Jump to content


Photo

Can't Show Hidden Files


  • Please log in to reply
81 replies to this topic

#1 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 02 February 2007 - 03:47 AM

Hi,

I have no idea what was going wrong with my PC. If it is because of the settings, I have tried many times to click on the "Show hidden files and folders" in "Folder Options". But once I have clicked on the "Apply" button, it will still remain in the "Do not show hidden files and folders" option. I have scanned my PC with Kaspersky Antivirus & Spyware Doctor, but they resulted my PC was not infected.

If this is helpful, my HijackThis Log is as below:-

Logfile of HijackThis v1.99.1
Scan saved at 11:34, on 07-02-02
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [upxdn] C:\DOCUME~1\user\LOCALS~1\Temp\upxdn.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spcolsv.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7DD4D29-1A67-4752-8327-0A9D7FC6F019}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

Edited by victorywp, 02 February 2007 - 03:54 AM.


#2 teacup61

teacup61

    Is GSF inventory

  • Charter Members
  • 1,558 posts

Posted 02 February 2007 - 04:57 AM

Hello victorywp,

QUOTE
I have no idea what was going wrong with my PC.
It's infected with this : http://www.sophos.co...l?_log_from=rss

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log

Thanks,
tea

#3 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 05 February 2007 - 02:45 AM

Hi,

This is the Report from SDFix:-


SDFix: Version 1.63

Mon 02/05/2007 - 10:31:10.35

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:

Path:


Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting...

Normal Mode:
Checking Files:

Below files will be copied to Backups folder then removed:

C:\WINDOWS\system32\avginet.exe.exe - Deleted
C:\WINDOWS\system32\sdhelp.exe.exe - Deleted



ADS Check:

C:\WINDOWS\system32
No streams found.

Final Check:

Remaining Services:
------------------


Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\DAP\\DAP.exe"="C:\\Program Files\\DAP\\DAP.exe:*:Enabled:Download Accelerator Plus (DAP)"
"C:\\Program Files\\BitComet\\BitComet.exe"="C:\\Program Files\\BitComet\\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\\Program Files\\Chinese Star XP\\CStar.exe"="C:\\Program Files\\Chinese Star XP\\CStar.exe:*:Enabled:Chinese Star XP"
"C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:?Torrent"
"C:\\Program Files\\Real\\RealPlayer\\trueplay.exe"="C:\\Program Files\\Real\\RealPlayer\\trueplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"


[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.0"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip


Checking For Files with Hidden Attributes :

C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\Tools\All.exe
C:\WINDOWS\system32\Tools\Change.exe
C:\WINDOWS\system32\Tools\CheckPath.exe
C:\WINDOWS\system32\Tools\Counter.exe
C:\WINDOWS\system32\Tools\DelFolders.exe
C:\WINDOWS\system32\Tools\DirectSetup.exe
C:\WINDOWS\system32\Tools\RegClean.exe
C:\WINDOWS\system32\Tools\Regexe.exe
C:\WINDOWS\system32\Tools\Restart.exe
C:\WINDOWS\system32\Tools\RunRegexe.exe

Finished


My new HijackThis Log:-


Logfile of HijackThis v1.99.1
Scan saved at 10:41, on 07-02-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\lxcecoms.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\user\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [upxdn] C:\DOCUME~1\user\LOCALS~1\Temp\upxdn.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spcolsv.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7DD4D29-1A67-4752-8327-0A9D7FC6F019}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe


Thanks!

#4 teacup61

teacup61

    Is GSF inventory

  • Charter Members
  • 1,558 posts

Posted 05 February 2007 - 05:07 AM

Hello,

Please run HijackThis! and click "Scan." Place checks next to the following entries, if present:

O4 - HKLM\..\Run: [upxdn] C:\DOCUME~1\user\LOCALS~1\Temp\upxdn.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [svcshare] C:\WINDOWS\system32\drivers\spcolsv.exe
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)


Close all browsers and other windows except for HijackThis!, and click "Fix Checked".

Navigate to and delete the following files (if they exist):

C:\DOCUME~1\user\LOCALS~1\Temp\upxdn.exe
C:\WINDOWS\system32\drivers\spcolsv.exe

NOTE: You will have to be sure to unhide files and folders to see these, if it will allow you to do so now :

Please enable viewing of hidden files as follows:
1) Go to My Computer, and click on the "Tools" menu
2) Click "Folder options"
3) Select the "View" tab
4) Make sure "Show hidden files and folders" is selected
5) Make sure "Hide extensions for known file types" is unchecked
6) Make sure "Hide protected operating system files (recommended)" is unchecked

Be sure to rehide them when you're done.

Reboot your computer.

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it will produce a log for you. Post that log in your next reply please, along with a new HijackThis log.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall.

Thanks,
tea

Edited by teacup61, 05 February 2007 - 05:23 AM.


#5 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 05 February 2007 - 08:28 AM

