February 13, 2012, 06:54:34 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: SMF - Just Installed!
 
   Home   Help Search Login Register  

computer running okay but still showing error loading c:\WIN


AddThis Social Bookmark Button AddThis Feed Button
Pages: [1]
  Print  
Author Topic: computer running okay but still showing error loading c:\WIN  (Read 5696 times)
reem2514
Newbie
*
Posts: 4


View Profile
« on: July 03, 2008, 11:01:25 AM »

here is the error :error loading c:\WINDOWS\system32\dpfxfjeq.dll

I just regained the ability to update my spybot and panda anti

here are the logs from hijackthis and spybot


Logfile of HijackThis v1.99.1
Scan saved at 2:21:58 PM, on 7/2/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Security\Panda Antivirus 2008\Apvxdwin.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
C:\Documents and Settings\Natella\My Documents\LimeWire\Saved\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net?cid=NET_mmhpset
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [c858a77a] rundll32.exe "C:\WINDOWS\system32\dpfxfjeq.dll",b
O4 - HKLM\..\Run: [LanzarL2007] "C:\DOCUME~1\Natella\LOCALS~1\Temp\{2001FEE3-1582-4ACB-9E4D-0DD07470B59A}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe" /SETUP:"/l0x0009"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
O23 - Service: Stormser - Huh? - C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE


--- Search result list ---
Microsoft.Windows.System: [SBI $D619D565] Settings (Registry change, fixed)
  HKEY_USERS\S-1-5-21-484763869-162531612-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage

Microsoft.Windows.System: [SBI $7F8E43F4] User settings (Registry change, fixed)
  HKEY_USERS\S-1-5-21-484763869-162531612-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage

Virtumonde: [SBI $42352499] User settings (Registry key, fixed)
  HKEY_USERS\S-1-5-21-484763869-162531612-839522115-1003\Software\Microsoft\rdfa

Virtumonde: [SBI $47E741CD] Settings (Registry key, fixed)
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws

Virtumonde.dll: [SBI $4DB0E149]  Library (File, fixed)
  C:\WINDOWS\system32\iifeEWoN.dll

Virtumonde.dll: [SBI $5795EDCE] Browser helper object (Registry key, fixed)
  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DEDD4350-E160-4741-84C4-31B9980660F1}

Virtumonde.dll: [SBI $5795EDCE] Class ID (Registry key, fixed)
  HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DEDD4350-E160-4741-84C4-31B9980660F1}


--- Spybot - Search & Destroy version: 1.5.2  (build: 20080128) ---

2008-01-28 blindman.exe (1.0.0.7)
2008-01-28 SDDelFile.exe (1.0.2.4)
2008-01-28 SDMain.exe (1.0.0.5)
2007-10-07 SDShred.exe (1.0.1.2)
2008-01-28 SDUpdate.exe (1.0.8.Cool
2008-01-28 SDWinSec.exe (1.0.0.11)
2008-01-28 SpybotSD.exe (1.5.2.20)
2007-01-12 spybotsd_plugins.exe
2008-01-28 TeaTimer.exe (1.5.2.16)
2008-07-03 unins000.exe (51.49.0.0)
2008-01-28 Update.exe (1.4.0.6)
2008-01-28 advcheck.dll (1.5.4.5)
2007-04-02 aports.dll (2.1.0.0)
2007-11-17 DelZip179.dll (1.79.7.4)
2008-01-28 SDFiles.dll (1.5.1.19)
2008-01-28 SDHelper.dll (1.5.0.11)
2008-01-28 Tools.dll (2.1.3.3)
2008-06-17 Includes\Adware.sbi (*)
2008-06-18 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-06-03 Includes\Dialer.sbi (*)
2008-06-24 Includes\DialerC.sbi (*)
2008-06-03 Includes\HeavyDuty.sbi (*)
2008-06-16 Includes\Hijackers.sbi (*)
2008-06-17 Includes\HijackersC.sbi (*)
2008-06-25 Includes\Keyloggers.sbi (*)
2008-07-02 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2008-07-02 Includes\Malware.sbi (*)
2008-07-01 Includes\MalwareC.sbi (*)
2008-06-17 Includes\PUPS.sbi (*)
2008-07-01 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-10 Includes\Security.sbi (*)
2008-07-01 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-06-17 Includes\Spyware.sbi (*)
2008-06-17 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-06-24 Includes\Trojans.sbi (*)
2008-07-01 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll



--- System information ---
Windows XP (Build: 2600) Service Pack 2 (5.1.2600)
 / MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
 / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
 / Windows / SP1: Microsoft National Language Support Downlevel APIs
 / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
 / Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782)
 / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
 / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
 / Windows Media Player 9: Security Update for Windows Media Player 9 (KB936782)
 / Windows XP: Security Update for Windows XP (KB923689)
 / Windows XP: Security Update for Windows XP (KB941569)
 / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127)
 / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB942615)
 / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB944533)
 / Windows XP / SP0: Hotfix for Windows Internet Explorer 7 (KB947864)
 / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB950759)
 / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
 / Windows XP / SP2: Windows XP Service Pack 2
 / Windows XP / SP3: Windows XP Hotfix - KB873339
 / Windows XP / SP3: Windows XP Hotfix - KB885835
 / Windows XP / SP3: Windows XP Hotfix - KB885836
 / Windows XP / SP3: Windows XP Hotfix - KB886185
 / Windows XP / SP3: Windows XP Hotfix - KB887472
 / Windows XP / SP3: Windows XP Hotfix - KB888302
 / Windows XP / SP3: Security Update for Windows XP (KB890046)
 / Windows XP / SP3: Windows XP Hotfix - KB890859
 / Windows XP / SP3: Windows XP Hotfix - KB891781
 / Windows XP / SP3: Security Update for Windows XP (KB893756)
 / Windows XP / SP3: Windows Installer 3.1 (KB893803)
 / Windows XP / SP3: Update for Windows XP (KB894391)
 / Windows XP / SP3: Security Update for Windows XP (KB896358)
 / Windows XP / SP3: Security Update for Windows XP (KB896423)
 / Windows XP / SP3: Security Update for Windows XP (KB896428)
 / Windows XP / SP3: Update for Windows XP (KB898461)
 / Windows XP / SP3: Security Update for Windows XP (KB899587)
 / Windows XP / SP3: Security Update for Windows XP (KB899591)
 / Windows XP / SP3: Update for Windows XP (KB900485)
 / Windows XP / SP3: Security Update for Windows XP (KB900725)
 / Windows XP / SP3: Security Update for Windows XP (KB901017)
 / Windows XP / SP3: Security Update for Windows XP (KB901214)
 / Windows XP / SP3: Security Update for Windows XP (KB902400)
 / Windows XP / SP3: Update for Windows XP (KB904942)
 / Windows XP / SP3: Security Update for Windows XP (KB905414)
 / Windows XP / SP3: Security Update for Windows XP (KB905749)
 / Windows XP / SP3: Security Update for Windows XP (KB908519)
 / Windows XP / SP3: Update for Windows XP (KB908531)
 / Windows XP / SP3: Update for Windows XP (KB910437)
 / Windows XP / SP3: Update for Windows XP (KB911280)
 / Windows XP / SP3: Security Update for Windows XP (KB911562)
 / Windows XP / SP3: Security Update for Windows XP (KB911927)
 / Windows XP / SP3: Security Update for Windows XP (KB913580)
 / Windows XP / SP3: Security Update for Windows XP (KB914388)
 / Windows XP / SP3: Security Update for Windows XP (KB914389)
 / Windows XP / SP3: Hotfix for Windows XP (KB914440)
 / Windows XP / SP3: Hotfix for Windows XP (KB915865)
 / Windows XP / SP3: Update for Windows XP (KB916595)
 / Windows XP / SP3: Security Update for Windows XP (KB917344)
 / Windows XP / SP3: Security Update for Windows XP (KB918118)
 / Windows XP / SP3: Security Update for Windows XP (KB918439)
 / Windows XP / SP3: Security Update for Windows XP (KB919007)
 / Windows XP / SP3: Security Update for Windows XP (KB920213)
 / Windows XP / SP3: Security Update for Windows XP (KB920670)
 / Windows XP / SP3: Security Update for Windows XP (KB920683)
 / Windows XP / SP3: Security Update for Windows XP (KB920685)
 / Windows XP / SP3: Update for Windows XP (KB920872)
 / Windows XP / SP3: Update for Windows XP (KB922582)
 / Windows XP / SP3: Security Update for Windows XP (KB922819)
 / Windows XP / SP3: Security Update for Windows XP (KB923191)
 / Windows XP / SP3: Security Update for Windows XP (KB923414)
 / Windows XP / SP3: Security Update for Windows XP (KB923980)
 / Windows XP / SP3: Security Update for Windows XP (KB924270)
 / Windows XP / SP3: Security Update for Windows XP (KB924496)
 / Windows XP / SP3: Security Update for Windows XP (KB924667)
 / Windows XP / SP3: Security Update for Windows XP (KB925902)
 / Windows XP / SP3: Hotfix for Windows XP (KB926239)
 / Windows XP / SP3: Security Update for Windows XP (KB926255)
 / Windows XP / SP3: Security Update for Windows XP (KB926436)
 / Windows XP / SP3: Security Update for Windows XP (KB927779)
 / Windows XP / SP3: Security Update for Windows XP (KB927802)
 / Windows XP / SP3: Update for Windows XP (KB927891)
 / Windows XP / SP3: Security Update for Windows XP (KB928255)
 / Windows XP / SP3: Security Update for Windows XP (KB928843)
 / Windows XP / SP3: Security Update for Windows XP (KB929123)
 / Windows XP / SP3: Security Update for Windows XP (KB930178)
 / Windows XP / SP3: Update for Windows XP (KB930916)
 / Windows XP / SP3: Security Update for Windows XP (KB931261)
 / Windows XP / SP3: Security Update for Windows XP (KB931784)
 / Windows XP / SP3: Security Update for Windows XP (KB932168)
 / Windows XP / SP3: Update for Windows XP (KB932823-v3)
 / Windows XP / SP3: Security Update for Windows XP (KB933729)
 / Windows XP / SP3: Security Update for Windows XP (KB935839)
 / Windows XP / SP3: Security Update for Windows XP (KB935840)
 / Windows XP / SP3: Security Update for Windows XP (KB936021)
 / Windows XP / SP3: Security Update for Windows XP (KB937894)
 / Windows XP / SP3: Security Update for Windows XP (KB938127)
 / Windows XP / SP3: Update for Windows XP (KB938828)
 / Windows XP / SP3: Security Update for Windows XP (KB938829)
 / Windows XP / SP3: Security Update for Windows XP (KB941202)
 / Windows XP / SP3: Security Update for Windows XP (KB941568)
 / Windows XP / SP3: Security Update for Windows XP (KB941644)
 / Windows XP / SP3: Security Update for Windows XP (KB941693)
 / Windows XP / SP3: Update for Windows XP (KB942763)
 / Windows XP / SP3: Update for Windows XP (KB942840)
 / Windows XP / SP3: Security Update for Windows XP (KB943055)
 / Windows XP / SP3: Security Update for Windows XP (KB943460)
 / Windows XP / SP3: Security Update for Windows XP (KB943485)
 / Windows XP / SP3: Security Update for Windows XP (KB944533)
 / Windows XP / SP3: Security Update for Windows XP (KB944653)
 / Windows XP / SP3: Security Update for Windows XP (KB945553)
 / Windows XP / SP3: Security Update for Windows XP (KB946026)
 / Windows XP / SP3: Security Update for Windows XP (KB948590)
 / Windows XP / SP3: Security Update for Windows XP (KB948881)
 / Windows XP / SP3: Security Update for Windows XP (KB950749)
 / Windows XP / SP4: Security Update for Windows XP (KB950760)
 / Windows XP / SP4: Security Update for Windows XP (KB950762)
 / Windows XP / SP4: Security Update for Windows XP (KB951376)
 / Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
 / Windows XP / SP4: Security Update for Windows XP (KB951698)
 / Windows XP OOB / SP10: High Definition Audio Driver Package - KB835221


