﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Tweaks.com Forum  / Windows &amp; System Security / HiJack This Logs  / Persistent Spyware pop-ups (Virus Heat et.al) / Latest Posts</title><generator>InstantForum.NET v4.1.4</generator><description>Tweaks.com Forum </description><link>http://tweaks.com/forum/</link><webMaster>forum@tweaks.com</webMaster><lastBuildDate>Wed, 10 Mar 2010 18:29:04 GMT</lastBuildDate><ttl>20</ttl><item><title>RE: Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>You're most welcome:)</description><pubDate>Wed, 14 May 2008 01:48:29 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>PC is running smoothly now. Thank you very much for the help RichieUK, God bless.:)</description><pubDate>Wed, 14 May 2008 00:08:27 GMT</pubDate><dc:creator>antral917</dc:creator></item><item><title>RE: Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>Your log is clean:),please do the following:&lt;br&gt;&lt;br&gt;Click on Start/Run,copy and paste [b]ComboFix /u[/b] into the 'Open:' space,then press Ok.&lt;br&gt;This will uninstall Combofix,delete its related folders and files,reset your clock settings,hide file extensions,hide the system/hidden files and resets System Restore.&lt;br&gt;&lt;br&gt;[IMG]http://img.photobucket.com/albums/v624/29wood/comu.gif[/IMG]&lt;br&gt;&lt;br&gt;&lt;br&gt;You should take the time to read and follow the information found in the links below,to help you prevent any possible future infections and stay safe and secure while online:&lt;br&gt;&lt;br&gt;[b][color="blue"]Simple and easy ways to keep your computer safe and secure on the Internet[/color][/b]:&lt;br&gt;[url]http://www.bleepingcomputer.com/tutorials/tutorial82.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]How to prevent Malware[/color][/b]:&lt;br&gt;[url]http://users.telenet.be/bluepatchy/miekiemoes/prevention.html[/url]&lt;br&gt;&lt;br&gt;[B][color="blue"]So how did I get infected in the first place[/color][/B]:&lt;br&gt;[URL]http://forums.spybot.info/showthread.php?t=279[/URL]&lt;br&gt;&lt;br&gt;[B][color="blue"]Malware Cleanup Programs and Preventative Procedures[/color][/B]: &lt;br&gt;[URL]http://russelltexas.com/malware/allclear.htm[/URL]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 1[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/Malware-Prevention-Hardening-Windows-Security1.html[/url]&lt;br&gt;&lt;br&gt;[b][color="blue"]Hardening Windows Security - Part 2[/color][/b]:&lt;br&gt;[url]http://www.malwarehelp.org/malware-prevention-hardening-windows-security2.html[/url]</description><pubDate>Mon, 12 May 2008 04:02:51 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>Did as per instruction, detected 3 threats although Avira also detected two trojans while Super AntiSpyware was scanning (I deleted them:unsure:)... after rebooting, PC is running fine... no threats detected so far.&lt;/P&gt;&lt;P&gt;Here's the report you requested:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Super AntiSpyware Scan Log:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;SUPERAntiSpyware Scan Log&lt;BR&gt;&lt;A href="http://www.superantispyware.com"&gt;http://www.superantispyware.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Generated 05/12/2008 at 04:03 PM&lt;/P&gt;&lt;P&gt;Application Version : 4.0.1154&lt;/P&gt;&lt;P&gt;Core Rules Database Version : 3458&lt;BR&gt;Trace Rules Database Version: 1449&lt;/P&gt;&lt;P&gt;Scan type       : Complete Scan&lt;BR&gt;Total Scan Time : 01:27:18&lt;/P&gt;&lt;P&gt;Memory items scanned      : 329&lt;BR&gt;Memory threats detected   : 0&lt;BR&gt;Registry items scanned    : 3742&lt;BR&gt;Registry threats detected : 0&lt;BR&gt;File items scanned        : 9302&lt;BR&gt;File threats detected     : 3&lt;/P&gt;&lt;P&gt;Rogue.VirusHeat&lt;BR&gt; C:\SYSTEM VOLUME INFORMATION\_RESTORE{61551398-1387-45C8-B816-B8193A5D57EE}\RP86\A0076031.EXE&lt;/P&gt;&lt;P&gt;Unclassified.Unknown Origin&lt;BR&gt; C:\SYSTEM VOLUME INFORMATION\_RESTORE{61551398-1387-45C8-B816-B8193A5D57EE}\RP90\A0076147.DLL&lt;/P&gt;&lt;P&gt;Adware.Vundo-Variant/H&lt;BR&gt; C:\SYSTEM VOLUME INFORMATION\_RESTORE{61551398-1387-45C8-B816-B8193A5D57EE}\RP90\A0076148.DLL&lt;BR&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;HiJackThis Log:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 4:33:07 PM, on 5/12/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v7.00 (7.00.6000.16640)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\WgaTray.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\Program Files\PCI Audio Applications\Mixer.exe&lt;BR&gt;C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;BR&gt;C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;BR&gt;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&lt;BR&gt;C:\Program Files\Winamp\winampa.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe&lt;BR&gt;C:\Program Files\Ares\Ares.exe&lt;BR&gt;C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Mixer.exe /startup&lt;BR&gt;O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;BR&gt;O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;BR&gt;O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"&lt;BR&gt;O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"&lt;BR&gt;O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h&lt;BR&gt;O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe&lt;BR&gt;O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll&lt;BR&gt;O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 4793 bytes&lt;BR&gt;</description><pubDate>Mon, 12 May 2008 03:40:55 GMT</pubDate><dc:creator>antral917</dc:creator></item><item><title>RE: Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>Your version of [b]Sun Java[/b] is out of date.&lt;br&gt;Older versions have vulnerabilities that malware can use to infect your system.&lt;br&gt;Please follow these steps to remove older versions of Sun Java,and then update.&lt;br&gt;1. Download the latest version of [b][url=http://java.sun.com/javase/downloads/index.jsp][color="blue"]Java Runtime Environment (JRE)[/color][/url][/b]&lt;br&gt;2. Scroll down to where it says '[b]Java Runtime Environment (JRE) 6u6[/b]'.