0

hey.. i haven't replied for a while but i was just doing a clean up on the computer and thought i would give you my hijack this report.. if you could just take a look at it and tell me if its ok.. that would be great,
thanks alot

Logfile of HijackThis v1.99.1
Scan saved at 12:05:47 AM, on 5/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mik3\Desktop\Desktop stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [PAV.EXE] 16
O4 - HKLM\..\Run: [Zonavirus] 0
O4 - HKLM\..\Run: [BNexe] C:\WINDOWS\Listado.txt.by.Microsoft.com
O4 - HKLM\..\Run: [BN] c:\BanderaNegra.vbs
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - Startup: csrss.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Program Files\PokerTimeMPP\MPPoker.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab_adult/180solutions/ie/Bridge-c139.cab
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotdate/NPC/MaxisHotDateTeleX.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2DAE59A1-B355-4653-8D33-33A3A8F8C078} (MaxisVacationTeleX Control) - http://thesims.ea.com/teleport/vacation/MaxisVacationTeleX.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.jetsetpoker.com/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} (MaxisUnleashedLotTeleX Control) - http://thesims.ea.com/teleport/unleashed/LOT/MaxisUnleashedLotTeleX.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4438/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

2
Contributors
17
Replies
18
Views
11 Years
Discussion Span
Last Post by crunchie
0

Can you please do the following.

===============

Scan with HiJackThis, then check(tick) the following, if present:


O4 - Startup: csrss.lnk = ?

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

O11 - Options group: [INTERNATIONAL] International*

O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab_ad...ridge-c139.cab


Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked".

===============

To help protect your system from hostile ActiveX content, or special 'downloadable' files:

Download, install and keep updated, SpywareBlaster. If you've installed it for the first time:

1) Check for any available updates; if present, they'll be automatically downloaded and installed.
2) Next, "Enable all protection".
3) Exit the program.

-

Note: Remember to regularly check for updates.

===============

After rebooting, rescan with hijackthis and post back a new log. Please let me know how your pc is now.

0

hey crunchie.. after i fixed the problems you gave to me these messages came up:
Message 1
Unexpected error occurred!
Error #52 (Bad file name or number) in Sub GetLongPath(?.exe).

Please send a report to merijn@spywareinfo.com, mentioning what you were doing, and what version of Windows you have.

This message has been copied to your clipboard.

Message 2
Unable to delete the file:

04 – startup:csrss.lnk = ?

Now i don't know if this is important at all but i took a hijack this log file from both accounts on my computer and to me they look different, if you could help me with this it would be awsome

Original Computer Account - the one you looked at before:

Logfile of HijackThis v1.99.1
Scan saved at 1:05:08 PM, on 5/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\devldr32.exe
C:\Documents and Settings\Mik3\Desktop\Desktop stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [PAV.EXE] 16
O4 - HKLM\..\Run: [Zonavirus] 0
O4 - HKLM\..\Run: [BNexe] C:\WINDOWS\Listado.txt.by.Microsoft.com
O4 - HKLM\..\Run: [BN] c:\BanderaNegra.vbs
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - Startup: csrss.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Program Files\PokerTimeMPP\MPPoker.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotda...tDateTeleX.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2DAE59A1-B355-4653-8D33-33A3A8F8C078} (MaxisVacationTeleX Control) - http://thesims.ea.com/teleport/vacat...ationTeleX.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.jetsetpoker.com/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/...s/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} (MaxisUnleashedLotTeleX Control) - http://thesims.ea.com/teleport/unlea...edLotTeleX.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/instal...sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhel...7/dlhelper.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...38/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

Other Account - Different one on computer:

Logfile of HijackThis v1.99.1
Scan saved at 1:03:10 PM, on 5/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Utopia\Angel\Angel.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Mik3\Desktop\Desktop stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.qqmchuhtnt.biz/glOdhZVSrD...qBlh5/Qiv.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [PAV.EXE] 16
O4 - HKLM\..\Run: [Zonavirus] 0
O4 - HKLM\..\Run: [BNexe] C:\WINDOWS\Listado.txt.by.Microsoft.com
O4 - HKLM\..\Run: [BN] c:\BanderaNegra.vbs
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [WormsArmageddon.exe] C:\DOCUME~1\Marvin\Desktop\Worms.exe /r
O4 - HKCU\..\Run: [Rulejunk] C:\DOCUME~1\Marvin\APPLIC~1\OKAYBA~1\ListDoes.exe
O4 - HKCU\..\Run: [Utopia Angel] "C:\Utopia\Angel\Angel.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: DLHelperEXE.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearc...p=ZBzeb030YYCA
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Program Files\PokerTimeMPP\MPPoker.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotda...tDateTeleX.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2DAE59A1-B355-4653-8D33-33A3A8F8C078} (MaxisVacationTeleX Control) - http://thesims.ea.com/teleport/vacat...ationTeleX.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.jetsetpoker.com/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/...s/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} (MaxisUnleashedLotTeleX Control) - http://thesims.ea.com/teleport/unlea...edLotTeleX.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/instal...sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhel...7/dlhelper.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...38/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

0

Let's get log one out of the way first, then we can check the other account :).

==

Can you please do the following.

===============

Please visit at least two of the following sites for an online virus scan:

BitDefender Free Online Virus Scan
http://www.bitdefender.com/scan/licence.php
Make sure you tick AutoClean under Scan Options.

Panda ActiveScan
http://www.pandasoftware.com/activescan/com/activescan_principal.htm
Make sure you tick Disinfect automatically under Scan Options.

Housecall at TrendMicro
http://housecall.trendmicro.com/housecall/start_corp.asp
Make sure you tick Auto Clean.
When it completes, post back the full filename of any files that cannot be cleaned or deleted.

eTrust Antivirus Web Scanner
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx

===============

Scan with HiJackThis, then check(tick) the following, if present:


O4 - HKLM\..\Run: [PAV.EXE] 16
O4 - HKLM\..\Run: [Zonavirus] 0
O4 - HKLM\..\Run: [BNexe] C:\WINDOWS\Listado.txt.by.Microsoft.com
O4 - HKLM\..\Run: [BN] c:\BanderaNegra.vbs
O4 - Startup: csrss.lnk = ?


Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked".