Hi,

Combofix Log:-

"user" - 07-02-05 16:04:33 Service Pack 2
ComboFix 07.02.04 - Running from: "C:\Documents and Settings\user\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\All Users\Documents\My Music\Desktop_.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Desktop_.ini
C:\Downloads\Desktop_.ini
C:\Program Files\Desktop_.ini
C:\Program Files\ACD Systems\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\Desktop_.ini
C:\Program Files\Adobe\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\ActiveX\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Esl\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Help\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Help\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Browser\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\HowTo\ENU\Images\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Javascripts\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Legal\Adobe Reader\7.0.0\en_US\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Messages\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Optional\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\AcroForm\PMP\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Annotations\Stamps\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\ImageViewer\en_US\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\Multimedia\MPP\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Howto\images\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\OLS\Locale\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\PictureTasks\Templates\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins\VDKHome\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\plug_ins3d\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\SPPlugins\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\Updater\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Reader\WebSearch\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\CMap\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Font\PFM\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\LanguageNames\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Resource\Linguistics\Providers\Proximity\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig705\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig705\ENU\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\Desktop_.ini
C:\Program Files\Adobe\Acrobat 7.0\Setup Files\RdrBig707\ENU\Desktop_.ini
C:\Program Files\Ahead\Desktop_.ini
C:\Program Files\Ahead\CoverDesigner\Desktop_.ini
C:\Program Files\Ahead\CoverDesigner\LSTemplates\Desktop_.ini
C:\Program Files\Ahead\CoverDesigner\Templates\Desktop_.ini
C:\Program Files\Ahead\ImageDrive\Desktop_.ini
C:\Program Files\Ahead\Nero\Desktop_.ini
C:\Program Files\Ahead\Nero\CDI\Desktop_.ini
C:\Program Files\Ahead\Nero\Uninstall\Desktop_.ini
C:\Program Files\Ahead\Nero BackItUp\Desktop_.ini
C:\Program Files\Ahead\Nero MediaHome\Desktop_.ini
C:\Program Files\Ahead\Nero PhotoSnap\Desktop_.ini
C:\Program Files\Ahead\Nero Recode\Desktop_.ini
C:\Program Files\Ahead\Nero ShowTime\Desktop_.ini
C:\Program Files\Ahead\Nero ShowTime\Skins\Desktop_.ini
C:\Program Files\Ahead\Nero SoundTrax\Desktop_.ini
C:\Program Files\Ahead\Nero StartSmart\Desktop_.ini
C:\Program Files\Ahead\Nero Toolkit\Desktop_.ini
C:\Program Files\Ahead\Nero Wave Editor\Desktop_.ini
C:\Program Files\Ahead\Nero Wave Editor\Presets\Desktop_.ini
C:\Program Files\Ahead\NeroVision\Desktop_.ini
C:\Program Files\Ahead\NeroVision\Buttons\Desktop_.ini
C:\Program Files\Ahead\NeroVision\MenuTemplates\Desktop_.ini
C:\Program Files\Ahead\NeroVision\MenuTemplates\Pictures\Desktop_.ini
C:\Program Files\Ahead\NeroVision\NeroFiles\Desktop_.ini
C:\Program Files\Ahead\NeroVision\NeroFiles\CDI\Desktop_.ini
C:\Program Files\Ahead\NeroVision\Video\Desktop_.ini
C:\Program Files\Ahead\WMPBurn\Desktop_.ini
C:\Program Files\AvRack\Desktop_.ini
C:\Program Files\BitComet\Desktop_.ini
C:\Program Files\BitComet\rules\Desktop_.ini
C:\Program Files\BitComet\tools\Desktop_.ini
C:\Program Files\BitComet\torrents\Desktop_.ini
C:\Program Files\Chinese Star XP\Desktop_.ini
C:\Program Files\Chinese Star XP\cspyII\Desktop_.ini
C:\Program Files\Chinese Star XP\Fonts\Desktop_.ini
C:\Program Files\Chinese Star XP\UserWord\Desktop_.ini
C:\Program Files\Chinese Star XP\UserWord\user\Desktop_.ini
C:\Program Files\Chinese Star XP\UserWord\user\CsIme\Desktop_.ini
C:\Program Files\CyberLink\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\AudioFilter\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\AVSettings\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\AVSettings\Images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\AVSettings\Languages\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\AVSettings\Sounds\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Config\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\InterActual\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_aac\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_aac\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_cprm\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_cprm\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_divx\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_divx\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dolby\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dolby\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dolbyoem\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dolbyoem\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dts\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dts\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dts_es_neo\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dts_es_neo\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dvdaudio\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_dvdaudio\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_h264\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_h264\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_ia\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_ia\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_mpeg-la\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_mpeg-la\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_nb\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Chs\pdvd7_nb\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_aac\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_aac\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_cprm\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_cprm\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_divx\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_divx\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dolby\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dolby\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dolbyoem\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dolbyoem\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dts\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dts\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dts_es_neo\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dts_es_neo\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dvdaudio\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_dvdaudio\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_h264\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_h264\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_ia\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_ia\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_mpeg-la\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_mpeg-la\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_nb\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Cht\pdvd7_nb\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_aac\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_aac\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_cprm\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_cprm\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_divx\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_divx\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dolby\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dolby\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dolbyoem\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dolbyoem\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dts\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dts\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dts_es_neo\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dts_es_neo\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dvdaudio\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_dvdaudio\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_h264\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_h264\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_ia\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_ia\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_mpeg-la\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_mpeg-la\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_nb\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Deu\pdvd7_nb\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_aac\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_aac\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_cprm\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_cprm\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_divx\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_divx\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dolby\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dolby\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dolbyoem\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dolbyoem\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dts\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dts\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dts_es_neo\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dts_es_neo\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dvdaudio\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_dvdaudio\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_h264\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_h264\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_ia\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_ia\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_mpeg-la\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_mpeg-la\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_nb\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Enu\pdvd7_nb\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_aac\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_aac\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_cprm\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_cprm\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_divx\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_divx\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dolby\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dolby\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dolbyoem\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dolbyoem\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dts\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dts\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dts_es_neo\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dts_es_neo\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dvdaudio\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_dvdaudio\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_h264\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_h264\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_ia\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_ia\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_mpeg-la\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_mpeg-la\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_nb\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Esp\pdvd7_nb\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_aac\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_aac\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_cprm\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_cprm\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_divx\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_divx\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dolby\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dolby\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dolbyoem\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dolbyoem\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dts\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dts\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dts_es_neo\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dts_es_neo\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dvdaudio\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_dvdaudio\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_h264\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_h264\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_ia\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_ia\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_mpeg-la\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_mpeg-la\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_nb\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Fra\pdvd7_nb\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_aac\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_aac\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_cprm\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_cprm\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_divx\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_divx\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dolby\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dolby\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dolbyoem\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dolbyoem\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dts\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dts\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dts_es_neo\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dts_es_neo\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dvdaudio\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_dvdaudio\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_h264\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_h264\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_ia\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_ia\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_mpeg-la\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_mpeg-la\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_nb\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Ita\pdvd7_nb\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_aac\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_aac\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_cprm\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_cprm\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_divx\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_divx\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dolby\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dolby\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dolbyoem\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dolbyoem\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dts\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dts\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dts_es_neo\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dts_es_neo\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dvdaudio\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_dvdaudio\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_h264\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_h264\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_ia\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_ia\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_mpeg-la\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_mpeg-la\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_nb\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Jpn\pdvd7_nb\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_aac\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_aac\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_cprm\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_cprm\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_divx\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_divx\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dolby\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dolby\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dolbyoem\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dolbyoem\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dts\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dts\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dts_es_neo\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dts_es_neo\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dvdaudio\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_dvdaudio\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_h264\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_h264\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_ia\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_ia\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_mpeg-la\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_mpeg-la\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_nb\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Language\Kor\pdvd7_nb\images\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\NavFilter\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\OLRSubmission\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Skins\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\Trial\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\UPnP\Desktop_.ini