&lt;br&gt;3. Click the "Download" button to the right.&lt;br&gt;4. Select the Platform and Language for your download,then check the box that says: "Accept License Agreement".&lt;br&gt;5. The page will refresh.&lt;br&gt;6. Click on the link to download [b]'Windows Offline Installation, Multi-language - jre-6u6-windows-i586-p.exe'[/b] [15.21 MB] and save to your desktop.&lt;br&gt;7. Close any programs you may have running - especially your web browser.&lt;br&gt;8. Go to Start &gt; Control Panel double-click on Add/Remove programs and remove all older versions of Java.&lt;br&gt;9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.&lt;br&gt;10. Click the Change/Remove button.&lt;br&gt;11. Repeat as many times as necessary to remove each Java version.&lt;br&gt;12. Reboot your computer once all Java components are removed.&lt;br&gt;13. Then from your desktop double-click on [b]jre-6u6-windows-i586-p.exe[/b] to install the newest version.&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b]ATF Cleaner[/b] by [b]Atribune[/b]:&lt;br&gt;[url]http://www.atribune.org/ccount/click.php?id=1[/url]&lt;br&gt;[b]Do not run it just yet.[/b]&lt;br&gt;&lt;br&gt;Download\install [b]'SuperAntiSpyware Free Version Home Users'[/b] from here:&lt;br&gt;[URL]http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE[/URL]&lt;br&gt;&lt;br&gt;Launch SuperAntiSpyware and click on 'Check for updates'.&lt;br&gt;If you encounter any error messages while downloading the updates,manually download them from [B][URL=http://www.superantispyware.com/definitions.html][COLOR="BLUE"]Here[/COLOR][/URL][/B].&lt;br&gt;Once the updates have been installed,[b]exit[/b] SuperAntiSpyware.&lt;br&gt;[b]Do not run it just yet.[/b]&lt;br&gt;&lt;br&gt;Have Hijack This fix the following by placing a check in the appropriate boxes and selecting 'Fix checked'. &lt;br&gt;Make sure all browser and all Windows Explorer windows are closed before fixing:&lt;br&gt;[b]R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com&lt;br&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://internetsearchservice.com/ie6.html&lt;br&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com[/b]&lt;br&gt;Exit Hijackthis.&lt;br&gt;&lt;br&gt;[b]Now double-click ATF-Cleaner.exe to run the program.[/b]&lt;br&gt;Click 'Select All' found at the bottom of the list.&lt;br&gt;Click the 'Empty Selected' button.&lt;br&gt;If you use [b]Firefox[/b] browser, do this also:&lt;br&gt;Click Firefox at the top and choose 'Select All' from the list.&lt;br&gt;Click the 'Empty Selected' button.&lt;br&gt;[b][color="blue"]NOTE:[/color][/b] &lt;br&gt;[color="blue"]If you would like to keep your saved passwords,please click [b]'No'[/b] at the prompt.[/color]&lt;br&gt;If you use [b]Opera[/b] browser,do this also:&lt;br&gt;Click Opera at the top and choose 'Select All' from the list.&lt;br&gt;Click the 'Empty Selected' button.&lt;br&gt;[b][color="blue"]NOTE:[/color][/b] &lt;br&gt;[color="blue"]If you would like to keep your saved passwords,please click [b]'No'[/b] at the prompt.[/color]&lt;br&gt;Click 'Exit' on the Main menu to close the program.&lt;br&gt;&lt;br&gt;[b]Now Start SuperAntiSpyware.[/b]&lt;br&gt;On the main screen click on 'Scan your computer'.&lt;br&gt;Check: 'Perform Complete Scan'.&lt;br&gt;Click 'Next' to start the scan.&lt;br&gt;&lt;br&gt;Superantispyware will now scan your computer,when it's finished it will list all/any infections found.&lt;br&gt;Make sure everything found has a checkmark next to it,then press 'Next'.&lt;br&gt;Click on 'Finish' when you've done.&lt;br&gt;&lt;br&gt;It's possible that the program will ask you to reboot in order to delete some files.&lt;br&gt;&lt;br&gt;Obtain the SuperAntiSpyware log as follows:&lt;br&gt;Click on 'Preferences'.&lt;br&gt;Click on the 'Statistics/Logs' tab.&lt;br&gt;Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.&lt;br&gt;It will then open in your default text editor,such as Notepad.&lt;br&gt;[b]Copy and paste the contents of that report into your next reply.&lt;br&gt;Also post a new Hijackthis log,let me know how your pc is running now.[/b]&lt;br&gt;</description><pubDate>Sat, 10 May 2008 02:37:09 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>&lt;STRONG&gt;ComboFix Report:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ComboFix 08-05-07.1 - user 2008-05-10 14:06:32.2 - NTFSx86&lt;BR&gt;Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe&lt;BR&gt;Command switches used :: C:\Documents and Settings\user\Desktop\CFScript.txt&lt;BR&gt; * Created a new restore point&lt;/P&gt;&lt;P&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;/P&gt;&lt;P&gt;FILE ::&lt;BR&gt;C:\WINDOWS\BM73f6d938.xml&lt;BR&gt;C:\WINDOWS\system32\ssqPihIc.VIR&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url&lt;BR&gt;C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url&lt;BR&gt;C:\Documents and Settings\user\Favorites\Online Security Test.url&lt;BR&gt;C:\WINDOWS\BM73f6d938.xml&lt;BR&gt;C:\WINDOWS\system32\ssqPihIc.VIR&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-04-10 to 2008-05-10  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-05-09 13:35 . 2008-05-09 13:35 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Avira&lt;BR&gt;2008-05-09 13:35 . 2008-05-09 13:35 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Avira&lt;BR&gt;2008-05-07 14:17 . 2008-05-07 14:17 50,688 --a------ C:\ATF-Cleaner.exe&lt;BR&gt;2008-05-04 03:13 . 2008-05-07 18:42 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\527631&lt;BR&gt;2008-04-27 22:29 . 2004-08-04 20:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll&lt;BR&gt;2008-04-27 05:32 . 2008-04-27 22:56 &amp;lt;DIR&amp;gt; d--h----- C:\WINDOWS\$hf_mig$&lt;BR&gt;2008-04-27 05:32 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe&lt;BR&gt;2008-04-26 21:33 . 2008-05-07 23:04 &amp;lt;DIR&amp;gt; d-a------ C:\Documents and Settings\All Users\Application Data\TEMP&lt;BR&gt;2008-04-26 21:31 . 2008-05-09 19:07 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\717305&lt;BR&gt;2008-04-21 02:38 . 2008-04-21 02:38 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\Sun&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-05-07 15:12 --------- d-----w C:\Program Files\Yahoo!