===============

Locate and delete the following item(s), if present. Make sure you are able to view system and hidden files/ folders:

Search for...

[PAV.EXE

...using "Start | Search...".

-

Note that some of these file(s)/folder(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in "Safe Mode".

-

Reboot.

===============

After rebooting, rescan with hijackthis and post back a new log. Please let me know how your pc is now.

0

Ok.. so I had a couple problems that occured,
First.. It wouldn't let me fix the

O4 - Startup: csrss.lnk = ?

in the hijack this scan

Second... I couldn't find [PAV.EXE even after I checked off show hidden files and folders and hide protected operating systems in the Folder Options and went into safe mode

Third.... I didn't see the autoclean option at http://www.bitdefender.com/scan/licence.php so i just did the scan which came up with the results: (they're pretty long.. sorry)

C:\Documents and Settings\Marvin\Application Data\Okay Bait Face\bind dent extra.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Application Data\Okay Bait Face\bind dent extra.exe


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Okay Bait Face\bind dent extra.exe


Deleted

C:\Documents and Settings\Marvin\Application Data\Okay Bait Face\slowcurbacidstyle.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Application Data\Okay Bait Face\slowcurbacidstyle.exe


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Okay Bait Face\slowcurbacidstyle.exe


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>BlackBox.class


Infected with: Java.Trojan.ClassLoader.GH

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>BlackBox.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>BlackBox.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>VB.class


Infected with: Java.Trojan.Exploit.Bytverify.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>VB.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>VB.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>Dummy.class


Infected with: Trojan.Java.Byteverify.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>Dummy.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>Dummy.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>Beyond.class


Infected with: Java.Trojan.Exploit.Bytverify.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>Beyond.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip=>Beyond.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-1a0c24f4-5206c2f4.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Counter.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Counter.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Counter.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Gummy.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Gummy.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Gummy.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>VerifierBug.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>VerifierBug.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>VerifierBug.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>web.exe


Infected with: Trojan.LowZones.CG

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>web.exe


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>web.exe


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Worker.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Worker.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Worker.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Xeyond.class


Infected with: Java.Trojan.Femad.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Xeyond.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip=>Xeyond.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1a980a85-3b06aa5c.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Counter.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Counter.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Counter.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Gummy.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Gummy.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Gummy.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>VerifierBug.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>VerifierBug.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>VerifierBug.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>web.exe


Infected with: Trojan.Fakealert.AW

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>web.exe


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>web.exe


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Worker.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Worker.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Worker.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Xeyond.class


Infected with: Java.Trojan.Femad.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Xeyond.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip=>Xeyond.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-1ba13978-2c4b79f7.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Counter.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Counter.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Counter.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Gummy.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Gummy.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Gummy.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>VerifierBug.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>VerifierBug.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>VerifierBug.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>web.exe


Infected with: Trojan.LowZones.CX

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>web.exe


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>web.exe


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Worker.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Worker.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Worker.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Xeyond.class


Infected with: Java.Trojan.Femad.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Xeyond.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip=>Xeyond.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2583f9fa-78fe8435.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Counter.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Counter.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Counter.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Gummy.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Gummy.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Gummy.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>VerifierBug.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>VerifierBug.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>VerifierBug.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>web.exe


Infected with: Trojan.LowZones.CX

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>web.exe


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>web.exe


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Worker.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Worker.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Worker.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Xeyond.class


Infected with: Java.Trojan.Femad.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Xeyond.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip=>Xeyond.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2ad522e1-6b7b1348.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Counter.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Counter.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Counter.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Gummy.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Gummy.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Gummy.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>VerifierBug.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>VerifierBug.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>VerifierBug.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>web.exe


Infected with: Trojan.Small.WA

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>web.exe


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>web.exe


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Worker.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Worker.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Worker.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Xeyond.class


Infected with: Java.Trojan.Femad.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Xeyond.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip=>Xeyond.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5a0ba3cf-7e88da01.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Counter.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Counter.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Counter.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Gummy.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Gummy.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Gummy.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>VerifierBug.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>VerifierBug.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>VerifierBug.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>web.exe


Infected with: MemScan:Trojan.Small.Y

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>web.exe


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>web.exe


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Worker.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Worker.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Worker.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Xeyond.class


Infected with: Java.Trojan.Femad.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Xeyond.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip=>Xeyond.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-5f5cccb6-197c9eda.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Counter.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Counter.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Counter.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Gummy.class


Infected with: Java.Trojan.Exploit.Bytverify

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Gummy.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Gummy.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>VerifierBug.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>VerifierBug.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>VerifierBug.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>web.exe


Infected with: Trojan.LowZones.DM

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>web.exe


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Worker.class


Infected with: Java.Trojan.Femad.A

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Worker.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Worker.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip


Updated

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Xeyond.class


Infected with: Java.Trojan.Femad.B

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Xeyond.class


Disinfection failed

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip=>Xeyond.class


Deleted

C:\Documents and Settings\Marvin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-6539b84-6c9da108.zip