C:\Program Files\CyberLink\PowerDVD\VideoFilter\Desktop_.ini
C:\Program Files\CyberLink\Shared files\Desktop_.ini
C:\Program Files\DivX\Desktop_.ini
C:\Program Files\DivX\Artwork\Desktop_.ini
C:\Program Files\DivX\AutoUpdate\Desktop_.ini
C:\Program Files\DivX\DivX Codec\Desktop_.ini
C:\Program Files\DivX\DivX Player\Desktop_.ini
C:\Program Files\DivX\DivX Player\Microsoft.VC80.CRT\Desktop_.ini
C:\Program Files\DivX\DivX Player\Skins\Desktop_.ini
C:\Program Files\Grisoft\Desktop_.ini
C:\Program Files\Java\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\bin\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\bin\client\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\applet\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\cmm\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\ext\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\fonts\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\i386\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\im\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\images\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\images\cursors\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\javaws\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\management\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\security\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Africa\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\America\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\America\Argentina\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\America\Indiana\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\America\Kentucky\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\America\North_Dakota\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Antarctica\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Asia\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Atlantic\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Australia\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Etc\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Europe\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Indian\Desktop_.ini
C:\Program Files\Java\jre1.5.0_06\lib\zi\Pacific\Desktop_.ini
C:\Program Files\Keyboard Driver\Desktop_.ini
C:\Program Files\Lexmark 4300 Series\Desktop_.ini
C:\Program Files\Lexmark 4300 Series\Drivers\Desktop_.ini
C:\Program Files\Lexmark 4300 Series\Drivers\english\Desktop_.ini
C:\Program Files\Lexmark Fax Solutions\Desktop_.ini
C:\Program Files\Lexmark Fax Solutions\Install\Desktop_.ini
C:\Program Files\Lexmark Fax Solutions\Install\Config\Desktop_.ini
C:\Program Files\Lexmark Fax Solutions\Install\Config\Image\Desktop_.ini
C:\Program Files\Lexmark Fax Solutions\Install\Config\NLS\Desktop_.ini
C:\Program Files\Lexmark Fax Solutions\Install\x86\Desktop_.ini
C:\Program Files\Lx_cats\Desktop_.ini
C:\Program Files\Microsoft ActiveSync\Desktop_.ini
C:\Program Files\Microsoft Office\Desktop_.ini
C:\Program Files\Microsoft Office\CLIPART\Desktop_.ini
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\Desktop_.ini
C:\Program Files\Microsoft Office\CLIPART\Publisher\Desktop_.ini
C:\Program Files\Microsoft Office\CLIPART\Publisher\Backgrounds\Desktop_.ini
C:\Program Files\Microsoft Office\MEDIA\Desktop_.ini
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\Desktop_.ini
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\1033\Desktop_.ini
C:\Program Files\Microsoft Office\MEDIA\OFFICE11\Desktop_.ini
C:\Program Files\Microsoft Office\MEDIA\OFFICE11\1033\Desktop_.ini
C:\Program Files\Microsoft Office\MEDIA\OFFICE11\AUTOSHAP\Desktop_.ini
C:\Program Files\Microsoft Office\MEDIA\OFFICE11\BULLETS\Desktop_.ini
C:\Program Files\Microsoft Office\MEDIA\OFFICE11\LINES\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\1033\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\1033\011\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\1033\BOTSTYLE\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\1033\DataServices\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\1033\PUBBRD\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\1033\PUBFTSCM\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\1033\PUBWIZ\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\AccessWeb\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\ADDINS\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\BITMAPS\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\BITMAPS\DBWIZ\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\BITMAPS\STYLES\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\CONVERT\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\CONVERT\1033\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\FORMS\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\FORMS\1033\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\HTML\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\INFFORMS\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\INFFORMS\1033\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\Library\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\Migration\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\QUERIES\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\SAMPLES\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\SAMPLES\INFOPATH\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\STARTUP\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\XLATORS\Desktop_.ini
C:\Program Files\Microsoft Office\OFFICE11\XLSTART\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\1033\FAX\Desktop_.ini
C:\Program Files\Microsoft Office\Templates\Presentation Designs\Desktop_.ini
C:\Program Files\Microsoft.NET\Desktop_.ini
C:\Program Files\Microsoft.NET\Primary Interop Assemblies\Desktop_.ini
C:\Program Files\MSN Gaming Zone\Desktop_.ini
C:\Program Files\MSN Messenger\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\10\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\1046\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\11\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\12\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\16\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\19\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\20\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\22\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\29\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\31\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\6\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\7\Desktop_.ini
C:\Program Files\MSN Messenger\Device Manager\Loc\9\Desktop_.ini
C:\Program Files\On-line Help Console\Desktop_.ini
C:\Program Files\Online Services\Desktop_.ini
C:\Program Files\Real\Desktop_.ini
C:\Program Files\Real\RealPlayer\Desktop_.ini
C:\Program Files\Real\RealPlayer\cache_db\Desktop_.ini
C:\Program Files\Real\RealPlayer\cache_db\c_data\Desktop_.ini
C:\Program Files\Real\RealPlayer\cache_db\c_header\Desktop_.ini
C:\Program Files\Real\RealPlayer\cache_db\c_usage\Desktop_.ini
C:\Program Files\Real\RealPlayer\CDBurning\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\attributedto\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\CDBurning\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Channels\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Devices\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Formats\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\CTW\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\CTW\Images\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\images\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\404\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\acct\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\cdburning\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\Central\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\Channels\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\Common\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\CTW\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\custsupport\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\custsupport\pccontrols\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\custsupport\prodsurvey\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\custsupport\sersupport\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\custsupport\techsupport\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\default\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\Devices\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\Error\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\Guide\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\Home\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\musicguide\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\musicstore\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\radio\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\search\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\skins\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\toc\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\trig\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\tutorials\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\upsell\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\visualizations\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\Web\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\wrn\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\loc\en\xpr\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\page\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GetMedia\page\Common\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\GPFeat\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Help\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\howto\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\keywords\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\library\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\data\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\images\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\images\alerts\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\images\btns\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\images\btns\139x24\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\images\btns\139x28\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\images\btns\184x24\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\images\btns\184x28\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\images\btns\94x24\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\images\btns\94x28\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\js\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\loc\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\loc\en\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Login\templates\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\mstore\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\musicguide\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\prefs\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\Radio\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\search\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\sendlink\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\web\Desktop_.ini
C:\Program Files\Real\RealPlayer\DataCache\webresources\Desktop_.ini
C:\Program Files\Real\RealPlayer\Devices\Desktop_.ini
C:\Program Files\Real\RealPlayer\Firstrun\Desktop_.ini
C:\Program Files\Real\RealPlayer\Firstrun\localguide_files\Desktop_.ini
C:\Program Files\Real\RealPlayer\library\Desktop_.ini
C:\Program Files\Real\RealPlayer\Netscape6\Desktop_.ini
C:\Program Files\Real\RealPlayer\plugins\Desktop_.ini
C:\Program Files\Real\RealPlayer\Producer\Desktop_.ini
C:\Program Files\Real\RealPlayer\Producer\Plugins\Desktop_.ini
C:\Program Files\Real\RealPlayer\Producer\Tools\Desktop_.ini
C:\Program Files\Real\RealPlayer\rpplugins\Desktop_.ini
C:\Program Files\Real\RealPlayer\Setup\Desktop_.ini
C:\Program Files\Real\RealPlayer\Setup\accesspoints\Desktop_.ini
C:\Program Files\Real\RealPlayer\templates\Desktop_.ini
C:\Program Files\Realtek AC97\Desktop_.ini
C:\Program Files\Realtek Sound Manager\Desktop_.ini
C:\Program Files\S3\Desktop_.ini
C:\Program Files\S3\UChromeP\Desktop_.ini
C:\Program Files\Skype\Desktop_.ini
C:\Program Files\Skype\Phone\Desktop_.ini
C:\Program Files\Spyware Nuker\Desktop_.ini
C:\Program Files\Uninstall Information\Desktop_.ini
C:\Program Files\VIA\Desktop_.ini
C:\Program Files\VIA\Setup\Desktop_.ini
C:\Program Files\VIA\Setup\viamach\Desktop_.ini
C:\Program Files\VIA\Setup\videfilt\Desktop_.ini
C:\Program Files\Winamp\Desktop_.ini
C:\Program Files\Winamp\Plugins\Desktop_.ini
C:\Program Files\Winamp\Plugins\avs\Desktop_.ini
C:\Program Files\Winamp\Plugins\avs\Community Picks\Desktop_.ini
C:\Program Files\Winamp\Plugins\avs\Winamp 5 Picks\Desktop_.ini
C:\Program Files\Winamp\Plugins\DSP_SPS\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\wacs\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\wacs\jpgload\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\about\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\checkbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\combobox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\dropdownlist\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\historyeditbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\menubutton\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\msgbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\pathpicker\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\popupmenu\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\statusbar\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\tabsheet\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\titlebox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\tooltips\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\fonts\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\garbage\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\menu\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\Scripts\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\window\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\groups\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\button\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\editbox\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\slider\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\standardframe\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\text\Desktop_.ini
C:\Program Files\Winamp\Plugins\freeform\xml\wasabi\xml\xui\titlebar\Desktop_.ini
C:\Program Files\Winamp\Plugins\Milkdrop\Desktop_.ini
C:\Program Files\Winamp\Plugins\ml\Desktop_.ini
C:\Program Files\Winamp\Plugins\ml\cache\Desktop_.ini
C:\Program Files\Winamp\Plugins\Predixis MusicMagic\Desktop_.ini
C:\Program Files\Winamp\Plugins\Predixis MusicMagic\images\Desktop_.ini
C:\Program Files\Winamp\Skins\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\about\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\notifier\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\player\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\scripts\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\shade\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\standardframe\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\titlebar\Desktop_.ini
C:\Program Files\Winamp\

