mrdingdong

Members
  • Content Count

    9
  • Joined

  • Last visited

Posts posted by mrdingdong

  1. GOD! After almost 10 hours it finally finished.

    Do you still want me to do what you just said?

    -------------------------------------------------------------------------------

    KASPERSKY ONLINE SCANNER REPORT

    Wednesday, February 20, 2008 4:38:35 AM

    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)

    Kaspersky Online Scanner version: 5.0.98.0

    Kaspersky Anti-Virus database last update: 19/02/2008

    Kaspersky Anti-Virus database records: 573314

    -------------------------------------------------------------------------------

    Scan Settings:

    Scan using the following antivirus database: extended

    Scan Archives: true

    Scan Mail Bases: true

    Scan Target - My Computer:

    A:\

    C:\

    D:\

    Scan Statistics:

    Total number of scanned objects: 59559

    Number of viruses found: 6

    Number of infected objects: 9

    Number of suspicious objects: 0

    Duration of the scan process: 09:47:50

    Infected Object Name / Virus Name / Last Action

    C:\Documents and Settings\All Users\Application Data\Juno\Isp\BootExceptions.log Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Juno\Isp\ExecExceptions.log Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Juno\Isp\IspDblog.txt Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Juno\Isp\MainExceptions.log Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

    C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped

    C:\Documents and Settings\Bob\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Quarantine\QUAR1.37101 Infected: Trojan-Downloader.Win32.Bojo.ai skipped

    C:\Documents and Settings\Bob\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\Bob\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\Bob\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\Bob\Local Settings\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Bob\Local Settings\Temp\Perflib_Perfdata_100.dat Object is locked skipped

    C:\Documents and Settings\Bob\Local Settings\Temp\Perflib_Perfdata_c50.dat Object is locked skipped

    C:\Documents and Settings\Bob\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

    C:\Documents and Settings\Bob\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Bob\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\Bob\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\temp\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\temp\History\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Local Settings\temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

    C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\eMachines_Vista.dat Object is locked skipped

    C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\eMachine_Specific.dat Object is locked skipped

    C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Security.dat Object is locked skipped

    C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\UK_Specific.dat Object is locked skipped

    C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Urgent.dat Object is locked skipped

    C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Virus.dat Object is locked skipped

    C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\Welcome.dat Object is locked skipped

    C:\Program Files\BigFix\__Data\emachines\__Local\Tmp\WinXP.dat Object is locked skipped

    C:\Program Files\Juno\qsacc\dblog.txt Object is locked skipped

    C:\Program Files\Juno\qsacc\MainExceptions.log Object is locked skipped

    C:\Program Files\Juno\qsacc\sdi.db Object is locked skipped

    C:\Program Files\Juno\qsacc\sdi.lg Object is locked skipped

    C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped

    C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped

    C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped

    C:\QooBox\Quarantine\C\Program Files\Helper\1202511920.dll.vir Infected: not-a-virus:AdWare.Win32.E404.f skipped

    C:\QooBox\Quarantine\C\Program Files\Video Add-on\isfmdl.dll.vir Infected: Trojan-Downloader.Win32.Zlob.hkq skipped

    C:\QooBox\Quarantine\C\Program Files\Video Add-on\isfmm.exe.vir Infected: Trojan-Downloader.Win32.Zlob.hka skipped

    C:\QooBox\Quarantine\C\setup.exe.vir/data0007 Infected: Trojan-Downloader.Win32.Zlob.hkm skipped

    C:\QooBox\Quarantine\C\setup.exe.vir NSIS: infected - 1 skipped

    C:\SmitfraudFix\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

    C:\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

    C:\SmitfraudFix.zip ZIP: infected - 1 skipped

    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    C:\System Volume Information\_restore{879E598B-020E-408B-AC9B-13ABBD7D02C3}\RP443\change.log Object is locked skipped

    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

    C:\WINDOWS\SchedLgU.Txt Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\EventCache\{D7B7ECE2-84BC-477D-8645-FC3345C4F396}.bin Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

    C:\WINDOWS\Sti_Trace.log Object is locked skipped

    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\default Object is locked skipped

    C:\WINDOWS\system32\config\default.LOG Object is locked skipped

    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

    C:\WINDOWS\system32\config\SAM Object is locked skipped

    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

    C:\WINDOWS\system32\config\software Object is locked skipped

    C:\WINDOWS\system32\config\software.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\system Object is locked skipped

    C:\WINDOWS\system32\config\system.LOG Object is locked skipped

    C:\WINDOWS\system32\h323log.txt Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    C:\WINDOWS\wiadebug.log Object is locked skipped

    C:\WINDOWS\wiaservc.log Object is locked skipped

    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.

