Hello malwarebytes,
Thank you again for your full and clear response; I appreciate the considerable time and effort you are dedicating to my case.
Report:
STEP 1: reglooks: d/l OK; on running, the program reported a number of 'could not find' and 'does not exist' warnings on its screen; otherwise, it seemed to run and finish OK. Logs pasted below as requested.
STEP 2: HJT: did a scan and checked the 5 items you specified, as requested (of course, the name of the exe file associated with UeQaYzakOp entry changes on every start up, so the file in the list I checked to be fixed had, of course, a different exe name to the one shown in your statement). Clicked fix; seemed to run OK - these items specified were accurately listed in the backups log on completion (did not delete them). IMPORTANT, PLEASE NOTE: a new entry: O4 - HKLM\..\RunServices: [UeQaYzakOp] C:\WINDOWS\system32\nlqpj.exe was generated by the scan; I did NOT check and fix this – but thinking further about it (as I believe UeQaYzakOp is the/a malware) perhaps I should have done?
STEP 3: Java removal; removed Java and Java 6 update 7 via Windows Add/Remove; d/l and ran JavaRa (logs below) seemed OK; later manually deleted, as requested, lots of small files and then folders in C:\Docsandset\username\appdata\Sun\Java – , plus a .java folder. Seems to have worked – not present in later logs. Cant find/see any further java.
STEP 4: CCleaner. d/l and installed to desktop OK (unchecked boxes to leave 'make desktop icon' only in set up). All OK, however, app. would not run: on d/clicking, program loaded and showed its first page normally but only for c. 3 seconds then disappeared from the screen. So, this program was NOT executed at this time. Your comments would be most welcome here.
STEP 5: Avenger: d/l OK; copied and pasted your code as requested into main page. Unchecked roots option as requested and clicked execute. It reported that it had prepared successfully and was ready to execute on rebooting; then did so. System rebooted normally but no sign of Avenger or any report; I cannot be certain that this application ran OK or what the results were.
STEP 6: MBAM: seemed to run OK logs below as requested; HJT: ran OK log below as requested.
Other notes/noticings: 20 or so tmp files remain in Task Manager processes and end process remains disabled; probably not relevant but something odd was happening with Netscape during above step sequence: the icon was replaced by an IE icon; and it was replaced by IE as my default browser.
Thank you once again for your ongoing efforts; it may be cornered but it looks like our malware is not giving up without a fight! A little knowledge is probably a dangerous thing but I'm thinking, by not checking/fixing that other new UeQaYzakOp runservices entry above in Step 2, I may have allowed the malware to slip through again. Please advise.
Fmajor7th
REGLOOKS logfile
version 0.977
08/02/2009 18:18:49.46
running from: "C:\Documents and Settings\User One\My Documents\My Pictures"
--- SSODL regkeys ---
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
only standard or legit regkeys found
--- STS regkeys ---
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
only standard or legit regkeys found
--- USERINIT regkey ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
--- SHELL regkey ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
"Shell"="Explorer.exe"
--- SYSTEM regkey ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
"System"=""
--- APPINIT_DLLS regkey ---
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows
"AppInit_DLLs"=""
--- NOTIFY regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
"!SASWinLogon" "DllName"="C:\\Program Files\\SUPERAntiSpyware\\SASWINLO.dll"
"dimsntfy" "DllName"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,53,79,73,74,65,6d,33,\
--- BOOTEXECUTE regkey ---
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
BootExecute= autocheck autochk *\0\0
--- PENDINGFILERENAMEOPERATIONS regkey ---
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager
Pendingfilerenameoperations= \??\C:\Program Files\OpenOffice.org 3\program\quickstart.exe.tmp\0\??\C:\Program Files\OpenOffice.org 3\program\quickstart.exe\0\0
--- SHELLEXECUTEHOOKS regkey ---
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="Eudora's Shell Extension"
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=""
--- HKLM\Run regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"Ptipbmf"="rundll32.exe ptipbmf.dll,SetWriteCacheMode"