Updated

C:\Documents and Settings\Marvin\Local Settings\Temp\103cf0a6.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\103cf0a6.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\103cf0a6.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\10524b7b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\10524b7b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\10524b7b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\10ce58e7.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\10ce58e7.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\10ce58e7.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\122dadeb.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\122dadeb.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\122dadeb.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1274ba7b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1274ba7b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1274ba7b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\12d9bd67.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\12d9bd67.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\12d9bd67.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\12e08be7.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\12e08be7.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\12e08be7.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1306cc4.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1306cc4.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1306cc4.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\14603e6b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\14603e6b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\14603e6b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\14f21d78.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\14f21d78.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\14f21d78.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\159ff9f.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\159ff9f.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\159ff9f.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\17a82516.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\17a82516.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\17a82516.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\18bdbeeb.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\18bdbeeb.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\18bdbeeb.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1b42ee29.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1b42ee29.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1b42ee29.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1c996415.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1c996415.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1c996415.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1e21f9eb.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1e21f9eb.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1e21f9eb.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1e68c66b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1e68c66b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1e68c66b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1eb3d4db.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1eb3d4db.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1eb3d4db.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1efaa56b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1efaa56b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1efaa56b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1f0db23a.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1f0db23a.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1f0db23a.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\1f54806b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\1f54806b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\1f54806b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\211f146b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\211f146b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\211f146b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\233047ba.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\233047ba.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\233047ba.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\237b542a.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\237b542a.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\237b542a.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\238222ba.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\238222ba.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\238222ba.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\23d530db.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\23d530db.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\23d530db.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\241c015b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\241c015b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\241c015b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\246efc5b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\246efc5b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\246efc5b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\24c81b7.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\24c81b7.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\24c81b7.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\2631705b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\2631705b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\2631705b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\284ba35b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\284ba35b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\284ba35b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\2892b1db.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\2892b1db.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\2892b1db.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\28a59eba.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\28a59eba.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\28a59eba.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\28ef6ceb.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\28ef6ceb.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\28ef6ceb.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\29367d7b.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\29367d7b.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\29367d7b.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\2966fc4.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\2966fc4.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\2966fc4.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\29794bca.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\29794bca.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\29794bca.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\29cb26eb.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\29cb26eb.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\29cb26eb.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\2ab7e0eb.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\2ab7e0eb.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\2ab7e0eb.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\2d97c44.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\2d97c44.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\2d97c44.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\2e04ac4.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\2e04ac4.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\2e04ac4.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\37229c4.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\37229c4.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\37229c4.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\3cc0727.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\3cc0727.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\3cc0727.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\3ee72e7.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\3ee72e7.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\3ee72e7.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\4171586.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\4171586.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\4171586.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\4d21e04.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\4d21e04.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\4d21e04.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\52e878f.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\52e878f.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\52e878f.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\69a9214.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\69a9214.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\69a9214.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\8fe1889.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\8fe1889.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\8fe1889.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\aa62c86.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\aa62c86.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\aa62c86.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\ae4aa5.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\ae4aa5.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\ae4aa5.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\bb4fcd7.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\bb4fcd7.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\bb4fcd7.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\f0928cd.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\f0928cd.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\f0928cd.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\f91a3d7.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\f91a3d7.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\f91a3d7.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temp\ff5e3e4.exe


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temp\ff5e3e4.exe


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temp\ff5e3e4.exe


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BDCGEKSR\R1hZcmFVVXl0Sm9BQUdZMHJZZ0FBQUVY[1].wmf


Infected with: Exploit.Win32.WMF-PFV

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BDCGEKSR\R1hZcmFVVXl0Sm9BQUdZMHJZZ0FBQUVY[1].wmf


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BDCGEKSR\R1hZcmFVVXl0Sm9BQUdZMHJZZ0FBQUVY[1].wmf


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BEI8KUR7\hardcore[1].htm=>(JAVASCRIPT 7)


Infected with: Trojan.Clicker.Js.Linker.H

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BEI8KUR7\hardcore[1].htm=>(JAVASCRIPT 7)


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BEI8KUR7\hardcore[1].htm=>(JAVASCRIPT 7)


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BEI8KUR7\hardcore[1].htm


Updated

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BEI8KUR7\S01IV1AwVXl0Sm9BQUdTMFFjWUFBQURz[1].wmf


Infected with: Exploit.Win32.WMF-PFV

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BEI8KUR7\S01IV1AwVXl0Sm9BQUdTMFFjWUFBQURz[1].wmf


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BEI8KUR7\S01IV1AwVXl0Sm9BQUdTMFFjWUFBQURz[1].wmf


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\FC0VF2KN\reality[1].htm=>(JAVASCRIPT 5)


Infected with: Trojan.Clicker.Js.Linker.H

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\FC0VF2KN\reality[1].htm=>(JAVASCRIPT 5)


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\FC0VF2KN\reality[1].htm=>(JAVASCRIPT 5)


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\FC0VF2KN\reality[1].htm


Updated

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\FC0VF2KN\video[1].htm=>(JAVASCRIPT 5)


Infected with: Trojan.Clicker.Js.Linker.H

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\FC0VF2KN\video[1].htm=>(JAVASCRIPT 5)


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\FC0VF2KN\video[1].htm=>(JAVASCRIPT 5)


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\FC0VF2KN\video[1].htm


Updated

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\MZYRE1EB\upAYB_unk[1].int


Infected with: Trojan.Swizzor.DH

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\MZYRE1EB\upAYB_unk[1].int


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\MZYRE1EB\upAYB_unk[1].int


Deleted

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\U57CT07Q\aUFpWnBFVXl0Sm9BQUFwWUIxRUFBQUJj[1].wmf


Infected with: Exploit.Win32.WMF-PFV

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\U57CT07Q\aUFpWnBFVXl0Sm9BQUFwWUIxRUFBQUJj[1].wmf


Disinfection failed

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\U57CT07Q\aUFpWnBFVXl0Sm9BQUFwWUIxRUFBQUJj[1].wmf


Deleted

C:\Documents and Settings\Marvin\My Documents\Justin\MsgPlus-301.exe


Infected with: Trojan.Swizzor.DP

C:\Documents and Settings\Marvin\My Documents\Justin\MsgPlus-301.exe


Disinfection failed

C:\Documents and Settings\Marvin\My Documents\Justin\MsgPlus-301.exe


Deleted

C:\Documents and Settings\Marvin\My Documents\Ryan\Word Perfect\lakefree.exe=>(ZIP Sfx s)=>lakesetup.exe=>(ZIP Sfx o)=>FREEZE_388.EXE


Detected with: Application.Adware.NewDotNet.Dropper

C:\Documents and Settings\Marvin\My Documents\Ryan\Word Perfect\lakefree.exe=>(ZIP Sfx s)=>lakesetup.exe=>(ZIP Sfx o)=>FREEZE_388.EXE


Deleted

C:\Documents and Settings\Marvin\My Documents\Ryan\Word Perfect\lakefree.exe=>(ZIP Sfx s)=>lakesetup.exe=>(ZIP Sfx o)


Updated

C:\Documents and Settings\Marvin\My Documents\Ryan\Word Perfect\lakefree.exe=>(ZIP Sfx s)=>lakesetup.exe


