Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: TR/FakeSpyPro6  (Read 11937 times)

0 Members and 1 Guest are viewing this topic.

Mikex79

    Topic Starter


    Rookie

    • Computer: Specs
    • Experience: Familiar
    • OS: Windows XP
    TR/FakeSpyPro6
    « on: November 23, 2010, 11:54:50 AM »
    This bug has taken over my computer and internet access. I'm new to this but ran my antivirus prog and it located and quarantined the bug. I ran hijack this and this was the log. I'm running XPsp3 on an old computer. here is the log...

    Logfile of HijackThis v1.99.1
    Scan saved at 1:46:27 PM, on 11/23/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)

    Running processes:
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    C:\WINDOWS\Logi_MwX.Exe
    C:\WINDOWS\system32\CTHELPER.EXE
    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
    C:\Program Files\Logitech\SetPointP\SetPoint.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
    O1 - Hosts: 65.75.216.6 www.winmx.com err.winmx.com
    O1 - Hosts: 205.238.40.54 www.winmx.com err.winmx.com
    O1 - Hosts: 65.75.216.6 cache0.winmx.com test3201.winmx.com test3206.winmx.com
    O1 - Hosts: 65.75.216.7 cache1.winmx.com test3202.winmx.com test3207.winmx.com
    O1 - Hosts: 82.43.229.238 cache2.winmx.com test3203.winmx.com test3208.winmx.com
    O1 - Hosts: 205.238.40.1 cache3.winmx.com test3204.winmx.com
    O1 - Hosts: 205.238.40.2 cache4.winmx.com test3205.winmx.com
    O1 - Hosts: 65.75.216.6 c3310.z1301.winmx.com c3310.z1302.winmx.com c3310.z1303.winmx.com c3310.z1304.winmx.com c3310.z1305.winmx.com c3310.z1306.winmx.com
    O1 - Hosts: 65.75.216.6 c3311.z1301.winmx.com c3311.z1302.winmx.com c3311.z1303.winmx.com c3311.z1304.winmx.com c3311.z1305.winmx.com c3311.z1306.winmx.com
    O1 - Hosts: 65.75.216.6 c3312.z1301.winmx.com c3312.z1302.winmx.com c3312.z1303.winmx.com c3312.z1304.winmx.com c3312.z1305.winmx.com c3312.z1306.winmx.com
    O1 - Hosts: 65.75.216.7 c3313.z1301.winmx.com c3313.z1302.winmx.com c3313.z1303.winmx.com c3313.z1304.winmx.com c3313.z1305.winmx.com c3313.z1306.winmx.com
    O1 - Hosts: 65.75.216.7 c3314.z1301.winmx.com c3314.z1302.winmx.com c3314.z1303.winmx.com c3314.z1304.winmx.com c3314.z1305.winmx.com c3314.z1306.winmx.com
    O1 - Hosts: 65.75.216.7 c3315.z1301.winmx.com c3315.z1302.winmx.com c3315.z1303.winmx.com c3315.z1304.winmx.com c3315.z1305.winmx.com c3315.z1306.winmx.com
    O1 - Hosts: 82.43.229.238 c3316.z1301.winmx.com c3316.z1302.winmx.com c3316.z1303.winmx.com c3316.z1304.winmx.com c3316.z1305.winmx.com c3316.z1306.winmx.com
    O1 - Hosts: 82.43.229.238 c3317.z1301.winmx.com c3317.z1302.winmx.com c3317.z1303.winmx.com c3317.z1304.winmx.com c3317.z1305.winmx.com c3317.z1306.winmx.com
    O1 - Hosts: 205.238.40.1 c3318.z1301.winmx.com c3318.z1302.winmx.com c3318.z1303.winmx.com c3318.z1304.winmx.com c3318.z1305.winmx.com c3318.z1306.winmx.com
    O1 - Hosts: 205.238.40.2 c3319.z1301.winmx.com c3319.z1302.winmx.com c3319.z1303.winmx.com c3319.z1304.winmx.com c3319.z1305.winmx.com c3319.z1306.winmx.com
    O1 - Hosts: 65.75.216.6 c3520.z1301.winmx.com c3520.z1302.winmx.com c3520.z1303.winmx.com c3520.z1304.winmx.com c3520.z1305.winmx.com c3520.z1306.winmx.com
    O1 - Hosts: 65.75.216.6 c3521.z1301.winmx.com c3521.z1302.winmx.com c3521.z1303.winmx.com c3521.z1304.winmx.com c3521.z1305.winmx.com c3521.z1306.winmx.com
    O1 - Hosts: 65.75.216.6 c3522.z1301.winmx.com c3522.z1302.winmx.com c3522.z1303.winmx.com c3522.z1304.winmx.com c3522.z1305.winmx.com c3522.z1306.winmx.com
    O1 - Hosts: 65.75.216.7 c3523.z1301.winmx.com c3523.z1302.winmx.com c3523.z1303.winmx.com c3523.z1304.winmx.com c3523.z1305.winmx.com c3523.z1306.winmx.com
    O1 - Hosts: 65.75.216.7 c3524.z1301.winmx.com c3524.z1302.winmx.com c3524.z1303.winmx.com c3524.z1304.winmx.com c3524.z1305.winmx.com c3524.z1306.winmx.com
    O1 - Hosts: 65.75.216.7 c3525.z1301.winmx.com c3525.z1302.winmx.com c3525.z1303.winmx.com c3525.z1304.winmx.com c3525.z1305.winmx.com c3525.z1306.winmx.com
    O1 - Hosts: 82.43.229.238 c3526.z1301.winmx.com c3526.z1302.winmx.com c3526.z1303.winmx.com c3526.z1304.winmx.com c3526.z1305.winmx.com c3526.z1306.winmx.com
    O1 - Hosts: 82.43.229.238 c3527.z1301.winmx.com c3527.z1302.winmx.com c3527.z1303.winmx.com c3527.z1304.winmx.com c3527.z1305.winmx.com c3527.z1306.winmx.com
    O1 - Hosts: 205.238.40.1 c3528.z1301.winmx.com c3528.z1302.winmx.com c3528.z1303.winmx.com c3528.z1304.winmx.com c3528.z1305.winmx.com c3528.z1306.winmx.com
    O1 - Hosts: 205.238.40.2 c3529.z1301.winmx.com c3529.z1302.winmx.com c3529.z1303.winmx.com c3529.z1304.winmx.com c3529.z1305.winmx.com c3529.z1306.winmx.com
    O1 - Hosts: 65.75.216.6 winmx-com.winmxgroup.com winmx-com-v30.winmxgroup.com
    O1 - Hosts: 205.238.40.54 winmx-com.winmxgroup.com winmx-com-v30.winmxgroup.com
    O1 - Hosts: 65.75.216.6 test0.winmxgroup.net test5.winmxgroup.net
    O1 - Hosts: 65.75.216.7 test1.winmxgroup.net test6.winmxgroup.net
    O1 - Hosts: 82.43.229.238 test2.winmxgroup.net
    O1 - Hosts: 205.238.40.1 test3.winmxgroup.net
    O1 - Hosts: 205.238.40.2 test4.winmxgroup.net
    O1 - Hosts: 65.75.216.6 cache0.winmxgroup.com cache5.winmxgroup.com cache0.winmxgroup.net cache5.winmxgroup.net cache10.winmxgroup.net cache15.winmxgroup.net
    O1 - Hosts: 65.75.216.7 cache1.winmxgroup.com cache6.winmxgroup.com cache1.winmxgroup.net cache6.winmxgroup.net cache11.winmxgroup.net cache16.winmxgroup.net
    O1 - Hosts: 82.43.229.238 cache2.winmxgroup.com cache7.winmxgroup.com cache2.winmxgroup.net cache7.winmxgroup.net cache12.winmxgroup.net cache17.winmxgroup.net
    O1 - Hosts: 205.238.40.1 cache3.winmxgroup.com cache8.winmxgroup.com cache3.winmxgroup.net cache8.winmxgroup.net cache13.winmxgroup.net cache18.winmxgroup.net
    O1 - Hosts: 205.238.40.2 cache4.winmxgroup.com cache9.winmxgroup.com cache4.winmxgroup.net cache9.winmxgroup.net cache14.winmxgroup.net cache19.winmxgroup.net
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
    O2 - BHO: eSnipBHO - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - (no file)
    O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
    O2 - BHO: Updater For My.Freeze.com Toolbar - {C26CD490-5F01-41E3-B150-EB29F19DA056} - (no file)
    O2 - BHO: (no name) - {CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
    O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
    O11 - Options group: [INTERNATIONAL] International
    O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
    O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
    O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} (MetaStreamCtl Class) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251843650682
    O16 - DPF: {7E9522CF-6B95-46D6-8E2F-7638F507313F} (BLS_SpeedOP.systemcheck) - http://www.fastaccess.drivers.bellsouth.net/software/DSLspeedtool/bls_speedop.cab
    O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://support.gateway.com/support/serialharvest/gwCID.CAB
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
    O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
    O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
    O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15016/CTPID.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
    O20 - Winlogon Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
    O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Unknown owner - C:\Program Files\Google\Update\GoogleUpdate.exe" /svc (file missing)
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
    O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
    O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe


    Any help would be greatly appreciated.....TIA


    Allan

    • Moderator

    • Mastermind
    • Thanked: 1260
    • Experience: Guru
    • OS: Windows 10
    Re: TR/FakeSpyPro6
    « Reply #1 on: November 23, 2010, 12:45:40 PM »
    Please follow the instructions in the following link and post your logs:
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    Mikex79

      Topic Starter


      Rookie

      • Computer: Specs
      • Experience: Familiar
      • OS: Windows XP
      Re: TR/FakeSpyPro6
      « Reply #2 on: November 23, 2010, 01:11:37 PM »
      I'll run MBAM and post the log but I get an error when trying to install SAS. Either Registry entry error or error creating shortcuts. Thanks.

      Mikex79

        Topic Starter


        Rookie

        • Computer: Specs
        • Experience: Familiar
        • OS: Windows XP
        Re: TR/FakeSpyPro6
        « Reply #3 on: November 23, 2010, 01:17:35 PM »
        Malwarebytes' Anti-Malware 1.46
        www.malwarebytes.org

        Database version: 4052

        Windows 5.1.2600 Service Pack 3
        Internet Explorer 8.0.6001.18702

        11/23/2010 1:25:14 PM
        mbam-log-2010-11-23 (13-25-14).txt

        Scan type: Quick scan
        Objects scanned: 106310
        Time elapsed: 16 minute(s), 5 second(s)

        Memory Processes Infected: 0
        Memory Modules Infected: 0
        Registry Keys Infected: 0
        Registry Values Infected: 0
        Registry Data Items Infected: 0
        Folders Infected: 0
        Files Infected: 0

        Memory Processes Infected:
        (No malicious items detected)

        Memory Modules Infected:
        (No malicious items detected)

        Registry Keys Infected:
        (No malicious items detected)

        Registry Values Infected:
        (No malicious items detected)

        Registry Data Items Infected:
        (No malicious items detected)

        Folders Infected:
        (No malicious items detected)

        Files Infected:
        (No malicious items detected)

        Mikex79

          Topic Starter


          Rookie

          • Computer: Specs
          • Experience: Familiar
          • OS: Windows XP
          Re: TR/FakeSpyPro6
          « Reply #4 on: November 23, 2010, 03:11:29 PM »
          Ok restarted in safe mode and was able to log on as admin and install SAS.Post log shortly

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: TR/FakeSpyPro6
          « Reply #5 on: November 23, 2010, 04:53:48 PM »
          Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

          1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
          2. The fixes are specific to your problem and should only be used for this issue on this machine.
          3. If you don't know or understand something, please don't hesitate to ask.
          4. Please DO NOT run any other tools or scans while I am helping you.
          5. It is important that you reply to this thread. Do not start a new topic.
          6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
          7. Absence of symptoms does not mean that everything is clear.

          Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

          Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

          Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

          Exit out of MessengerDisable then delete the two files that were put on the desktop.
          ************************************************
          This is a very old version of HJT. Please uninstall it, download and run a new scan and post the log.

          Please download: HiJackThis to your Desktop.
          • Double Click the HijackThis icon, located on your Desktop.
          • By Default, it will install to: C:\Program Files\Trend Micro\HijackThis
          • Accept the license agreement.
          • Click the Open the Misc Tools section button.
          • Place a checkmark beside Calculate MD5 of files if possible. Then, click Back.
          • Click Do a System Scan and Save a Logfile. Or, if you see a white screen, click Scan.
          • Please post the log in your next reply.
          *******************************************
          Download Security Check by screen317 from one of the following links and save it to your desktop.

          Link 1
          Link 2

          * Unzip SecurityCheck.zip and a folder named Security Check should appear.
          * Open the Security Check folder and double-click Security Check.bat
          * Follow the on-screen instructions inside of the black box.
          * A Notepad document should open automatically called checkup.txt
          * Post the contents of that document in your next reply.

          Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
          Windows 8 and Windows 10 dual boot with two SSD's

          Mikex79

            Topic Starter


            Rookie

            • Computer: Specs
            • Experience: Familiar
            • OS: Windows XP
            Re: TR/FakeSpyPro6
            « Reply #6 on: November 24, 2010, 12:44:51 AM »
            New HJT log

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 02:33:54, on 11/24/2010
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Safe mode

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ATT.net
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BellSouth
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:23012
            O1 - Hosts: 65.75.216.6 www.winmx.com err.winmx.com
            O1 - Hosts: 205.238.40.54 www.winmx.com err.winmx.com
            O1 - Hosts: 65.75.216.6 cache0.winmx.com test3201.winmx.com test3206.winmx.com
            O1 - Hosts: 65.75.216.7 cache1.winmx.com test3202.winmx.com test3207.winmx.com
            O1 - Hosts: 82.43.229.238 cache2.winmx.com test3203.winmx.com test3208.winmx.com
            O1 - Hosts: 205.238.40.1 cache3.winmx.com test3204.winmx.com
            O1 - Hosts: 205.238.40.2 cache4.winmx.com test3205.winmx.com
            O1 - Hosts: 65.75.216.6 c3310.z1301.winmx.com c3310.z1302.winmx.com c3310.z1303.winmx.com c3310.z1304.winmx.com c3310.z1305.winmx.com c3310.z1306.winmx.com
            O1 - Hosts: 65.75.216.6 c3311.z1301.winmx.com c3311.z1302.winmx.com c3311.z1303.winmx.com c3311.z1304.winmx.com c3311.z1305.winmx.com c3311.z1306.winmx.com
            O1 - Hosts: 65.75.216.6 c3312.z1301.winmx.com c3312.z1302.winmx.com c3312.z1303.winmx.com c3312.z1304.winmx.com c3312.z1305.winmx.com c3312.z1306.winmx.com
            O1 - Hosts: 65.75.216.7 c3313.z1301.winmx.com c3313.z1302.winmx.com c3313.z1303.winmx.com c3313.z1304.winmx.com c3313.z1305.winmx.com c3313.z1306.winmx.com
            O1 - Hosts: 65.75.216.7 c3314.z1301.winmx.com c3314.z1302.winmx.com c3314.z1303.winmx.com c3314.z1304.winmx.com c3314.z1305.winmx.com c3314.z1306.winmx.com
            O1 - Hosts: 65.75.216.7 c3315.z1301.winmx.com c3315.z1302.winmx.com c3315.z1303.winmx.com c3315.z1304.winmx.com c3315.z1305.winmx.com c3315.z1306.winmx.com
            O1 - Hosts: 82.43.229.238 c3316.z1301.winmx.com c3316.z1302.winmx.com c3316.z1303.winmx.com c3316.z1304.winmx.com c3316.z1305.winmx.com c3316.z1306.winmx.com
            O1 - Hosts: 82.43.229.238 c3317.z1301.winmx.com c3317.z1302.winmx.com c3317.z1303.winmx.com c3317.z1304.winmx.com c3317.z1305.winmx.com c3317.z1306.winmx.com
            O1 - Hosts: 205.238.40.1 c3318.z1301.winmx.com c3318.z1302.winmx.com c3318.z1303.winmx.com c3318.z1304.winmx.com c3318.z1305.winmx.com c3318.z1306.winmx.com
            O1 - Hosts: 205.238.40.2 c3319.z1301.winmx.com c3319.z1302.winmx.com c3319.z1303.winmx.com c3319.z1304.winmx.com c3319.z1305.winmx.com c3319.z1306.winmx.com
            O1 - Hosts: 65.75.216.6 c3520.z1301.winmx.com c3520.z1302.winmx.com c3520.z1303.winmx.com c3520.z1304.winmx.com c3520.z1305.winmx.com c3520.z1306.winmx.com
            O1 - Hosts: 65.75.216.6 c3521.z1301.winmx.com c3521.z1302.winmx.com c3521.z1303.winmx.com c3521.z1304.winmx.com c3521.z1305.winmx.com c3521.z1306.winmx.com
            O1 - Hosts: 65.75.216.6 c3522.z1301.winmx.com c3522.z1302.winmx.com c3522.z1303.winmx.com c3522.z1304.winmx.com c3522.z1305.winmx.com c3522.z1306.winmx.com
            O1 - Hosts: 65.75.216.7 c3523.z1301.winmx.com c3523.z1302.winmx.com c3523.z1303.winmx.com c3523.z1304.winmx.com c3523.z1305.winmx.com c3523.z1306.winmx.com
            O1 - Hosts: 65.75.216.7 c3524.z1301.winmx.com c3524.z1302.winmx.com c3524.z1303.winmx.com c3524.z1304.winmx.com c3524.z1305.winmx.com c3524.z1306.winmx.com
            O1 - Hosts: 65.75.216.7 c3525.z1301.winmx.com c3525.z1302.winmx.com c3525.z1303.winmx.com c3525.z1304.winmx.com c3525.z1305.winmx.com c3525.z1306.winmx.com
            O1 - Hosts: 82.43.229.238 c3526.z1301.winmx.com c3526.z1302.winmx.com c3526.z1303.winmx.com c3526.z1304.winmx.com c3526.z1305.winmx.com c3526.z1306.winmx.com
            O1 - Hosts: 82.43.229.238 c3527.z1301.winmx.com c3527.z1302.winmx.com c3527.z1303.winmx.com c3527.z1304.winmx.com c3527.z1305.winmx.com c3527.z1306.winmx.com
            O1 - Hosts: 205.238.40.1 c3528.z1301.winmx.com c3528.z1302.winmx.com c3528.z1303.winmx.com c3528.z1304.winmx.com c3528.z1305.winmx.com c3528.z1306.winmx.com
            O1 - Hosts: 205.238.40.2 c3529.z1301.winmx.com c3529.z1302.winmx.com c3529.z1303.winmx.com c3529.z1304.winmx.com c3529.z1305.winmx.com c3529.z1306.winmx.com
            O1 - Hosts: 65.75.216.6 winmx-com.winmxgroup.com winmx-com-v30.winmxgroup.com
            O1 - Hosts: 205.238.40.54 winmx-com.winmxgroup.com winmx-com-v30.winmxgroup.com
            O1 - Hosts: 65.75.216.6 test0.winmxgroup.net test5.winmxgroup.net
            O1 - Hosts: 65.75.216.7 test1.winmxgroup.net test6.winmxgroup.net
            O1 - Hosts: 82.43.229.238 test2.winmxgroup.net
            O1 - Hosts: 205.238.40.1 test3.winmxgroup.net
            O1 - Hosts: 205.238.40.2 test4.winmxgroup.net
            O1 - Hosts: 65.75.216.6 cache0.winmxgroup.com cache5.winmxgroup.com cache0.winmxgroup.net cache5.winmxgroup.net cache10.winmxgroup.net cache15.winmxgroup.net
            O1 - Hosts: 65.75.216.7 cache1.winmxgroup.com cache6.winmxgroup.com cache1.winmxgroup.net cache6.winmxgroup.net cache11.winmxgroup.net cache16.winmxgroup.net
            O1 - Hosts: 82.43.229.238 cache2.winmxgroup.com cache7.winmxgroup.com cache2.winmxgroup.net cache7.winmxgroup.net cache12.winmxgroup.net cache17.winmxgroup.net
            O1 - Hosts: 205.238.40.1 cache3.winmxgroup.com cache8.winmxgroup.com cache3.winmxgroup.net cache8.winmxgroup.net cache13.winmxgroup.net cache18.winmxgroup.net
            O1 - Hosts: 205.238.40.2 cache4.winmxgroup.com cache9.winmxgroup.com cache4.winmxgroup.net cache9.winmxgroup.net cache14.winmxgroup.net cache19.winmxgroup.net
            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
            O2 - BHO: eSnipBHO - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - (no file)
            O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
            O2 - BHO: Updater For My.Freeze.com Toolbar - {C26CD490-5F01-41E3-B150-EB29F19DA056} - (no file)
            O2 - BHO: (no name) - {CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
            O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
            O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
            O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
            O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
            O4 - HKLM\..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe /launchGaming
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
            O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
            O4 - HKCU\..\Run: [Voobly] "C:\Program Files\Voobly\voobly.exe" --startup
            O4 - HKCU\..\Run: [esrkvwjj] C:\DOCUME~1\Mike\LOCALS~1\Temp\wfondnlcj\jsqvavntsbl.exe
            O4 - HKCU\..\Run: [iigoipxn] C:\DOCUME~1\Mike\LOCALS~1\Temp\ygrmehmwr\jadfebmtsbl.exe
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Documents and Settings\Mike\Desktop\SUPERAntiSpyware.exe
            O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.5; .NET CLR 1.1.4322; Creative ZENcast v1.02.10; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.1; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)" -"http://etnies.com/games/street-sesh/"
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
            O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
            O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
            O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
            O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=http://www.bellsouth.net
            O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
            O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
            O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://support.gateway.com/support/profiler/PCPitStop.CAB
            O16 - DPF: {1B00725B-C455-4DE6-BFB6-AD540AD427CD} (MetaStreamCtl Class) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1251843650682
            O16 - DPF: {7E9522CF-6B95-46D6-8E2F-7638F507313F} (BLS_SpeedOP.systemcheck) - http://www.fastaccess.drivers.bellsouth.net/software/DSLspeedtool/bls_speedop.cab
            O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://support.gateway.com/support/serialharvest/gwCID.CAB
            O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
            O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
            O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
            O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15016/CTPID.cab
            O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
            O20 - Winlogon Notify: !SASWinLogon - C:\Documents and Settings\Mike\Desktop\SASWINLO.DLL
            O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
            O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
            O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
            O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
            O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
            O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
            O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
            O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe

            --
            End of file - 16507 bytes

            Mikex79

              Topic Starter


              Rookie

              • Computer: Specs
              • Experience: Familiar
              • OS: Windows XP
              Re: TR/FakeSpyPro6
              « Reply #7 on: November 24, 2010, 12:46:29 AM »
              SAS log

              SUPERAntiSpyware Scan Log
              http://www.superantispyware.com

              Generated 11/23/2010 at 04:30 PM

              Application Version : 4.45.1000

              Core Rules Database Version : 5767
              Trace Rules Database Version: 3579

              Scan type       : Quick Scan
              Total Scan Time : 00:46:48

              Memory items scanned      : 261
              Memory threats detected   : 0
              Registry items scanned    : 2864
              Registry threats detected : 2
              File items scanned        : 9347
              File threats detected     : 169

              Adware.IWinGames
                 HKU\S-1-5-21-1004336348-842925246-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8CA5ED52-F3FB-4414-A105-2E3491156990}
                 HKCR\CLSID\{8CA5ED52-F3FB-4414-A105-2E3491156990}

              Adware.Tracking Cookie
                 C:\Documents and Settings\Mike\Cookies\mike@media6degrees[1].txt
                 C:\Documents and Settings\Mike\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Mike\Cookies\mike@adbrite[2].txt
                 C:\Documents and Settings\Mike\Cookies\[email protected][3].txt
                 C:\Documents and Settings\Mike\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Mike\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Mike\Cookies\mike@tribalfusion[3].txt
                 C:\Documents and Settings\Mike\Cookies\[email protected][1].txt
                 adknowledge.com [ C:\Documents and Settings\Gabrielle\Application Data\Macromedia\Flash Player\#SharedObjects\7V7ZQTLW ]
                 web.adknowledge.com [ C:\Documents and Settings\Gabrielle\Application Data\Macromedia\Flash Player\#SharedObjects\7V7ZQTLW ]
                 .gaiainteractive.112.2o7.net [ C:\Documents and Settings\Mike\Application Data\Mozilla\Firefox\Profiles\7qlx1bie.default\cookies.sqlite ]
                 adknowledge.com [ C:\Documents and Settings\Ryan\Application Data\Macromedia\Flash Player\#SharedObjects\SFVUXS8H ]
                 macromedia.com [ C:\Documents and Settings\Ryan\Application Data\Macromedia\Flash Player\#SharedObjects\SFVUXS8H ]
                 web.adknowledge.com [ C:\Documents and Settings\Ryan\Application Data\Macromedia\Flash Player\#SharedObjects\SFVUXS8H ]
                 C:\Documents and Settings\Ryan\Cookies\ryan@specificclick[2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@tribalfusion[1].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@chitika[2].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@adbrite[2].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@media6degrees[2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@collective-media[1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@247realmedia[1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@2o7[1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@aaascreensavers[2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@azjmp[2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@eyewonder[1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@interclick[1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@invitemedia[2].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@kontera[2].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@legolas-media[2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@pointroll[2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@questionmarket[1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@realmedia[1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@revsci[1].txt
                 C:\Documents and Settings\Ryan\Cookies\ryan@serving-sys[2].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Ryan\Cookies\[email protected][1].txt
                 statse.webtrendslive.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .smartadserver.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .smartadserver.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .advertising.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .advertising.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .advertising.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .advertising.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .doubleclick.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .smartadserver.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .smartadserver.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .collective-media.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .collective-media.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .collective-media.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .collective-media.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .ads.pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .ads.pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .ads.pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .ads.pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .ads.pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .ads.pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .ads.pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .ads.pointroll.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .collective-media.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .atdmt.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .atdmt.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .kontera.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .xiti.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .tacoda.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .tacoda.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .tacoda.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .advertising.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .advertising.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .at.atwola.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .at.atwola.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .adbrite.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .adbrite.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .invitemedia.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .invitemedia.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .interclick.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .revsci.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .revsci.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .revsci.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .interclick.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .tribalfusion.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .apmebf.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .mediaplex.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .invitemedia.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .statcounter.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .legolas-media.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .legolas-media.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .collective-media.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .collective-media.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .collective-media.net [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .bs.serving-sys.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .serving-sys.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .serving-sys.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .serving-sys.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .serving-sys.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .serving-sys.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .serving-sys.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .serving-sys.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .zedo.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .zedo.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .zedo.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .zedo.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .zedo.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .zedo.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .zedo.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .adinterax.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 .adinterax.com [ C:\Documents and Settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\cookies.sqlite ]
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@pointroll[2].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@fastclick[1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@collective-media[2].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@adbrite[2].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@advertising[2].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@chitika[1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@smartadserver[1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@doubleclick[1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@yieldmanager[1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@tacoda[2].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@invitemedia[1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@interclick[1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@atdmt[1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@kontera[1].txt
                 C:\Documents and Settings\Smoking Guns BBQ\Cookies\smoking_guns_bbq@xiti[1].txt
                 ads1.msn.com [ C:\Documents and Settings\Stephanie\Application Data\Macromedia\Flash Player\#SharedObjects\WF3WB9DF ]
                 cdn4.specificclick.net [ C:\Documents and Settings\Stephanie\Application Data\Macromedia\Flash Player\#SharedObjects\WF3WB9DF ]
                 interclick.com [ C:\Documents and Settings\Stephanie\Application Data\Macromedia\Flash Player\#SharedObjects\WF3WB9DF ]
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@media6degrees[1].txt
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][3].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@tribalfusion[1].txt
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][3].txt
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@chitika[1].txt
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][2].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@tacoda[1].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@realmedia[2].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@liveperson[1].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@liveperson[2].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@questionmarket[1].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@atwola[2].txt
                 C:\Documents and Settings\Stephanie\Cookies\[email protected][1].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@myroitracking[1].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@collective-media[1].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@azjmp[2].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@kontera[1].txt
                 C:\Documents and Settings\Stephanie\Cookies\stephanie@adbrite[2].txt