--- Startup entries list ---
Located: HK_LM:Run, Apoint
command: C:\Program Files\DellTPad\Apoint.exe
   file: C:\Program Files\DellTPad\Apoint.exe
   size: 159744
    MD5: 5EF24621ABCE6965E32A365CA613A544

Located: HK_LM:Run, APVXDWIN
command: "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s
   file: C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE
   size: 455984
    MD5: 5152665DFA59EFA632E85C45315C765A

Located: HK_LM:Run, Broadcom Wireless Manager UI
command: C:\WINDOWS\system32\WLTRAY.exe
   file: C:\WINDOWS\system32\WLTRAY.exe
   size: 2183168
    MD5: 90F267169C3EC50908A97102026A23DE

Located: HK_LM:Run, c858a77a
command: rundll32.exe "C:\WINDOWS\system32\dpfxfjeq.dll",b
   file:
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: HK_LM:Run, HP Software Update
command: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
   file: C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
   size: 49152
    MD5: 7AF5A466CF4AECA28E3DCBCF5B6FD220

Located: HK_LM:Run, iTunesHelper
command: "C:\Program Files\iTunes\iTunesHelper.exe"
   file: C:\Program Files\iTunes\iTunesHelper.exe
   size: 267048
    MD5: 04A9F0C58B170F30445BCC0683EF9FFC

Located: HK_LM:Run, LanzarL2007
command: "C:\DOCUME~1\Natella\LOCALS~1\Temp\{2001FEE3-1582-4ACB-9E4D-0DD07470B59A}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe" /SETUP:"/l0x0009"
   file:
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: HK_LM:Run, NeroFilterCheck
command: C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
   file: C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
   size: 155648
    MD5: C93AB037A8C792D5F8A1A9FC88A7C7C5

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
   file: C:\Program Files\QuickTime\qttask.exe
   size: 413696
    MD5: 6DF76965A0FB8237E9C3B3CAB9815EC2

Located: HK_LM:Run, SigmatelSysTrayApp
command: %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
   file: C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
   size: 405504
    MD5: 012844A8E13BE3941C9CAF1F91F47DF2

Located: HK_LM:Run, StormCodec_Helper
command: "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
   file: C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe
   size: 97357
    MD5: F29EFBEB45E4B95AE94CC08F44B7AE47

Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
   file: C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
   size: 144784
    MD5: 836DC47E6CAD975304D1D3EB2F516A1C

Located: HK_LM:Run, Windows Defender
command: "C:\Program Files\Windows Defender\MSASCui.exe" -hide
   file: C:\Program Files\Windows Defender\MSASCui.exe
   size: 866584
    MD5: 77C03BF23AE56B0A31AE4D5BB4B3D0AC

Located: HK_LM:RunOnce, Spybot - Search & Destroy
command: "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
   file: C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
   size: 5146448
    MD5: 2ECA8CDEED7C82F879E766DA92A3561A

Located: HK_CU:Run, ctfmon.exe
  where: PE_C_ADMINISTRATOR...
command: C:\WINDOWS\system32\ctfmon.exe
   file: C:\WINDOWS\system32\ctfmon.exe
   size: 15360
    MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:RunOnce, NeroHomeFirstStart
  where: PE_C_ADMINISTRATOR...
command: C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
   file: C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
   size: 10752
    MD5: E15AAD68F518E2C6C91E790FDD6B9820

Located: HK_CU:Run, BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
  where: S-1-5-21-484763869-162531612-839522115-1003...
command: "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
   file: C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
   size: 143360
    MD5: CE8D6FF5BEDDA023F7A1BB3FA34130DE

Located: HK_CU:Run, ctfmon.exe
  where: S-1-5-21-484763869-162531612-839522115-1003...
command: C:\WINDOWS\system32\ctfmon.exe
   file: C:\WINDOWS\system32\ctfmon.exe
   size: 15360
    MD5: 24232996A38C0B0CF151C2140AE29FC8

Located: HK_CU:Run, MSMSGS
  where: S-1-5-21-484763869-162531612-839522115-1003...
command: "C:\Program Files\Messenger\msmsgs.exe" /background
   file: C:\Program Files\Messenger\msmsgs.exe
   size: 1694208
    MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259

Located: HK_CU:Run, SpybotSD TeaTimer
  where: S-1-5-21-484763869-162531612-839522115-1003...
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
   file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
   size: 2097488
    MD5: A9A5DB6AC3721BE698B996913693D73F

Located: HK_CU:Run, swg
  where: S-1-5-21-484763869-162531612-839522115-1003...
command: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
   file: C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
   size: 68856
    MD5: E616A6A6E91B0A86F2F6217CDE835FFE

Located: HK_CU:Run, Universal Installer
  where: S-1-5-21-484763869-162531612-839522115-1003...
command: "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
   file: C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
   size: 984616
    MD5: F008F2FD1FC0A1728ECA2C361D3E4F72

Located: HK_CU:Run, WMPNSCFG
  where: S-1-5-21-484763869-162531612-839522115-1003...
command: C:\Program Files\Windows Media Player\WMPNSCFG.exe
   file: C:\Program Files\Windows Media Player\WMPNSCFG.exe
   size: 204288
    MD5: 7EAED08CCCA4DDDE61A388C82598CFA9

Located: Startup (common), Adobe Reader Speed Launch.lnk
  where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
   file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
   size: 29696
    MD5: DFCB9ADE94A4F8A7C42EEF41101A30AD

Located: Startup (common), Digital Line Detect.lnk
  where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\Digital Line Detect\DLG.exe
   file: C:\Program Files\Digital Line Detect\DLG.exe
   size: 50688
    MD5: F03FFC962E18F36A922E61F96BE09925

Located: Startup (common), HP Digital Imaging Monitor.lnk
  where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
command: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
   file: C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
   size: 210520
    MD5: F14219FC767F1383526AB423F278A8E3

Located: WinLogon, avldr
command: avldr.dll
   file: avldr.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, crypt32chain
command: crypt32.dll
   file: crypt32.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, cryptnet
command: cryptnet.dll
   file: cryptnet.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, cscdll
command: cscdll.dll
   file: cscdll.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, opnKdCrP
command: opnKdCrP.dll
   file: opnKdCrP.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, ScCertProp
command: wlnotify.dll
   file: wlnotify.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, Schedule
command: wlnotify.dll
   file: wlnotify.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, sclgntfy
command: sclgntfy.dll
   file: sclgntfy.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, SensLogn
command: WlNotify.dll
   file: WlNotify.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, termsrv
command: wlnotify.dll
   file: wlnotify.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, WgaLogon
command: WgaLogon.dll
   file: WgaLogon.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!