&lt;BR&gt;2008-04-25 12:58 --------- d-----w C:\Documents and Settings\user\Application Data\mIRC&lt;BR&gt;2008-04-25 12:57 --------- d-----w C:\Program Files\mIRC&lt;BR&gt;2008-03-30 18:05 --------- d-----w C:\Program Files\Java&lt;BR&gt;2008-03-30 17:41 --------- d-----w C:\Program Files\Common Files\Java&lt;BR&gt;2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys&lt;BR&gt;2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll&lt;BR&gt;2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll&lt;BR&gt;2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll&lt;BR&gt;1999-12-31 17:09 1,491,592 ----a-w C:\Program Files\install_flash_player.exe&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;((((((((((((((((((((((((((((((((((((((((((((   Look   )))))))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;---- Directory of C:\WINDOWS\system32\527631 ----&lt;/P&gt;&lt;P&gt;&lt;BR&gt;---- Directory of C:\WINDOWS\system32\717305 ----&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((   &lt;A href="mailto:snapshot@2008-05-09_19.59.48.74"&gt;snapshot@2008-05-09_19.59.48.74&lt;/A&gt;   )))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;- 2008-05-09 11:46:52 2,048 --s-a-w C:\WINDOWS\bootstat.dat&lt;BR&gt;+ 1999-12-31 16:01:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat&lt;BR&gt;.&lt;BR&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"ares"="C:\Program Files\Ares\Ares.exe" [2007-12-31 22:29 962560]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"C-Media Mixer"="C:\Program Files\PCI Audio Applications\Mixer.exe" [2000-09-14 04:02 1077248]&lt;BR&gt;"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-11-24 07:04 1544192]&lt;BR&gt;"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-10-20 10:19 49152]&lt;BR&gt;"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-09 09:35 32768]&lt;BR&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]&lt;BR&gt;"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2003-12-13 08:50 33792]&lt;BR&gt;"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-10 02:50 155648]&lt;BR&gt;"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]&lt;/P&gt;&lt;P&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 20:00 15360]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center]&lt;BR&gt;"AntiVirusOverride"=dword:00000001&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"=&lt;BR&gt;"C:\\Program Files\\Ares\\Ares.exe"=&lt;/P&gt;&lt;P&gt;&lt;BR&gt;*Newly Created Service* - CATCHME&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;/P&gt;&lt;P&gt;catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-05-10 14:12:35&lt;BR&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden files: 0&lt;/P&gt;&lt;P&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;Completion time: 2008-05-10 14:18:03&lt;BR&gt;ComboFix-quarantined-files.txt  2008-05-10 06:17:23&lt;BR&gt;ComboFix2.txt  2008-05-09 12:01:57&lt;/P&gt;&lt;P&gt;Pre-Run: 11,822,874,624 bytes free&lt;BR&gt;Post-Run: 11,815,497,728 bytes free&lt;/P&gt;&lt;P&gt;93 --- E O F --- 1999-12-31 16:16:43&lt;BR&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;HiJackThis Log:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 2:59:38 PM, on 5/10/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\WINDOWS\system32\WgaTray.exe&lt;BR&gt;C:\WINDOWS\Explorer.EXE&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\Program Files\PCI Audio Applications\Mixer.exe&lt;BR&gt;C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;BR&gt;C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;BR&gt;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;BR&gt;C:\Program Files\Winamp\winampa.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\Program Files\Ares\Ares.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;A href="http://internetsearchservice.com/ie6.html"&gt;http://internetsearchservice.com/ie6.html&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Mixer.exe /startup&lt;BR&gt;O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;BR&gt;O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;BR&gt;O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 4660 bytes&lt;BR&gt;</description><pubDate>Sat, 10 May 2008 02:10:02 GMT</pubDate><dc:creator>antral917</dc:creator></item><item><title>RE: Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>Copy and paste ALL the following text in the code box below into [b]Notepad[/b].&lt;br&gt;Click on File(in the menu at the top)&gt;Save as../Save as Type: 'All Files' /File name: [b]CFScript[/b] to your desktop.&lt;br&gt;[quote]File::&lt;br&gt;C:\WINDOWS\BM73f6d938.xml&lt;br&gt;C:\WINDOWS\system32\ssqPihIc.VIR&lt;br&gt;DirLook::&lt;br&gt;C:\WINDOWS\system32\527631&lt;br&gt;C:\WINDOWS\system32\717305&lt;br&gt;Registry::&lt;br&gt;[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1F8E8CCB-55D2-440C-BFB5-4B3180BA7A5C}]&lt;br&gt;[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}]&lt;br&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;br&gt;"70c5eaa4"=-&lt;br&gt;[/quote]&lt;br&gt;Now drag then drop the [b]CFScript[/b] file onto [b]ComboFix.exe[/b] as seen in the image below.&lt;br&gt;&lt;br&gt;[img]http://img.photobucket.com/albums/v624/29wood/CFScript.gif[/img]&lt;br&gt;&lt;br&gt;This will start ComboFix again. &lt;br&gt;After reboot, (in case it asks to reboot), [b]post the contents of Combofix.txt in your next reply along with a new HijackThis log.[/b]</description><pubDate>Fri, 09 May 2008 07:28:20 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>RE: Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>&lt;STRONG&gt;FixWareout Log:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Username "user" - 01/01/2000  2:13:07 [Fixwareout edited 9/01/2007]&lt;/P&gt;&lt;P&gt;~~~~~ Prerun check&lt;BR&gt;HKLM\SOFTWARE\~\Winlogon\ "System"="kdivz.exe"&lt;/P&gt;&lt;P&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters&lt;BR&gt;"nameserver"="85.255.113.118 85.255.112.101" &amp;lt;Value cleared.&lt;BR&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{4062C091-BA42-4D76-9356-89C52D2CE5B3} &lt;BR&gt;"nameserver"="85.255.113.118,85.255.112.101" &amp;lt;Value cleared.