#6 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 05 February 2007 - 08:37 AM

C:\Program Files\Winamp\Skins\Winamp Modern\titlebar\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\window\Desktop_.ini
C:\Program Files\Winamp\Skins\Winamp Modern\xml\Desktop_.ini
C:\Program Files\Winamp\System\Desktop_.ini
C:\Program Files\WinRAR\Desktop_.ini
C:\Program Files\WinRAR\Formats\Desktop_.ini
C:\Program Files\xerox\Desktop_.ini
C:\Program Files\xerox\nwwia\Desktop_.ini
C:\Program Files\Yahoo!\Desktop_.ini
C:\Program Files\Yahoo!\Common\Desktop_.ini
C:\Program Files\Yahoo!\Companion\Desktop_.ini
C:\Program Files\Yahoo!\Companion\Installs\Desktop_.ini
C:\Program Files\Yahoo!\Companion\Installs\cpn\Desktop_.ini
C:\Program Files\Yahoo!\Installs\Desktop_.ini
C:\Program Files\Yahoo!\Shared\Desktop_.ini
C:\Program Files\Yahoo!\Shared\Graphics\Desktop_.ini
C:\Program Files\Yahoo!\Shared\Graphics\Indigo\Desktop_.ini
C:\Program Files\Yahoo!\Shared\Graphics\Maverick\Desktop_.ini
C:\RECYCLER\Desktop_.ini
C:\Temp\Desktop_.ini
C:\Temp\{9F5FBC24-EFE2-4f90-B498-EC0FB7D47D15}\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style1\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style1\css\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style1\pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style1\pages\image\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style1\pages\thumbnail\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style1\resources\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style2\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style2\css\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style2\pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style2\pages\image\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style2\pages\thumbnail\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style2\resources\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style3\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style3\css\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style3\pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style3\pages\image\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style3\pages\index\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style3\pages\thumbnail\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style3\resources\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style4\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style4\css\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style4\pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style4\pages\image\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style4\pages\index\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style4\pages\thumbnail\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style4\resources\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style5\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style5\css\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style5\pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style5\pages\image\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style5\pages\thumbnail\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style5\resources\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style6\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style6\css\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style6\pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style6\pages\image\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style6\pages\thumbnail\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style6\resources\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style7\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style7\css\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style7\pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style7\pages\image\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style7\pages\thumbnail\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style7\resources\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style8\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style8\css\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style8\pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style8\pages\image\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style8\pages\thumbnail\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style8\resources\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style9\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style9\css\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style9\pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style9\pages\image\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style9\pages\index\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style9\pages\thumbnail\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\AlbumGenerator\Styles\Style9\resources\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Effects\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Artistic\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Birthday\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Classic\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Contemporary\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Industrial\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Modern\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Nature\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Sports\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Urban\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\NTSC\Wedding\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Artistic\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Birthday\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Classic\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Contemporary\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Industrial\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Modern\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Nature\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Sports\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Urban\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Templates\PAL\Wedding\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Welcome\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\bin\Welcome\Graphics\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\LM\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\LM\Pages\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\LM\Products\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\QuickStart\Desktop_.ini
C:\Program Files\ACD Systems\ACDSee\8.0.Pro\QuickStart\img\Desktop_.ini


((((((((((((((((((((((((((((((( Files Created from 2007-01-05 to 2007-02-05 ))))))))))))))))))))))))))))))))))


2007-02-05 16:15 <DIR> d-------- C:\WINDOWS\ERDNT
2007-02-05 16:02 <DIR> d-------- C:\!KillBox
2007-02-05 10:27 <DIR> d-------- C:\SDFix
2007-02-01 16:16 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2007-02-01 16:16 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2007-02-01 16:16 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-02-01 16:16 <DIR> d-------- C:\DOCUME~1\user\Application Data\PC Tools
2007-02-01 16:14 <DIR> d--h----- C:\WINDOWS\PIF
2007-01-29 14:56 1,035,688 --a------ C:\WINDOWS\system32\exec1.exe
2007-01-25 17:41 <DIR> d-------- C:\DOCUME~1\user\Application Data\WinRAR
2007-01-24 18:40 <DIR> d-------- C:\DOCUME~1\user\Application Data\uTorrent
2007-01-24 09:53 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2007-01-24 09:53 <DIR> d-------- C:\Program Files\DAP
2007-01-24 08:44 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-01-24 08:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Kaspersky Lab
2007-01-24 08:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Avg7
2007-01-24 08:33 <DIR> d-------- C:\kav
2007-01-23 11:56 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2007-01-23 11:32 67,645 --a------ C:\WINDOWS\system32\drivers\pshook11.sys
2007-01-23 11:32 <DIR> d-------- C:\Program Files\Spyware Nuker
2007-01-22 08:20 <DIR> d-------- C:\DOCUME~1\user\Application Data\FaxCtr
2007-01-19 16:06 98,345 --a------ C:\WINDOWS\system32\IMHOST32.DLL
2007-01-19 16:06 339,968 --a------ C:\WINDOWS\system32\IMGMAN32.DLL
2007-01-19 16:06 32,768 --a------ C:\WINDOWS\system32\LXPRMON.DLL
2007-01-19 16:06 20,480 --a------ C:\WINDOWS\system32\LXPMONUI.DLL
2007-01-19 16:06 12,288 --a------ C:\WINDOWS\system32\LXPMONRC.DLL
2007-01-19 16:06 <DIR> d-------- C:\Program Files\Lexmark Fax Solutions
2007-01-19 16:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\FaxCtr
2007-01-19 10:54 <DIR> d-------- C:\WINDOWS\system32\bak
2007-01-18 10:08 38,912 --------- C:\WINDOWS\system32\picn20.dll
2007-01-18 10:08 3,051,520 --------- C:\WINDOWS\UNNeroVision.exe
2007-01-18 10:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Ahead
2007-01-18 10:04 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2007-01-08 15:28 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-01-08 15:25 <DIR> d-------- C:\Temp
2007-01-08 15:19 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll
2007-01-08 15:19 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-01-08 15:19 <DIR> d-------- C:\Program Files\Lexmark 4300 Series