Located: WinLogon, wlballoon
command: wlnotify.dll
   file: wlnotify.dll
   size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
         Warning: if the file is actually larger than 0 bytes,
         the checksum could not be properly calculated!



--- Browser helper object list ---
{0347C33E-8762-4905-BF09-768834316C61} (HP Print Enhancer)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name: HP Print Enhancer
        CLSID name: HP Print Enhancer
              Path: C:\Program Files\HP\Smart Web Printing\
         Long name: hpswp_printenhancer.dll
        Short name:       HPSWP_~1.DLL
    Date (created): 3/2/2007 4:52:24 PM
Date (last access): 7/3/2008 12:35:38 PM
 Date (last write): 3/2/2007 4:52:24 PM
          Filesize:            1298024
        Attributes:  readonly archive
               MD5: 1062E80907867BFC14EB844241391331
             CRC32:           4B194A34
           Version:           2.15.7.0

{053F9267-DC04-4294-A72C-58F732D338C0} (HP Print Clips)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name: HP Print Clips
              Path: C:\Program Files\HP\Smart Web Printing\
         Long name: hpswp_framework.dll
        Short name:       HPSWP_~4.DLL
    Date (created): 3/2/2007 4:52:08 PM
Date (last access): 7/3/2008 12:44:30 PM
 Date (last write): 3/2/2007 4:52:08 PM
          Filesize:             177768
        Attributes:  readonly archive
               MD5: A40456DE4EF7E318104955361C72AC9D
             CRC32:           6F06AAE2
           Version:           2.15.7.0

{37F0C601-C555-491B-BDEE-EAAD0BB7A31A} ()
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name:
              Path: C:\WINDOWS\system32\
         Long name:       opnKdCrP.dll

{738AB6DD-093C-4278-8D6F-B367AD30837F} ()
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name:

{8CD060F6-4652-4B9A-8789-3A553EEF229B} ()
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name:

{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name: Google Toolbar Helper
       description: Google toolbar
    classification: Open for discussion
    known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll
         info link: http://toolbar.google.com/
       info source: TonyKlein
              Path: c:\program files\google\
         Long name: GoogleToolbar1.dll
        Short name:       GOOGLE~1.DLL
    Date (created): 4/18/2008 4:48:14 PM
Date (last access): 7/3/2008 12:50:18 PM
 Date (last write): 4/18/2008 4:48:14 PM
          Filesize:            3253368
        Attributes:  readonly archive
               MD5: CFBD7A4B674F6BFD1F78268159DAC947
             CRC32:           0A2EBFE0
           Version:      5.0.1112.7760

{AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name: Google Toolbar Notifier BHO
              Path: C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\
         Long name:            swg.dll
        Short name:                  
    Date (created): 4/23/2008 1:06:40 PM
Date (last access): 7/3/2008 12:35:38 PM
 Date (last write): 4/23/2008 1:06:40 PM
          Filesize:             734704
        Attributes:           archive
               MD5: F1D0608833F726C8FF84E11A46843CDE
             CRC32:           0AF4F0EF
           Version:      3.0.1225.9868

{DEDD4350-E160-4741-84C4-31B9980660F1} ()
          location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
          BHO name:
        CLSID name:
              Path: C:\WINDOWS\system32\
         Long name:       iifeEWoN.dll



--- ActiveX list ---
{2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class)
          DPF name:
        CLSID name: ActiveScan 2.0 Installer Class
         Installer: C:\WINDOWS\Downloaded Program Files\as2stubie.inf
          Codebase: http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
              Path: C:\WINDOWS\Downloaded Program Files\
         Long name:      as2stubie.dll
        Short name:       AS2STU~1.DLL
    Date (created): 6/30/2008 10:39:58 AM
Date (last access): 7/3/2008 12:45:54 PM
 Date (last write): 6/30/2008 10:39:58 AM
          Filesize:             128256
        Attributes:           archive
               MD5: BB482DD127289F0FAD474610F5A4C3E3
             CRC32:           1CF0CB03
           Version:           1.0.0.10

{6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
          DPF name:
        CLSID name: MUWebControl Class
         Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
          Codebase: http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215102048734
       description:
    classification: Legitimate
    known filename: muweb.dll
         info link:
       info source: Safer Networking Ltd.
              Path: C:\WINDOWS\system32\
         Long name:          muweb.dll
        Short name:                  
    Date (created): 7/30/2007 7:18:34 PM
Date (last access): 7/3/2008 1:24:36 PM
 Date (last write): 7/30/2007 7:18:34 PM
          Filesize:             207736
        Attributes:           archive
               MD5: 8038B166CE79E58E193566150CE26465
             CRC32:           9137D395
           Version:       7.0.6000.381

{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
          DPF name: Java Runtime Environment 1.6.0
        CLSID name: Java Plug-in 1.6.0_05
         Installer:
          Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
       description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
         info link:
       info source: Patrick M. Kolla
              Path: C:\Program Files\Java\jre1.6.0_05\bin\
         Long name:    npjpi160_05.dll
        Short name:       NPJPI1~1.DLL
    Date (created): 2/22/2008 2:33:32 AM
Date (last access): 7/3/2008 12:45:54 PM
 Date (last write): 2/22/2008 4:25:20 AM
          Filesize:             132496
        Attributes:           archive
               MD5: 4FDFB86D78994BD71CBB779A7809E9CD
             CRC32:           5A0EB880
           Version:          6.0.50.13

{CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
          DPF name: Java Runtime Environment 1.6.0
        CLSID name: Java Plug-in 1.6.0_04
         Installer:
          Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
              Path: C:\Program Files\Java\jre1.6.0_04\bin\
         Long name:    npjpi160_04.dll
        Short name:       NPJPI1~1.DLL
    Date (created): 12/14/2007 1:59:16 AM
Date (last access): 7/3/2008 12:45:56 PM
 Date (last write): 12/14/2007 3:42:38 AM
          Filesize:             132496
        Attributes:           archive
               MD5: 58A1C3B13CC79E76F66CA6F8FED3B36A
             CRC32:           A4EACB48
           Version:          6.0.40.12

{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
          DPF name: Java Runtime Environment 1.6.0
        CLSID name: Java Plug-in 1.6.0_05
         Installer:
          Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
              Path: C:\Program Files\Java\jre1.6.0_05\bin\
         Long name:    npjpi160_05.dll
        Short name:       NPJPI1~1.DLL
    Date (created): 2/22/2008 2:33:32 AM
Date (last access): 7/3/2008 12:45:54 PM
 Date (last write): 2/22/2008 4:25:20 AM
          Filesize:             132496
        Attributes:           archive
               MD5: 4FDFB86D78994BD71CBB779A7809E9CD
             CRC32:           5A0EB880
           Version:          6.0.50.13

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
          DPF name: Java Runtime Environment 1.6.0
        CLSID name: Java Plug-in 1.6.0_05
         Installer:
          Codebase: http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
       description:
    classification: Legitimate
    known filename: npjpi150_06.dll
         info link:
       info source: Safer Networking Ltd.
              Path: C:\Program Files\Java\jre1.6.0_05\bin\
         Long name:    npjpi160_05.dll
        Short name:       NPJPI1~1.DLL
    Date (created): 2/22/2008 2:33:32 AM
Date (last access): 7/3/2008 12:45:54 PM
 Date (last write): 2/22/2008 4:25:20 AM
          Filesize:             132496
        Attributes:           archive
               MD5: 4FDFB86D78994BD71CBB779A7809E9CD
             CRC32:           5A0EB880
           Version:          6.0.50.13

{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
          DPF name:
        CLSID name: Shockwave Flash Object
         Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
          Codebase: http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
       description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename:
         info link:
       info source: Patrick M. Kolla
              Path: C:\WINDOWS\system32\Macromed\Flash\
         Long name:        Flash9f.ocx
        Short name:                  
    Date (created): 3/24/2008 10:32:42 PM
Date (last access): 7/3/2008 1:24:36 PM
 Date (last write): 3/24/2008 10:32:42 PM
          Filesize:            2991488
        Attributes:  readonly archive
               MD5: 48FDF435B8595604E54125B321924510
             CRC32:           12335E29
           Version:          9.0.124.0