&lt;BR&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{67296F48-A252-434E-A81D-076EAA5DBA54} &lt;BR&gt;"nameserver"="85.255.113.118,85.255.112.101" &amp;lt;Value cleared.&lt;BR&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{802FB6B8-DC90-4084-A720-5FB4EEFCE2AF} &lt;BR&gt;"nameserver"="85.255.113.118,85.255.112.101" &amp;lt;Value cleared.&lt;BR&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{F230753C-F5C4-42B1-882D-F152132F52FE} &lt;BR&gt;"nameserver"="85.255.113.118,85.255.112.101" &amp;lt;Value cleared.&lt;BR&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{67296F48-A252-434E-A81D-076EAA5DBA54}&lt;BR&gt;"DhcpNameServer"="85.255.113.118,85.255.112.101" &amp;lt;Value cleared.&lt;BR&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{802FB6B8-DC90-4084-A720-5FB4EEFCE2AF}&lt;BR&gt;"DhcpNameServer"="85.255.113.118,85.255.112.101" &amp;lt;Value cleared.&lt;BR&gt;HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{F230753C-F5C4-42B1-882D-F152132F52FE}&lt;BR&gt;"DhcpNameServer"="85.255.113.118,85.255.112.101" &amp;lt;Value cleared.&lt;/P&gt;&lt;P&gt;Successfully flushed the DNS Resolver Cache.&lt;/P&gt;&lt;P&gt;&lt;BR&gt;System was rebooted successfully. &lt;BR&gt; &lt;BR&gt;~~~~~ Postrun check &lt;BR&gt;HKLM\SOFTWARE\~\Winlogon\ "system"="" &lt;BR&gt;....&lt;BR&gt;....&lt;BR&gt;~~~~~ Misc files. &lt;BR&gt;....&lt;BR&gt;~~~~~ Checking for older varients.&lt;BR&gt;....&lt;BR&gt;~~~~~ Other&lt;BR&gt;C:\WINDOWS\Temp\kdivz.ren 60416 06/13/2007 &lt;/P&gt;&lt;P&gt;~~~~~ Current runs (hklm hkcu "run" Keys Only)&lt;BR&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"C-Media Mixer"="C:\\Program Files\\PCI Audio Applications\\Mixer.exe /startup"&lt;BR&gt;"D-Link AirPlus G"="C:\\Program Files\\D-Link\\AirPlus G\\AirGCFG.exe"&lt;BR&gt;"ANIWZCS2Service"="C:\\Program Files\\ANI\\ANIWZCS2 Service\\WZCSLDR2.exe"&lt;BR&gt;"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""&lt;BR&gt;"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_05\\bin\\jusched.exe\""&lt;BR&gt;"WinampAgent"="C:\\Program Files\\Winamp\\winampa.exe"&lt;BR&gt;"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"&lt;BR&gt;"70c5eaa4"="rundll32.exe \"C:\\WINDOWS\\system32\\vxndfcos.dll\",b"&lt;BR&gt;"BM73f6d938"="Rundll32.exe \"C:\\WINDOWS\\system32\\mnrecgwh.dll\",s"&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"ares"="\"C:\\Program Files\\Ares\\Ares.exe\" -h"&lt;BR&gt;....&lt;BR&gt;Hosts file was reset, If you use a custom hosts file please replace it...&lt;BR&gt;~~~~~ End report ~~~~~&lt;BR&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Avira AntiVir PE Report:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Avira AntiVir Personal&lt;BR&gt;Report file date: Friday, May 09, 2008  13:50&lt;/P&gt;&lt;P&gt;Scanning for 1165085 virus strains and unwanted programs.&lt;/P&gt;&lt;P&gt;Licensed to:      Avira AntiVir PersonalEdition Classic&lt;BR&gt;Serial number:    0000149996-ADJIE-0001&lt;BR&gt;Platform:         Windows XP&lt;BR&gt;Windows version:  (Service Pack 2)  [5.1.2600]&lt;BR&gt;Boot mode:        Normally booted&lt;BR&gt;Username:         SYSTEM&lt;BR&gt;Computer name:    USER-BF5756DC9B&lt;/P&gt;&lt;P&gt;Version information:&lt;BR&gt;BUILD.DAT     : 8.1.00.295      16479 Bytes    4/9/2008 16:24:00&lt;BR&gt;AVSCAN.EXE    : 8.1.2.12       311553 Bytes   3/18/2008 03:02:56&lt;BR&gt;AVSCAN.DLL    : 8.1.1.0         53505 Bytes    2/7/2008 02:43:37&lt;BR&gt;LUKE.DLL      : 8.1.2.9        151809 Bytes   2/28/2008 02:41:23&lt;BR&gt;LUKERES.DLL   : 8.1.2.1         12033 Bytes   2/21/2008 02:28:40&lt;BR&gt;ANTIVIR0.VDF  : 6.40.0.0     11030528 Bytes   7/18/2007 04:33:34&lt;BR&gt;ANTIVIR1.VDF  : 7.0.3.2       5447168 Bytes    3/7/2008 07:08:58&lt;BR&gt;ANTIVIR2.VDF  : 7.0.3.62       337408 Bytes   3/21/2008 13:12:34&lt;BR&gt;ANTIVIR3.VDF  : 7.0.3.68        57856 Bytes   3/25/2008 02:27:50&lt;BR&gt;Engineversion : 8.1.0.28  &lt;BR&gt;AEVDF.DLL     : 8.1.0.5        102772 Bytes   2/25/2008 03:58:21&lt;BR&gt;AESCRIPT.DLL  : 8.1.0.19       229754 Bytes    4/7/2008 09:34:44&lt;BR&gt;AESCN.DLL     : 8.1.0.12       115060 Bytes    4/7/2008 09:34:44&lt;BR&gt;AERDL.DLL     : 8.1.0.19       418164 Bytes    4/7/2008 09:34:44&lt;BR&gt;AEPACK.DLL    : 8.1.1.0        364918 Bytes   3/18/2008 05:20:42&lt;BR&gt;AEOFFICE.DLL  : 8.1.0.15       192889 Bytes    4/7/2008 09:34:44&lt;BR&gt;AEHEUR.DLL    : 8.1.0.15      1147253 Bytes    4/7/2008 09:34:44&lt;BR&gt;AEHELP.DLL    : 8.1.0.11       115061 Bytes    4/7/2008 09:34:43&lt;BR&gt;AEGEN.DLL     : 8.1.0.15       299379 Bytes    4/7/2008 09:34:43&lt;BR&gt;AEEMU.DLL     : 8.1.0.5        430450 Bytes    4/7/2008 09:34:43&lt;BR&gt;AECORE.DLL    : 8.1.0.25       168309 Bytes    4/8/2008 03:58:32&lt;BR&gt;AVWINLL.DLL   : 1.0.0.7         14593 Bytes   1/23/2008 11:07:53&lt;BR&gt;AVPREF.DLL    : 8.0.0.1         25857 Bytes   2/18/2008 04:37:50&lt;BR&gt;AVREP.DLL     : 7.0.0.1        155688 Bytes   4/16/2007 07:26:47&lt;BR&gt;AVREG.DLL     : 8.0.0.0         30977 Bytes   1/23/2008 11:07:49&lt;BR&gt;AVARKT.DLL    : 1.0.0.23       307457 Bytes   2/12/2008 02:29:23&lt;BR&gt;AVEVTLOG.DLL  : 8.0.0.11       114945 Bytes   2/28/2008 02:31:31&lt;BR&gt;SQLITE3.DLL   : 3.3.17.1       339968 Bytes   1/22/2008 11:28:02&lt;BR&gt;SMTPLIB.DLL   : 1.2.0.19        28929 Bytes   1/23/2008 11:08:39&lt;BR&gt;NETNT.DLL     : 8.0.0.1          7937 Bytes   1/25/2008 06:05:10&lt;BR&gt;RCIMAGE.DLL   : 8.0.0.35      2371841 Bytes   3/10/2008 08:37:25&lt;BR&gt;RCTEXT.DLL    : 8.0.32.0        86273 Bytes    3/6/2008 06:02:11&lt;/P&gt;&lt;P&gt;Configuration settings for the scan:&lt;BR&gt;Jobname..........................: Complete system scan&lt;BR&gt;Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp&lt;BR&gt;Logging..........................: low&lt;BR&gt;Primary action...................: interactive&lt;BR&gt;Secondary action.................: ignore&lt;BR&gt;Scan master boot sector..........: on&lt;BR&gt;Scan boot sector.................: on&lt;BR&gt;Boot sectors.....................: C:, E:, &lt;BR&gt;Scan memory......................: on&lt;BR&gt;Process scan.....................: on&lt;BR&gt;Scan registry....................: on&lt;BR&gt;Search for rootkits..............: off&lt;BR&gt;Scan all files...................: Intelligent file selection&lt;BR&gt;Scan archives....................: on&lt;BR&gt;Recursion depth..................: 20&lt;BR&gt;Smart extensions.................: on&lt;BR&gt;Macro heuristic..................: on&lt;BR&gt;File heuristic...................: medium&lt;/P&gt;&lt;P&gt;Start of the scan: Friday, May 09, 2008  13:50&lt;/P&gt;&lt;P&gt;The scan of running processes will be started&lt;BR&gt;Scan process 'avscan.