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-05 16:13 -------- d-------- C:\Program Files\yahoo!
2007-02-05 16:13 -------- d-------- C:\Program Files\winamp
2007-02-05 16:13 -------- d-------- C:\Program Files\via
2007-02-05 16:13 -------- d-------- C:\Program Files\skype
2007-02-05 16:13 -------- d-------- C:\Program Files\s3
2007-02-05 16:13 -------- d-------- C:\Program Files\realtek sound manager
2007-02-05 16:13 -------- d-------- C:\Program Files\realtek ac97
2007-02-05 16:13 -------- d-------- C:\Program Files\real
2007-02-05 16:13 -------- d-------- C:\Program Files\online services
2007-02-05 16:13 -------- d-------- C:\Program Files\on-line help console
2007-02-05 16:12 -------- d-------- C:\Program Files\msn messenger
2007-02-05 16:12 -------- d-------- C:\Program Files\msn gaming zone
2007-02-05 16:12 -------- d-------- C:\Program Files\microsoft.net
2007-02-05 16:11 -------- d-------- C:\Program Files\microsoft activesync
2007-02-05 16:11 -------- d-------- C:\Program Files\lx_cats
2007-02-05 16:11 -------- d-------- C:\Program Files\keyboard driver
2007-02-05 16:11 -------- d-------- C:\Program Files\java
2007-02-05 16:11 -------- d-------- C:\Program Files\grisoft
2007-02-05 16:11 -------- d-------- C:\Program Files\divx
2007-02-05 16:10 -------- d-------- C:\Program Files\cyberlink
2007-02-05 16:10 -------- d-------- C:\Program Files\chinese star xp
2007-02-05 16:10 -------- d-------- C:\Program Files\bitcomet
2007-02-05 16:10 -------- d-------- C:\Program Files\avrack
2007-02-05 16:10 -------- d-------- C:\Program Files\ahead
2007-02-05 16:09 -------- d-------- C:\Program Files\acd systems
2007-02-01 16:16 -------- d-------- C:\Documents and Settings\user\Application Data\pc tools
2007-01-29 15:31 2560 --a------ C:\WINDOWS\system32\bitcometres.dll
2007-01-25 17:41 -------- d-------- C:\Documents and Settings\user\Application Data\winrar
2007-01-25 15:48 -------- d-------- C:\Documents and Settings\user\Application Data\utorrent
2007-01-24 10:04 -------- d-------- C:\Program Files\freerip
2007-01-24 09:45 -------- d---s---- C:\Documents and Settings\user\Application Data\microsoft
2007-01-24 09:04 17505 --a------ C:\DBI.EXE
2007-01-22 08:20 -------- d-------- C:\Documents and Settings\user\Application Data\faxctr
2007-01-19 11:24 38412 --a------ C:\WINDOWS\system32\nerocheck.exe
2006-12-26 14:19 -------- d-------- C:\Documents and Settings\user\Application Data\divx
2006-12-20 09:30 -------- dr-h----- C:\Documents and Settings\user\Application Data\yahoo!
2006-12-18 16:25 -------- d-------- C:\Documents and Settings\user\Application Data\sun
2006-12-18 16:09 -------- d-------- C:\Documents and Settings\user\Application Data\skype
2006-12-18 15:47 -------- d-------- C:\Documents and Settings\user\Application Data\macromedia
2006-12-18 11:55 -------- d-------- C:\Documents and Settings\user\Application Data\adobeum
2006-12-18 11:34 -------- d-------- C:\Documents and Settings\user\Application Data\adobe
2006-12-15 18:46 176167 --a------ C:\WINDOWS\system32\rmocx.dll
2006-12-15 18:35 -------- d-------- C:\Documents and Settings\user\Application Data\acd systems
2006-12-13 00:30 520192 --a------ C:\WINDOWS\system32\divxsm.exe
2006-12-13 00:30 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2006-12-13 00:30 20640 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2006-12-13 00:30 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2006-12-13 00:30 109568 --------- C:\WINDOWS\system32\pxinsi64.exe
2006-12-13 00:30 108544 --------- C:\WINDOWS\system32\pxcpyi64.exe
2006-12-13 00:30 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2006-12-13 00:25 806912 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-12-13 00:25 806912 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-12-13 00:25 790528 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-12-13 00:25 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2006-12-13 00:25 635486 --a------ C:\WINDOWS\system32\divx.dll
2006-12-13 00:25 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2006-12-13 00:25 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2006-12-13 00:25 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2006-12-13 00:25 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2006-12-13 00:25 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2006-12-13 00:25 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2006-12-13 00:25 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2006-12-13 00:24 12288 --a------ C:\WINDOWS\system32\divxwmpexttype.dll
2006-12-13 00:24 118784 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"PHIME2002ASync"="\"C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE\" /SYNC"
"PHIME2002A"="\"C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE\" /IMEName"
"VTTimer"="VTTimer.exe"
"VTTrayp"="VTtrayp.exe"
"SoundMan"="SOUNDMAN.EXE"
"LXCECATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXCEtime.dll,_RunDLLEntry@16"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"FaxCenterServer"="\"C:\\Program Files\\Lexmark Fax Solutions\\fm3032.exe\" /s"
"AVP"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgcc"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Device Detector]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DevDetect"
"hkey"="HKLM"
"command"="DevDetect.exe -autorun"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Language"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winampa"
"hkey"="HKLM"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0

*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_MCHINJDRV


********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-02-05 16:18:25


Hijackthis Log:-

Logfile of HijackThis v1.99.1
Scan saved at 4:20:03 PM, on 2/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\Documents and Settings\user\Desktop\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7DD4D29-1A67-4752-8327-0A9D7FC6F019}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

Thanks!

Edited by victorywp, 05 February 2007 - 08:40 AM.


#7 teacup61

teacup61

    Is GSF inventory

  • Charter Members
  • 1,558 posts

Posted 05 February 2007 - 02:51 PM

Youch! That was really nasty. :( Your system could be damaged, and we may not be able to fix it. We can clean the malware, but you may be left with errors that can't be fixed. This is what happens when you download c-racks from P2P sites! Free is not really free when you do this....this is the price you pay. :( After it's clean again you'll have to change all your passwords, because they've likely been got. Don't do it now, or they'll be gotten again. The installer is still present, and there is a lot to do. Before beginning, you may want to save these instructions to Notepad or print them out for easier reference.

Please do everything in the order I give, because I need the installer file first.

Go here: http://www.bleepingc...e.php?channel=8

Enter the link to this thread in the box " Link to topic where this file was requested:"
Click the browse button and find the file C:\WINDOWS\system32\exec1.exe Highlight it and click open. Then click " Send File ".

1) Please download the Killbox.
Save it to the desktop and run it.

2) Select "Delete on Reboot", and then select "All files".

3) Copy the file name below to the clipboard by highlighting it and pressing Ctrl-C:

C:\WINDOWS\system32\exec1.exe

4) Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

5) Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

Please download ATF Cleaner by Atribune.
    Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

I'd like you to perform an online virus scan with Kaspersky Online Virus Scanner

Navigate (using Internet Explorer only, other browsers won't work) to the following site: http://www.kaspersky.com/virusscanner

Click the "Kaspersky Online Scanner" button (NOT "Kaspersky File Scanner").

