---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 2:19:17 PM 12/26/2006
+ Scan result:
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA0D26BD-9029-431A-86E0-83152D67828A} -> Adware.180Solutions : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA0D26BD-9029-431A-86E0-83152D67828A} -> Adware.180Solutions : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dtxfeoeg.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ehfslqbn.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\psmixsyu.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\scnojooc.exe -> Adware.Searchcolor : Cleaned with backup (quarantined).
HKU\S-1-5-21-3262279746-2724449815-732588747-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CA356D79-679B-4B4C-8E49-5AF97014F4C1} -> Adware.Starware : Cleaned with backup (quarantined).
HKU\S-1-5-21-3262279746-2724449815-732588747-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D49E9D35-254C-4C6A-9D17-95018D228FF5} -> Adware.Starware : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\AppID\{4F5E5D72-C915-4f3b-908B-527D064B0FAA} -> Adware.SysProtect : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{EF130E77-0A34-4365-BFB7-218FD3DDCD5F} -> Adware.SysProtect : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\Interface\{02946FD1-2D99-46E6-A790-3A089714EDD9} -> Adware.SysProtect : Cleaned with backup (quarantined).
HKU\S-1-5-21-3262279746-2724449815-732588747-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Cleaned with backup (quarantined).
C:\Documents and Settings\Justin\Application Data\sysprotectscannerinstall[1].exe -> Downloader.Agent.alr : Cleaned with backup (quarantined).
C:\Program Files\Common Files\kuwq\kuwqd\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected]r[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Emily\Cookies\
[email protected][3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][2].txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][2].txt -> TrackingCookie.Onestat : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][2].txt -> TrackingCookie.Searchingbooth : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][1].txt -> TrackingCookie.Top-banners : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Wendy\Cookies\
[email protected][2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Emily\Cookies\
[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Justin\Cookies\
[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\LocalService\Cookies\
[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt -> TrackingCookie.Zedo : Cleaned.
::Report end
Incident Status Location
Spyware:spyware/media-motor Not disinfected Windows Registry
Adware:adware/sqwire Not disinfected Windows Registry
Potentially unwanted tool:application/sysprotect Not disinfected hkey_local_machine\software\classes\CheckProd.CheckProduct
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Dad\Cookies\
[email protected][2].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Dad\Cookies\
[email protected][1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Dad\Desktop\SDFix.exe[SDFix\apps\Process.exe]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Emily\Cookies\
[email protected][2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Emily\Cookies\
[email protected][1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Justin\Cookies\
[email protected][1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Justin\Cookies\
[email protected][1].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Justin\Cookies\
[email protected][1].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Justin\Cookies\
[email protected][1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Justin\Cookies\
[email protected][2].txt
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Justin\Local Settings\Temp\gahgsyof.dll
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\LocalService\Cookies\
[email protected][1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\LocalService\Cookies\
[email protected][1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][2].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Melissa\Cookies\
[email protected][2].txt
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\agfimmeu.exe
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\Cookies\
[email protected][1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\Cookies\
[email protected][2].txt
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\Cookies\
[email protected][2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\Cookies\
[email protected][1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\Cookies\
[email protected][2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\Cookies\
[email protected][2].txt
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\cyyfhokv.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\ijnvksuc.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\jhnbmabf.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\lngivilx.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\loogilfm.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\ojsjahho.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\oxumdcje.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\papgnasf.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\qyebpifg.exe
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\Documents and Settings\Melissa\Local Settings\Temp\wqfwjdwj.exe
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Wendy\Cookies\
[email protected][2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Wendy\Cookies\
[email protected][1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Wendy\Cookies\
[email protected][2].txt
Spyware:Cookie/Advertising Not disinfected C:\RECYCLER\NPROTECT\00052239.TXT
Spyware:Cookie/Adrevolver Not disinfected C:\RECYCLER\NPROTECT\00052240.TXT
Spyware:Cookie/Adrevolver Not disinfected C:\RECYCLER\NPROTECT\00052241.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052247.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052248.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052249.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052250.TXT