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avcenter.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avgnt.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'avguard.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'sched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'explorer.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'Ares.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'wuauclt.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'winampa.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'jusched.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'PDVDServ.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'WZCSLDR2.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'AirGCFG.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'Mixer.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'WgaTray.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'alg.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'spoolsv.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'svchost.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'lsass.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'services.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'winlogon.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'csrss.exe' - '1' Module(s) have been scanned&lt;BR&gt;Scan process 'smss.exe' - '1' Module(s) have been scanned&lt;BR&gt;28 processes with 28 modules were scanned&lt;/P&gt;&lt;P&gt;Starting master boot sector scan:&lt;BR&gt;Master boot sector HD0&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Start scanning boot sectors:&lt;BR&gt;Boot sector 'C:\'&lt;BR&gt;      [INFO]      No virus was found!&lt;BR&gt;Boot sector 'E:\'&lt;BR&gt;      [INFO]      No virus was found!&lt;/P&gt;&lt;P&gt;Starting to scan the registry.&lt;BR&gt;C:\WINDOWS\system32\xaqwbqpd.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [WARNING]   The file could not be deleted!&lt;BR&gt;C:\WINDOWS\system32\bwuffbrv.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '4898e77b.qua'!&lt;/P&gt;&lt;P&gt;The registry was scanned ( '25' files ).&lt;/P&gt;&lt;P&gt;&lt;BR&gt;Starting the file scan:&lt;/P&gt;&lt;P&gt;Begin scan in 'C:\'&lt;BR&gt;C:\hiberfil.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;BR&gt;C:\pagefile.sys&lt;BR&gt;      [WARNING]   The file could not be opened!&lt;BR&gt;C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\12UD83P2\yaypalassamosvala[1]&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen&lt;BR&gt;      [NOTE]      The file was moved to '489ce801.qua'!&lt;BR&gt;C:\System Volume Information\_restore{61551398-1387-45C8-B816-B8193A5D57EE}\RP86\A0076036.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '4853fbe3.qua'!&lt;BR&gt;C:\System Volume Information\_restore{61551398-1387-45C8-B816-B8193A5D57EE}\RP87\A0076053.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '4853fbf9.qua'!&lt;BR&gt;C:\System Volume Information\_restore{61551398-1387-45C8-B816-B8193A5D57EE}\RP89\A0076092.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '4853fc10.qua'!&lt;BR&gt;C:\System Volume Information\_restore{61551398-1387-45C8-B816-B8193A5D57EE}\RP89\A0076093.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '4853fc19.qua'!&lt;BR&gt;C:\WINDOWS\system32\bueyydnr.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '48890940.qua'!&lt;BR&gt;C:\WINDOWS\system32\bwehxbyr.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '48890954.qua'!&lt;BR&gt;C:\WINDOWS\system32\fjnppfut.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '48920e19.qua'!&lt;BR&gt;C:\WINDOWS\system32\fthhiatn.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen&lt;BR&gt;      [NOTE]      The file was moved to '488c1c2d.qua'!&lt;BR&gt;C:\WINDOWS\system32\kvamvicm.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen&lt;BR&gt;      [NOTE]      The file was moved to '48851c63.qua'!&lt;BR&gt;C:\WINDOWS\system32\mnrecgwh.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '48961c73.qua'!&lt;BR&gt;C:\WINDOWS\system32\nndetcmm.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen&lt;BR&gt;      [NOTE]      The file was moved to '48881cd6.qua'!&lt;BR&gt;C:\WINDOWS\system32\ojphqisl.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '48941cf0.qua'!&lt;BR&gt;C:\WINDOWS\system32\ojtppkwa.exe&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen&lt;BR&gt;      [NOTE]      The file was moved to '48981cf2.qua'!&lt;BR&gt;C:\WINDOWS\system32\ssqPihIc.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [WARNING]   An error has occurred and the file was not deleted. ErrorID: 26003&lt;BR&gt;      [WARNING]   &lt;BR&gt;C:\WINDOWS\system32\svcaggmj.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [NOTE]      The file was moved to '48871d5b.qua'!&lt;BR&gt;C:\WINDOWS\system32\vxndfcos.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [WARNING]   An error has occurred and the file was not deleted. ErrorID: 26003&lt;BR&gt;      [WARNING]   &lt;BR&gt;C:\WINDOWS\system32\xaqwbqpd.dll&lt;BR&gt;      [DETECTION] Is the Trojan horse TR/Vundo.Gen&lt;BR&gt;      [WARNING]   An error has occurred and the file was not deleted. ErrorID: 26003&lt;BR&gt;      [WARNING]   &lt;BR&gt;Begin scan in 'E:\'&lt;/P&gt;&lt;P&gt;&lt;BR&gt;End of the scan: Friday, May 09, 2008  17:52&lt;BR&gt;Used time:  4:04:25 min&lt;/P&gt;&lt;P&gt;The scan has been done completely.