Update failed

C:\WINDOWS\system32\drivers\etc\hosts


Infected with: Generic.Qhost

C:\WINDOWS\system32\drivers\etc\hosts


Disinfection failed

C:\WINDOWS\system32\drivers\etc\hosts


Deleted

C:\WINDOWS\system32\drivers\etc\hosts.20051202-231041.backup


Infected with: Generic.Qhost

C:\WINDOWS\system32\drivers\etc\hosts.20051202-231041.backup


Disinfection failed

C:\WINDOWS\system32\drivers\etc\hosts.20051202-231041.backup


Deleted

C:\WINDOWS\system32\drivers\etc\hosts.msn


Infected with: Generic.Qhost

C:\WINDOWS\system32\drivers\etc\hosts.msn


Disinfection failed

C:\WINDOWS\system32\drivers\etc\hosts.msn


Deleted

Ok.... i also found that the other sites that you gave me did not work.. not sure why
Anywayz... here is the hijack this file after changing what you told me.. thanks for the help so far

Logfile of HijackThis v1.99.1
Scan saved at 10:07:09 PM, on 6/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mik3\Desktop\Desktop stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://go.microsoft.com/fwlink/?LinkId=54729[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - Startup: csrss.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Program Files\PokerTimeMPP\MPPoker.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - [url]http://messenger.zone.msn.com/binary/msgrchkr.cab[/url]
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - [url]http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab[/url]
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - [url]http://thesims.ea.com/teleport/hotdate/NPC/MaxisHotDateTeleX.cab[/url]
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - [url]http://messenger.zone.msn.com/binary/MineSweeper.cab[/url]
O16 - DPF: {2DAE59A1-B355-4653-8D33-33A3A8F8C078} (MaxisVacationTeleX Control) - [url]http://thesims.ea.com/teleport/vacation/MaxisVacationTeleX.cab[/url]
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - [url]http://www.jetsetpoker.com/setup.exe[/url]
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - [url]http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab[/url]
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - [url]http://download.bitdefender.com/resources/scan8/oscan8.cab[/url]
O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} (MaxisUnleashedLotTeleX Control) - [url]http://thesims.ea.com/teleport/unleashed/LOT/MaxisUnleashedLotTeleX.cab[/url]
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - [url]http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab[/url]
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - [url]http://messenger.zone.msn.com/binary/MessengerStatsClient.cab[/url]
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - [url]http://activex.microgaming.com/DLhelper/version7/dlhelper.cab[/url]
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - [url]http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab[/url]
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - [url]http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab[/url]
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - [url]http://simcity.ea.com/play/classic/SimCityX.cab[/url]
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - [url]http://messenger.zone.msn.com/binary/WoF.cab31267.cab[/url]
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - [url]http://messenger.zone.msn.com/binary/Chess.cab31267.cab[/url]
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - [url]http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4438/mcfscan.cab[/url]
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - [url]http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab[/url]
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - [url]http://cdn.digitalcity.com/_media/dalaillama/ampx.cab[/url]
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - [url]http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab[/url]
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

Edited by mike_2000_17: Fixed formatting

0

Ok. Whatever was not fixed during the online scans needs you to manually delete it/them. But first, do the following;
Go to your Control Panel and double click the Java icon. Go to the 'cache' and delete or clear the contents.

Download CCleaner and install, then run it.

  1. Uncheck "Cookies" under "Internet Explorer".
  2. Click on Run Cleaner in the lower right-hand corner. This can take quite a while to run.
  3. Close when finished.

When you've done that, do another online scan and see what comes up.

0

hey... well this is what came up for the virus report after i did the other thing
Scanned File

 Status

C:\Documents and Settings\Marvin\My Documents\Ryan\Word Perfect\lakefree.exe=>(ZIP Sfx s)=>lakesetup.exe=>(ZIP Sfx o)=>FREEZE_388.EXE


Detected with: Application.Adware.NewDotNet.Dropper

C:\Documents and Settings\Marvin\My Documents\Ryan\Word Perfect\lakefree.exe=>(ZIP Sfx s)=>lakesetup.exe=>(ZIP Sfx o)=>FREEZE_388.EXE


Deleted

C:\Documents and Settings\Marvin\My Documents\Ryan\Word Perfect\lakefree.exe=>(ZIP Sfx s)=>lakesetup.exe=>(ZIP Sfx o)


Updated

C:\Documents and Settings\Marvin\My Documents\Ryan\Word Perfect\lakefree.exe=>(ZIP Sfx s)=>lakesetup.exe


Update failed

alright... well thats it, a little shorter this time.. umm i know where that document is should i just delete it or do i have to do anything else to get rid of it, thanks 

This is the hijack log as of now:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\COMMON~1\Logitech\WebColct\WebColct.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mik3\Desktop\Desktop stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url]http://go.microsoft.com/fwlink/?LinkId=54729[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [url]http://go.microsoft.com/fwlink/?LinkId=54896[/url]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - Startup: csrss.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Program Files\PokerTimeMPP\MPPoker.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - [url]http://messenger.zone.msn.com/binary/msgrchkr.cab[/url]
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - [url]http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab[/url]
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - [url]http://thesims.ea.com/teleport/hotdate/NPC/MaxisHotDateTeleX.cab[/url]
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - [url]http://messenger.zone.msn.com/binary/MineSweeper.cab[/url]
O16 - DPF: {2DAE59A1-B355-4653-8D33-33A3A8F8C078} (MaxisVacationTeleX Control) - [url]http://thesims.ea.com/teleport/vacation/MaxisVacationTeleX.cab[/url]
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - [url]http://www.jetsetpoker.com/setup.exe[/url]
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - [url]http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab[/url]
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - [url]http://download.bitdefender.com/resources/scan8/oscan8.cab[/url]
O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} (MaxisUnleashedLotTeleX Control) - [url]http://thesims.ea.com/teleport/unleashed/LOT/MaxisUnleashedLotTeleX.cab[/url]
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - [url]http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab[/url]
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - [url]http://messenger.zone.msn.com/binary/MessengerStatsClient.cab[/url]
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - [url]http://activex.microgaming.com/DLhelper/version7/dlhelper.cab[/url]
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - [url]http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab[/url]
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - [url]http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab[/url]
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - [url]http://simcity.ea.com/play/classic/SimCityX.cab[/url]
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - [url]http://messenger.zone.msn.com/binary/WoF.cab31267.cab[/url]
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - [url]http://messenger.zone.msn.com/binary/Chess.cab31267.cab[/url]
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - [url]http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4438/mcfscan.cab[/url]
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - [url]http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab[/url]
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - [url]http://cdn.digitalcity.com/_media/dalaillama/ampx.cab[/url]
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - [url]http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab[/url]
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