              Mikex79

                Topic Starter


                Rookie

                • Computer: Specs
                • Experience: Familiar
                • OS: Windows XP
                Re: TR/FakeSpyPro6
                « Reply #8 on: November 24, 2010, 12:53:07 AM »
                Security check log

                Results of screen317's Security Check version 0.99.6 
                 Windows XP Service Pack 3 
                 Internet Explorer 8 
                ``````````````````````````````
                Antivirus/Firewall Check:

                 Windows Firewall Disabled! 
                 Avira AntiVir Personal - Free Antivirus
                 WMI entry may not exist for antivirus; attempting automatic update.
                 Avira successfully updated!
                ```````````````````````````````
                Anti-malware/Other Utilities Check:

                 Malwarebytes' Anti-Malware   
                 HijackThis 2.0.2   
                 CCleaner     
                 Java(TM) 6 Update 20 
                 Out of date Java installed!
                 Adobe Flash Player 10.1.102.64 
                Adobe Reader 9.4.1
                 Mozilla Firefox (3.6.10) Firefox Out of Date! 
                ````````````````````````````````
                Process Check: 
                objlist.exe by Laurent

                 Avira Antivir avgnt.exe
                 Avira Antivir avguard.exe
                ````````````````````````````````
                DNS Vulnerability Check:

                 GREAT! (Not vulnerable to DNS cache poisoning)

                ``````````End of Log````````````


                Thanks.

                SuperDave

                • Malware Removal Specialist


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: TR/FakeSpyPro6
                « Reply #9 on: November 24, 2010, 05:04:18 PM »
                  Why did you run HJT in Safe Mode?

                  Update Your Java (JRE)

                  Old versions of Java have vulnerabilities that malware can use to infect your system.


                  First Verify your Java Version

                  If there are any other version(s) installed then update now.

                  Get the new version (if needed)

                  If your version is out of date install the newest version of the Sun Java Runtime Environment.

                  Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

                  Be sure to close ALL open web browsers before starting the installation.

                  Remove any old versions

                  1. Download JavaRa and unzip the file to your Desktop.
                  2. Open JavaRA.exe and choose Remove Older Versions
                  3. Once complete exit JavaRA.
                  4. Run CCleaner.

                  Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
                  *************************************

                  Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

                  Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

                  Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

                  Exit out of MessengerDisable then delete the two files that were put on the desktop.
                  ***********************************************

                  Open HijackThis and select Do a system scan only

                  Place a check mark next to the following entries: (if there)