&lt;/P&gt;&lt;P&gt;   2001 Scanning directories&lt;BR&gt; 142707 Files were scanned&lt;BR&gt;     20 viruses and/or unwanted programs were found&lt;BR&gt;      0 Files were classified as suspicious:&lt;BR&gt;      0 files were deleted&lt;BR&gt;      0 files were repaired&lt;BR&gt;     16 files were moved to quarantine&lt;BR&gt;      0 files were renamed&lt;BR&gt;      2 Files cannot be scanned&lt;BR&gt; 142687 Files not concerned&lt;BR&gt;    607 Archives were scanned&lt;BR&gt;      6 Warnings&lt;BR&gt;     16 Notes&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ComboFix Report:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ComboFix 08-05-07.1 - user 2008-05-09 18:49:51.1 - NTFSx86&lt;BR&gt;Running from: C:\Documents and Settings\user\Desktop\ComboFix.exe&lt;/P&gt;&lt;P&gt;[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;C:\Program Files\NetProject&lt;BR&gt;C:\Program Files\NetProject\Thumbs.db&lt;BR&gt;C:\WINDOWS\cookies.ini&lt;BR&gt;C:\WINDOWS\pskt.ini&lt;BR&gt;C:\WINDOWS\system32\717305\717305.dll&lt;BR&gt;C:\WINDOWS\system32\cIhiPqss.ini&lt;BR&gt;C:\WINDOWS\system32\cIhiPqss.ini2&lt;BR&gt;C:\WINDOWS\system32\dpqbwqax.ini&lt;BR&gt;C:\WINDOWS\system32\dshnxwwg.ini&lt;BR&gt;C:\WINDOWS\system32\efechrcn.ini&lt;BR&gt;C:\WINDOWS\system32\kyxiwngi.ini&lt;BR&gt;C:\WINDOWS\system32\lsiqhpjo.ini&lt;BR&gt;C:\WINDOWS\system32\mcrh.tmp&lt;BR&gt;C:\WINDOWS\system32\socfdnxv.ini&lt;BR&gt;C:\WINDOWS\system32\ssqQiifG.dll&lt;BR&gt;C:\WINDOWS\system32\vounokkx.ini&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;(((((((((((((((((((((((((   Files Created from 2008-04-09 to 2008-05-09  )))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;2008-05-09 13:35 . 2008-05-09 13:35 &amp;lt;DIR&amp;gt; d-------- C:\Program Files\Avira&lt;BR&gt;2008-05-09 13:35 . 2008-05-09 13:35 &amp;lt;DIR&amp;gt; d-------- C:\Documents and Settings\All Users\Application Data\Avira&lt;BR&gt;2008-05-07 14:17 . 2008-05-07 14:17 50,688 --a------ C:\ATF-Cleaner.exe&lt;BR&gt;2008-05-04 03:25 . 2008-05-09 13:04 109,816 --a------ C:\WINDOWS\BM73f6d938.xml&lt;BR&gt;2008-05-04 03:19 . 2008-05-04 03:19 281,600 --a------ C:\WINDOWS\system32\ssqPihIc.VIR&lt;BR&gt;2008-05-04 03:13 . 2008-05-07 18:42 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\527631&lt;BR&gt;2008-04-27 22:29 . 2004-08-04 20:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll&lt;BR&gt;2008-04-27 05:32 . 2008-04-27 22:56 &amp;lt;DIR&amp;gt; d--h----- C:\WINDOWS\$hf_mig$&lt;BR&gt;2008-04-27 05:32 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe&lt;BR&gt;2008-04-26 21:33 . 2008-05-07 23:04 &amp;lt;DIR&amp;gt; d-a------ C:\Documents and Settings\All Users\Application Data\TEMP&lt;BR&gt;2008-04-26 21:31 . 2008-05-09 19:07 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\system32\717305&lt;BR&gt;2008-04-21 02:38 . 2008-04-21 02:38 &amp;lt;DIR&amp;gt; d-------- C:\WINDOWS\Sun&lt;/P&gt;&lt;P&gt;.&lt;BR&gt;((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;2008-05-07 15:12 --------- d-----w C:\Program Files\Yahoo!&lt;BR&gt;2008-04-25 12:58 --------- d-----w C:\Documents and Settings\user\Application Data\mIRC&lt;BR&gt;2008-04-25 12:57 --------- d-----w C:\Program Files\mIRC&lt;BR&gt;2008-03-30 18:05 --------- d-----w C:\Program Files\Java&lt;BR&gt;2008-03-30 17:41 --------- d-----w C:\Program Files\Common Files\Java&lt;BR&gt;2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys&lt;BR&gt;2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll&lt;BR&gt;2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll&lt;BR&gt;2008-02-16 08:59 659,456 ----a-w C:\WINDOWS\system32\wininet.dll&lt;BR&gt;1999-12-31 17:09 1,491,592 ----a-w C:\Program Files\install_flash_player.exe&lt;BR&gt;.&lt;/P&gt;&lt;P&gt;(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))&lt;BR&gt;.&lt;BR&gt;.&lt;BR&gt;*Note* empty entries &amp;amp; legit default entries are not shown &lt;BR&gt;REGEDIT4&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1F8E8CCB-55D2-440C-BFB5-4B3180BA7A5C}]&lt;BR&gt;   C:\WINDOWS\system32\ssqPihIc.dll&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7C109800-A5D5-438F-9640-18D17E168B88}]&lt;/P&gt;&lt;P&gt;[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"ares"="C:\Program Files\Ares\Ares.exe" [2007-12-31 22:29 962560]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"C-Media Mixer"="C:\Program Files\PCI Audio Applications\Mixer.exe" [2000-09-14 04:02 1077248]&lt;BR&gt;"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-11-24 07:04 1544192]&lt;BR&gt;"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2005-10-20 10:19 49152]&lt;BR&gt;"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-09 09:35 32768]&lt;BR&gt;"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]&lt;BR&gt;"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2003-12-13 08:50 33792]&lt;BR&gt;"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-10 02:50 155648]&lt;BR&gt;"70c5eaa4"="C:\WINDOWS\system32\xaqwbqpd.dll" [ ]&lt;BR&gt;"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]&lt;/P&gt;&lt;P&gt;[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]&lt;BR&gt;"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 20:00 15360]&lt;/P&gt;&lt;P&gt;[HKEY_LOCAL_MACHINE\software\microsoft\security center]&lt;BR&gt;"AntiVirusOverride"=dword:00000001&lt;/P&gt;&lt;P&gt;[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]&lt;BR&gt;"%windir%\\system32\\sessmgr.exe"=&lt;BR&gt;"C:\\Program Files\\Ares\\Ares.exe"=&lt;/P&gt;&lt;P&gt;&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;/P&gt;&lt;P&gt;catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, &lt;A href="http://www.gmer.net"&gt;http://www.gmer.net&lt;/A&gt;&lt;BR&gt;Rootkit scan 2008-05-09 19:52:33&lt;BR&gt;Windows 5.1.2600 Service Pack 2 NTFS&lt;/P&gt;&lt;P&gt;scanning hidden processes ... &lt;/P&gt;&lt;P&gt;scanning hidden autostart entries ...&lt;/P&gt;&lt;P&gt;scanning hidden files ... &lt;/P&gt;&lt;P&gt;scan completed successfully&lt;BR&gt;hidden files: 0&lt;/P&gt;&lt;P&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;------------------------ Other Running Processes ------------------------&lt;BR&gt;.&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;.&lt;BR&gt;**************************************************************************&lt;BR&gt;.