Edited by mike_2000_17: Fixed formatting

0

i dunno what you meant by system search but i did the windows search which came up with:

Name: CSRSS.EXE-12B63473.ph In Folder: C:\WINDOWS\Prefectch

Name:
csrss In Folder: C:\WINDOWS\system32

Name:
csrss In Folder: C:\WINDOWS\ServicePackFiles\i386

0

Alright... it came up with nothing on the online upload and scan..
moving on to the next problem, I am using one account on my computer while the rest of my family is using the other account, just to make sure that the other account is alright.. can you just take a look at the hijack log for that account, because it is having some problems with internet explorer..... I was also wondering if i could delete internet explorer in windows task manager/processes for example explorer.exe, I also have Mozilla firefox.. which is the one used by everyone...
One more question.... my high-speed internet has been doing some pretty weird stuff lately... on the toolbar it tells me that it is running with excellent speed but realistically it turns off and on till the point where it is on for 30 seconds at times and off for 5 minutes... although this only happens every once and a while, it has been turning off every half an hour or so lately... so my question is if this is a problem many people have or if its something wrong with my computer... thanks alot for your help....
Heres the log file for the family's account:

Logfile of HijackThis v1.99.1
Scan saved at 1:03:10 PM, on 5/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Utopia\Angel\Angel.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Mik3\Desktop\Desktop stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.qqmchuhtnt.biz/glOdhZVSrD...qBlh5/Qiv.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [PAV.EXE] 16
O4 - HKLM\..\Run: [Zonavirus] 0
O4 - HKLM\..\Run: [BNexe] C:\WINDOWS\Listado.txt.by.Microsoft.com
O4 - HKLM\..\Run: [BN] c:\BanderaNegra.vbs
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [WormsArmageddon.exe] C:\DOCUME~1\Marvin\Desktop\Worms.exe /r
O4 - HKCU\..\Run: [Rulejunk] C:\DOCUME~1\Marvin\APPLIC~1\OKAYBA~1\ListDoes.exe
O4 - HKCU\..\Run: [Utopia Angel] "C:\Utopia\Angel\Angel.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: DLHelperEXE.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearc...p=ZBzeb030YYCA
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Program Files\PokerTimeMPP\MPPoker.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotda...tDateTeleX.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2DAE59A1-B355-4653-8D33-33A3A8F8C078} (MaxisVacationTeleX Control) - http://thesims.ea.com/teleport/vacat...ationTeleX.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.jetsetpoker.com/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/...s/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} (MaxisUnleashedLotTeleX Control) - http://thesims.ea.com/teleport/unlea...edLotTeleX.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/instal...sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhel...7/dlhelper.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/is...38/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/...ampx_en_dl.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

0

Looks like you need to run the LOP uninstaller on this account too. When done, proceed with the following. Not certain about the connection problems.


===============

Go to Add/Remove programs and remove(uninstall) the following, if present:

MyWebSearch

The above could appear anywhere within the entry. Be careful not to remove any personal or system software.

===============

Scan with HiJackThis, then check(tick) the following, if present:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.qqmchuhtnt.biz/glOdhZVSrD...qBlh5/Qiv.html

O4 - HKLM\..\Run: [PAV.EXE] 16
O4 - HKLM\..\Run: [Zonavirus] 0
O4 - HKLM\..\Run: [BNexe] C:\WINDOWS\Listado.txt.by.Microsoft.com
O4 - HKLM\..\Run: [BN] c:\BanderaNegra.vbs
O4 - HKCU\..\Run: [Rulejunk] C:\DOCUME~1\Marvin\APPLIC~1\OKAYBA~1\ListDoes.exe
O4 - Startup: DLHelperEXE.exe

O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearc...p=ZBzeb030YYCA


Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked".

===============

Locate and delete the following item(s), if present. Make sure you are able to view system and hidden files/ folders:

folders...

C:\DOCUME~1\Marvin\APPLIC~1\OKAYBA~1

Search for...

[PAV.EXE
DLHelperEXE.exe

...using "Start | Search...".

-

Note that some of these file(s)/folder(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in "Safe Mode".

-

Reboot.

===============

After rebooting, rescan with hijackthis and post back a new log. Please let me know how your pc is now.

0

hey... i did most of the stuff you told me to but i couldn't delete C:\DOCUME~1\Marvin\APPLIC~1\OKAYBA~1 because of some restrictions or something... I'm still having some problems with pop-ups from internet explorer tho(even though we do not use it)

heres the hijack log tho:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\system32\devldr32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Utopia\Angel\Angel.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\plugins\GetFlash.exe
C:\Documents and Settings\Mik3\Desktop\Desktop stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [WormsArmageddon.exe] C:\DOCUME~1\Marvin\Desktop\Worms.exe /r
O4 - HKCU\..\Run: [Utopia Angel] "C:\Utopia\Angel\Angel.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Program Files\PokerTimeMPP\MPPoker.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotdate/NPC/MaxisHotDateTeleX.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2DAE59A1-B355-4653-8D33-33A3A8F8C078} (MaxisVacationTeleX Control) - http://thesims.ea.com/teleport/vacation/MaxisVacationTeleX.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.jetsetpoker.com/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} (MaxisUnleashedLotTeleX Control) - http://thesims.ea.com/teleport/unleashed/LOT/MaxisUnleashedLotTeleX.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4438/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

0

Go here and download then run Silent Runners.vbs. It generates a log. Please post the information back in this thread.
If you have a script blocking program, please allow the file to run. It is not malicious.