* In the new window that opens, click the "Accept" button to accept the user agreement, install the ActiveX control, and download the program.
* When you get the Windows dialog asking if you want to install this software, click the "Install" button.
* The scanner will download the latest definition files. When the "Update progress" line changes to "Ready" and the "NEXT ->" button lights up with a green arrow, click it.
* Click on the "Scan Settings" button, and in the next window select the "extended" database, and click Ok.
* Under "Please select a target to scan:", click My Computer to start the scan.

When the scan is finished, click the "Save as Text" button, and save the file as kavscan.txt to your Desktop. Post the report in your reply, please. Close the Kaspersky On-line Scanner window.


* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:

    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously, along with a new HijackThis log in your next reply.

So, in your reply I need to see the reports from Kaspersky, Dr. Web, and a new HijackThis log. Please also let me know how your computer is running now.

Thanks,
tea

#8 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 06 February 2007 - 02:51 AM

Hi,

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Tuesday, February 06, 2007 10:09:06 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 6/02/2007
Kaspersky Anti-Virus database records: 265249
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\

Scan Statistics:
Total number of scanned objects: 28659
Number of viruses found: 17
Number of infected objects: 26 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:18:18

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\0308_File_Monitoring_eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\030a_Web_Monitoring_eventcritlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\030a_Web_Monitoring_eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\030c_pdm_eventcritlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\030c_pdm_eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\030c_pdm_eventlog_reg.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\detected.idx Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\detected.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\eventlog.rpt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP6\Report\report.rpt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\user\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\user\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\Temp\Perflib_Perfdata_780.dat Object is locked skipped
C:\Documents and Settings\user\Local Settings\Temp\~DFA5D5.tmp Object is locked skipped
C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\user\My Documents\My Received Files\Cyril - Magic Revolution (FujiTV 2006.06.20).avi Object is locked skipped
C:\Documents and Settings\user\My Documents\My Received Files\Learn Korean\Pimsleur - Korean [10units]\Pimsleur Korean I Lesson 01.mp3 Object is locked skipped
C:\Documents and Settings\user\My Documents\My Received Files\Learn Korean\Pimsleur - Korean [10units]\Pimsleur Korean I Lesson 03.mp3 Object is locked skipped
C:\Documents and Settings\user\My Documents\My Received Files\Learn Korean\Pimsleur - Korean [10units]\Pimsleur Korean I Lesson 06.mp3 Object is locked skipped
C:\Documents and Settings\user\My Documents\My Received Files\Learn Korean\Pimsleur - Korean [10units]\Pimsleur Korean I Lesson 09.mp3 Object is locked skipped
C:\Documents and Settings\user\My Documents\My Received Files\Lynda.com - eBay Essential Training\Lynda.com.eBay.Essential.Training-MOJO.rar Object is locked skipped
C:\Documents and Settings\user\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\user\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0015593.sys Infected: Virus.Win32.Sality.s skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0015594.sys Infected: Email-Worm.Win32.Zhelatin.d skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0016612.exe Infected: Virus.Win32.Sality.s skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0016613.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0016614.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0016615.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0016616.dll Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0016617.exe Infected: not-a-virus:FraudTool.Win32.SpySheriff.a skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0016619.dll Infected: Email-Worm.Win32.Banwarum.f skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0016620.sys Infected: SpamTool.Win32.Agent.s skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0016624.exe Infected: Email-Worm.Win32.Zhelatin.p skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0017637.dll Infected: Trojan-Proxy.Win32.Agent.df skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0017638.exe Infected: Packed.Win32.PePatch.dw skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0017639.dll Infected: Email-Worm.Win32.-- not allowed here --ov.et skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0017640.exe Infected: not-virus:Hoax.Win32.Renos.gc skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0017641.exe Infected: Trojan-Downloader.Win32.Small.awa skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0017642.exe Infected: Trojan-Downloader.Win32.Small.ciw skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0017643.exe Infected: Trojan-Dropper.Win32.Delf.va skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\A0017644.exe Infected: Trojan-Downloader.Win32.Agent.bca skipped
C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\aa.exe.exe Infected: Email-Worm.Win32.Zhelatin.p skipped
C:\WINDOWS\system32\af.exe.exe Infected: Email-Worm.Win32.Zhelatin.d skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\2JSJI14T\sev2[1].exe Infected: Email-Worm.Win32.Zhelatin.p skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\2JSJI14T\t100[1].exe Infected: Virus.Win32.Sality.s skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\EB2YRYEB\inst318ss[1].exe Infected: Trojan-Dropper.Win32.Agent.ol skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\EB2YRYEB\nldr[1].exe Infected: Trojan-Downloader.Win32.Small.cib skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\P0792C2S\msits[1].exe Infected: Trojan-Downloader.Win32.Delf.aeu skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44\change.log Object is locked skipped

Scan process completed.

#9 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 06 February 2007 - 02:56 AM

Dr.Web Log:-

system.dll;C:\Program Files\Common Files\{DC4D7858-074A-1033-0720-060905050001};Trojan.DownLoader.18142;Deleted.;
Update.exe;C:\Program Files\Common Files\{DC4D7858-074A-1033-0720-060905050001};Trojan.DownLoader.18142;Deleted.;
system.dll;C:\RECYCLER\S-1-5-18\Dc1;Trojan.DownLoader.18142;Deleted.;
Update.exe;C:\RECYCLER\S-1-5-18\Dc1;Trojan.DownLoader.18142;Deleted.;
system.dll;C:\RECYCLER\S-1-5-18\Dc2;Trojan.DownLoader.18142;Deleted.;
Update.exe;C:\RECYCLER\S-1-5-18\Dc2;Trojan.DownLoader.18142;Deleted.;
system.dll;C:\RECYCLER\S-1-5-18\Dc3;Trojan.DownLoader.18142;Deleted.;
Update.exe;C:\RECYCLER\S-1-5-18\Dc3;Trojan.DownLoader.18142;Deleted.;
system.dll;C:\RECYCLER\S-1-5-18\Dc4;Trojan.DownLoader.18142;Deleted.;
Update.exe;C:\RECYCLER\S-1-5-18\Dc4;Trojan.DownLoader.18142;Deleted.;
Process.exe;C:\SDFix\apps;Tool.Prockill;;
A0016622.exe;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0016624.exe;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.Packed.11;Deleted.;
A0017660.dll;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0017661.exe;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0017662.dll;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0017663.exe;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0017664.dll;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0017665.exe;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0017666.dll;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0017667.exe;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0017668.dll;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
A0017669.exe;C:\System Volume Information\_restore{1AFDC2F5-93B1-42B8-A0C2-CFC9BD7A202E}\RP44;Trojan.DownLoader.18142;Deleted.;
aa.exe.exe;C:\WINDOWS\system32;Trojan.Packed.11;Deleted.;
af.exe.exe;C:\WINDOWS\system32;Trojan.Packed.11;Deleted.;
sev2[1].exe;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\2JSJI14T;Trojan.Packed.8;Deleted.;
v30_crab_106[1].exe;C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\ULKXINKX;Trojan.EmailSpy;Deleted.;

#10 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 06 February 2007 - 02:57 AM

Logfile of HijackThis v1.99.1
Scan saved at 10:48:37 AM, on 2/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\system32\VTtrayp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\lxcecoms.exe
c:\program files\internet explorer\iexplore.exe
C:\Documents and Settings\user\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: c.uloec.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /SYNC
O4 - HKLM\..\Run: [PHIME2002A] "C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" /IMEName
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7DD4D29-1A67-4752-8327-0A9D7FC6F019}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Client IP-IPX - Unknown owner - -e,te-110-12-0000273, (file missing)
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: Macromedia Updater (mmupdate) - Unknown owner - C:\WINDOWS\TEMP\1A.tmp".exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

Edited by victorywp, 06 February 2007 - 03:14 AM.