                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:23012
                  O1 - Hosts: 65.75.216.6 www.winmx.com err.winmx.com
                  O1 - Hosts: 205.238.40.54 www.winmx.com err.winmx.com
                  O1 - Hosts: 65.75.216.6 cache0.winmx.com test3201.winmx.com test3206.winmx.com
                  O1 - Hosts: 65.75.216.7 cache1.winmx.com test3202.winmx.com test3207.winmx.com
                  O1 - Hosts: 82.43.229.238 cache2.winmx.com test3203.winmx.com test3208.winmx.com
                  O1 - Hosts: 205.238.40.1 cache3.winmx.com test3204.winmx.com
                  O1 - Hosts: 205.238.40.2 cache4.winmx.com test3205.winmx.com
                  O1 - Hosts: 65.75.216.6 c3310.z1301.winmx.com c3310.z1302.winmx.com c3310.z1303.winmx.com c3310.z1304.winmx.com c3310.z1305.winmx.com c3310.z1306.winmx.com
                  O1 - Hosts: 65.75.216.6 c3311.z1301.winmx.com c3311.z1302.winmx.com c3311.z1303.winmx.com c3311.z1304.winmx.com c3311.z1305.winmx.com c3311.z1306.winmx.com
                  O1 - Hosts: 65.75.216.6 c3312.z1301.winmx.com c3312.z1302.winmx.com c3312.z1303.winmx.com c3312.z1304.winmx.com c3312.z1305.winmx.com c3312.z1306.winmx.com
                  O1 - Hosts: 65.75.216.7 c3313.z1301.winmx.com c3313.z1302.winmx.com c3313.z1303.winmx.com c3313.z1304.winmx.com c3313.z1305.winmx.com c3313.z1306.winmx.com
                  O1 - Hosts: 65.75.216.7 c3314.z1301.winmx.com c3314.z1302.winmx.com c3314.z1303.winmx.com c3314.z1304.winmx.com c3314.z1305.winmx.com c3314.z1306.winmx.com
                  O1 - Hosts: 65.75.216.7 c3315.z1301.winmx.com c3315.z1302.winmx.com c3315.z1303.winmx.com c3315.z1304.winmx.com c3315.z1305.winmx.com c3315.z1306.winmx.com
                  O1 - Hosts: 82.43.229.238 c3316.z1301.winmx.com c3316.z1302.winmx.com c3316.z1303.winmx.com c3316.z1304.winmx.com c3316.z1305.winmx.com c3316.z1306.winmx.com
                  O1 - Hosts: 82.43.229.238 c3317.z1301.winmx.com c3317.z1302.winmx.com c3317.z1303.winmx.com c3317.z1304.winmx.com c3317.z1305.winmx.com c3317.z1306.winmx.com
                  O1 - Hosts: 205.238.40.1 c3318.z1301.winmx.com c3318.z1302.winmx.com c3318.z1303.winmx.com c3318.z1304.winmx.com c3318.z1305.winmx.com c3318.z1306.winmx.com
                  O1 - Hosts: 205.238.40.2 c3319.z1301.winmx.com c3319.z1302.winmx.com c3319.z1303.winmx.com c3319.z1304.winmx.com c3319.z1305.winmx.com c3319.z1306.winmx.com
                  O1 - Hosts: 65.75.216.6 c3520.z1301.winmx.com c3520.z1302.winmx.com c3520.z1303.winmx.com c3520.z1304.winmx.com c3520.z1305.winmx.com c3520.z1306.winmx.com
                  O1 - Hosts: 65.75.216.6 c3521.z1301.winmx.com c3521.z1302.winmx.com c3521.z1303.winmx.com c3521.z1304.winmx.com c3521.z1305.winmx.com c3521.z1306.winmx.com
                  O1 - Hosts: 65.75.216.6 c3522.z1301.winmx.com c3522.z1302.winmx.com c3522.z1303.winmx.com c3522.z1304.winmx.com c3522.z1305.winmx.com c3522.z1306.winmx.com
                  O1 - Hosts: 65.75.216.7 c3523.z1301.winmx.com c3523.z1302.winmx.com c3523.z1303.winmx.com c3523.z1304.winmx.com c3523.z1305.winmx.com c3523.z1306.winmx.com
                  O1 - Hosts: 65.75.216.7 c3524.z1301.winmx.com c3524.z1302.winmx.com c3524.z1303.winmx.com c3524.z1304.winmx.com c3524.z1305.winmx.com c3524.z1306.winmx.com
                  O1 - Hosts: 65.75.216.7 c3525.z1301.winmx.com c3525.z1302.winmx.com c3525.z1303.winmx.com c3525.z1304.winmx.com c3525.z1305.winmx.com c3525.z1306.winmx.com
                  O1 - Hosts: 82.43.229.238 c3526.z1301.winmx.com c3526.z1302.winmx.com c3526.z1303.winmx.com c3526.z1304.winmx.com c3526.z1305.winmx.com c3526.z1306.winmx.com
                  O1 - Hosts: 82.43.229.238 c3527.z1301.winmx.com c3527.z1302.winmx.com c3527.z1303.winmx.com c3527.z1304.winmx.com c3527.z1305.winmx.com c3527.z1306.winmx.com
                  O1 - Hosts: 205.238.40.1 c3528.z1301.winmx.com c3528.z1302.winmx.com c3528.z1303.winmx.com c3528.z1304.winmx.com c3528.z1305.winmx.com c3528.z1306.winmx.com
                  O1 - Hosts: 205.238.40.2 c3529.z1301.winmx.com c3529.z1302.winmx.com c3529.z1303.winmx.com c3529.z1304.winmx.com c3529.z1305.winmx.com c3529.z1306.winmx.com
                  O1 - Hosts: 65.75.216.6 winmx-com.winmxgroup.com winmx-com-v30.winmxgroup.com
                  O1 - Hosts: 205.238.40.54 winmx-com.winmxgroup.com winmx-com-v30.winmxgroup.com
                  O1 - Hosts: 65.75.216.6 test0.winmxgroup.net test5.winmxgroup.net
                  O1 - Hosts: 65.75.216.7 test1.winmxgroup.net test6.winmxgroup.net
                  O1 - Hosts: 82.43.229.238 test2.winmxgroup.net
                  O1 - Hosts: 205.238.40.1 test3.winmxgroup.net
                  O1 - Hosts: 205.238.40.2 test4.winmxgroup.net
                  O1 - Hosts: 65.75.216.6 cache0.winmxgroup.com cache5.winmxgroup.com cache0.winmxgroup.net cache5.winmxgroup.net cache10.winmxgroup.net cache15.winmxgroup.net
                  O1 - Hosts: 65.75.216.7 cache1.winmxgroup.com cache6.winmxgroup.com cache1.winmxgroup.net cache6.winmxgroup.net cache11.winmxgroup.net cache16.winmxgroup.net
                  O1 - Hosts: 82.43.229.238 cache2.winmxgroup.com cache7.winmxgroup.com cache2.winmxgroup.net cache7.winmxgroup.net cache12.winmxgroup.net cache17.winmxgroup.net
                  O1 - Hosts: 205.238.40.1 cache3.winmxgroup.com cache8.winmxgroup.com cache3.winmxgroup.net cache8.winmxgroup.net cache13.winmxgroup.net cache18.winmxgroup.net
                  O1 - Hosts: 205.238.40.2 cache4.winmxgroup.com cache9.winmxgroup.com cache4.winmxgroup.net cache9.winmxgroup.net cache14.winmxgroup.net cache19.winmxgroup.net
                  O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: eSnipBHO - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - (no file)
                  O2 - BHO: Updater For My.Freeze.com Toolbar - {C26CD490-5F01-41E3-B150-EB29F19DA056} - (no file)
                  O2 - BHO: (no name) - {CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
                  O4 - HKCU\..\Run: [esrkvwjj] C:\DOCUME~1\Mike\LOCALS~1\Temp\wfondnlcj\jsqvavntsbl.exe
                  O4 - HKCU\..\Run: [iigoipxn] C:\DOCUME~1\Mike\LOCALS~1\Temp\ygrmehmwr\jadfebmtsbl.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


                  Important: Close all open windows except for HijackThis and then click Fix checked.

                  Once completed, exit HijackThis.
                  *******************************************
                  Please download ComboFix from BleepingComputer.com

                  Alternate link: GeeksToGo.com

                  Rename ComboFix.exe to commy.exe before you save it to your Desktop
                  Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
                  Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
                  As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
                  Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console[/list]

                  Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

                  Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


                  Click on Yes, to continue scanning for malware.
                  When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

                  If you have problems with ComboFix usage, see How to use ComboFix

                  Windows 8 and Windows 10 dual boot with two SSD's

                  Mikex79

                    Topic Starter


                    Rookie

                    • Computer: Specs
                    • Experience: Familiar
                    • OS: Windows XP
                    Re: TR/FakeSpyPro6
                    « Reply #10 on: November 24, 2010, 10:45:20 PM »
                    I ran HJT in safemode because I can't run any program on the admin login except the antivirus unless I boot in safe mode. then I can use and install. The alternate login won't let me install programs but I can use programs and firefox here. I'll try what you've posted and get back to you. Thanks.

                    Mikex79

                      Topic Starter


                      Rookie

                      • Computer: Specs
                      • Experience: Familiar
                      • OS: Windows XP
                      Re: TR/FakeSpyPro6
                      « Reply #11 on: November 25, 2010, 07:58:18 AM »
                      I am going to post this log now but please enjoy your thanksgiving holiday and get to it when you can.
                      Thanks in advance.....


                      ComboFix 10-11-24.02 - Smoking Guns BBQ 11/25/2010   4:08.1.1 - x86
                      Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.383.124 [GMT -5:00]
                      Running from: c:\documents and settings\Smoking Guns BBQ\Desktop\commy.exe.exe
                      AV: AntiVir PersonalEdition Classic Virus Protection *On-access scanning enabled* (Updated) {00000000-0000-0000-0000-000000000000}
                      AV: AntiVir PersonalEdition Classic Virus Protection *On-access scanning enabled* (Updated) {806ED0B3-FFA4-00C8-0D24-347CA8A3377C}
                      AV: AntiVir PersonalEdition Classic Virus Protection *On-access scanning enabled* (Updated) {806ED0B3-FFA4-00EB-0D24-347CA8A3377C}
                      .

                      (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      c:\documents and settings\Mike\Favorites\Thumbs.db
                      c:\documents and settings\Stephanie\Application Data\PriceGong
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\1.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\a.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\b.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\c.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\d.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\e.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\f.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\g.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\h.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\i.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\J.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\k.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\l.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\m.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\mru.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\n.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\o.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\p.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\q.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\r.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\s.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\t.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\u.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\v.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\w.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\x.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\y.xml
                      c:\documents and settings\Stephanie\Application Data\PriceGong\Data\z.xml
                      c:\windows\system32\cfbxrttn.ini
                      c:\windows\system32\qeoroqre.ini

                      .
                      (((((((((((((((((((((((((   Files Created from 2010-10-25 to 2010-11-25  )))))))))))))))))))))))))))))))
                      .