Spyware:Cookie/Adrevolver Not disinfected C:\RECYCLER\NPROTECT\00052331.TXT
Spyware:Cookie/Adrevolver Not disinfected C:\RECYCLER\NPROTECT\00052332.TXT
Spyware:Cookie/Advertising Not disinfected C:\RECYCLER\NPROTECT\00052333.TXT
Spyware:Cookie/RealMedia Not disinfected C:\RECYCLER\NPROTECT\00052342.TXT
Spyware:Cookie/Advertising Not disinfected C:\RECYCLER\NPROTECT\00052343.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052349.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052350.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052351.TXT
Spyware:Cookie/FastClick Not disinfected C:\RECYCLER\NPROTECT\00052359.TXT
Spyware:Cookie/FastClick Not disinfected C:\RECYCLER\NPROTECT\00052360.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052366.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052397.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052398.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052399.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052419.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052420.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052421.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052422.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052434.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052435.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052436.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052437.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052445.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052455.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052464.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052470.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052471.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052472.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052489.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052490.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052491.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052492.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052497.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052516.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052567.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052568.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052569.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052570.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052571.TXT
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\NPROTECT\00052572.TXT
Spyware:Cookie/Advertising Not disinfected C:\RECYCLER\NPROTECT\00052576.TXT
Spyware:Cookie/2o7 Not disinfected C:\RECYCLER\NPROTECT\00053573.TXT
Spyware:Cookie/2o7 Not disinfected C:\RECYCLER\NPROTECT\00053574.TXT
Spyware:Cookie/2o7 Not disinfected C:\RECYCLER\NPROTECT\00053575.TXT
Spyware:Cookie/2o7 Not disinfected C:\RECYCLER\NPROTECT\00053612.TXT
Spyware:Cookie/2o7 Not disinfected C:\RECYCLER\NPROTECT\00053613.TXT
Spyware:Cookie/2o7 Not disinfected C:\RECYCLER\NPROTECT\00053614.TXT
Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe
Adware:Adware/AdwareShooter Not disinfected C:\WINDOWS\system\paars.dll
Adware:Adware/WebSearch Not disinfected C:\WINDOWS\system32\enayqkjq.dll
Potentially unwanted tool:Application/VSToolbar Not disinfected C:\WINDOWS\system32\twcqxplw.exe
"Dad" - 06-12-27 13:08:40.84 Service Pack 2
ComboFix 06-12-23W-BetaE2 - Running from: "C:\Documents and Settings\Dad\Desktop"
((((((((((((((((((((((((((((((( Files Created from 2006-11-27 to 2006-12-27 ))))))))))))))))))))))))))))))))))
2006-12-26 14:23 <DIR> d-------- C:\bintheredunthat
2006-12-24 14:18 <DIR> d-------- C:\bfu
2006-12-24 13:58 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-12-24 13:57 <DIR> d-------- C:\Program Files\Grisoft
2006-12-24 07:20 <DIR> d-------- C:\WINDOWS\erdnt
2006-12-24 00:03 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2006-12-23 23:56 <DIR> d-------- C:\Program Files\Common Files\Java
2006-12-23 18:52 <DIR> d-------- C:\SDFix
2006-12-21 22:14 <DIR> d-------- C:\hijackthis
2006-12-21 21:45 <DIR> d-------- C:\DOCUME~1\Wendy\APPLIC~1\Template
2006-12-21 19:51 <DIR> d-------- C:\DOCUME~1\ADMINI~1\WINDOWS
2006-12-21 19:51 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver
2006-12-21 19:51 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2006-12-21 19:51 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
2006-12-21 19:51 <DIR> d-------- C:\DOCUME~1\ADMINI~1\APPLIC~1\CyberLink
2006-12-21 19:36 <DIR> d---s---- C:\DOCUME~1\Wendy\UserData
2006-12-17 17:06 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2006-12-16 19:07 <DIR> d-------- C:\WINDOWS\McAfee.com
2006-12-14 21:31 118,804 --a------ C:\WINDOWS\system32\mscirpqb.dll
2006-12-13 18:17 <DIR> d-------- C:\DOCUME~1\Dad\Shared
2006-12-13 18:17 <DIR> d-------- C:\DOCUME~1\Dad\Incomplete
2006-12-13 18:16 <DIR> d-------- C:\Program Files\LimeWire
2006-12-13 18:06 <DIR> d-------- C:\DOCUME~1\Dad\.limewire
2006-12-04 19:40 5,968 --a------ C:\WINDOWSvundofix.reg
2006-12-04 19:28 <DIR> d-------- C:\VundoFix Backups
2006-12-04 18:46 <DIR> d---s---- C:\DOCUME~1\Justin\UserData
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-12-26 16:08 -------- d-------- C:\Program Files\symantec
2006-12-26 16:08 -------- d-------- C:\Program Files\spyware doctor
2006-12-26 16:08 -------- d-------- C:\Program Files\quicktime
2006-12-26 16:05 -------- d-------- C:\Program Files\messenger
2006-12-26 16:00 -------- d-------- C:\Program Files\google
2006-12-26 15:59 -------- d-------- C:\Program Files\corecomm speedstream
2006-12-26 15:58 -------- d-------- C:\Program Files\Common Files\symantec shared
2006-12-26 15:56 -------- d-------- C:\Program Files\aim
2006-12-26 15:24 -------- d-------- C:\DOCUME~1\Dad\Application Data\symantec
2006-12-23 23:56 -------- d-------- C:\Program Files\java
2006-12-23 17:26 -------- d---s---- C:\DOCUME~1\Dad\Application Data\microsoft
2006-12-21 19:35 48776 --a------ C:\WINDOWS\system32\s32evnt1.dll
2006-12-21 19:35 115000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-12-04 19:08 -------- d-------- C:\Program Files\viewpoint
2006-12-01 21:56 -------- d-------- C:\Program Files\norton antivirus