#11 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 06 February 2007 - 03:13 AM

QUOTE (teacup61 @ Feb 5 2007, 10:51 PM) <{POST_SNAPBACK}>
So, in your reply I need to see the reports from Kaspersky, Dr. Web, and a new HijackThis log. Please also let me know how your computer is running now.

Hi,

So the above 3 posts are my Kaspersky Log, Dr. Web Log & new HijackThis Log. Regarding how my computer is running now, the "Show hidden files and folders" in "Folder Options" is working already. Temporarily my operating system seems fine & it has not cause other serious problems. Anyway, I am waiting for your next advice.

Thanks!

Edited by victorywp, 06 February 2007 - 03:15 AM.


#12 teacup61

teacup61

    Is GSF inventory

  • Charter Members
  • 1,558 posts

Posted 06 February 2007 - 04:23 AM

Hello,

Good to know there's been progress! :) Did you get the file uploaded that I asked for?

Please run ComboFix again, and post the report.

Thanks,
tea

#13 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 06 February 2007 - 05:37 AM

Hi,

Yup I have uploaded the file that you have requested to http://www.bleepingc...e.php?channel=8

New Combofix Log:-

"user" - 07-02-06 13:24:01 Service Pack 2
ComboFix 07.02.04 - Running from: "C:\Documents and Settings\user\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\unsvchosts.exe
C:\Program Files\Common Files\{DC4D7~1


((((((((((((((((((((((((((((((( Files Created from 2007-01-06 to 2007-02-06 ))))))))))))))))))))))))))))))))))


2007-02-06 10:12 <DIR> d-------- C:\DOCUME~1\user\DoctorWeb
2007-02-06 09:26 <DIR> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-02-05 19:13 391 --a------ C:\WINDOWS\system32\z14.exe
2007-02-05 19:13 34,069 --a------ C:\WINDOWS\system32\jsywrt32.dll
2007-02-05 19:13 169,984 --a------ C:\WINDOWS\system32\tevfclx.dll
2007-02-05 16:15 <DIR> d-------- C:\WINDOWS\ERDNT
2007-02-05 16:02 <DIR> d-------- C:\!KillBox
2007-02-05 10:27 <DIR> d-------- C:\SDFix
2007-02-01 16:16 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2007-02-01 16:16 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2007-02-01 16:16 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-02-01 16:16 <DIR> d-------- C:\DOCUME~1\user\Application Data\PC Tools
2007-02-01 16:14 <DIR> d--h----- C:\WINDOWS\PIF
2007-01-25 17:41 <DIR> d-------- C:\DOCUME~1\user\Application Data\WinRAR
2007-01-24 18:40 <DIR> d-------- C:\DOCUME~1\user\Application Data\uTorrent
2007-01-24 09:53 50,688 --a------ C:\WINDOWS\system32\wbhelp2.dll
2007-01-24 09:53 <DIR> d-------- C:\Program Files\DAP
2007-01-24 08:44 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-01-24 08:44 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Kaspersky Lab
2007-01-24 08:42 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Avg7
2007-01-24 08:33 <DIR> d-------- C:\kav
2007-01-23 11:56 <DIR> d-a------ C:\DOCUME~1\ALLUSE~1\Application Data\TEMP
2007-01-23 11:32 67,645 --a------ C:\WINDOWS\system32\drivers\pshook11.sys
2007-01-23 11:32 <DIR> d-------- C:\Program Files\Spyware Nuker
2007-01-22 08:20 <DIR> d-------- C:\DOCUME~1\user\Application Data\FaxCtr
2007-01-19 16:06 98,345 --a------ C:\WINDOWS\system32\IMHOST32.DLL
2007-01-19 16:06 339,968 --a------ C:\WINDOWS\system32\IMGMAN32.DLL
2007-01-19 16:06 32,768 --a------ C:\WINDOWS\system32\LXPRMON.DLL
2007-01-19 16:06 20,480 --a------ C:\WINDOWS\system32\LXPMONUI.DLL
2007-01-19 16:06 12,288 --a------ C:\WINDOWS\system32\LXPMONRC.DLL
2007-01-19 16:06 <DIR> d-------- C:\Program Files\Lexmark Fax Solutions
2007-01-19 16:06 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\FaxCtr
2007-01-19 10:54 <DIR> d-------- C:\WINDOWS\system32\bak
2007-01-18 10:08 38,912 --------- C:\WINDOWS\system32\picn20.dll
2007-01-18 10:08 3,051,520 --------- C:\WINDOWS\UNNeroVision.exe
2007-01-18 10:08 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Ahead
2007-01-18 10:04 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2007-01-08 15:28 <DIR> d-------- C:\WINDOWS\system32\appmgmt
2007-01-08 15:25 <DIR> d-------- C:\Temp
2007-01-08 15:19 87,040 --a------ C:\WINDOWS\system32\wiafbdrv.dll
2007-01-08 15:19 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-01-08 15:19 <DIR> d-------- C:\Program Files\Lexmark 4300 Series