--- Process list ---
PID:    0 (   0) [System]
PID:  608 (   4) \SystemRoot\System32\smss.exe
 size: 50688
PID:  680 ( 608) \??\C:\WINDOWS\system32\csrss.exe
 size: 6144
PID:  704 ( 608) \??\C:\WINDOWS\system32\winlogon.exe
 size: 502272
PID:  752 ( 704) C:\WINDOWS\system32\services.exe
 size: 108032
  MD5: C6CE6EEC82F187615D1002BB3BB50ED4
PID:  764 ( 704) C:\WINDOWS\system32\lsass.exe
 size: 13312
  MD5: 84885F9B82F4D55C6146EBF6065D75D2
PID:  960 ( 752) C:\WINDOWS\system32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1028 ( 752) C:\WINDOWS\system32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1136 ( 752) C:\Program Files\Windows Defender\MsMpEng.exe
 size: 13592
  MD5: F45DD1E1365D857DD08BC23563370D0E
PID: 1188 ( 752) C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
 size: 148272
  MD5: 8AFBCAFBEF6E5CE391FD2DDF663F4CFB
PID: 1228 (1188) C:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
 size: 96560
  MD5: 2E1AC6937AF17D0384E097E2123EC315
PID: 1392 ( 752) C:\WINDOWS\System32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1428 ( 752) C:\WINDOWS\system32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1620 ( 752) C:\WINDOWS\System32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1728 ( 752) C:\WINDOWS\System32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1784 ( 752) C:\WINDOWS\System32\WLTRYSVC.EXE
 size: 24064
  MD5: BCD7DB5C2FD6BFB59416F125DDE077FF
PID: 1828 (1784) C:\WINDOWS\System32\bcmwltry.exe
 size: 1921024
  MD5: DE691DD74FFFD9A39E784000255BF67C
PID:  192 ( 752) C:\WINDOWS\system32\spoolsv.exe
 size: 57856
  MD5: DA81EC57ACD4CDC3D4C51CF3D409AF9F
PID:  476 ( 752) C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
 size: 110592
  MD5: 1961CB10BB48EB4D97E37DB6373E9E63
PID:  516 ( 752) C:\WINDOWS\system32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID:  404 ( 752) C:\WINDOWS\System32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID:  812 ( 752) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
 size: 61440
  MD5: 559C9B7800FAC92FC515CD0003D7C631
PID: 1080 ( 752) C:\WINDOWS\System32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1688 ( 752) C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
 size: 169264
  MD5: 5731CB4D1D167793F8B27301B845AB9A
PID: 1764 ( 752) C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
 size: 63024
  MD5: F41AD950FABA0AD91D9D323074A6AF65
PID: 1808 ( 752) C:\WINDOWS\System32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 1924 ( 752) C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
 size: 108592
  MD5: AB75889B63CB3B761FB71072AC79DF94
PID: 2148 (1576) C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
 size: 405504
  MD5: 012844A8E13BE3941C9CAF1F91F47DF2
PID: 2156 (1576) C:\WINDOWS\system32\WLTRAY.exe
 size: 2183168
  MD5: 90F267169C3EC50908A97102026A23DE
PID: 2164 (1576) C:\Program Files\DellTPad\Apoint.exe
 size: 159744
  MD5: 5EF24621ABCE6965E32A365CA613A544
PID: 2172 (1576) C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
 size: 144784
  MD5: 836DC47E6CAD975304D1D3EB2F516A1C
PID: 2184 (1576) C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
 size: 49152
  MD5: 7AF5A466CF4AECA28E3DCBCF5B6FD220
PID: 2240 (1576) C:\Program Files\iTunes\iTunesHelper.exe
 size: 267048
  MD5: 04A9F0C58B170F30445BCC0683EF9FFC
PID: 2268 (1576) C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE
 size: 455984
  MD5: 5152665DFA59EFA632E85C45315C765A
PID: 2328 (1576) C:\Program Files\Windows Defender\MSASCui.exe
 size: 866584
  MD5: 77C03BF23AE56B0A31AE4D5BB4B3D0AC
PID: 2360 (1576) C:\Program Files\Messenger\msmsgs.exe
 size: 1694208
  MD5: 74E6E96C6F0E2ECA4EDBB7F7A468F259
PID: 2380 (1576) C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
 size: 143360
  MD5: CE8D6FF5BEDDA023F7A1BB3FA34130DE
PID: 2392 (1576) C:\WINDOWS\system32\ctfmon.exe
 size: 15360
  MD5: 24232996A38C0B0CF151C2140AE29FC8
PID: 2400 (1576) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 size: 68856
  MD5: E616A6A6E91B0A86F2F6217CDE835FFE
PID: 2436 (1576) C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
 size: 984616
  MD5: F008F2FD1FC0A1728ECA2C361D3E4F72
PID: 2460 (2164) C:\Program Files\DellTPad\ApMsgFwd.exe
 size: 50736
  MD5: 42370C1DE2B83844B253478DB8A907D5
PID: 2468 (1576) C:\Program Files\Windows Media Player\WMPNSCFG.exe
 size: 204288
  MD5: 7EAED08CCCA4DDDE61A388C82598CFA9
PID: 2556 ( 960) C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
 size: 905216
  MD5: 4D7659E640A60CF69DF6911CDDCF9788
PID: 2692 (1576) C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
 size: 210520
  MD5: F14219FC767F1383526AB423F278A8E3
PID: 2804 (2728) C:\Program Files\DellTPad\Apntex.exe
 size: 49152
  MD5: 8D78BE3690DB07A2FD03D2A6B61E3DCD
PID: 2944 (2164) C:\Program Files\DellTPad\HidFind.exe
 size: 40960
  MD5: C574C551637734B13278898FE2D12D15
PID: 3200 ( 752) C:\WINDOWS\System32\svchost.exe
 size: 14336
  MD5: 8F078AE4ED187AAABC0A305146DE6716
PID: 3364 ( 752) C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe
 size: 991232
  MD5: 47E1A4F539CC03C3C405E6E5A691CA6A
PID: 3572 ( 752) C:\Program Files\Windows Media Player\WMPNetwk.exe
 size: 913408
  MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B
PID:  368 (1392) C:\WINDOWS\system32\wscntfy.exe
 size: 13824
  MD5: 49911DD39E023BB6C45E4E436CFBD297
PID: 1592 ( 752) C:\Program Files\iPod\bin\iPodService.exe
 size: 504104
  MD5: 1CB96E83FD76EB5580451CEF29E24303
PID: 1408 ( 752) C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
 size: 262144
  MD5: C4EBBBD7165BE535F0BFD06B80601D91
PID: 4048 ( 752) C:\WINDOWS\System32\alg.exe
 size: 44544
  MD5: F1958FBF86D5C004CF19A5951A9514B7
PID: 4348 (2268) C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
 size: 83248
  MD5: F4E316730E0BEA920C0C0205AA18392D
PID: 4480 (2692) C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
 size: 151552
  MD5: FEDDD3579FEE51A9873D856DF3933C68
PID: 4912 ( 704) C:\WINDOWS\explorer.exe
 size: 1033216
  MD5: 97BD6515465659FF8F3B7BE375B2EA87
PID: 5488 (1588) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
 size: 2097488
  MD5: A9A5DB6AC3721BE698B996913693D73F
PID: 1444 (3648) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
 size: 5146448
  MD5: 2ECA8CDEED7C82F879E766DA92A3561A
PID:    4 (   0) System


--- Browser start & search pages list ---
Spybot - Search & Destroy browser pages report, 7/3/2008 1:25:02 PM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
  C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
  http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
  http://www.comcast.net?cid=NET_mmhpset
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
  %SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
  http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
  http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
  http://go.microsoft.com/fwlink/?LinkId=69157
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
  http://go.microsoft.com/fwlink/?LinkId=54896
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
  http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
  http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


--- Winsock Layered Service Provider list ---
Protocol  0: PAV_LAYERED over [MSAFD Tcpip [TCP/IP]]
        GUID: {98CC7B59-65CE-44AA-9F6C-8ADC3CB7949E}
    Filename: C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll

Protocol  1: PAV_LAYERED over [MSAFD Tcpip [UDP/IP]]
        GUID: {98CC7B59-65CE-44AA-9F6C-8ADC3CB7949E}
    Filename: C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll

Protocol  2: PAV_LAYERED over [MSAFD Tcpip [RAW/IP]]
        GUID: {98CC7B59-65CE-44AA-9F6C-8ADC3CB7949E}
    Filename: C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll

Protocol 22: PAV_LAYERED
        GUID: {6B320271-E041-22D0-9A38-11BB1164A02D}
    Filename: C:\Program Files\Panda Security\Panda Antivirus 2008\pavlsp.dll



--- Uninstall list ---
Windows Driver Package - Ricoh Company (rimsptsk) hdc  (11/14/2006 6.00.01.04) 11/14/2006 6.00.01.04 (4569969E1360D2854474C661EF9B4D54F143EB16)
   uninstall cmd: C:\PROGRA~1\DIFX\7B44739871F4D539FA473F57A832EA4B6A59EF06\dpinst.exe /us C:\PROGRA~1\DIFX\UninstallScripts\4569969E1360D2854474C661EF9B4D54F143EB16
       publisher: Ricoh Company

Panda ActiveScan 2.0 01.02.00.0009 (ActiveScan 2.0)
  estimated size: 4000
install location: C:\Program Files\Panda Security\ActiveScan 2.0
   uninstall cmd: C:\Program Files\Panda Security\ActiveScan 2.0\as2uninst.exe
       publisher: Panda Security
       help link: http://www.pandasecurity.com/activescan/help/

  (AddressBook)

