Posts: 67
OS: XP



Thanks for all your help. I think I got it all right.
alanh is offline  
Old 07-06-2009, 12:27 AM   #16
Security Team
Analyst
 
Join Date: Jan 2009
Posts: 553
OS: Win98SE, XP Home SP3, Windows 7 64-bit



You're welcome. I'm glad I was able to help you out.

Good luck and safe surfing!
km2357 is offline  
 

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Post a Question


» Site Navigation
 > FAQ
  > 10.0.0.2
Powered by vBadvanced CMPS v3.2.3


All times are GMT -7. The time now is 01:26 PM.


Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2020, vBulletin Solutions, Inc.
vBulletin Security provided by vBSecurity v2.2.2 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
User Alert System provided by Advanced User Tagging v3.1.0 (Pro) - vBulletin Mods & Addons Copyright © 2020 DragonByte Technologies Ltd.
Copyright 2001 - 2018, Tech Support Forum

Windows 10 - Windows 7 - Windows XP - Windows Vista - Trojan Removal - Spyware Removal - Virus Removal - Networking - Security - Top Web Hosts