&lt;BR&gt;Completion time: 2008-05-09 20:01:44 - machine was rebooted&lt;BR&gt;ComboFix-quarantined-files.txt  2008-05-09 12:01:17&lt;/P&gt;&lt;P&gt;Pre-Run: 11,857,731,584 bytes free&lt;BR&gt;Post-Run: 11,832,512,512 bytes free&lt;/P&gt;&lt;P&gt;101 --- E O F --- 1999-12-31 16:16:43&lt;BR&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;HiJackThis Log:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 8:05:18 PM, on 5/9/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;C:\Program Files\PCI Audio Applications\Mixer.exe&lt;BR&gt;C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;BR&gt;C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;BR&gt;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;BR&gt;C:\Program Files\Winamp\winampa.exe&lt;BR&gt;C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe&lt;BR&gt;C:\Program Files\Ares\Ares.exe&lt;BR&gt;C:\WINDOWS\system32\wuauclt.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=69157"&gt;http://go.microsoft.com/fwlink/?LinkId=69157&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;A href="http://internetsearchservice.com/ie6.html"&gt;http://internetsearchservice.com/ie6.html&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://go.microsoft.com/fwlink/?LinkId=54896"&gt;http://go.microsoft.com/fwlink/?LinkId=54896&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;O2 - BHO: (no name) - {1F8E8CCB-55D2-440C-BFB5-4B3180BA7A5C} - C:\WINDOWS\system32\ssqPihIc.dll (file missing)&lt;BR&gt;O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O2 - BHO: (no name) - {7C109800-A5D5-438F-9640-18D17E168B88} - (no file)&lt;BR&gt;O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Mixer.exe /startup&lt;BR&gt;O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;BR&gt;O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;BR&gt;O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [70c5eaa4] rundll32.exe "C:\WINDOWS\system32\xaqwbqpd.dll",b&lt;BR&gt;O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min&lt;BR&gt;O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe&lt;BR&gt;O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe&lt;BR&gt;O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 4839 bytes&lt;BR&gt;</description><pubDate>Fri, 09 May 2008 07:16:29 GMT</pubDate><dc:creator>antral917</dc:creator></item><item><title>RE: Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>Welcome:)&lt;br&gt;&lt;br&gt;Please download [b][color="red"]FixWareout[/color][/b]:&lt;br&gt;[url]http://downloads.subratam.org/Fixwareout.exe[/url]&lt;br&gt;&lt;br&gt;Save it to your desktop and run it. &lt;br&gt;Click Next,then Install,then make sure "[b]Run fixit[/b]" is checked and click Finish.&lt;br&gt;The fix will begin; follow the prompts. &lt;br&gt;You will be asked to reboot your computer; [b]please do so[/b]. &lt;br&gt;Your system may take longer than usual to load,this is normal.&lt;br&gt;&lt;br&gt;When your system reboots,follow the prompts. &lt;br&gt;Afterwards, HijackThis will launch,if it doesn't,launch it manually. &lt;br&gt;Please click Scan, and checkmark the following items:&lt;br&gt;&lt;br&gt;[b]O17 - HKLM\System\CCS\Services\Tcpip\..\{4062C091-BA42-4D76-9356-89C52D2CE5B3}: NameServer = 85.255.113.118,85.255.112.101&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{67296F48-A252-434E-A81D-076EAA5DBA54}: NameServer = 85.255.113.118,85.255.112.101&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{802FB6B8-DC90-4084-A720-5FB4EEFCE2AF}: NameServer = 85.255.113.118,85.255.112.101&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{F230753C-F5C4-42B1-882D-F152132F52FE}: NameServer = 85.255.113.118,85.255.112.101&lt;br&gt;O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.118 85.255.112.101&lt;br&gt;O17 - HKLM\System\CS1\Services\Tcpip\..\{4062C091-BA42-4D76-9356-89C52D2CE5B3}: NameServer = 85.255.113.118,85.255.112.101&lt;br&gt;O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.118 85.255.112.101&lt;br&gt;O17 - HKLM\System\CS2\Services\Tcpip\..\{4062C091-BA42-4D76-9356-89C52D2CE5B3}: NameServer = 85.255.113.118,85.255.112.101&lt;br&gt;O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.118 85.255.112.101[/b]&lt;br&gt;&lt;br&gt;Click 'Fix Checked'. &lt;br&gt;Close HijackThis,and click OK to proceed.&lt;br&gt;At the end of the fix you may need to restart your computer again.&lt;br&gt;&lt;br&gt;Finally, please post the contents of the logfile C:\fixwareout\report.txt into your next reply. &lt;br&gt;&lt;br&gt;[b]Please Note[/b]:&lt;br&gt;Only do the following if you have connection problems after performing the above steps:&lt;br&gt;Go to Start&gt;Control Panel,and choose 'Network Connections'. &lt;br&gt;Then right click on your default connection,usually 'Local Area Connection' or 'Dial-up Connection' if you are using Dial-up,then left click on 'Properties'. &lt;br&gt;Double-click on the 'Internet Protocol (TCP/IP)' item and select the radio button that says: 'Obtain DNS servers Automatically'. &lt;br&gt;Click OK twice,restart your computer.&lt;br&gt;&lt;br&gt;&lt;br&gt;It appears you've no virus protection installed,which is somewhat suicidal.&lt;br&gt;Please download/install [b]Avira AntiVir Personal - FREE Antivirus[/b]: &lt;br&gt;[url]http://www.free-av.com/en/download/1/download_avira_antivir_personal__free_antivirus.html[/url]&lt;br&gt;Perform a full scan with Avira and allow it to delete everything it detects.&lt;br&gt;[b]Restart your pc when you've done.[/b]&lt;br&gt;After restart,open Avira Antivirus and select "Reports".&lt;br&gt;Then double click the report from the full scan you have just completed. &lt;br&gt;Click the "Report File" button,then [b]copy and paste the report into your next reply[/b].&lt;br&gt;&lt;br&gt;&lt;br&gt;Download [b][url=http://download.bleepingcomputer.com/sUBs/ComboFix.exe][color="blue"]Combofix[/color][/url][/b] by [b]sUBs[/b] and save to your desktop.&lt;br&gt;Alternative Combofix download link [b][url=http://subs.geekstogo.com/ComboFix.exe][color="blue"]HERE[/color][/url][/b].&lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;It is important that it is saved directly to your desktop[/color]&lt;br&gt;&lt;br&gt;Now close any open browsers.