Adobe Flash Player ActiveX 9.0.124.0 (Adobe Flash Player ActiveX)
   uninstall cmd: C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
       publisher: Adobe Systems Incorporated
       help link: http://www.adobe.com/go/flashplayer_support/

Audacity 1.3.5 (Unicode)  (Audacity 1.3 Beta (Unicode)_is1)
    install date: 20080616
install location: C:\Program Files\Audacity 1.3 Beta (Unicode)\
   uninstall cmd: "C:\Program Files\Audacity 1.3 Beta (Unicode)\unins000.exe"
       publisher: Audacity Team
       help link: http://audacity.sourceforge.net

AviSynth 2.5  (AviSynth)
   uninstall cmd: "C:\Program Files\AviSynth 2.5\Uninstall.exe"

BlackBerry Desktop Software 4.3 4.3.0.15 (BlackBerry_{D793A12F-E362-48BB-B332-1DA5E936B52D})
         version: 67108864
 version (major): 4
install location: C:\Program Files\Research In Motion\BlackBerry\
  install source: C:\DOCUME~1\Natella\LOCALS~1\Temp\WZSE0.TMP\430_b23_multilanguage\
   uninstall cmd: MsiExec.exe /i{D793A12F-E362-48BB-B332-1DA5E936B52D}
       publisher: Research In Motion Ltd.

  (Branding)

Dell Wireless WLAN Card 4.170.25.12 (Broadcom 802.11b Network Adapter)
   uninstall cmd: "C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwlu00.exe" verbose /rootkey="Software\Broadcom\802.11\UninstallInfo" /rootdir="C:\Program Files\Dell\Dell Wireless WLAN Card"
       publisher: Dell Inc.

CA Yahoo! Anti-Spy (remove only)  (cayahooantispy)
   uninstall cmd: "C:\Program Files\CA Yahoo! Anti-Spy\uninstall.exe"
       publisher: CA, Inc.

  (Connection Manager)

Laptop Integrated Webcam Driver (1.04.01.1011)    (Creative OEM002)
   uninstall cmd: C:\WINDOWS\CtDrvIns.exe -uninstall -script OEM002.uns -plugin OEM02Pin.dll -pluginres OEM02Pin.crl -nodisconprompt -langid 0x0409

  (DirectAnimation)

  (DirectDrawEx)

  (DXM_Runtime)

  (Fontcore)

HijackThis 1.99.1 1.99.1 (HijackThis)
   uninstall cmd: C:\Documents and Settings\Natella\My Documents\LimeWire\Saved\HijackThis.exe /uninstall
       publisher: Soeperman Enterprises Ltd.

HP Imaging Device Functions 9.0 9.0 (HP Imaging Device Functions)
   uninstall cmd: C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
       publisher: HP
       help link: http://www.hp.com/support

HP Photosmart Essential 2.01 2.01 (HP Photosmart Essential)
   uninstall cmd: C:\Program Files\HP\Digital Imaging\PhotoSmartEssential\hpzscr01.exe -datfile hpqbud13.dat
       publisher: HP
       help link: http://www.hp.com/support

HP Solution Center 9.0 9.0 (HP Solution Center & Imaging Support Tools)
   uninstall cmd: C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
       publisher: HP
       help link: http://www.hp.com/support

HP Customer Participation Program 9.0 9.0 (HPExtendedCapabilities)
   uninstall cmd: C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
       publisher: HP
       help link: http://www.hp.com/support

  (ICW)

Microsoft Internationalized Domain Names Mitigation APIs  (IDNMitigationAPIs)
    install date: 20080312
   uninstall cmd: "C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation

  (IE40)

  (IE4Data)

  (IE5BAKEX)

Windows Internet Explorer 7 20070813.185237 (ie7)
    install date: 20080312
   uninstall cmd: "C:\WINDOWS\ie7\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://www.microsoft.com/ie

  (IEData)

  (InstallShield Uninstall Information)

AVerMedia HC82 Express-Card Hybrid Analog 2.00.0001 (InstallShield_{1F295031-E793-4308-A384-5553977DFD13})
         version: 33554433
 version (major): 2
  estimated size: 6660
    install date: 20080311
install location: C:\Program Files\AVerMedia HC82 Express-Card Hybrid Analog\
  install source: C:\DOCUME~1\Natella\LOCALS~1\Temp\{0CBA6F02-78AD-4023-BBDD-955CFD6C19F2}\
   uninstall cmd: C:\Program Files\InstallShield Installation Information\{1F295031-E793-4308-A384-5553977DFD13}\setup.exe -runfromtemp -l0x0409
       publisher: AVerMedia

High Definition Audio Driver Package - KB835221 20040219.000000 (KB835221WXP)
   uninstall cmd: C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=KB835221

Windows XP Hotfix - KB873339 20041117.092459 (KB873339)
   uninstall cmd: C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=873339

  (KB884016)

  (KB884267)

  (KB885353)

Windows XP Hotfix - KB885835 20041027.181713 (KB885835)
   uninstall cmd: C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=885835

Windows XP Hotfix - KB885836 20041028.173203 (KB885836)
   uninstall cmd: C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=885836

Windows XP Hotfix - KB886185 20041021.090540 (KB886185)
   uninstall cmd: C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=886185

  (KB886612)

  (KB887078)

Windows XP Hotfix - KB887472 20041014.162858 (KB887472)
   uninstall cmd: C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=887472

  (KB887626)

Windows XP Hotfix - KB888302 20041207.111426 (KB888302)
   uninstall cmd: C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=888302

  (KB888656)

  (KB889858)

Security Update for Windows XP (KB890046) 1 (KB890046)
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=890046

Windows XP Hotfix - KB890859 1 (KB890859)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=890859

  (KB891122)

Windows XP Hotfix - KB891781 20050110.165439 (KB891781)
   uninstall cmd: C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=891781

Windows Genuine Advantage Validation Tool (KB892130)  (KB892130)
    install date: 20080311
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=892130

  (KB892313)

  (KB893240)

  (KB893241)

Security Update for Windows XP (KB893756) 1 (KB893756)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=893756

  (KB893803)

Windows Installer 3.1 (KB893803) 3.1 (KB893803v2)
   uninstall cmd: "C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://go.microsoft.com/fwlink/?LinkId=42467