"B'sCLiP"="C:\\PROGRA~1\\B'SCLI~1\\Win2K\\BSCLIP.exe"
"WinampAgent"="\"C:\\Program Files\\Winamp\\Winampa.exe\""
"PCguardadvisor.exe"="\"C:\\Program Files\\blueyonder\\PCguard advisor\\PCguardadvisor.exe\""
"PCguard"="\"C:\\Program Files\\blueyonder\\PCguard\\Rps.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"UeQaYzakOp"="C:\\WINDOWS\\system32\\nlqpj.exe"
--- HKLM\RunOnce regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
no HKLM RunOnce keys found
--- HKLM\RunOnceEx regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
no HKLM RunOnceEx keys found
--- HKLM\RunServices regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
"UeQaYzakOp"="C:\\WINDOWS\\system32\\nlqpj.exe"
--- HKLM\RunServicesOnce regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
no HKLM RunServicesOnce keys found
--- HKCU\Run regkeys ---
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SUPERAntiSpyware"="C:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"
--- HKCU\RunOnce regkeys ---
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
no HKCU RunOnce keys found
--- HKCU\RunOnceEx regkeys ---
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
regkey does not exist
--- HKCU\RunServices regkeys ---
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
no HKCU RunServices keys found
--- HKCU\RunServicesOnce regkeys ---
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
no HKCU RunServicesOnce keys found
--- HKU\.DEFAULT\Run regkeys - Default user ---
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
--- HKU\S-1-5-18\Run regkeys - user SYSTEM ---
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
--- HKU\S-1-5-19\Run regkeys - User Lokale service ---
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
regkey does not exist
--- HKU\S-1-5-20\Run regkeys - User Netwerkservice ---
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
regkey does not exist
--- HKLM\Explorer\Run regkeys ---
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
no HKLM Explorer\Run keys found
--- HKCU\Explorer\Run regkeys ---
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
no HKCU Explorer\Run keys found
--- Image File Execution regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options
no debuggers found
--- BROWSER HELPER OBJECTS regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}" FILE ="C:\\Program Files\\Adobe\\Acrobat 6.0\\Reader\\ActiveX\\AcroIEHelper.dll"
"{3C060EA2-E6A9-4E49-A530-D4657B8C449A}" FILE ="C:\\Program Files\\blueyonder\\PCguard\\pkR.dll"
"{53707962-6F74-2D53-2644-206D7942484F}" FILE ="C:\\PROGRA~1\\SPYBOT~1\\SDHelper.dll"
"{56071E0D-C61B-11D3-B41C-00E02927A304}" FILE ="C:\\Program Files\\blueyonder\\PCguard\\FBHR.dll"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" FILE ="C:\\Program Files\\Java\\jre1.6.0_07\\bin\\ssv.dll"
--- TOOLBAR regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
no toolbars found
--- URLSEARCHHOOKS regkeys ---
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks
only standard regkeys found
--- CONTEXTMENUHANDLERS regkeys ---
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers
"Offline Files" CLSID ={750fdf0e-2a26-11d1-a3ea-080036587f03} FILE =%SystemRoot%\System32\cscui.dll
"Open With" CLSID ={09799AFB-AD67-11d1-ABCD-00C04FC30936} FILE =%SystemRoot%\system32\SHELL32.dll
"Open With EncryptionMenu" CLSID ={A470F8CF-A1E8-4f65-8335-227475AA5C46} FILE =%SystemRoot%\system32\SHELL32.dll
"yEnc32" CLSID ={8CDA2F05-B2BA-4AC7-B731-51E9E6B006E1} FILE ="C:\\Program Files\\eSite Media\\yEnc32\\yEnc32Shell.dll"
"{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}" Start Menu Pin FILE =%SystemRoot%\system32\SHELL32.dll
"{CA8ACAFA-5FBB-467B-B348-90DD488DE003}" SUPERAntiSpyware Context Menu FILE ="C:\\Program Files\\SUPERAntiSpyware\\SASCTXMN.DLL"
"{FFFFE5C1-34AF-4d4d-B3D3-5BB86A2BAA7B}" ECHO is off. FILE ="C:\\Program Files\\blueyonder\\PCguard\\AVCntxtR.dll"
HKEY_CLASSES_ROOT\Directory\shellex\ContextMenuHandlers
"EncryptionMenu" CLSID ={A470F8CF-A1E8-4f65-8335-227475AA5C46} FILE =%SystemRoot%\system32\SHELL32.dll
"Offline Files" CLSID ={750fdf0e-2a26-11d1-a3ea-080036587f03} FILE =%SystemRoot%\System32\cscui.dll
"Sharing" CLSID ={f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} FILE ="ntshrui.dll"
"{CA8ACAFA-5FBB-467B-B348-90DD488DE003}" SUPERAntiSpyware Context Menu FILE ="C:\\Program Files\\SUPERAntiSpyware\\SASCTXMN.DLL"
"{FFFFE5C1-34AF-4d4d-B3D3-5BB86A2BAA7B}" ECHO is off. FILE ="C:\\Program Files\\blueyonder\\PCguard\\AVCntxtR.dll"
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers
"MBAMShlExt" CLSID ={57CE581A-0CB6-4266-9CA0-19364C90A0B3} FILE ="C:\\Program Files\\Malwarebytes' Anti-Malware\\mbamext.dll"
"{FFFFE5C1-34AF-4d4d-B3D3-5BB86A2BAA7B}" ECHO is off. FILE ="C:\\Program Files\\blueyonder\\PCguard\\AVCntxtR.dll"
--- SAFEBOOT MINIMAL SERVICES ---
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
no unknown services found
--- SAFEBOOT NETWORK SERVICES ---
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
no unknown services found
--- SERVICES ---
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\avgntdd
"DisplayName"="avgntdd"
\??\C:\Program Files\AVPersonal\AVGNTDD.SYS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AVWUpSrv
"DisplayName"="AntiVir Update"
"C:\Program Files\AVPersonal\AVWUPSRV.EXE"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BsStor
"DisplayName"="B.H.A Storage Helper Driver"
no imagepath value found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BsUDF
"DisplayName"="B.H.A UDF Filesystem"
no imagepath value found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\CSS DVP
"DisplayName"="CSS DVP"
System32\DRIVERS\css-dvp.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DVD-RAM_Service
"DisplayName"="DVD-RAM_Service"
C:\WINDOWS\System32\DVDRAMSV.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\dvpapi
"DisplayName"="DvpApi"
C:\Program Files\Common Files\Command Software\dvpapi.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\E1000
"DisplayName"="Intel® PRO/1000 Adapter Driver"
System32\DRIVERS\e1000325.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fasttx2k
system32\drivers\fasttx2k.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Freedom
"DisplayName"="Freedom Miniport"
System32\DRIVERS\FREEDOM.SYS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FreeTdi
"DisplayName"="Radialpoint Filter"
System32\Drivers\FreeTdi.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\GMSIPCI
"DisplayName"="GMSIPCI"
\??\D:\INSTALL\GMSIPCI.SYS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\HCF_MSFT
System32\DRIVERS\HCF_MSFT.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\InternetClient
no imagepath value found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\meiudf
"DisplayName"="meiudf"
System32\Drivers\meiudf.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PCAlertDriver
"DisplayName"="PCAlertDriver"
\??\C:\Program Files\MSI\Core Center\NTGLM7X.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RP_FWS
"DisplayName"="PCguard Firewall"
C:\Program Files\blueyonder\PCguard\fws.exe
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RushTopDevice
"DisplayName"="RushTopDevice"
\??\C:\Program Files\MSI\Core Center\RushTop.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\s3legacy
System32\DRIVERS\s3legacy.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SASDIFSV
"DisplayName"="SASDIFSV"
\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SASENUM
"DisplayName"="SASENUM"
\??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SASKUTIL
"DisplayName"="SASKUTIL"
\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swwd
no imagepath value found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\VXD
no imagepath value found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{39993C85-56C8-4EA1-A198-F9864F0EAFCB}
no imagepath value found
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{5F161803-BD67-4794-A14E-D67C1A3C0252}
no imagepath value found
--- SECURITYPROVIDERS regkey ---
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
--- SVCHOST regkey ---
HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost
LocalService: Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService: DnsCache\0\0
netsvcs: 6to4\0AppMgmt\0AudioSrv\0Browser\0CryptSvc\0DMServer\0DHCP\0ERSvc\0EventSystem\0FastUserSwitchingCompatibility\0HidServ\0Ias\0Iprip\0Irmon\0LanmanServer\0LanmanWorkstation\0Messenger\0Netman\0Nla\0Ntmssvc\0NWCWorkstation\0Nwsapagent\0Rasauto\0Rasman\0Remoteaccess\0Schedule\0Seclogon\0SENS\0Sharedaccess\0SRService\0Tapisrv\0Themes\0TrkWks\0W32Time\0WZCSVC\0Wmi\0WmdmPmSp\0winmgmt\0TermService\0wuauserv\0BITS\0ShellHWDetection\0helpsvc\0xmlprov\0wscsvc\0WmdmPmSN\0napagent\0hkmsvc\0\0
rpcss: RpcSs\0\0
imgsvc: StiSvc\0\0
termsvcs: TermService\0\0
HTTPFilter: HTTPFilter\0\0
DcomLaunch: DcomLaunch\0TermService\0\0
eapsvcs: eaphost\0\0
dot3svc: dot3svc\0\0
--- WOW-CMDLINE regkeys ---
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WOW
"cmdline" = %SystemRoot%\system32\ntvdm.exe
"wowcmdline" = %SystemRoot%\system32\ntvdm.exe -a %SystemRoot%\system32\krnl386