&lt;br&gt;Double click on Combofix.exe and follow the prompts. &lt;br&gt;When it's finished it will produce a log. &lt;br&gt;[b]Post the entire contents of C:\ComboFix.txt into your next reply[/b]. &lt;br&gt;[color="red"][b][u]Note[/u][/b] &lt;br&gt;Do not mouseclick combofix's window or do anything else on your pc while it's running. &lt;br&gt;That may cause the program/system to freeze/hang. [/color]&lt;br&gt;Do NOT post the ComboFix-quarantined-files.txt unless I ask.&lt;br&gt;[b][color="RED"][U]Note[/U][/color][/b]&lt;br&gt;In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.&lt;br&gt;Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.&lt;br&gt;&lt;br&gt;[b]Also post a new Hijackthis log please[/b].</description><pubDate>Thu, 08 May 2008 02:23:46 GMT</pubDate><dc:creator>RichieUK</dc:creator></item><item><title>Persistent Spyware pop-ups (Virus Heat et.al)</title><link>http://tweaks.com/forum/Topic239030-29-1.aspx</link><description>I have the same problem as KingNet's, and although I got rid of the shield icon ( via AVG AS 7.5), pop-ups still appear instructing me to download an anti-spyware software, scanning for spywares and directing my browser to another website. this happens everytime I open Internet Explorer.&lt;/P&gt;&lt;P&gt;Here is the HiJackThis Log:&lt;/P&gt;&lt;P&gt;Logfile of Trend Micro HijackThis v2.0.2&lt;BR&gt;Scan saved at 3:35:19 AM, on 4/8/2008&lt;BR&gt;Platform: Windows XP SP2 (WinNT 5.01.2600)&lt;BR&gt;MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)&lt;BR&gt;Boot mode: Normal&lt;/P&gt;&lt;P&gt;Running processes:&lt;BR&gt;C:\WINDOWS\System32\smss.exe&lt;BR&gt;C:\WINDOWS\system32\csrss.exe&lt;BR&gt;C:\WINDOWS\system32\winlogon.exe&lt;BR&gt;C:\WINDOWS\system32\services.exe&lt;BR&gt;C:\WINDOWS\system32\lsass.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\System32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\svchost.exe&lt;BR&gt;C:\WINDOWS\system32\spoolsv.exe&lt;BR&gt;C:\Program Files\PCI Audio Applications\Mixer.exe&lt;BR&gt;C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;BR&gt;C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;BR&gt;C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe&lt;BR&gt;C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe&lt;BR&gt;C:\Program Files\Winamp\winampa.exe&lt;BR&gt;C:\WINDOWS\System32\alg.exe&lt;BR&gt;C:\Program Files\Ares\Ares.exe&lt;BR&gt;C:\WINDOWS\system32\rundll32.exe&lt;BR&gt;C:\WINDOWS\explorer.exe&lt;BR&gt;C:\Program Files\Internet Explorer\iexplore.exe&lt;BR&gt;C:\Program Files\Trend Micro\HijackThis\HijackThis.exe&lt;BR&gt;C:\WINDOWS\system32\wbem\wmiprvse.exe&lt;/P&gt;&lt;P&gt;R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;A href="http://internetsearchservice.com/ie6.html"&gt;http://internetsearchservice.com/ie6.html&lt;/A&gt;&lt;BR&gt;R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = &lt;A href="http://internetsearchservice.com/ie6.html"&gt;http://internetsearchservice.com/ie6.html&lt;/A&gt;&lt;BR&gt;R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = &lt;A href="http://internetsearchservice.com"&gt;http://internetsearchservice.com&lt;/A&gt;&lt;BR&gt;O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Mixer.exe /startup&lt;BR&gt;O4 - HKLM\..\Run: [D-Link AirPlus G] C:\Program Files\D-Link\AirPlus G\AirGCFG.exe&lt;BR&gt;O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe&lt;BR&gt;O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"&lt;BR&gt;O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"&lt;BR&gt;O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe&lt;BR&gt;O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe&lt;BR&gt;O4 - HKLM\..\Run: [BM73f6d938] Rundll32.exe "C:\WINDOWS\system32\escicoyi.dll",s&lt;BR&gt;O4 - HKLM\..\Run: [70c5eaa4] rundll32.exe "C:\WINDOWS\system32\ignwixyk.dll",b&lt;BR&gt;O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h&lt;BR&gt;O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe&lt;BR&gt;O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')&lt;BR&gt;O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')&lt;BR&gt;O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')&lt;BR&gt;O8 - Extra context menu item: E&amp;amp;xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000&lt;BR&gt;O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll&lt;BR&gt;O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - &lt;A href="http://www.gateietool.com/redirect.php"&gt;http://www.gateietool.com/redirect.php&lt;/A&gt; (file missing)&lt;BR&gt;O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - &lt;A href="http://www.gateietool.com/redirect.php"&gt;http://www.gateietool.com/redirect.php&lt;/A&gt; (file missing)&lt;BR&gt;O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL&lt;BR&gt;O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{4062C091-BA42-4D76-9356-89C52D2CE5B3}: NameServer = 85.255.113.118,85.255.112.101&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{67296F48-A252-434E-A81D-076EAA5DBA54}: NameServer = 85.255.113.118,85.255.112.101&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{802FB6B8-DC90-4084-A720-5FB4EEFCE2AF}: NameServer = 85.255.113.118,85.255.112.101&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\..\{F230753C-F5C4-42B1-882D-F152132F52FE}: NameServer = 85.255.113.118,85.255.112.101&lt;BR&gt;O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.118 85.255.112.101&lt;BR&gt;O17 - HKLM\System\CS1\Services\Tcpip\..\{4062C091-BA42-4D76-9356-89C52D2CE5B3}: NameServer = 85.255.113.118,85.255.112.101&lt;BR&gt;O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.118 85.255.112.101&lt;BR&gt;O17 - HKLM\System\CS2\Services\Tcpip\..\{4062C091-BA42-4D76-9356-89C52D2CE5B3}: NameServer = 85.255.113.118,85.255.112.101&lt;BR&gt;O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.118 85.255.112.101&lt;BR&gt;O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe&lt;BR&gt;O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe&lt;/P&gt;&lt;P&gt;--&lt;BR&gt;End of file - 5689 bytes&lt;BR&gt;</description><pubDate>Thu, 08 May 2008 00:46:22 GMT</pubDate><dc:creator>antral917</dc:creator></item></channel></rss>