Update for Windows XP (KB894391) 1 (KB894391)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=894391

  (KB895181)

  (KB895316)

  (KB895572)

Security Update for Windows XP (KB896358) 1 (KB896358)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=896358

Security Update for Windows XP (KB896423) 1 (KB896423)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=896423

Security Update for Windows XP (KB896428) 1 (KB896428)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=896428

  (KB897586)

Update for Windows XP (KB898461) 1 (KB898461)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=898461

  (KB898549)

Security Update for Windows XP (KB899587) 1 (KB899587)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=899587

Security Update for Windows XP (KB899591) 1 (KB899591)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=899591

  (KB900399)

Update for Windows XP (KB900485) 2 (KB900485)
    install date: 20080312
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=900485

Security Update for Windows XP (KB900725) 1 (KB900725)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=900725

Security Update for Windows XP (KB901017) 1 (KB901017)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=901017

Security Update for Windows XP (KB901214) 1 (KB901214)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=901214

  (KB902344)

Security Update for Windows XP (KB902400) 1 (KB902400)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=902400

Update for Windows XP (KB904942) 2 (KB904942)
    install date: 20080312
   uninstall cmd: "C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
       publisher: Microsoft Corporation
       help link: http://support.microsoft.com?kbid=904942

Security Update for Windows XP (KB905414) 1 (KB905414)
    install date: 20080311
   uninstall cmd: "C:\WINDOWS\$NtUninstal
Logged
Guest
Guest
« Reply #1 on: July 03, 2008, 11:01:31 AM »

Hello, visitor!

The Hijack This log analyzer has analyzed your log. Please take a closer look on the results.

Your system seems to be infected with malicious parasites. Please follow the steps below in order to eliminate the infection and clean up your computer.

1.   Download the Pocket KillBox utility. You will need it later to delete parasite-related files and folders.
2. Use HijackThis to fix the following entries:

O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe

3. The following entries are not malicious, but some of them are not used anymore. You may use HijackThis to fix a few of them. However, please keep in mind that some of the entries marked as Questionable or Not Needed are fully legitimate and might be required by installed software to work properly, while some others might be related to certain parasites. It is up to you to decide whether you need any of them, or not.
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net?cid=NET_mmhpset
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [LanzarL2007] "C:\DOCUME~1\Natella\LOCALS~1\Temp\{2001FEE3-1582-4ACB-9E4D-0DD07470B59A}\{D1DA2BA7-2592-4036-9BB2-DCCABDE8DC1A}\..\..\L2007tmp\Setup.exe" /SETUP:"/l0x0009"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra ''Tools'' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra ''Tools'' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra ''Tools'' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe


4. Now restart your system in Safe Mode. This step is very important!
5.   Use the Pocket KillBox utility to delete the following files:

C:\Program Files\Digital Line Detect\DLG.exe


The following files and Windows registry entries are marked as "unknown". Currently, the HijackThis Log Analyzer cannot provide required information on these items. The files and entries in the list below can be both malicious and fully legitimate. Because of this, please do not take any action! Wait for the forum responders or other forum users to provide you with necessary details and further instructions.
C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\WINDOWS\OEM02Mon.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [c858a77a] rundll32.exe "C:\WINDOWS\system32\dpfxfjeq.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Stormser - Huh? - C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe

After going through all the steps, run another HijackThis scan and post a fresh log to the HijackThis analyzer. It is possible that some parasites your system was infected with were not removed completely and may restore themselves later.


If you want to see more detailed analysis of your log, click here.

Thank you for using the 2-Spyware.com HijackThis log analyzer!
Logged
reem2514
Newbie
*
Posts: 4


View Profile
« Reply #2 on: July 03, 2008, 12:12:52 PM »

I deleted the files via hijackthis and then I used kill box to search for and delete the entry you spoke of but when i searched for it using the entry line you specified it couldnt be found. I decided to search for it manually and yup it was there and I deleted it.

Here is a new hijackthis log


Logfile of HijackThis v1.99.1
Scan saved at 3:31:01 PM, on 7/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Panda Security\Panda Antivirus 2008\WebProxy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HP\Smart Web Printing\hpswp_clipbook.exe
C:\Documents and Settings\Natella\My Documents\LimeWire\Saved\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net?cid=NET_mmhpset
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Security\Panda Antivirus 2008\APVXDWIN.EXE" /s
O4 - HKLM\..\Run: [c858a77a] rundll32.exe "C:\WINDOWS\system32\dpfxfjeq.dll",b
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Universal Installer] "C:\Program Files\ComcastUI\Universal Installer\uinstaller.exe" /fromrun /starthidden
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: HP Clipbook - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: HP Smart Select - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215102048734
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: avldr - C:\WINDOWS\SYSTEM32\avldr.dll
O20 - Winlogon Notify: opnKdCrP - opnKdCrP.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Panda Software Controller - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsCtrls.exe
O23 - Service: Panda Process Protection Service (PavPrSrv) - Panda Software - C:\Program Files\Common Files\Panda Software\PavShld\pavprsrv.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\pavsrv51.exe
O23 - Service: Panda IManager Service (PSIMSVC) - Panda Software International - C:\Program Files\Panda Security\Panda Antivirus 2008\PsImSvc.exe
O23 - Service: Stormser - Huh? - C:\PROGRA~1\RINGZS~1\STORMC~1\Stormser.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
Logged
Pages: [1]
  Print  
 
Jump to:  




Recommended software:
STOPzilla
(90/100)
STOPzilla is a powerful anti-spyware program that detects, blocks, and removes malicious software allowing users to surf the Web not worrying about spyware, Trojan horses,...
Malwarebytes Anti Malware
(88/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t...
Spyware Doctor
(87/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and...
SpyHunter
(86/100)
SpyHunter is a quite simple, but yet highly effective spyware remover with an easy-to-use interface. This program is an excellent choice for users, who are...
XoftSpySE Anti Spyware
(84/100)
XoftSpySE, an anti-spyware program made by ParetoLogic, Inc., is a simple, but effective on-demand scanner with the typical set of functions but very easy to...
Encyclopedia of parasites:

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other