--- DNS SERVER regkeys ---
no "NameServer" values found
--- STARTUP FOLDERS ---
C:\Documents and Settings\User One\Start Menu\Programs\Startup\desktop.ini
C:\Documents and Settings\User One\Start Menu\Programs\Startup\OpenOffice.org 1.0.1.lnk
C:\Documents and Settings\User One\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CoreCenter.lnk
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk
--- TASK SCHEDULER JOBS ---
no .job files found
--- File associations ---
.BAT files: ("%1" %*)
.COM files: ("%1" %*)
.EXE files: ("%1" %*)
.HLP files: (%SystemRoot%\System32\winhlp32.exe %1)
.INF files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
.INI files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
.JS files: (%SystemRoot%\System32\WScript.exe "%1" %*)
.PIF files: ("%1" %*)
.REG files: (regedit.exe "%1")
.SCR files: ("%1" /S)
.TXT files: (%SystemRoot%\system32\NOTEPAD.EXE %1)
.VBS files: (%SystemRoot%\System32\WScript.exe "%1" %*)
FINISHED
-----------------------------------------------------
JavaRa 1.13 Removal Log.
Report follows after line.
------------------------------------
The JavaRa removal process was started on Sun Feb 08 18:45:17 2009
Found and removed: C:\Program Files\JavaSoft
------------------------------------
Finished reporting.
------------------------------------
Malwarebytes' Anti-Malware 1.33
Database version: 1739
Windows 5.1.2600 Service Pack 3
08/02/2009 20:55:50
mbam-log-2009-02-08 (20-55-50).txt
Scan type: Quick Scan
Objects scanned: 46118
Time elapsed: 2 minute(s), 54 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ptipbmf (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
--------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:26:27, on 08/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\blueyonder\PCguard\fws.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~3A.tmp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~3B.tmp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~4B.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~41.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~4A.tmp.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\WINDOWS\system32\RAMASST.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~6C.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~5D.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~5E.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~70.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~71.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~74.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~78.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~7F.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~80.tmp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~83.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~85.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~87.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~88.tmp.exe
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~8B.tmp.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\DOCUME~1\USERON~1\LOCALS~1\Temp\~8D.tmp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896N2 - Netscape 6: user_pref("browser.startup.homepage", "http://www.demon.net/"); (C:\Documents and Settings\USER ONE\Application Data\Mozilla\Profiles\default\p5xnmo1h.slt\prefs.js)
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\USER ONE\Application Data\Mozilla\Profiles\default\p5xnmo1h.slt\prefs.js)
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\blueyonder\PCguard\pkR.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\blueyonder\PCguard\FBHR.dll
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [PCguardadvisor.exe] "C:\Program Files\blueyonder\PCguard advisor\PCguardadvisor.exe"
O4 - HKLM\..\Run: [PCguard] "C:\Program Files\blueyonder\PCguard\Rps.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [UeQaYzakOp] C:\WINDOWS\system32\untoevl.exe
O4 - HKLM\..\RunServices: [UeQaYzakOp] C:\WINDOWS\system32\untoevl.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 1.0.1.lnk = C:\Program Files\OpenOffice.org1.0.1\program\quickstart.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AntiVir Service (AntiVirService) - Unknown owner - C:\Program Files\AVPersonal\AVGUARD.EXE (file missing)
O23 - Service: AntiVir Update (AVWUpSrv) - Unknown owner - C:\Program Files\AVPersonal\AVWUPSRV.EXE (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: PCguard Firewall (RP_FWS) - Radialpoint Inc. - C:\Program Files\blueyonder\PCguard\fws.exe
--
End of file - 6283 bytes