  2. It appears that the Kaspersky scan got stuck at file c:\windows\$NtServicePackUninstall$\msobshel.htm.

    Scan Progress [90%]:

    Total number of scanned objects: 37958

    Number of viruses found: 6

    Number of infected objects: 9

    Number of suspicious objects: 0

    Duration of the scan process: 04:05:45

    Here's the uninstall log:

    Total number of scanned objects: 37958

    Number of viruses found: 6

    Number of infected objects: 9

    Number of suspicious objects: 0

    Duration of the scan process: 04:05:11

    Ad-Aware SE Personal

    Adobe Flash Player 9 ActiveX

    Adobe Flash Player ActiveX

    Adobe Reader 8.1.2

    Adobe® Photoshop® Album Starter Edition 3.2

    America Online (Choose which version to remove)

    AOL Coach Version 1.0(Build:20030807.3)

    AOL Instant Messenger (SM)

    Apple Software Update

    BigFix

    CC_ccStart

    ccCommon

    CompuServe

    Google Earth

    Google Updater

    HijackThis 2.0.2

    Hotfix for Windows Media Format 11 SDK (KB929399)

    Hotfix for Windows Media Player 11 (KB939683)

    Hotfix for Windows XP (KB914440)

    Hotfix for Windows XP (KB915865)

    Hotfix for Windows XP (KB926239)

    ICQ

    ICQ6

    Java 2 Runtime Environment, SE v1.4.2

    Juno Internet

    Kaspersky Online Scanner

    Learn2 Player (Uninstall Only)

    Lexmark Z700-P700 Series

    LiveReg (Symantec Corporation)

    LiveUpdate 1.90 (Symantec Corporation)

    Magic ISO Maker v5.3 (build 0229)

    Malwarebytes' Anti-Malware

    Microsoft Compression Client Pack 1.0 for Windows XP

    Microsoft Internationalized Domain Names Mitigation APIs

    Microsoft Money 2004

    Microsoft Money 2004 System Pack

    Microsoft National Language Support Downlevel APIs

    Microsoft Office XP Professional

    Microsoft User-Mode Driver Framework Feature Pack 1.0

    Microsoft Works 7.0

    MSRedist

    MSXML 4.0 SP2 (KB925672)

    MSXML 4.0 SP2 (KB936181)

    msxml4

    Multimedia Keyboard Driver

    Need For Speed Hot Pursuit 2

    Need For Speed III

    Netscape 6 (6.2.1)

    Norton AntiVirus 2004

    Norton AntiVirus 2004 (Symantec Corporation)

    Norton AntiVirus Parent MSI

    NVIDIA Display Driver

    NVIDIA Ethernet Driver

    NVIDIA nForce Drivers

    PowerDVD

    QuickTime

    RealPlayer

    Security Update for Windows Internet Explorer 7 (KB938127)

    Security Update for Windows Internet Explorer 7 (KB939653)

    Security Update for Windows Internet Explorer 7 (KB942615)

    Security Update for Windows Internet Explorer 7 (KB944533)

    Security Update for Windows Media Player (KB911564)

    Security Update for Windows Media Player 11 (KB936782)

    Security Update for Windows Media Player 6.4 (KB925398)

    Security Update for Windows Media Player 9 (KB917734)

    Security Update for Windows XP (KB890046)

    Security Update for Windows XP (KB893756)

    Security Update for Windows XP (KB896358)

    Security Update for Windows XP (KB896423)

    Security Update for Windows XP (KB896424)

    Security Update for Windows XP (KB896428)

    Security Update for Windows XP (KB899587)

    Security Update for Windows XP (KB899591)

    Security Update for Windows XP (KB900725)

    Security Update for Windows XP (KB901017)

    Security Update for Windows XP (KB901190)

    Security Update for Windows XP (KB901214)

    Security Update for Windows XP (KB902400)

    Security Update for Windows XP (KB905414)

    Security Update for Windows XP (KB905749)

    Security Update for Windows XP (KB908519)

    Security Update for Windows XP (KB911562)

    Security Update for Windows XP (KB911927)

    Security Update for Windows XP (KB912919)

    Security Update for Windows XP (KB913580)

    Security Update for Windows XP (KB914388)

    Security Update for Windows XP (KB914389)