0

heres the log:

"Silent Runners.vbs", revision 45, [url]http://www.silentrunners.org/[/url]
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS]
"MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]
"Registry Cleaner" = ""C:\Program Files\Registry Cleaner Trial\regclean.exe"" [file not found]
"Spyware Doctor" = (empty string)
"csrss" = "*b" (unwritable string) [file not found]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"zBrowser Launcher" = "C:\Program Files\Logitech\iTouch\iTouch.exe" ["Logitech Inc.                    "]
"EM_EXEC" = "C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" ["Logitech Inc.                    "]
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup" [MS]
"nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
"NeroCheck" = "C:\WINDOWS\System32\\NeroCheck.exe" ["Ahead Software Gmbh"]
"AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" ["GRISOFT, s.r.o."]
"Easy-PrintToolBox" = "C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon" ["CANON INC."]
"UserFaultCheck" = "C:\WINDOWS\system32\dumprep 0 -u" [MS]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = "C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe" ["Google Inc."]
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" ["Sun Microsystems, Inc."]
"csrss" = "*Z" (unwritable string) [file not found]
"iTunesHelper" = ""C:\Program Files\iTunes\iTunesHelper.exe"" ["Apple Computer, Inc."]
"QuickTime Task" = ""C:\Program Files\QuickTime\qttask.exe" -atboottime" ["Apple Computer, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "SSVHelper Class"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]
{9394EDE7-C8B5-483E-8773-474BF36AF6E4}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "ST"
                   \InProcServer32\(Default) = "C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll" [MS]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "MSNToolBandBHO"
                   \InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
  -> {HKLM...CLSID} = "Display Panning CPL Extension"
                   \InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{30D02401-6A81-11d0-8274-00C04FD5AE38}" = "IE Search Band"
  -> {HKLM...CLSID} = "IE Search Band"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}" = "Shell DocObject Viewer"
  -> {HKLM...CLSID} = "Shell DocObject Viewer"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}" = "InternetShortcut"
  -> {HKLM...CLSID} = "Internet Shortcut"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}" = "Microsoft Url History Service"
  -> {HKLM...CLSID} = "Microsoft Url History Service"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FF393560-C2A7-11CF-BFF4-444553540000}" = "History"
  -> {HKLM...CLSID} = "History"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files"
  -> {HKLM...CLSID} = "Temporary Internet Files"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}" = "Temporary Internet Files"
  -> {HKLM...CLSID} = "Temporary Internet Files"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}" = "Microsoft Url Search Hook"
  -> {HKLM...CLSID} = "Microsoft Url Search Hook"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}" = "The Internet"
  -> {HKLM...CLSID} = "The Internet"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{871C5380-42A0-1069-A2EA-08002B30309D}" = "Internet Name Space"
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
  -> {HKLM...CLSID} = "Outlook File Icon Extension"
                   \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
  -> {HKLM...CLSID} = "Desktop Explorer"
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{6B19FEC2-A45B-11CF-9045-00A0C9039735}" = "Registered ActiveX Controls"
  -> {HKLM...CLSID} = "Registered ActiveX Controls"
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\DEVXPGL.DLL" [MS]
"{D545EBD1-BD92-11CF-8772-00A0C9039735}" = "Developer Studio Components"
  -> {HKLM...CLSID} = "Developer Studio Components"
                   \InProcServer32\(Default) = "C:\Program Files\Microsoft Visual Studio\Common\MSDev98\Bin\IDE\DEVXPGL.DLL" [MS]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
  -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
                   \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
  -> {HKLM...CLSID} = "AVG7 Find Extension Class"
                   \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{640167b4-59b0-47a6-b335-a6b3c0695aea}" = "Portable Media Devices"
  -> {HKLM...CLSID} = "Portable Media Devices"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}" = "Portable Media Devices Menu"
  -> {HKLM...CLSID} = "Portable Media Devices Menu"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\Audiodev.dll" [MS]
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
  -> {HKLM...CLSID} = "iTunes"
                   \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Computer, Inc."]
"{21569614-B795-46b1-85F4-E737A8DC09AD}" = "Shell Search Band"
  -> {HKLM...CLSID} = "Shell Search Band"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\browseui.dll" [MS]
"{07C45BB1-4A8C-4642-A1F5-237E7215FF66}" = "IE Microsoft BrowserBand"
  -> {HKLM...CLSID} = "IE Microsoft BrowserBand"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{0D6D4F41-2994-4ba0-8FEF-620E43CD2812}" = "IE Microsoft Internet Toolbar"
  -> {HKLM...CLSID} = "IE Microsoft Internet Toolbar"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{1C1EDB47-CE22-4bbb-B608-77B48F83C823}" = "IE Fade Task"
  -> {HKLM...CLSID} = "IE Fade Task"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{205D7A97-F16D-4691-86EF-F3075DCCA57D}" = "IE Menu Desk Bar"
  -> {HKLM...CLSID} = "IE Menu Desk Bar"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{3028902F-6374-48b2-8DC6-9725E775B926}" = "IE AutoComplete"
  -> {HKLM...CLSID} = "IE AutoComplete"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{43886CD5-6529-41c4-A707-7B3C92C05E68}" = "IE Navigation Bar"
  -> {HKLM...CLSID} = "IE Navigation Bar"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{44C76ECD-F7FA-411c-9929-1B77BA77F524}" = "IE Menu Site"
  -> {HKLM...CLSID} = "IE Menu Site"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{482A7CB3-2EDF-4595-A315-A5244F1E96E6}" = "IE Search Control"
  -> {HKLM...CLSID} = "IE Search Control"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{4B78D326-D922-44f9-AF2A-07805C2A3560}" = "IE Menu Band"
  -> {HKLM...CLSID} = "IE Menu Band"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6038EF75-ABFC-4e59-AB6F-12D397F6568D}" = "IE Microsoft History AutoComplete List"
  -> {HKLM...CLSID} = "IE Microsoft History AutoComplete List"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}" = "IE Tracking Shell Menu"
  -> {HKLM...CLSID} = "IE Tracking Shell Menu"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6CF48EF8-44CD-45d2-8832-A16EA016311B}" = "IE IShellFolderBand"
  -> {HKLM...CLSID} = (no title provided)
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F}" = "Explorer Search Band"
  -> {HKLM...CLSID} = "Explorer Search Band"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{73CFD649-CD48-4fd8-A272-2070EA56526B}" = "IE BandProxy"
  -> {HKLM...CLSID} = "IE BandProxy"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{7E48925F-FF5C-47fa-A99A-F5912A10623B}" = "IE Address EditBox"
  -> {HKLM...CLSID} = "IE Address EditBox"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}" = "IE MRU AutoComplete List"
  -> {HKLM...CLSID} = "IE MRU AutoComplete List"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}" = "IE Microsoft Shell Folder AutoComplete List"
  -> {HKLM...CLSID} = "IE Microsoft Shell Folder AutoComplete List"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{B31C5FAE-961F-415b-BAF0-E697A5178B94}" = "IE Microsoft Multiple AutoComplete List Container"
  -> {HKLM...CLSID} = "IE Microsoft Multiple AutoComplete List Container"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}" = "Microsoft Browser Architecture"
  -> {HKLM...CLSID} = "Microsoft Browser Architecture"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}" = "IE Shell Rebar BandSite"
  -> {HKLM...CLSID} = "IE Shell Rebar BandSite"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{C4EC38BD-4E9E-4b5e-935A-D1BFF237D980}" = "Explorer Travel Band"
  -> {HKLM...CLSID} = "Explorer Travel Band"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{DE011590-0531-4804-9C9C-3FEDC7E6E5C8}" = "IE &Address"
  -> {HKLM...CLSID} = "IE &Address"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{E6EE9AAC-F76B-4947-8260-A9F136138E11}" = "IE Shell Band Site Menu"
  -> {HKLM...CLSID} = "IE Shell Band Site Menu"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{F0353E1D-FEEC-474e-A984-1E5C6865E380}" = "IE Global Folder Settings"
  -> {HKLM...CLSID} = "IE Global Folder Settings"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{F2CF5485-4E02-4f68-819C-B92DE9277049}" = "&Links"
  -> {HKLM...CLSID} = "&Links"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}" = "IE Registry Tree Options Utility"
  -> {HKLM...CLSID} = "IE Registry Tree Options Utility"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}" = "IE User Assist"
  -> {HKLM...CLSID} = "IE User Assist"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
"{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}" = "IE Custom MRU AutoCompleted List"
  -> {HKLM...CLSID} = "IE Custom MRU AutoCompleted List"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
INFECTION WARNING! "{553858A7-4922-4e7e-B1C1-97140C1C16EF}" = "IE Component Categories cache daemon"
  -> {HKLM...CLSID} = "IE Component Categories cache daemon"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! WgaLogon\DLLName = "WgaLogon.dll" [MS]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
  -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
                   \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"
  -> {HKLM...CLSID} = "AVG7 Shell Extension Class"
                   \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                   \InProcServer32\(Default) = "C:\Program Files\WinRAR\rarext.dll" [null data]