                      2010-11-25 08:38 . 2010-11-25 08:38   --------   d-----w-   c:\program files\Common Files\Java
                      2010-11-25 08:38 . 2010-11-25 08:37   73728   ----a-w-   c:\windows\system32\javacpl.cpl
                      2010-11-25 08:00 . 2010-11-25 08:00   659968   ----a-w-   c:\documents and settings\Mike\Local Settings\Application Data\syssvc.exe
                      2010-11-24 15:20 . 2010-11-24 15:20   --------   d-----w-   c:\documents and settings\Gabrielle\Local Settings\Application Data\Apple
                      2010-11-24 07:33 . 2010-11-24 07:33   --------   d-----w-   c:\program files\Trend Micro
                      2010-11-23 23:16 . 2010-11-23 23:28   --------   d-----w-   C:\Pictures
                      2010-11-23 20:38 . 2010-11-23 20:38   --------   d-----w-   c:\documents and settings\Mike\Application Data\SUPERAntiSpyware.com
                      2010-11-23 20:38 . 2010-11-23 20:38   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
                      2010-11-23 09:46 . 2010-11-23 09:46   --------   d-----w-   c:\documents and settings\LocalService\Local Settings\Application Data\Xobni
                      2010-11-21 21:14 . 2010-11-21 21:22   --------   d-----w-   c:\program files\Lame For Audacity
                      2010-11-19 06:23 . 2010-11-19 06:24   --------   d-----w-   c:\program files\Voobly
                      2010-11-08 22:05 . 2010-11-08 22:05   --------   d-----w-   c:\program files\iPod
                      2010-11-08 22:04 . 2010-11-08 22:07   --------   d-----w-   c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
                      2010-11-08 22:04 . 2010-11-08 22:07   --------   d-----w-   c:\program files\iTunes
                      2010-11-08 21:39 . 2010-11-08 21:40   --------   d-----w-   c:\program files\Safari
                      2010-11-06 16:37 . 2010-11-06 16:37   103864   ----a-w-   c:\program files\Mozilla Firefox\plugins\nppdf32.dll
                      2010-11-06 16:37 . 2010-11-06 16:37   103864   ----a-w-   c:\program files\Internet Explorer\PLUGINS\nppdf32.dll
                      2010-10-30 19:35 . 2010-10-30 19:35   --------   d-----w-   c:\documents and settings\Ryan\Application Data\Apple Computer
                      2010-10-30 19:34 . 2010-10-30 19:35   --------   d-----w-   c:\documents and settings\Ryan\Local Settings\Application Data\Apple Computer
                      2010-10-28 21:31 . 2010-10-28 21:31   --------   d-sh--w-   c:\documents and settings\Gabrielle\PrivacIE
                      2010-10-28 21:30 . 2010-10-28 21:30   --------   d-----w-   c:\documents and settings\Gabrielle\C
                      2010-10-28 21:25 . 2010-11-24 23:54   --------   d-----w-   c:\documents and settings\Gabrielle\Application Data\Apple Computer
                      2010-10-28 21:25 . 2010-11-24 15:16   --------   d-----w-   c:\documents and settings\Gabrielle\Local Settings\Application Data\Apple Computer
                      2010-10-28 21:25 . 2010-10-28 21:25   --------   d-----w-   c:\documents and settings\Gabrielle\Application Data\Logitech
                      2010-10-28 03:29 . 2010-10-28 03:29   --------   d-----w-   c:\documents and settings\Smoking Guns BBQ\Local Settings\Application Data\Mozilla
                      2010-10-28 03:12 . 2010-10-28 03:12   --------   d-sh--w-   c:\documents and settings\Smoking Guns BBQ\PrivacIE
                      2010-10-28 03:11 . 2010-10-28 03:12   --------   d-----w-   c:\documents and settings\Smoking Guns BBQ\Local Settings\Application Data\Google
                      2010-10-28 03:09 . 2010-10-28 03:09   --------   d-----w-   c:\documents and settings\Smoking Guns BBQ\Application Data\Malwarebytes
                      2010-10-28 02:49 . 2010-10-28 02:49   --------   d-----w-   c:\documents and settings\Smoking Guns BBQ\Application Data\Avira
                      2010-10-28 02:49 . 2010-10-28 02:49   --------   d-----w-   c:\documents and settings\Smoking Guns BBQ\Application Data\Apple Computer
                      2010-10-28 02:48 . 2010-10-28 02:48   --------   d-----w-   c:\documents and settings\Smoking Guns BBQ\Local Settings\Application Data\Apple Computer
                      2010-10-27 23:11 . 2010-10-27 23:11   --------   d-----w-   c:\documents and settings\Stephanie\Application Data\Apple Computer
                      2010-10-27 23:11 . 2010-10-27 23:11   --------   d-----w-   c:\documents and settings\Stephanie\Local Settings\Application Data\Apple Computer
                      2010-10-27 06:44 . 2010-10-27 07:40   --------   d-----w-   C:\db84fb62b7c5d1a83eaf147f

                      .
                      ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2010-11-25 08:37 . 2010-04-29 03:43   472808   ----a-w-   c:\windows\system32\deployJava1.dll
                      2010-10-27 12:06 . 2010-04-29 23:00   16400   ----a-w-   c:\windows\system32\drivers\LNonPnP.sys
                      2010-09-08 16:17 . 2010-09-08 16:17   94208   ----a-w-   c:\windows\system32\QuickTimeVR.qtx
                      2010-09-08 16:17 . 2010-09-08 16:17   69632   ----a-w-   c:\windows\system32\QuickTime.qts
                      2008-02-09 19:07 . 2008-10-12 04:28   385024   ----a-w-   c:\program files\pribluda.dll
                      2003-05-05 13:09 . 2008-10-12 04:28   886   ----a-w-   c:\program files\PATCH.COM
                      2003-01-05 20:02 . 2008-10-12 06:35   63488   ----a-w-   c:\program files\bwpatch.exe
                      .