    Security Update for Windows XP (KB917344)

    Security Update for Windows XP (KB917422)

    Security Update for Windows XP (KB917953)

    Security Update for Windows XP (KB918118)

    Security Update for Windows XP (KB918899)

    Security Update for Windows XP (KB919007)

    Security Update for Windows XP (KB920213)

    Security Update for Windows XP (KB920214)

    Security Update for Windows XP (KB920670)

    Security Update for Windows XP (KB920683)

    Security Update for Windows XP (KB920685)

    Security Update for Windows XP (KB921398)

    Security Update for Windows XP (KB921503)

    Security Update for Windows XP (KB921883)

    Security Update for Windows XP (KB922616)

    Security Update for Windows XP (KB922819)

    Security Update for Windows XP (KB923191)

    Security Update for Windows XP (KB923414)

    Security Update for Windows XP (KB923689)

    Security Update for Windows XP (KB923694)

    Security Update for Windows XP (KB923980)

    Security Update for Windows XP (KB924191)

    Security Update for Windows XP (KB924270)

    Security Update for Windows XP (KB924496)

    Security Update for Windows XP (KB924667)

    Security Update for Windows XP (KB925486)

    Security Update for Windows XP (KB925902)

    Security Update for Windows XP (KB926255)

    Security Update for Windows XP (KB926436)

    Security Update for Windows XP (KB927779)

    Security Update for Windows XP (KB927802)

    Security Update for Windows XP (KB928090)

    Security Update for Windows XP (KB928255)

    Security Update for Windows XP (KB928843)

    Security Update for Windows XP (KB929123)

    Security Update for Windows XP (KB929969)

    Security Update for Windows XP (KB930178)

    Security Update for Windows XP (KB931261)

    Security Update for Windows XP (KB931768)

    Security Update for Windows XP (KB931784)

    Security Update for Windows XP (KB932168)

    Security Update for Windows XP (KB933566)

    Security Update for Windows XP (KB933729)

    Security Update for Windows XP (KB935839)

    Security Update for Windows XP (KB935840)

    Security Update for Windows XP (KB936021)

    Security Update for Windows XP (KB937143)

    Security Update for Windows XP (KB938127)

    Security Update for Windows XP (KB938829)

    Security Update for Windows XP (KB939653)

    Security Update for Windows XP (KB941202)

    Security Update for Windows XP (KB941568)

    Security Update for Windows XP (KB941569)

    Security Update for Windows XP (KB941644)

    Security Update for Windows XP (KB943055)

    Security Update for Windows XP (KB943460)

    Security Update for Windows XP (KB943485)

    Security Update for Windows XP (KB944653)

    Security Update for Windows XP (KB946026)

    SoftV92 Data Fax Modem with SmartCP

    Symantec Script Blocking Installer

    SymNet

    Update for Windows XP (KB898461)

    Update for Windows XP (KB900485)

    Update for Windows XP (KB904942)

    Update for Windows XP (KB908531)

    Update for Windows XP (KB910437)

    Update for Windows XP (KB911280)

    Update for Windows XP (KB916595)

    Update for Windows XP (KB920872)

    Update for Windows XP (KB922582)

    Update for Windows XP (KB927891)

    Update for Windows XP (KB929338)

    Update for Windows XP (KB930916)

    Update for Windows XP (KB931836)

    Update for Windows XP (KB933360)

    Update for Windows XP (KB938828)

    Update for Windows XP (KB942763)

    Viewpoint Media Player (Remove Only)

    Winamp (remove only)

    Windows Backup Utility

    Windows Installer 3.1 (KB893803)

    Windows Internet Explorer 7

    Windows Media Format 11 runtime

    Windows Media Format 11 runtime

    Windows Media Player 11

    Windows Media Player 11

    Windows XP Hotfix - KB873339

    Windows XP Hotfix - KB885835

    Windows XP Hotfix - KB885836

    Windows XP Hotfix - KB885884

    Windows XP Hotfix - KB886185

    Windows XP Hotfix - KB887472

    Windows XP Hotfix - KB888302

    Windows XP Hotfix - KB890859

    Windows XP Hotfix - KB891781

    Windows XP Service Pack 2

  3. Hi

    The computer is working fine now. Looks like the virus is gone. GREAT THANKS!!!!

    One question: My friend has similar problem. Can I use the programs you provided to scan his computer or do I need to look at the logs too?