Active Desktop and Wallpaper:
-----------------------------

Active Desktop is disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Mik3\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


DESKTOP.INI DLL launch in local fixed drive directories:
--------------------------------------------------------

C:\Documents and Settings\Default User\Local Settings\History\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Default User\Local Settings\History\History.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\OPSTGTQR\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\UHCB078V\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\UKBEHA5D\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\UTY74RAN\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\LocalService\Cookies\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\LocalService\Local Settings\History\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\29YT6VW9\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\GNKT81GH\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OJWRAN61\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\YBCJEXU5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Cookies\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Application Data\Microsoft\Feeds Cache\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Application Data\Microsoft\Feeds Cache\K6CVYV8L\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Application Data\Microsoft\Feeds Cache\LLIZM3BK\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Application Data\Microsoft\Feeds Cache\XF1CCQ4D\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Application Data\Microsoft\Feeds Cache\YKUAP3QJ\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\History\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\History\History.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temp\History\History.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temp\Temporary Internet Files\Content.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temp\Temporary Internet Files\Content.IE5\GLYJC5AJ\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temp\Temporary Internet Files\Content.IE5\LJKIPEL5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temp\Temporary Internet Files\Content.IE5\QOQ1QU1N\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temp\Temporary Internet Files\Content.IE5\QVQGCXSA\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\14SJPXGX\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\3J53Z9KW\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BDCGEKSR\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\BEI8KUR7\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\FC0VF2KN\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\GL8JWBSF\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\MZYRE1EB\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\OJNBQS1L\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\U18N65A5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\U57CT07Q\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\W1G9QRS1\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Marvin\Local Settings\Temporary Internet Files\Content.IE5\WLLD3IVS\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Cookies\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Application Data\Microsoft\Feeds Cache\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Application Data\Microsoft\Feeds Cache\J8OT8ZQ3\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Application Data\Microsoft\Feeds Cache\PPDKBWMO\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Application Data\Microsoft\Feeds Cache\UZYJOFTF\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Application Data\Microsoft\Feeds Cache\WYQ5UAC2\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\History\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\History\History.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Temporary Internet Files\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Temporary Internet Files\Content.IE5\11SQ7349\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Temporary Internet Files\Content.IE5\5W53DU7A\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Temporary Internet Files\Content.IE5\D08OJZKD\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\Mik3\Local Settings\Temporary Internet Files\Content.IE5\GKBZYDJH\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\OPSTGTQR\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\UHCB078V\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\UKBEHA5D\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\UTY74RAN\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\OEM\Local Settings\History\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\OEM\Local Settings\History\History.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\OEM\Local Settings\Temporary Internet Files\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\OEM\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\OEM\Local Settings\Temporary Internet Files\Content.IE5\OPSTGTQR\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\OEM\Local Settings\Temporary Internet Files\Content.IE5\UHCB078V\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\OEM\Local Settings\Temporary Internet Files\Content.IE5\UKBEHA5D\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\Documents and Settings\OEM\Local Settings\Temporary Internet Files\Content.IE5\UTY74RAN\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\WINDOWS\system32\config\systemprofile\Local Settings\History\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]
CLSID={FF393560-C2A7-11CF-BFF4-444553540000}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\OPSTGTQR\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UHCB078V\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UKBEHA5D\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]

C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UTY74RAN\DESKTOP.INI
[.ShellClassInfo]
UICLSID={7BD29E00-76C1-11CF-9DD0-00A0C9034933}
  -> {HKLM...CLSID}\InProcServer32\(Default) = "C:\WINDOWS\system32\ieframe.dll" [MS]


Startup items in "Mik3" & "All Users" startup folders:
------------------------------------------------------

C:\Documents and Settings\Mik3\Start Menu\Programs\Startup
"csrss" -> shortcut to: "" [file not found]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Cisco Systems VPN Client" -> shortcut to: "C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe "-run_only_if_connected" "-auto_initiation"" ["Cisco Systems, Inc."]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 21
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}"
  -> {HKLM...CLSID} = "MSN"
                   \InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll" [MS]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0}" = "0"
  -> {HKLM...CLSID} = "MSN"
                   \InProcServer32\(Default) = "C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll" [MS]
"{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"
  -> {HKLM...CLSID} = "Easy-WebPrint"
                   \InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]

Explorer Bars

Dormant Explorer Bars in "View, Explorer Bar" menu

HKLM\Software\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\(Default) = "Easy-WebPrint"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}"
  -> {HKCU...CLSID} = "Java Plug-in"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll" ["Sun Microsystems, Inc."]
  -> {HKLM...CLSID} = "Java Plug-in 1.5.0_06"
                   \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll" ["Sun Microsystems, Inc."]