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-06 10:47 -------- d-------- C:\Program Files\lx_cats
2007-02-05 16:19 -------- d-------- C:\Program Files\bitcomet
2007-02-05 16:13 -------- d-------- C:\Program Files\yahoo!
2007-02-05 16:13 -------- d-------- C:\Program Files\winamp
2007-02-05 16:13 -------- d-------- C:\Program Files\via
2007-02-05 16:13 -------- d-------- C:\Program Files\skype
2007-02-05 16:13 -------- d-------- C:\Program Files\s3
2007-02-05 16:13 -------- d-------- C:\Program Files\realtek sound manager
2007-02-05 16:13 -------- d-------- C:\Program Files\realtek ac97
2007-02-05 16:13 -------- d-------- C:\Program Files\real
2007-02-05 16:13 -------- d-------- C:\Program Files\online services
2007-02-05 16:13 -------- d-------- C:\Program Files\on-line help console
2007-02-05 16:12 -------- d-------- C:\Program Files\msn messenger
2007-02-05 16:12 -------- d-------- C:\Program Files\msn gaming zone
2007-02-05 16:12 -------- d-------- C:\Program Files\microsoft.net
2007-02-05 16:11 -------- d-------- C:\Program Files\microsoft activesync
2007-02-05 16:11 -------- d-------- C:\Program Files\keyboard driver
2007-02-05 16:11 -------- d-------- C:\Program Files\java
2007-02-05 16:11 -------- d-------- C:\Program Files\grisoft
2007-02-05 16:11 -------- d-------- C:\Program Files\divx
2007-02-05 16:10 -------- d-------- C:\Program Files\cyberlink
2007-02-05 16:10 -------- d-------- C:\Program Files\chinese star xp
2007-02-05 16:10 -------- d-------- C:\Program Files\avrack
2007-02-05 16:10 -------- d-------- C:\Program Files\ahead
2007-02-05 16:09 -------- d-------- C:\Program Files\acd systems
2007-01-29 15:31 2560 --a------ C:\WINDOWS\system32\bitcometres.dll
2007-01-24 10:04 -------- d-------- C:\Program Files\freerip
2007-01-24 09:45 -------- d---s---- C:\DOCUME~1\user\Application Data\microsoft
2007-01-24 09:04 17505 --a------ C:\DBI.EXE
2007-01-19 11:24 38412 --a------ C:\WINDOWS\system32\nerocheck.exe
2006-12-26 14:19 -------- d-------- C:\DOCUME~1\user\Application Data\divx
2006-12-20 09:30 -------- dr-h----- C:\DOCUME~1\user\Application Data\yahoo!
2006-12-18 16:25 -------- d-------- C:\DOCUME~1\user\Application Data\sun
2006-12-18 16:09 -------- d-------- C:\DOCUME~1\user\Application Data\skype
2006-12-18 15:47 -------- d-------- C:\DOCUME~1\user\Application Data\macromedia
2006-12-18 11:55 -------- d-------- C:\DOCUME~1\user\Application Data\adobeum
2006-12-18 11:34 -------- d-------- C:\DOCUME~1\user\Application Data\adobe
2006-12-15 18:46 176167 --a------ C:\WINDOWS\system32\rmocx.dll
2006-12-15 18:35 -------- d-------- C:\DOCUME~1\user\Application Data\acd systems
2006-12-13 00:30 520192 --a------ C:\WINDOWS\system32\divxsm.exe
2006-12-13 00:30 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2006-12-13 00:30 20640 --------- C:\WINDOWS\system32\drivers\PxHelp20.sys
2006-12-13 00:30 200704 --a------ C:\WINDOWS\system32\ssldivx.dll
2006-12-13 00:30 109568 --------- C:\WINDOWS\system32\pxinsi64.exe
2006-12-13 00:30 108544 --------- C:\WINDOWS\system32\pxcpyi64.exe
2006-12-13 00:30 1044480 --a------ C:\WINDOWS\system32\libdivx.dll
2006-12-13 00:25 806912 --a------ C:\WINDOWS\system32\divx_xx0c.dll
2006-12-13 00:25 806912 --a------ C:\WINDOWS\system32\divx_xx07.dll
2006-12-13 00:25 790528 --a------ C:\WINDOWS\system32\divx_xx11.dll
2006-12-13 00:25 73728 --a------ C:\WINDOWS\system32\dpl100.dll
2006-12-13 00:25 635486 --a------ C:\WINDOWS\system32\divx.dll
2006-12-13 00:25 593920 --a------ C:\WINDOWS\system32\dpugui11.dll
2006-12-13 00:25 57344 --a------ C:\WINDOWS\system32\dpv11.dll
2006-12-13 00:25 53248 --a------ C:\WINDOWS\system32\dpugui10.dll
2006-12-13 00:25 344064 --a------ C:\WINDOWS\system32\dpus11.dll
2006-12-13 00:25 294912 --a------ C:\WINDOWS\system32\dpu11.dll
2006-12-13 00:25 294912 --a------ C:\WINDOWS\system32\dpu10.dll
2006-12-13 00:25 196608 --a------ C:\WINDOWS\system32\dtu100.dll
2006-12-13 00:24 12288 --a------ C:\WINDOWS\system32\divxwmpexttype.dll
2006-12-13 00:24 118784 --a------ C:\WINDOWS\system32\divxcodecupdatechecker.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"BitComet"="\"C:\\Program Files\\BitComet\\BitComet.exe\""
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32"
"PHIME2002ASync"="\"C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE\" /SYNC"
"PHIME2002A"="\"C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE\" /IMEName"
"VTTimer"="VTTimer.exe"
"VTTrayp"="VTtrayp.exe"
"SoundMan"="SOUNDMAN.EXE"
"LXCECATS"="rundll32 C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\LXCEtime.dll,_RunDLLEntry@16"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"FaxCenterServer"="\"C:\\Program Files\\Lexmark Fax Solutions\\fm3032.exe\" /s"
"AVP"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG7_CC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgcc"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Device Detector]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DevDetect"
"hkey"="HKLM"
"command"="DevDetect.exe -autorun"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Language"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\Language\\Language.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="PDVDServ"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="winampa"
"hkey"="HKLM"
"command"="C:\\Program Files\\Winamp\\winampa.exe"
"inimapping"="0"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Spyware Doctor"="\"C:\\Program Files\\Spyware Doctor\\swdoctor.exe\" /Q"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

SafeBoot registry key needs to be repaired. This machine cannot enter Safe Mode.

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0



********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes ...

scanning hidden services ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-02-06 13:26:09
C:\ComboFix2.txt ... 07-02-05 16:25

#14 victorywp

victorywp

    Adv. Member

  • Active Members
  • 89 posts

Posted 06 February 2007 - 08:22 AM

Hi,

My MSN Messenger logs in itself upon computer start up. I think maybe it never logged out because I still can receive messages even after I have logged out. Besides, my computer running slow especially when I am on the internet. Can anyone help me with these problems? I will definitely appreciate your help. Thanks.

HijackThis Log:-
Logfile of HijackThis v1.99.1
Scan saved at 3:46:03 PM, on 2/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Documents and Settings\User\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.c...//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [qwertybot.exe] C:\WINDOWS\system32\qwertybot.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\User\LOCALS~1\Temp\winlogon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{3A5367D3-6621-4321-86BA-FBF1DC8E8A32}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{8141C4F5-9474-4946-B7DB-218FBCA21BFB}: NameServer = 202.188.0.133,202.188.1.5
O17 - HKLM\System\CS1\Services\Tcpip\..\{3A5367D3-6621-4321-86BA-FBF1DC8E8A32}: NameServer = 192.168.1.1
O17 - HKLM\System\CS2\Services\Tcpip\..\{3A5367D3-6621-4321-86BA-FBF1DC8E8A32}: NameServer = 192.168.1.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

Edited by victorywp, 06 February 2007 - 08:42 AM.


#15 Bobbi Flekman

Bobbi Flekman

    The computer whisperer

  • Charter Members
  • 5,990 posts

Posted 06 February 2007 - 01:04 PM

Hi victorywp,

You might want to save this page on your favorites, so you can find it again when you return. You can also click on your name and click on "Find All Posts" to find your thread.

Go to http://www.bleepingc...e.php?channel=7 and submit the following file(s):
C:\WINDOWS\system32\qwertybot.exe

Please download ATF Cleaner to your desktop.

Run HijackThis, click on "Scan" and check the boxes next to all these items.

O4 - HKLM\..\Run: [qwertybot.exe] C:\WINDOWS\system32\qwertybot.exe
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\User\LOCALS~1\Temp\winlogon.exe


Then close all windows, and browsers, except HijackThis. Tell HijackThis to "Fix checked".

Restart your computer in Safe Mode. How do I Safe Boot my computer?

Show hidden files. How do I show hidden files?
At the end if the fix you can return the files to hidden status if you want.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Delete the following files in red (it could be that they are deleted already):

C:\WINDOWS\system32\qwertybot.exe

Delete the following folders in red (it could be that they are deleted already):

Restart your computer and post a new log in this thread.


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users