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 9:25:06 PM, on 2/18/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16608)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\WINDOWS\system32\sstray.exe

    C:\WINDOWS\zHotkey.exe

    C:\Program Files\QuickTime\QTTask.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Juno\exec.exe

    C:\Program Files\Microsoft Money\System\mnyexpr.exe

    C:\Program Files\BigFix\BigFix.exe

    C:\Program Files\Google\Google Updater\GoogleUpdater.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\Program Files\Norton AntiVirus\SAVScan.exe

    C:\WINDOWS\wanmpsvc.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\Program Files\Juno\exec.exe

    C:\Program Files\Juno\qsacc\x1exec.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/

    R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\Juno\SearchEnh1.dll

    N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\BOB\Application Data\Mozilla\Profiles\default\h5k9xzhj.slt\prefs.js)

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\Juno\qsacc\X1IEBHO.dll

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll

    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: JunoBar - {5854FAC4-5BF0-47DD-B5A9-A5EA8CFF3CF4} - C:\Program Files\Juno\Toolbar.dll

    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r

    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe

    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

    O4 - HKCU\..\Run: [Juno_uoltray] C:\Program Files\Juno\exec.exe regrun

    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"

    O4 - HKCU\..\RunOnce: [untd_recovery] "C:\Program Files\Juno\qsacc\x1exec.exe"

    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe

    O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll

    O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe

    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe

    O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab

    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Bob/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

    --

    End of file - 8465 bytes

  4. Malwarebytes' Anti-Malware 1.03

    Database version: 371

    Scan type: Quick Scan

    Objects scanned: 24505

    Time elapsed: 6 minute(s), 24 second(s)

    Memory Processes Infected: 0

    Memory Modules Infected: 1

    Registry Keys Infected: 26

    Registry Values Infected: 4

    Registry Data Items Infected: 0

    Folders Infected: 0

    Files Infected: 7

    Memory Processes Infected:

    (No malicious items detected)

    Memory Modules Infected:

    c:\WINDOWS\system32\wuuawkz.dll (Trojan.Zlob) -> Unloaded module successfully.

    Registry Keys Infected:

    HKEY_CLASSES_ROOT\CLSID\{747e1fbe-b70f-441d-bbca-6e536c04924a} (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{daed9266-8c28-4c1c-8b58-5c66eff1d302} (Search.Hijack) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\CLSID\{e94eb13e-d78f-0857-7734-5e67a49ffff1} (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{0979850f-6c3e-4294-b225-b3d3c4a6f2a1} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{1bb2da5f-b78f-44ea-bda1-771cbe1dec68} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{2a4e73c5-ba3c-4391-b7e5-ffe8d3bd6245} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{44a923ca-f430-4f85-9f84-5153ecdb882e} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{4e6e21ec-9d72-4164-8a53-74786a467872} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{631e9e48-b066-43da-92ac-6dadf61b173b} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{65c1361c-e696-4af0-9e21-81910193f352} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{77dce805-c8ce-48aa-a47f-bfa6cc7704b3} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{8d42769f-07d8-494d-aab4-aa1652c541fa} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{a1922071-390c-418d-916d-91209e95d286} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{a1f8cd95-cfb3-43d1-a956-63441cc058c1} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{a63b46ad-96a7-4a2c-bd8f-8cd097e1593a} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{a65f98dd-2360-468c-b76e-b1b84c0d547c} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{ae2aeed0-be1b-4ba2-826e-20d1991081b8} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{d7f73787-6206-4bba-bdc0-7cfa9940dbcb} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Interface\{e770f739-2968-4ed9-a63c-dc1938dc82a2} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CLASSES_ROOT\Typelib\{cfafa83c-855b-4e3d-92b9-a587995b675a} (Rogue.VirusProtect) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\Software\Online Add-on (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE Custom Tools (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE Safety Features (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Information Center (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MultiMedia Software (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\videoPl.chl (Trojan.Zlob) -> Quarantined and deleted successfully.

    Registry Values Infected:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{747e1fbe-b70f-441d-bbca-6e536c04924a} (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully.

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully.

    Registry Data Items Infected:

    (No malicious items detected)

    Folders Infected:

    (No malicious items detected)

    Files Infected:

    c:\WINDOWS\system32\wuuawkz.dll (Trojan.Zlob) -> Quarantined and deleted successfully.

    C:\System22Player_1.26.exe (Trojan.Downloader) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Desktop\Security Troubleshooting.url (Rogue.Link) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Desktop\Online Security Guide.url (Rogue.Link) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url (Rogue.Link) -> Quarantined and deleted successfully.

    C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url (Rogue.Link) -> Quarantined and deleted successfully.

    C:\Documents and Settings\Bob\Favorites\Online Security Test.url (Rogue.Link) -> Quarantined and deleted successfully.

  5. ComboFix 08-02-17.2 - Bob 2008-02-17 13:53:32.1 - NTFSx86

    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.195 [GMT -5:00]

    Running from: C:\Documents and Settings\Bob\Desktop\ComboFix.exe

    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

    .

    C:\Program Files\Helper

    C:\Program Files\Helper\1202511920.dll

    C:\Program Files\Video Add-on

    C:\Program Files\Video Add-on\isfmdl.dll

    C:\Program Files\Video Add-on\isfmm.exe

    C:\setup.exe

    .

    ((((((((((((((((((((((((( Files Created from 2008-01-17 to 2008-02-17 )))))))))))))))))))))))))))))))

    .

    2008-02-17 12:06 . 2008-02-17 12:06 <DIR> d-------- C:\SmitfraudFix

    2008-02-17 12:04 . 2008-02-17 12:06 134 --a------ C:\Documents and Settings\Bob\GetPaths.vbs

    2008-02-17 12:03 . 2008-02-17 12:03 1,152,350 --a------ C:\SmitfraudFix.zip

    2008-02-17 11:00 . 2008-02-17 11:00 <DIR> d-------- C:\Program Files\Trend Micro

    2008-02-17 11:00 . 2008-02-17 11:00 812,344 --a------ C:\HJTInstall.exe

    2008-02-16 16:49 . 2008-02-16 22:15 <DIR> d-------- C:\WINDOWS\SxsCaPendDel

    2008-02-13 00:57 . 2008-02-13 00:57 197 --a------ C:\WINDOWS\system32\MRT.INI

    2008-02-08 18:05 . 2008-02-08 18:25 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP

    2008-02-01 03:21 . 2008-02-01 03:21 245,408 --a------ C:\WINDOWS\system32\unicows.dll

    .

    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    2008-02-16 23:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater

    2008-02-16 21:49 --------- d-----w C:\Program Files\Common Files\Adobe

    2008-02-02 03:34 13,312 --s-a-w C:\WINDOWS\system32\wuuawkz.dll

    2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys

    2007-12-17 03:32 --------- d-----w C:\Program Files\Player

    2007-12-17 03:12 12,580,696 ----a-w C:\mm20enu.exe

    2007-12-16 19:28 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll

    2007-12-16 19:28 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll

    2007-12-16 19:23 15,710,297 ----a-w C:\jahshaka-2.0-installer.exe

    2007-12-15 22:53 1,172,582 ----a-w C:\PlayerInstall.exe

    2007-12-15 22:41 1,095,349 ----a-w C:\VirtualDub-1.6.18-AMD64.zip

    2007-12-15 22:16 10,322,632 ----a-w C:\movie_morpher_gold_cnt.exe

    2007-12-15 21:25 6,217,678 ----a-w C:\greencrush.zip

    2007-12-15 20:52 6,735,758 ----a-w C:\System22Player_1.26.exe

    2007-12-15 04:21 3,338,752 ----a-w C:\cp6demo.exe

    2007-12-15 02:39 10,707,063 ----a-w C:\x-video-editor-CNET.exe

    2007-12-07 02:21 824,832 ----a-w C:\WINDOWS\system32\wininet.dll

    2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll

    2007-11-25 23:37 21,321,008 ----a-w C:\QuickTimeInstaller.exe

    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

    .

    .

    *Note* empty entries & legit default entries are not shown

    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]

    "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]

    "Juno_uoltray"="C:\Program Files\Juno\exec.exe" [2007-03-07 20:38 1629184]

    "MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 21:00 200704]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

    "untd_recovery"="C:\Program Files\Juno\qsacc\x1exec.exe" [2005-12-09 17:21 1230848]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-12-22 17:45 71280]

    "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-03-03 19:29 2904064]

    "nwiz"="nwiz.exe" [2004-03-03 19:29 782336 C:\WINDOWS\system32\nwiz.exe]

    "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-03-03 19:29 46080]

    "nForce Tray Options"="sstray.exe" [2003-09-03 03:25 73728 C:\WINDOWS\system32\sstray.exe]

    "CHotkey"="zHotkey.exe" [2003-06-03 20:01 496640 C:\WINDOWS\zHotkey.exe]

    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16 286720]

    "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-03-09 18:23 95960]

    "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 10:09 63712]

    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-13 07:50 185632]

    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\

    BigFix.lnk - C:\Program Files\BigFix\BigFix.exe [2004-05-01 13:09:15 1742384]

    Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-07-22 16:27:29 124912]

    Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 00:01:04 83360]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]

    "{747e1fbe-b70f-441d-bbca-6e536c04924a}"= C:\WINDOWS\system32\wuuawkz.dll [2008-02-01 22:34 13312]

    S3 IPN2120;Instant Wireless-B PCI Adapter Driver;C:\WINDOWS\system32\DRIVERS\LSIPNDS.sys [2003-06-25 12:17]

    .

    Contents of the 'Scheduled Tasks' folder

    "2008-01-31 23:45:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"

    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

    "2007-03-09 23:17:51 C:\WINDOWS\Tasks\Symantec NetDetect.job"

    - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE

    .

    **************************************************************************

    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

    Rootkit scan 2008-02-17 13:56:45

    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    **************************************************************************

    .

    Completion time: 2008-02-17 13:58:03

    ComboFix-quarantined-files.txt 2008-02-17 18:57:13

    .

    2008-02-13 05:57:39 --- E O F ---

  6. Hi

    Can someone please tell me what should I do to remove the virus I unknowingly installed on my PC? Neither Norton nor Ad-Aware works. I got an icon blinking on my toolbar and when I click on it it tells me I got viruses on my pc and I need to buy their software to remove it. I found the folder of that program but I could only delete few of its files.

    THANKS!

    Here is my log:

    Logfile of Trend Micro HijackThis v2.0.2

    Scan saved at 11:33:07 AM, on 2/17/2008

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v7.00 (7.00.6000.16608)

    Boot mode: Normal

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\Explorer.EXE

    C:\WINDOWS\system32\LEXBCES.EXE

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\system32\LEXPPS.EXE

    C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe

    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

    C:\Program Files\Norton AntiVirus\navapsvc.exe

    C:\WINDOWS\System32\nvsvc32.exe

    C:\Program Files\Norton AntiVirus\SAVScan.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\Program Files\Common Files\Symantec Shared\ccApp.exe

    C:\WINDOWS\system32\sstray.exe

    C:\WINDOWS\zHotkey.exe

    C:\Program Files\QuickTime\QTTask.exe

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe

    C:\WINDOWS\wanmpsvc.exe

    C:\Program Files\Messenger\msmsgs.exe

    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    C:\Program Files\Juno\exec.exe

    C:\Program Files\Microsoft Money\System\mnyexpr.exe

    C:\Program Files\BigFix\BigFix.exe

    C:\Program Files\Google\Google Updater\GoogleUpdater.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Juno\exec.exe

    C:\Program Files\Juno\qsacc\x1exec.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.juno.com/s/search?r=minisearch

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearch

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearch

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/

    R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\Juno\SearchEnh1.dll

    N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\BOB\Application Data\Mozilla\Profiles\default\h5k9xzhj.slt\prefs.js)

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

    O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\Juno\qsacc\X1IEBHO.dll

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)

    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll

    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\Video Add-on\isfmdl.dll

    O2 - BHO: e404 helper - {F10587E9-0E47-4CBE-ABCD-7DD20B862223} - C:\Program Files\Helper\1202511920.dll

    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll

    O3 - Toolbar: JunoBar - {5854FAC4-5BF0-47DD-B5A9-A5EA8CFF3CF4} - C:\Program Files\Juno\Toolbar.dll

    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"

    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup

    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit

    O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r

    O4 - HKLM\..\Run: [CHotkey] zHotkey.exe

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

    O4 - HKLM\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe

    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9

    O4 - HKCU\..\Run: [Juno_uoltray] C:\Program Files\Juno\exec.exe regrun

    O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"

    O4 - HKCU\..\RunOnce: [untd_recovery] "C:\Program Files\Juno\qsacc\x1exec.exe"

    O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\Video Add-on\icthis.exe

    O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe

    O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll

    O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe

    O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe

    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll

    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

    O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe

    O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com

    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

    O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab

    O22 - SharedTaskScheduler: didact - {747e1fbe-b70f-441d-bbca-6e536c04924a} - C:\WINDOWS\system32\wuuawkz.dll

    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe

    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe

    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe

    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe

    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe

    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe

    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Bob/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg

    --

    End of file - 9429 bytes