{7220F1C9-B7E0-47A6-A0BD-D5B3940BCC79}\
"ButtonText" = "PokerTime Poker"
"Exec" = "C:\Program Files\PokerTimeMPP\MPPoker.exe" ["Microgaming"]

{85D1F590-48F4-11D9-9669-0800200C9A66}\
"MenuText" = "Uninstall BitDefender Online Scanner v8"
"Exec" = "%windir%\bdoscandel.exe" [null data]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe" [MS]


Miscellaneous IE Hijack Points
------------------------------

C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")

Added lines (compared with English-language version):
[Strings]: START_PAGE_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[Strings]: MS_START_PAGE_URL="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

Missing lines (compared with English-language version):
[Strings]: 2 lines

HKLM\Software\Microsoft\Internet Explorer\AboutURLs\
HIJACK WARNING! "NavigationFailure" = "res://ieframe.dll/navcancl.htm" [MS]
HIJACK WARNING! "DesktopItemNavigationFailure" = "res://ieframe.dll/navcancl.htm" [MS]
HIJACK WARNING! "NavigationCanceled" = "res://ieframe.dll/navcancl.htm" [MS]
HIJACK WARNING! "OfflineInformation" = "res://ieframe.dll/offcancl.htm" [MS]
HIJACK WARNING! "PostNotCached" = "res://ieframe.dll/repost.htm" [MS]
HIJACK WARNING! "NoAdd-ons" = "res://ieframe.dll/noaddon.htm" [MS]
HIJACK WARNING! "NoAdd-onsInfo" = "res://ieframe.dll/noaddoninfo.htm" [MS]
HIJACK WARNING! "SecurityRisk" = "res://ieframe.dll/securityatrisk.htm" [MS]
HIJACK WARNING! "Tabs" = "res://ieframe.dll/tabswelcome.htm" [MS]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe" ["GRISOFT, s.r.o."]
AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe" ["GRISOFT, s.r.o."]
Cisco Systems, Inc. VPN Service, CVPND, ""C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe"" ["Cisco Systems, Inc."]
iPodService, iPodService, "C:\Program Files\iPod\bin\iPodService.exe" ["Apple Computer, Inc."]
NVIDIA Driver Helper Service, NVSvc, "C:\WINDOWS\System32\nvsvc32.exe" ["NVIDIA Corporation"]
Windows User Mode Driver Framework, UMWdf, "C:\WINDOWS\system32\wdfmgr.exe" [MS]


Keyboard Driver Filters:
------------------------

HKLM\System\CurrentControlSet\Control\Class\{4D36E96B-E325-11CE-BFC1-08002BE10318}\
"UpperFilters" = INFECTION WARNING! "Lkbdflt2" ["Logitech"]


Print Monitors:
---------------

HKLM\System\CurrentControlSet\Control\Print\Monitors\
Bluebeam PDF Monitor\Driver = "BBPDFPortMon.dll" [null data]
Canon BJ Language Monitor PIXMA iP1500\Driver = "CNMLM5y.DLL" ["CANON INC."]


----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
  took 70 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
  took 64 seconds.
---------- (total run time: 189 seconds)

Edited by mike_2000_17: Fixed formatting

0

Download the attached zip file and unzip fixme.reg. Close all browser windows. Double click the file to run it and when asked if you want to merge with your registry, answer yes.
Reboot when done.
I am not seeing LOP in that log, so after rebooting, post another hijackthis log please and let me know how the pc is.

0

alright... i think that the LOP is all gone, so thanks a lot for the help but right now im trying to get rid of Microgaming, I dunno if its to much but can you just take a look and mabye help get rid of that too.. thanks a lot

Logfile of HijackThis v1.99.1
Scan saved at 12:27:34 PM, on 6/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Mik3\Desktop\Desktop stuff\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.25.0\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Registry Cleaner] "C:\Program Files\Registry Cleaner Trial\regclean.exe"
O4 - Startup: csrss.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Program Files\PokerTimeMPP\MPPoker.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1671869C-25B3-4C80-9446-8AE6111F8765} (MaxisHotDateTeleX Control) - http://thesims.ea.com/teleport/hotdate/NPC/MaxisHotDateTeleX.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2DAE59A1-B355-4653-8D33-33A3A8F8C078} (MaxisVacationTeleX Control) - http://thesims.ea.com/teleport/vacation/MaxisVacationTeleX.cab
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://www.jetsetpoker.com/setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {8629CFEB-C31A-4429-9BB0-8765A8A24FDA} (MaxisUnleashedLotTeleX Control) - http://thesims.ea.com/teleport/unleashed/LOT/MaxisUnleashedLotTeleX.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/vso/en-us/tools/mcfscan/2,0,0,4438/mcfscan.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ums.uwo.ca
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

0

Can you please do the following.

===============

Scan with HiJackThis, then check(tick) the following, if present:

O9 - Extra button: PokerTime Poker - {7220F1C9-B7E0-47a6-A0BD-D5B3940BCC79} - C:\Program Files\PokerTimeMPP\MPPoker.exe

O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhel...7/dlhelper.cab


Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked".

===============

Locate and delete the following item(s), if present. Make sure you are able to view system and hidden files/ folders:

folders...

C:\Program Files\PokerTimeMPP

-

Note that some of these file(s)/folder(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in "Safe Mode".

-

Reboot.

===============

That's it :).

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.