2006-11-23 11:44 38420 --a------ C:\WINDOWS\system32\enayqkjq.dll
2006-11-19 01:51 -------- d-------- C:\Program Files\msxml 4.0
2006-11-10 18:14 -------- d-------- C:\DOCUME~1\Dad\Application Data\apple computer
2006-11-09 19:20 -------- d-------- C:\Program Files\microsoft broadband networking
2006-11-09 15:58 753684 --------- C:\WINDOWS\system32\rmbrlxkr.exe
2006-11-07 23:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll
2006-10-27 16:37 -------- d-------- C:\DOCUME~1\Dad\Application Data\google
2006-10-27 10:26 -------- dr------- C:\Program Files\knowledge adventure
2006-10-23 18:09 67604 --a------ C:\WINDOWS\system32\twcqxplw.exe
2006-10-19 07:56 713216 --a------ C:\WINDOWS\system32\sxs.dll
2006-10-13 06:35 142336 --a------ C:\WINDOWS\system32\nwprovau.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"AIM"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0\\bin\\jusched.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,da,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,b9,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{788D36B8-A862-4575-92FD-78D024637CF9}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer\Run]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\BigFix.lnk"
"backup"="C:\\WINDOWS\\pss\\BigFix.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\Program Files\\BigFix\\BigFix.exe /atstartup"
"item"="BigFix"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Broadband Networking.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Broadband Networking.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Broadband Networking.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\WINDOWS\\Installer\\{06B2B442-19FE-4398-BD4B-F5C00928DD8E}\\_18be6784.exe "
"item"="Microsoft Broadband Networking"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Microsoft Office.lnk"
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~3\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Dad^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
"path"="C:\\Documents and Settings\\Dad\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\LimeWire\\LimeWire.exe -startup"
"item"="LimeWire On Startup"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Justin^Start Menu^Programs^Startup^Morpheus.lnk]
"path"="C:\\Documents and Settings\\Justin\\Start Menu\\Programs\\Startup\\Morpheus.lnk"
"backup"="C:\\WINDOWS\\pss\\Morpheus.lnkStartup"
"location"="Startup"
"command"="C:\\Program Files\\Morpheus\\Morpheus.exe -min"
"item"="Morpheus"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Melissa^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
"path"="C:\\Documents and Settings\\Melissa\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\LimeWire\\LimeWire.exe -startup"
"item"="LimeWire On Startup"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced Tools Check]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ADVCHK"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\NORTON~1\\AdvTools\\ADVCHK.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOL Spyware Protection]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AOLSP Scheduler"
"hkey"="HKLM"
"command"="\"C:\\PROGRA~1\\COMMON~1\\AOL\\AOLSPY~1\\AOLSP Scheduler.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccRegVfy"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DSS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DSSAGENT"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\BBSTORE\\DSS\\DSSAGENT.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AOLHostManager"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\1131843125\\ee\\AOLHostManager.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nForce Tray Options]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sstray"
"hkey"="HKLM"
"command"="sstray.exe /r"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvMcTray"
"hkey"="HKLM"
"command"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\POINTER]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="point32"
"hkey"="HKLM"
"command"="point32.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Propel Accelerator]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="trayctl"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CoreComm SpeedStream\\trayctl.exe\" /STARTUPLAUNCH"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Pure Networks Port Magic]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PortAOL"
"hkey"="HKLM"
"command"="\"C:\\PROGRA~1\\PURENE~1\\PORTMA~1\\PortAOL.exe\" -Run"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SOUNDMAN"
"hkey"="HKLM"
"command"="SOUNDMAN.EXE"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpyHunter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SpyHunter"
"hkey"="HKLM"
"command"="C:\\Program Files\\Enigma Software Group\\SpyHunter\\SpyHunter.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="swdoctor"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_03\\bin\\jusched.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunKistEM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="shwiconem"
"hkey"="HKLM"
"command"="C:\\Program Files\\Digital Media Reader\\shwiconem.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="GoogleToolbarNotifier"
"hkey"="HKCU"
"command"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ViewMgr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="YAHOOM~1"
"hkey"="HKCU"
"command"="\"C:\\PROGRA~1\\Yahoo!\\MESSEN~1\\YAHOOM~1.EXE\" -quiet"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\ISP signup reminder 2.job
C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Melissa.job
Completion time: 06-12-27 13:12:21.07
C:\ComboFix2.txt ... 06-12-24 07:25
C:\ComboFix3.txt ... 06-12-23 18:50
Logfile of HijackThis v1.99.1
Scan saved at 1:14:33 PM, on 12/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/mcfscan/2,1,0,4918/mcfscan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2E130B47-423F-4B8F-AF6B-68BBD7624D90}: NameServer = 64.179.43.190 69.95.31.250
O17 - HKLM\System\CS1\Services\Tcpip\..\{2E130B47-423F-4B8F-AF6B-68BBD7624D90}: NameServer = 64.179.43.190 69.95.31.250
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe