I've run the SmitfraudFix and SysProtect Remover but am still getting these popups. I also ran spybot and removed many entries. I ran Blacklight but it didn't find anything. Below is the output of combofix, silent runners and hijackthis. Please help. I need to clean this up by Sat morning. Thank you!
COMBOFIX
Owner - 06-11-17 18:52:27.28 Service Pack 2
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\Owner\Desktop"
((((((((((((((((((((((((((
((((( Files Created from 2006-10-17 to 2006-11-17 ))))))))))))))))))))))))))
))))))))
2006-11-17 09:07 53,248 --a------ C:\WINDOWS\system32\Proces
s.exe
2006-11-17 09:07 40,960 --a------ C:\WINDOWS\system32\swsc.e
xe
2006-11-17 09:07 288,417 --a------ C:\WINDOWS\system32\SrchST
S.exe
2006-11-17 09:07 135,168 --a------ C:\WINDOWS\system32\swreg.
exe
2006-11-17 08:56 5,932 --a------ C:\WINDOWS\system32\tmp.re
g
2006-11-17 08:12 12,160 --a------ C:\WINDOWS\system32\driver
s\mouhid.s
ys
2006-11-17 08:11 9,600 --a------ C:\WINDOWS\system32\driver
s\hidusb.s
ys
2006-11-13 18:14 29,184 --a------ C:\Documents and Settings\Owner\aesznfkz.ex
e
2006-11-01 08:25 29,184 --a------ C:\Documents and Settings\Owner\ccrgnuvp.ex
e
2006-10-23 18:30 43,520 --a------ C:\WINDOWS\system32\CmdLin
eExt03.dll
2006-10-23 16:16 106,516 --a------ C:\WINDOWS\system32\lfmhsu
ue.dll
2006-10-22 16:13 106,516 --a------ C:\WINDOWS\system32\rgevxw
cj.dll
2006-10-21 16:09 106,516 --a------ C:\WINDOWS\system32\xnnwde
ce.dll
2006-10-20 16:05 106,516 --a------ C:\WINDOWS\system32\ioarfy
rf.dll
2006-10-19 15:39 106,516 --a------ C:\WINDOWS\system32\hoevpe
fp.dll
2006-10-17 15:54 18,048 --a------ C:\WINDOWS\system32\driver
s\lirsgt.s
ys
2006-10-17 15:54 165,376 --a------ C:\WINDOWS\system32\driver
s\atksgt.s
ys
((((((((((((((((((((((((((
((((((((((
((((((((((
(( Find3M Report ))))))))))))))))))))))))))
))))))))))
))))))))))
)))))))
2006-11-17 18:47 -------- d-------- C:\Program Files\Viewpoint
2006-11-17 14:00 -------- d-------- C:\Program Files\MyWay
2006-11-17 09:32 -------- d-------- C:\Program Files\Yahoo!
2006-11-17 09:32 -------- d-------- C:\Program Files\CCleaner
2006-11-12 16:19 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-11-12 16:19 -------- d-------- C:\Program Files\The Creative Assembly
2006-11-12 13:23 -------- d-------- C:\Program Files\Strategy First
2006-11-06 17:18 -------- d-------- C:\Program Files\InterActual
2006-10-30 23:16 -------- d-------- C:\Documents and Settings\Owner\Application
Data\SpieleEntwicklungsKom
binat
2006-10-30 23:15 -------- d-------- C:\Program Files\LimeWire
2006-10-25 15:21 -------- d-------- C:\Program Files\SEGA
2006-10-18 10:09 -------- d-------- C:\Program Files\iTunes
2006-10-18 10:08 -------- d-------- C:\Program Files\iPod
2006-10-18 10:06 -------- d-------- C:\Program Files\QuickTime
2006-10-18 10:01 -------- d-------- C:\Program Files\Apple Software Update
2006-10-10 14:53 -------- d-------- C:\Program Files\THQ
2006-10-10 14:47 -------- d-------- C:\Documents and Settings\Owner\Application
Data\InstallShield
2006-10-09 20:55 106516 --a------ C:\WINDOWS\system32\cvshwr
ye.dll
2006-10-09 20:54 1547724 ---hs---- C:\WINDOWS\system32\hjjlm.
bak2
2006-10-09 09:57 98304 --a------ C:\WINDOWS\system32\CmdLin
eExt.dll
2006-10-03 06:07 143380 --a------ C:\WINDOWS\system32\xgpusu
fc.exe
2006-10-03 06:07 106516 --a------ C:\WINDOWS\system32\atumpd
tg.dll
2006-10-03 06:05 106516 --a------ C:\WINDOWS\system32\mvujvc
nf.dll
2006-09-25 21:03 106516 --a------ C:\WINDOWS\system32\rmpvjq
uj.dll
2006-09-21 21:36 106516 --a------ C:\WINDOWS\system32\vbmvwf
tk.dll
2006-09-20 19:12 106516 --a------ C:\WINDOWS\system32\jdhlds
pe.dll
2006-09-20 19:11 106516 --a------ C:\WINDOWS\system32\rxdbed
xc.dll
2006-09-19 15:46 106516 --a------ C:\WINDOWS\system32\qtquwq
we.dll
2006-09-19 15:46 106516 --a------ C:\WINDOWS\system32\ishetr
ua.dll
2006-09-13 00:01 1084416 --a------ C:\WINDOWS\system32\msxml3
.dll
2006-09-11 18:28 106516 --a------ C:\WINDOWS\system32\voeaqr
ae.dll
2006-09-10 18:23 106516 --a------ C:\WINDOWS\system32\xubfnk
pl.dll
2006-09-09 17:21 106516 --a------ C:\WINDOWS\system32\ecfabr
bh.dll
2006-09-08 17:18 106516 --a------ C:\WINDOWS\system32\nfpdhh
qk.dll
2006-09-06 21:40 106516 --a------ C:\WINDOWS\system32\xuhjkj
dq.dll
2006-09-05 11:33 106516 --a------ C:\WINDOWS\system32\mppkih
pl.dll
2006-09-02 18:42 21840 --a----t- C:\WINDOWS\system32\SIntfN
T.dll
2006-09-02 18:42 17212 --a----t- C:\WINDOWS\system32\SIntf3
2.dll
2006-09-02 18:42 12067 --a----t- C:\WINDOWS\system32\SIntf1
6.dll
2006-08-25 10:45 617472 --a------ C:\WINDOWS\system32\comctl
32.dll
2006-08-24 11:29 2829 --a------ C:\WINDOWS\War3Unin.pif
2006-08-24 11:29 139264 --a------ C:\WINDOWS\War3Unin.exe
2006-08-21 11:29 28672 --a------ C:\WINDOWS\system32\f3PSSa
vr.scr
2006-08-21 07:21 16896 --a------ C:\WINDOWS\system32\fltlib
.dll
2006-08-21 04:14 23040 --a------ C:\WINDOWS\system32\fltmc.
exe
2006-08-17 13:56 13844 --a------ C:\WINDOWS\system32\combey
gy.exe
((((((((((((((((((((((((((
((((((((((
(((((( Reg Loading Points ))))))))))))))))))))))))))
))))))))))
))))))))))
))
*Note* empty entries are not shown
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\run]
"Hwt9RUbsl"="avtatson.exe"
"You've Got Pictures Screensaver"="C:\\Program Files\\Common Files\\AOL\\Screensaver\\y
gpsstra.ex
e"
"MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYW
EBS~1\\bar
\\1.bin\\m
wsoemon.ex
e"
"BackupNotify"="c:\\Progra
m Files\\HP\\Digital Imaging\\bin\\backupnotify
.exe"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\run]
"SunJavaUpdateSched"="C:\\
Program Files\\Java\\jre1.5.0_03\\
bin\\jusch
ed.exe"
"hpsysdrv"="c:\\windows\\s
ystem\\hps
ysdrv.exe"
"HotKeysCmds"="C:\\WINDOWS
\\system32
\\hkcmd.ex
e"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpc
mpmgr.exe\
""
"HPHUPD05"="c:\\Program Files\\HP\\{45B6180B-DCAB-
4093-8EE8-
6164457517
F0}\\hphup
d05.exe"
"HPHmon05"="C:\\WINDOWS\\S
ystem32\\h
phmon05.ex
e"
"Recguard"="C:\\WINDOWS\\S
MINST\\REC
GUARD.EXE"
"VTTimer"="VTTimer.exe"
"AGRSMMSG"="AGRSMMSG.exe"
"PS2"="C:\\WINDOWS\\system
32\\ps2.ex
e"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\Sys
tem32\\spo
ol\\driver
s\\w32x86\
\3\\hpztsb
08.exe"
"IgfxTray"="C:\\WINDOWS\\s
ystem32\\i
gfxtray.ex
e"
"HostManager"="C:\\Program
Files\\Common Files\\AOL\\1102937549\\ee
\\AOLSoftw
are.exe"
"-
"="C:\\WINDOWS\\itlhb.exe
"
"rylajgd"="C:\\WINDOWS\\ry
lajgd.exe"
"Tcsxu"="C:\\Program Files\\Twru\\Dxivcvp.exe"
"072V38X"="batctrac.exe"
"SoundMan"="SOUNDMAN.EXE"
"AlcWzrd"="ALCWZRD.EXE"
"Alcmtr"="ALCMTR.EXE"
"Á³# L\"h'þ9Óð3rÅWC:\\Progra
m Files\\ISTsvc\\istsvc.exe"
="C:\\WIND
OWS\\itlhb
.exe"
"Á²# L\"h'þ9Óð3rÅWC:\\Progra
m Files\\ISTsvc\\istsvc.exe"
="C:\\WIND
OWS\\itlhb
.exe"
"RoxioDragToDisc"="\"C:\\P
rogram Files\\Roxio\\Easy Media Creator 7\\Drag to Disc\\DrgToDsc.exe\""
"NvCplDaemon"="RUNDLL32.EX
E C:\\WINDOWS\\system32\\NvC
pl.dll,NvS
tartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.
EXE C:\\WINDOWS\\system32\\NvM
cTray.dll,
NvTaskbarI
nit"
"sscRun"="C:\\Program Files\\Common Files\\AOL\\1102937549\\ee
\\services
\\sscFirew
allPlugin\
\ver1_210_
2_1\\SSCRu
n.exe"
"OASClnt"="C:\\Program Files\\mcafee.com\\antivir
us\\oascln
t.exe"
"EmailScan"="C:\\Program Files\\mcafee.com\\antivir
us\\mcvses
cn.exe"
"MPFExe"="C:\\Program Files\\mcafee.com\\persona
l firewall\\MPfTray.exe"
"TkBellExe"="\"C:\\Program
Files\\Common Files\\Real\\Update_OB\\re
alsched.ex
e\" -osboot"
"My Web Search Bar"="rundll32 C:\\PROGRA~1\\MYWEBS~1\\ba
r\\1.bin\\
MWSBAR.DLL
,S"
"MyWebSearch Email Plugin"="C:\\PROGRA~1\\MYW
EBS~1\\bar
\\1.bin\\m
wsoemon.ex
e"
"MSConfig"="C:\\WINDOWS\\P
CHealth\\H
elpCtr\\Bi
naries\\MS
Config.exe
/auto"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\run\
OptionalCo
mponents]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\run\
OptionalCo
mponents\I
MAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\run\
OptionalCo
mponents\M
API]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\run\
OptionalCo
mponents\M
SFS]
"Installed"="1"
[HKEY_CURRENT_USER\softwar
e\microsof
t\internet
explorer\desktop\component
s]
"DeskHtmlVersion"=dword:00
000110
"DeskHtmlMinorVersion"=dwo
rd:0000000
5
"Settings"=dword:00000001
"GeneralFlags"=dword:00000
000
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\expl
orer\share
dtasksched
uler]
"{438755C2-A8BA-11D1-B96B-
00A0C90312
E1}"="Brow
seui preloader"
"{8C7461EF-2B13-11d2-BE35-
3078302C20
30}"="Comp
onent Categories cache daemon"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\expl
orer\shell
executehoo
ks]
"{AEB6717E-7E19-11d0-97EE-
00C04FD919
72}"=""
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\polic
ies\explor
er]
"NoDriveTypeAutoRun"=dword
:00000091
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\polic
ies\explor
er\Run]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\poli
cies\syste
m]
"dontdisplaylastusername"=
dword:0000
0000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dwo
rd:0000000
1
"undockwithoutlogon"=dword
:00000001
[HKEY_USERS\.default\softw
are\micros
oft\window
s\currentv
ersion\pol
icies\expl
orer]
"NoDriveTypeAutoRun"=dword
:00000091
"CDRAutoRun"=dword:0000000
0
[HKEY_USERS\s-1-5-18\softw
are\micros
oft\window
s\currentv
ersion\pol
icies\expl
orer]
"NoDriveTypeAutoRun"=dword
:00000091
"CDRAutoRun"=dword:0000000
0
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\windows
\currentve
rsion\shel
lserviceob
jectdelayl
oad]
"PostBootReminder"="{78495
96a-48ea-4
86e-8937-a
2a3009f31a
9}"
"CDBurn"="{fbeb8a05-beee-4
442-804e-4
09d6c4515e
9}"
"WebCheck"="{E6FB5E20-DE35
-11CF-9C87
-00AA00512
7ED}"
"SysTray"="{35CEC8A3-2BE6-
11D2-8773-
92E2205241
53}"
"WPDShServiceObj"="{AAA288
BA-9A4C-45
B0-95D7-94
D524869DB5
}"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupfold
er]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupfold
er\C:^Docu
ments and Settings^All Users^Start Menu^Programs^Startup^Upda
tes from HP.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\U
pdates from HP.lnk"
"backup"="C:\\WINDOWS\\pss
\\Updates from HP.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\U
PDATE~1\\1
37903\\Pro
gram\\BACK
WE~1.EXE -startup"
"item"="Updates from HP"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
AOLDialer]
"key"="SOFTWARE\\Microsoft
\\Windows\
\CurrentVe
rsion\\Run
"
"item"="AOLDial"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.e
xe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
iTunesHelp
er]
"key"="SOFTWARE\\Microsoft
\\Windows\
\CurrentVe
rsion\\Run
"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelpe
r.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
MSMSGS]
"key"="SOFTWARE\\Microsoft
\\Windows\
\CurrentVe
rsion\\Run
"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.e
xe\" /background"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\softwa
re\microso
ft\shared tools\msconfig\startupreg\
QuickTime Task]
"key"="SOFTWARE\\Microsoft
\\Windows\
\CurrentVe
rsion\\Run
"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.e
xe\" -atboottime"
"inimapping"="0"
HKEY_LOCAL_MACHINE\softwar
e\microsof
t\windows nt\currentversion\winlogon
\notify\ml
jjh
[HKEY_LOCAL_MACHINE\system
\currentco
ntrolset\c
ontrol\sec
urityprovi
ders]
"SecurityProviders"="msaps
spc.dll, schannel.dll, digest.dll, msnsspc.dll"
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoft
wareUpdate
.job
Completion time: 06-11-17 18:54:20.76
C:\ComboFix.txt ... 06-11-17 18:54
SILENT RUNNERS
"Silent Runners.vbs", revision 49,
http://www.silentrunners.org/Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
--------------------------
-------
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run\ {++}
"Hwt9RUbsl" = "avtatson.exe" [file not found]
"You've Got Pictures Screensaver" = "C:\Program Files\Common Files\AOL\Screensaver\ygps
stra.exe" ["America Online Inc"]
"MyWebSearch Email Plugin" = "C:\PROGRA~1\MYWEBS~1\bar\
1.bin\mwso
emon.exe" [file not found]
"BackupNotify" = "c:\Program Files\HP\Digital Imaging\bin\backupnotify.e
xe" [null data]
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run\ {++}
"SunJavaUpdateSched" = "C:\Program Files\Java\jre1.5.0_03\bin
\jusched.e
xe" ["Sun Microsystems, Inc."]
"hpsysdrv" = "c:\windows\system\hpsysdr
v.exe" ["Hewlett-Packard Company"]
"HotKeysCmds" = "C:\WINDOWS\system32\hkcmd
.exe" ["Intel Corporation"]
"HP Component Manager" = ""C:\Program Files\HP\hpcoretech\hpcmpm
gr.exe"" ["Hewlett-Packard Company"]
"HPHUPD05" = "c:\Program Files\HP\{45B6180B-DCAB-40
93-8EE8-61
64457517F0
}\hphupd05
.exe" ["Hewlett-Packard"]
"HPHmon05" = "C:\WINDOWS\System32\hphmo
n05.exe" ["Hewlett-Packard"]
"Recguard" = "C:\WINDOWS\SMINST\RECGUAR
D.EXE" [empty string]
"VTTimer" = "VTTimer.exe" [file not found]
"AGRSMMSG" = "AGRSMMSG.exe" ["Agere Systems"]
"PS2" = "C:\WINDOWS\system32\ps2.e
xe" ["Hewlett-Packard Company"]
"HPDJ Taskbar Utility" = "C:\WINDOWS\System32\spool
\drivers\w
32x86\3\hp
ztsb08.exe
" ["HP"]
"IgfxTray" = "C:\WINDOWS\system32\igfxt
ray.exe" ["Intel Corporation"]
"HostManager" = "C:\Program Files\Common Files\AOL\1102937549\ee\AO
LSoftware.
exe" ["America Online, Inc."]
"-**" (unwritable string) = "C:\WINDOWS\itlhb.exe" [file not found]
"rylajgd" = "C:\WINDOWS\rylajgd.exe" [file not found]
"Tcsxu" = "C:\Program Files\Twru\Dxivcvp.exe" [null data]
"072V38X" = "batctrac.exe" [file not found]
"SoundMan" = "SOUNDMAN.EXE" ["Realtek Semiconductor Corp."]
"AlcWzrd" = "ALCWZRD.EXE" ["RealTek Semicoductor Corp."]
"Alcmtr" = "ALCMTR.EXE" ["Realtek Semiconductor Corp."]
"Á*³#* L"h'þ9Óð3rÅ*WC:\Pr
ogram Files\ISTsvc\istsvc.exe" (unwritable string) = "C:\WINDOWS\itlhb.exe" [file not found]
"Á*²#* L"h'þ9Óð3rÅ*WC:\Pr
ogram Files\ISTsvc\istsvc.exe" (unwritable string) = "C:\WINDOWS\itlhb.exe" [file not found]
"RoxioDragToDisc" = ""C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"" ["Sonic Solutions"]
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup" [MS]
"nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
"NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr
ay.dll,NvT
askbarInit
" [MS]
"sscRun" = "C:\Program Files\Common Files\AOL\1102937549\ee\se
rvices\ssc
FirewallPl
ugin\ver1_
210_2_1\SS
CRun.exe" ["America Online"]
"OASClnt" = "C:\Program Files\mcafee.com\antivirus
\oasclnt.e
xe" ["McAfee, Inc."]
"EmailScan" = "C:\Program Files\mcafee.com\antivirus
\mcvsescn.
exe" ["McAfee, Inc."]
"MPFExe" = "C:\Program Files\mcafee.com\personal firewall\MPfTray.exe" ["McAfee Security"]
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot" ["RealNetworks, Inc."]
"My Web Search Bar" = "rundll32 C:\PROGRA~1\MYWEBS~1\bar\1
.bin\MWSBA
R.DLL,S" [MS]
"MyWebSearch Email Plugin" = "C:\PROGRA~1\MYWEBS~1\bar\
1.bin\mwso
emon.exe" [file not found]
"MSConfig" = "C:\WINDOWS\PCHealth\HelpC
tr\Binarie
s\MSConfig
.exe /auto" [MS]
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
Browser Helper Objects\
{02478D38-C3F9-4EFB-9B51-7
695ECA0567
0}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = "AcroIEHlprObj Class"
\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll"
["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-2
06D7942484
F}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHe
lper.dll" ["Safer Networking Limited"]
{6D33B121-5C4C-4450-9D1F-7
B67085CC19
9}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = "WTLHelper Object"
\InProcServer32\(Default) = "C:\WINDOWS\system32\mljjh
.dll" [null data]
{7C554162-8CB7-45A4-B8F4-8
EA1C75885F
9}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = "AOL Toolbar Launcher"
\InProcServer32\(Default) = "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll" ["America Online, Inc."]
{D5F224B8-3D4F-3A58-F697-4
15C8C9D760
9}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\Lktbgzsf.dll" [file not found]
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-
00a0c9068f
f3}" = "Display Panning CPL Extension"
-> {HKLM...CLSID} = "Display Panning CPL Extension"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-
00AA0030EB
C8}" = "HyperTerminal Icon Ext"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "C:\WINDOWS\System32\htico
ns.dll" ["Hilgraeve, Inc."]
"{F0CB00CD-5A07-4D91-97F5-
A8C92CDA93
E4}" = "Shell Extensions for RealOne Player"
-> {HKLM...CLSID} = "RealOne Player Context Menu Class"
\InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpsh
ell.dll" ["RealNetworks, Inc."]
"{00020D75-0000-0000-C000-
0000000000
46}" = "Microsoft Office Outlook Desktop Icon Handler"
-> {HKLM...CLSID} = "Microsoft Office Outlook"
\InProcServer32\(Default) = "C:\PROGRA~1\MI1933~1\OFFI
CE11\MLSHE
XT.DLL" [MS]
"{0006F045-0000-0000-C000-
0000000000
46}" = "Microsoft Office Outlook Custom Icon Handler"
-> {HKLM...CLSID} = "Outlook File Icon Extension"
\InProcServer32\(Default) = "C:\PROGRA~1\MI1933~1\OFFI
CE11\OLKFS
TUB.DLL" [MS]
"{42042206-2D85-11D3-8CFF-
0050048385
97}" = "Microsoft Office HTML Icon Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Microsoft Office\OFFICE11\msohev.dll
" [MS]
"{7F67036B-66F1-411A-AD85-
759FB9C5B0
DB}" = "SampleView"
-> {HKLM...CLSID} = "SampleView"
\InProcServer32\(Default) = "C:\WINDOWS\System32\Shell
vRTF.dll" ["XSS"]
"{acb4a560-3606-11d3-aef4-
00104bd0f9
2d}" = "KodakShellExtension"
-> {HKLM...CLSID} = "KodakShellExtension"
\InProcServer32\(Default) = "C:\Program Files\Common Files\KODAK\IFSCore\kodaks
hx.dll" ["Eastman Kodak Company"]
"{B9E1D2CB-CCFF-4AA6-9579-
D7A4754030
EF}" = "iTunes"
-> {HKLM...CLSID} = "iTunes"
\InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPla
yer.dll" ["Apple Computer, Inc."]
"{0873D142-79EF-49fa-81B5-
211AAC0B0A
7F}" = "Target Finder Shell Extension"
-> {HKLM...CLSID} = "TargetFinderShlExt Class"
\InProcServer32\(Default) = "C:\Program Files\Roxio\Easy Media Creator 7\Creator Classic\TargetFinder.dll" [empty string]
"{5E44E225-A408-11CF-B581-
0080296011
08}" = "Roxio DragToDisc Shell Extension"
-> {HKLM...CLSID} = "Roxio DragToDisc Shell Extension"
\InProcServer32\(Default) = "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\Shellex.dll" ["Sonic Solutions"]
"{A70C977A-BF00-412C-90B7-
034C51DA24
39}" = "NvCpl DesktopContext Class"
-> {HKLM...CLSID} = "DesktopContext Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl
.dll" ["NVIDIA Corporation"]
"{FFB699E0-306A-11d3-8BD1-
00104B6F75
16}" = "Play on my TV helper"
-> {HKLM...CLSID} = "NVIDIA CPL Extension"
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvcpl
.dll" ["NVIDIA Corporation"]
"{1CDB2949-8F65-4355-8456-
263E7C208A
5D}" = "Desktop Explorer"
-> {HKLM...CLSID} = "Desktop Explorer"
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvshe
ll.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-
B8DA88302A
47}" = "Desktop Explorer Menu"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvshe
ll.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-
B8DA88302A
48}" = "nView Desktop Context Menu"
-> {HKLM...CLSID} = "nView Desktop Context Menu"
\InProcServer32\(Default) = "C:\WINDOWS\system32\nvshe
ll.dll" ["NVIDIA Corporation"]
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\ShellServ
iceObjectD
elayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-
94D524869D
B5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
\InProcServer32\(Default) = "C:\WINDOWS\system32\WPDSh
ServiceObj
.dll" [MS]
HKLM\Software\Microsoft\Wi
ndows NT\CurrentVersion\Winlogon
\Notify\
<<!>> igfxcui\DLLName = "igfxsrvc.dll" ["Intel Corporation"]
<<!>> mljjh\DLLName = "C:\WINDOWS\system32\mljjh
.dll" [null data]
HKLM\Software\Classes\PROT
OCOLS\Filt
er\
<<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-
00B0D022E9
45}"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.D
LL" [MS]
Group Policies {policy setting}:
--------------------------
------
Note: detected settings may not have any effect.
HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Policies\
System\
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Devices: Allow undock without having to log on}
Active Desktop and Wallpaper:
--------------------------
---
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Explorer\
ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\In
ternet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\web\wallpaper\
Bliss.bmp"
Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\System32\ssmyp
ics.scr" [MS]
Startup items in "Owner" & "All Users" startup folders:
--------------------------
----------
----------
---------
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"HP Digital Imaging Monitor" -> shortcut to: "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe" ["Hewlett-Packard Co."]
"Kodak EasyShare software" -> shortcut to: "C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
-h" ["Eastman Kodak Company"]
"Kodak software updater" -> shortcut to: "C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Ko
dak Software Updater.exe" [null data]
"Picture Package Menu" -> shortcut to: "C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe" ["Sony Corporation"]
"Picture Package VCD Maker" -> shortcut to: "C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
-h" ["Sony Corporation."]
Enabled Scheduled Tasks:
------------------------
"AppleSoftwareUpdate" -> launches: "C:\Program Files\Apple Software Update\SoftwareUpdate.exe -Task" ["Apple Computer, Inc."]
Winsock2 Service Provider DLLs:
--------------------------
-----
Namespace Service Providers
HKLM\System\CurrentControl
Set\Servic
es\Winsock
2\Paramete
rs\NameSpa
ce_Catalog
5\Catalog_
Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\msw
sock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\win
rnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\msw
sock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControl
Set\Servic
es\Winsock
2\Paramete
rs\Protoco
l_Catalog9
\Catalog_E
ntries\ {++}
0000000000##\PackedCatalog
Item (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\msws
ock.dll [MS], 01 - 03, 06 - 19
%SystemRoot%\system32\rsvp
sp.dll [MS], 04 - 05
Toolbars, Explorer Bars, Extensions:
--------------------------
----------
Toolbars
HKCU\Software\Microsoft\In
ternet Explorer\Toolbar\ShellBrow
ser\
"{07B18EA9-A523-4961-B6BB-
170DE4475C
CA}"
-> {HKLM...CLSID} = "My &Web Search"
\InProcServer32\(Default) = "C:\Program Files\MyWebSearch\bar\1.bi
n\MWSBAR.D
LL" [file not found]
HKCU\Software\Microsoft\In
ternet Explorer\Toolbar\WebBrowse
r\
"{DE9C389F-3316-41A7-809B-
AA305ED9D9
22}"
-> {HKLM...CLSID} = "AOL Toolbar"
\InProcServer32\(Default) = "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll" ["America Online, Inc."]
"{EF99BD32-C1FB-11D2-892F-
0090271D4F
88}"
-> {HKLM...CLSID} = "Yahoo! Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll" ["Yahoo! Inc."]
HKLM\Software\Microsoft\In
ternet Explorer\Toolbar\
"{B2847E28-5D7D-4DEB-8B67-
05D28BCF79
F5}" = (no title provided)
-> {HKLM...CLSID} = "HP view"
\InProcServer32\(Default) = "c:\program files\hp\digital imaging\bin\hpdtlk02.dll" ["Hewlett-Packard Company"]
"{33676672-676C-76E0-B73B-
543587D2AF
4E}" = (no title provided)
-> {HKLM...CLSID} = "Search"
\InProcServer32\(Default) = "C:\WINDOWS\Lktbgzsf.dll" [file not found]
"{DE9C389F-3316-41A7-809B-
AA305ED9D9
22}" = "AOL Toolbar"
-> {HKLM...CLSID} = "AOL Toolbar"
\InProcServer32\(Default) = "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll" ["America Online, Inc."]
"{EF99BD32-C1FB-11D2-892F-
0090271D4F
88}" = (no title provided)
-> {HKLM...CLSID} = "Yahoo! Toolbar"
\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll" ["Yahoo! Inc."]
Explorer Bars
HKLM\Software\Microsoft\In
ternet Explorer\Explorer Bars\
{8F4902B6-6C04-4ADE-8052-A
A58578A21B
D}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = "hp view"
\InProcServer32\(Default) = "C:\WINDOWS\System32\Shdoc
vw.dll" [MS]
{FE54FA40-D68C-11D2-98FA-0
0C0F0318AF
E}\(Defaul
t) = (no title provided)
-> {HKLM...CLSID} = "Real.com"
\InProcServer32\(Default) = "C:\WINDOWS\system32\Shdoc
vw.dll" [MS]
HKLM\Software\Classes\CLSI
D\{B2847E2
8-5D7D-4DE
B-8B67-05D
28BCF79F5}
\(Default)
= "HP view"
Implemented Categories\{00021494-0000-
0000-C000-
0000000000
46}\ [horizontal bar]
InProcServer32\(Default) = "c:\program files\hp\digital imaging\bin\hpdtlk02.dll" ["Hewlett-Packard Company"]
HKLM\Software\Classes\CLSI
D\{FF059E3
1-CC5A-4E2
E-BF3B-96E
929D65503}
\(Default)
= "&Research"
Implemented Categories\{00021493-0000-
0000-C000-
0000000000
46}\ [vertical bar]
InProcServer32\(Default) = "C:\PROGRA~1\MI1933~1\OFFI
CE11\REFIE
BAR.DLL" [MS]
Extensions (Tools menu items, main toolbar menu buttons)
HKCU\Software\Microsoft\In
ternet Explorer\Extensions\
{AF6CABAB-61F9-4F12-A198-B
7D41EF1CB5
2}\
"ButtonText" = "WeatherBug"
"CLSIDExtension" = "{AF6CABAB-61F9-4f12-A198-
B7D41EF1CB
52}"
"Exec" = "C:\Program Files\AWS\WeatherBug\Weath
er.exe" [file not found]
HKLM\Software\Microsoft\In
ternet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1}\
"MenuText" = "Sun Java Console"
"CLSIDExtension" = "{08B0E5C0-4FCB-11CF-AAA5-
00401C6085
01}"
-> {HKLM...CLSID} = "Web Browser Applet Control"
\InProcServer32\(Default) = "C:\WINDOWS\system32\msjav
a.dll" [MS]
{3369AF0D-62E9-4BDA-8103-B
4C75499B57
8}\
"ButtonText" = "AOL Toolbar"
"CLSIDExtension" = "{DE9C389F-3316-41A7-809B-
AA305ED9D9
22}"
-> {HKLM...CLSID} = "AOL Toolbar"
\InProcServer32\(Default) = "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll" ["America Online, Inc."]
{92780B25-18CC-41C8-B9BE-3
C9C571A826
3}\
"ButtonText" = "Research"
{CD67F990-D8E9-11D2-98FE-0
0C0F0318AF
E}\
"ButtonText" = "Real.com"
{FB5F1910-F110-11D2-BB9E-0
0C04F79568
3}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "C:\Program Files\Messenger\msmsgs.exe
" [MS]
Miscellaneous IE Hijack Points
--------------------------
----
C:\WINDOWS\INF\IERESET.INF
(used to "Reset Web Settings")
Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhomeMissing lines (compared with English-language version):
[Strings]: 1 line
HKCU\Software\Microsoft\In
ternet Explorer\URLSearchHooks\
<<H>> "{EA756889-2338-43DB-8F07-
D1CA6FB9C9
0D}" = "AOL Search"
-> {HKLM...CLSID} = "AOLTBSearch Class"
\InProcServer32\(Default) = "C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll" ["America Online, Inc."]
<<H>> "{F56910AD-489D-543A-6FB6-
F31CEA173F
E9}" = (no title provided)
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = "C:\WINDOWS\Lktbgzsf.dll" [file not found]
Running Services (Display Name, Service Name, Path {Service DLL}):
--------------------------
----------
----------
----------
----------
AOL Antivirus Update Service, aolavupd, ""C:\Program Files\Common Files\AOL\1102937549\ee\se
rvices\ssc
FirewallPl
ugin\ver1_
210_2_1\ao
lavupd.exe
"" ["America Online"]
AOL Connectivity Service, AOL ACS, ""C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe"
" ["America Online"]
AOL TopSpeed Monitor, AOL TopSpeedMonitor, "C:\Program Files\Common Files\AOL\TopSpeed\2.0\aol
tsmon.exe"
["America Online, Inc"]
iPod Service, iPod Service, ""C:\Program Files\iPod\bin\iPodService
.exe"" ["Apple Computer, Inc."]
Kodak Camera Connection Software, KodakCCS, "C:\WINDOWS\system32\drive
rs\KodakCC
S.exe" ["Eastman Kodak Company"]
McAfee McShield, McShield, "C:\PROGRA~1\mcafee.com\AN
TIVI~1\mcs
hield.exe"
["McAfee Inc."]
McAfee Personal Firewall Service, MpfService, ""C:\Program Files\mcafee.com\personal firewall\MPFService.exe"" ["McAfee Corporation"]
NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\system32\nvsvc
32.exe" ["NVIDIA Corporation"]
WAN Miniport (ATW) Service, WANMiniportService, ""C:\WINDOWS\wanmpsvc.exe"
" ["America Online, Inc."]
WMP54Gv4SVC, WMP54Gv4SVC, ""C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe"" ["GEMTEKS"]
Print Monitors:
---------------
HKLM\System\CurrentControl
Set\Contro
l\Print\Mo
nitors\
hpzlnt08\Driver = "hpzlnt08.dll" ["HP"]
Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]
Microsoft Shared Fax Monitor\Driver = "FXSMON.DLL" [MS]
----------
<<!>>: Suspicious data at a malware launch point.
<<H>>: Suspicious data at a browser hijack point.
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
DLL launch points, use the -supp parameter or answer "No" at the
first message box and "Yes" at the second message box.
---------- (total run time: 72 seconds, including 31 seconds for message boxes)
HIJACKTHIS
Logfile of HijackThis v1.99.1
Scan saved at 7:01:34 PM, on 11/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aol
tsmon.exe
C:\Program Files\Common Files\AOL\1102937549\ee\se
rvices\ssc
FirewallPl
ugin\ver1_
210_2_1\ao
lavupd.exe
C:\WINDOWS\system32\driver
s\KodakCCS
.exe
C:\PROGRA~1\mcafee.com\ANT
IVI~1\mcsh
ield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\mcafee.com\personal firewall\MPFService.exe
C:\PROGRA~1\mcafee.com\ANT
IVI~1\OasC
lnt.exe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\Program Files\Common Files\AOL\1102937549\ee\ao
lsoftware.
exe
c:\program files\common files\aol\1102937549\ee\se
rvices\ssc
AntiSpywar
ePlugin\ve
r1_210_2_1
\AOLSP Scheduler.exe
c:\program files\common files\aol\1102937549\ee\ao
lssc.exe
C:\Program Files\Java\jre1.5.0_03\bin
\jusched.e
xe
C:\windows\system\hpsysdrv
.exe
C:\Program Files\HP\hpcoretech\hpcmpm
gr.exe
C:\WINDOWS\System32\hphmon
05.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ps2.ex
e
C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb08.exe
C:\Program Files\Twru\Dxivcvp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\mcafee.com\antivirus
\mcvsescn.
exe
C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.
exe
C:\Program Files\Common Files\AOL\Screensaver\ygps
stra.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService
.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\AOL\1102937549\ee\se
rvices\ssc
FirewallPl
ugin\ver1_
210_2_1\SS
CEvtHdlr.e
xe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Ko
dak Software Updater.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-
137903.exe
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807N
etInstalle
r.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hijackthis\HijackThis.e
xe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page_bak =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q304&bd=pavilion&pf=desktopR1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D
1CA6FB9C90
D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: (no name) - {F56910AD-489D-543A-6FB6-F
31CEA173FE
9} - C:\WINDOWS\Lktbgzsf.dll (file missing)
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7
695ECA0567
0} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH
elper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
06D7942484
F} - C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-0
00874180BB
3} - (no file)
O2 - BHO: WTLHelper Object - {6D33B121-5C4C-4450-9D1F-7
B67085CC19
9} - C:\WINDOWS\system32\mljjh.
dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8
EA1C75885F
9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {D5F224B8-3D4F-3A58-F697-4
15C8C9D760
9} - C:\WINDOWS\Lktbgzsf.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-2
09B6AD74AC
C} - (no file)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-0
5D28BCF79F
5} - c:\program files\hp\digital imaging\bin\hpdtlk02.dll
O3 - Toolbar: Search - {33676672-676C-76E0-B73B-5
43587D2AF4
E} - C:\WINDOWS\Lktbgzsf.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A
A305ED9D92
2} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - C:\Program Files\Yahoo!\Companion\Ins
talls\cpn\
yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin
\jusched.e
xe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv
.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpm
gr.exe"
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-40
93-8EE8-61
64457517F0
}\hphupd05
.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon
05.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD
.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.ex
e
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
drivers\w3
2x86\3\hpz
tsb08.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1102937549\ee\AO
LSoftware.
exe
O4 - HKLM\..\Run: [-
] C:\WINDOWS\itlhb.exe
O4 - HKLM\..\Run: [rylajgd] C:\WINDOWS\rylajgd.exe
O4 - HKLM\..\Run: [Tcsxu] C:\Program Files\Twru\Dxivcvp.exe
O4 - HKLM\..\Run: [072V38X] batctrac.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Á³# L"h'þ9Óð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\itlhb.exe
O4 - HKLM\..\Run: [Á²# L"h'þ9Óð3rÅWC:\Program Files\ISTsvc\istsvc.exe] C:\WINDOWS\itlhb.exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr
ay.dll,NvT
askbarInit
O4 - HKLM\..\Run: [sscRun] C:\Program Files\Common Files\AOL\1102937549\ee\se
rvices\ssc
FirewallPl
ugin\ver1_
210_2_1\SS
CRun.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\mcafee.com\antivirus
\oasclnt.e
xe
O4 - HKLM\..\Run: [EmailScan] C:\Program Files\mcafee.com\antivirus
\mcvsescn.
exe
O4 - HKLM\..\Run: [MPFExe] C:\Program Files\mcafee.com\personal firewall\MPfTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1
.bin\MWSBA
R.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1
.bin\mwsoe
mon.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCt
r\Binaries
\MSConfig.
exe /auto
O4 - HKCU\..\Run: [Hwt9RUbsl] avtatson.exe
O4 - HKCU\..\Run: [You've Got Pictures Screensaver] C:\Program Files\Common Files\AOL\Screensaver\ygps
stra.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1
.bin\mwsoe
mon.exe
O4 - HKCU\..\Run: [BackupNotify] c:\Program Files\HP\Digital Imaging\bin\backupnotify.e
xe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Ko
dak Software Updater.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsear
ch.htm
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.h
tml
O8 - Extra context menu item: &Search -
http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm090YYUSO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\system32\msjava
.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\WINDOWS\system32\msjava
.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B
4C75499B57
8} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MI1933~1\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - C:\WINDOWS\system32\Shdocv
w.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B
7D41EF1CB5
2} - C:\Program Files\AWS\WeatherBug\Weath
er.exe (file missing) (HKCU)
O15 - Trusted Zone:
http://www.amaena.comO15 - Trusted Zone:
http://locator.cdn.imageservr.comO15 - Trusted Zone:
http://scanner.sysprotect.comO15 - Trusted Zone:
http://*.systemdoctor.comO15 - Trusted Zone:
http://www.winantivirus.comO15 - Trusted Zone:
http://www.winantiviruspro.comO15 - Trusted Zone:
http://download.cdn.winsoftware.comO15 - Trusted IP range:
http://195.95.*.*O15 - Trusted IP range:
http://195.225.*.*O15 - Trusted IP range:
http://205.177.*.*O15 - Trusted IP range:
http://205.188.*.*O15 - Trusted IP range:
http://216.239.*.*O16 - DPF: {26FCCDF9-A7E1-452A-A73D-7
BF7B4D0BA6
C} (AOL Pictures Uploader Class) -
http://o.aolcdn.com/pictures/ap/Resources/2.2.0.51g/cab/aolpPlugins.10.4.0.2.cabO16 - DPF: {2E12FB00-546B-4EE3-9CC2-0
57BF02E1C1
7} (Webshots Multiple Media Uploader - Container) -
http://community.webshots.com/html/atx/wsaxcontrol.cabO16 - DPF: {4A3CF76B-EC7A-405D-A67D-8
DC6B52AB35
B} -
http://aolcc.aol.com/computercheckup/qdiagcc.cabO16 - DPF: {4CC35DAD-40EA-4640-ACC2-A
1A3B6FB3E0
6} (NeoterisSetup Control) -
https://secure.vnsny.org/dana-cached/setup/NeoterisSetup.cabO16 - DPF: {55027008-315F-4F45-BBC3-8
BE11976474
1} (Slide Image Uploader Control) -
http://www.slide.com/uploader/SlideImageUploader.cabO16 - DPF: {9FC5238F-12C4-454F-B1B5-7
4599A21DE4
7} (Webshots Photo Uploader) -
http://community.webshots.com/html/WSPhotoUploader.CABO16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F
66BAD1E3F3
A} -
http://download.cdn.winsoftware.com/files/installers/cab/WinAntiVirusPro2006FreeInstall.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C
18E1ADA438
9} (DwnldGroupMgr Class) -
http://download.av.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-7
3DB16A1543
A} (PopCapLoader Object) -
http://aolsvc.aol.com/onlinegames/chuzzledeluxe/popcaploader_v7.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsr
vc.dll
O20 - Winlogon Notify: mljjh - C:\WINDOWS\system32\mljjh.
dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLog
on.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-9
4D524869DB
5} - C:\WINDOWS\system32\WPDShS
erviceObj.
dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aol
tsmon.exe
O23 - Service: AOL Antivirus Update Service (aolavupd) - America Online - C:\Program Files\Common Files\AOL\1102937549\ee\se
rvices\ssc
FirewallPl
ugin\ver1_
210_2_1\ao
lavupd.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\driver
s\KodakCCS
.exe
O23 - Service: McAfee McShield (McShield) - McAfee Inc. - C:\PROGRA~1\mcafee.com\ANT
IVI~1\mcsh
ield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\Program Files\mcafee.com\personal firewall\MPFService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: WMP54Gv4SVC - Unknown owner - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe" "WMP54Gv4.exe (file missing)
Start Free Trial