                      (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* empty entries & legit default entries are not shown
                      REGEDIT4

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
                      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-05 68856]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
                      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-09 7561216]
                      "nwiz"="nwiz.exe" [2006-03-09 1519616]
                      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-09 86016]
                      "Logitech Utility"="Logi_MwX.Exe" [2004-03-03 19968]
                      "CTHelper"="CTHELPER.EXE" [2003-08-28 24576]
                      "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
                      "EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2010-01-27 1312848]
                      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
                      "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
                      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-09-08 421888]
                      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
                      "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]

                      c:\documents and settings\All Users\Start Menu\Programs\Startup\
                      Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-2-22 113664]

                      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                      "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\documents and settings\Mike\Desktop\SASSEH.DLL" [2008-05-13 77824]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
                      2009-09-03 22:21   548352   ----a-w-   c:\documents and settings\Mike\Desktop\SASWINLO.DLL

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
                      2010-01-29 21:17   64592   ----a-w-   c:\program files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
                      SecurityProviders   msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
                      @=""

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
                      @=""

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
                      @="Driver"

                      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ymetray.lnk]
                      path=c:\documents and settings\All Users\Start Menu\Programs\Startup\ymetray.lnk
                      backup=c:\windows\pss\ymetray.lnkCommon Startup

                      [HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk]
                      path=c:\documents and settings\Mike\Start Menu\Programs\Startup\OpenOffice.org 3.1.lnk
                      backup=c:\windows\pss\OpenOffice.org 3.1.lnkStartup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
                      2007-03-09 15:09   63712   -c--a-w-   c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSyncU.exe]
                      2006-08-07 15:06   700416   ------w-   c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
                      2008-06-24 18:34   41824   ----a-w-   c:\program files\Common Files\AOL\1160619236\ee\aolsoftware.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
                      2005-04-12 09:15   1383936   ------w-   c:\program files\Ahead\InCD\InCD.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
                      2001-11-29 06:00   28672   -c--a-w-   c:\program files\Creative\SBLive\Program\ADGJDet.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
                      2009-11-10 20:39   5244216   ----a-w-   c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                      2008-04-14 00:12   1695232   ------w-   c:\program files\Messenger\msmsgs.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MtdAcqu]
                      2006-03-08 13:56   278528   ------w-   c:\program files\Creative\MediaSource5\MtdAcqu.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBJ]
                      2005-05-19 23:38   1957888   ------w-   c:\program files\Ahead\Nero BackItUp\NBJ.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
                      2001-07-09 15:50   155648   ----a-w-   c:\windows\system32\NeroCheck.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                      2010-09-08 16:17   421888   ----a-w-   c:\program files\QuickTime\QTTask.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
                      2006-08-08 01:47   208941   ----a-w-   c:\program files\Real\RealPlayer\realplay.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Search Protection]
                      2009-02-23 13:05   111856   ----a-w-   c:\program files\Yahoo!\Search Protection\SearchProtection.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
                      2007-07-05 23:34   68856   ----a-w-   c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ymetray]
                      2006-10-03 18:04   6104568   ----a-w-   c:\program files\Yahoo!\Yahoo! Music Engine\YahooMusicEngine.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YSearchProtection]
                      2009-02-23 13:05   111856   ----a-w-   c:\program files\Yahoo!\Search Protection\SearchProtection.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                      "InCDsrvR"=2 (0x2)
                      "InCDsrv"=2 (0x2)
                      "gusvc"=3 (0x3)
                      "CCALib8"=2 (0x2)

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                      "EnableFirewall"= 0 (0x0)

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%windir%\\system32\\sessmgr.exe"=
                      "c:\\Documents and Settings\\Mike\\My Documents\\B2R\\teammate\\Teammate.exe"=
                      "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
                      "c:\\Program Files\\America Online 9.0\\waol.exe"=
                      "c:\\Papyrus\\NASCAR Racing 2003 Season\\NR2003.exe"=
                      "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
                      "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
                      "c:\\Program Files\\Common Files\\AOL\\1160619236\\ee\\aolsoftware.exe"=
                      "c:\\Program Files\\Yahoo!\\Yahoo! Music Engine\\YahooMusicEngine.exe"=
                      "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
                      "c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
                      "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                      "c:\\Program Files\\AOL 9.0\\waol.exe"=
                      "c:\\Program Files\\Opera\\opera.exe"=
                      "c:\\Program Files\\Messenger\\msmsgs.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                      "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                      "c:\\Program Files\\iTunes\\iTunes.exe"=

                      R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/19/2006 10:23 PM 642560]
                      R1 SASDIFSV;SASDIFSV;c:\documents and settings\Mike\Desktop\sasdifsv.sys [2/17/2010 1:25 PM 12872]
                      R1 SASKUTIL;SASKUTIL;c:\documents and settings\Mike\Desktop\SASKUTIL.SYS [5/10/2010 1:41 PM 67656]
                      R2 VProt2k;BroadJump PPPoE Helper Protocol;c:\windows\system32\drivers\VPROT2K.sys [2/17/2006 11:26 PM 16690]
                      R2 XobniService;XobniService;c:\program files\Xobni\XobniService.exe [10/12/2009 11:33 AM 46824]
                      R3 VWan2k;BroadJump PPPoE Adapter;c:\windows\system32\drivers\VWAN2K.sys [2/17/2006 11:26 PM 29228]
                      S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/3/2010 1:38 PM 135664]
                      S3 BCM42XX;Broadcom iLine10(tm) Network Adapter Driver;c:\windows\system32\drivers\bcm42xx5.sys [2/17/2006 5:24 PM 54271]
                      S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [8/23/2001 7:00 AM 14336]
                      S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [1/25/2007 12:31 PM 42000]
                      S3 samhid;samhid;c:\windows\system32\drivers\samhid.sys --> c:\windows\system32\drivers\samhid.sys [?]
                      S3 vaxscsi;vaxscsi;c:\windows\system32\drivers\vaxscsi.sys [5/19/2006 10:26 PM 223128]
                      S3 WmAdiHid;Logitech WingMan Digital Devices Driver;c:\windows\system32\drivers\WmAdiHid.sys [6/20/2002 12:45 PM 20320]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                      nosGetPlusHelper   REG_MULTI_SZ      nosGetPlusHelper
                      .
                      Contents of the 'Scheduled Tasks' folder

                      2010-11-25 c:\windows\Tasks\AppleSoftwareUpdate.job
                      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

                      2010-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                      - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 18:38]

                      2010-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                      - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 18:38]
                      .
                      .
                      ------- Supplementary Scan -------
                      .
                      mStart Page = hxxp://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
                      mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
                      IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
                      FF - ProfilePath - c:\documents and settings\Smoking Guns BBQ\Application Data\Mozilla\Firefox\Profiles\1gd729ek.default\
                      FF - prefs.js: network.proxy.type - 0
                      FF - plugin: c:\program files\Common Files\Motive\npMotive.dll
                      FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
                      FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
                      FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
                      FF - plugin: c:\program files\Opera\program\plugins\NPMetaStream3.dll
                      FF - plugin: c:\program files\Opera\program\plugins\npqtplugin8.dll
                      FF - plugin: c:\program files\QuickTime\Plugins\npqtplugin8.dll
                      FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
                      FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
                      FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

                      ---- FIREFOX POLICIES ----
                      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
                      c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
                      c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
                      .
                      - - - - ORPHANS REMOVED - - - -

                      BHO-{CC3C8D60-29D6-4880-B9D8-443C4CBA2BEC} - (no file)
                      MSConfigStartUp-AdaptecDirectCD - c:\program files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
                      MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                      MSConfigStartUp-plxkpadq - c:\docume~1\Mike\LOCALS~1\Temp\qnqsbpkfr\qfmvudtdlta.exe
                      MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
                      MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe



                      **************************************************************************

                      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2010-11-25 09:42
                      Windows 5.1.2600 Service Pack 3 NTFS

                      scanning hidden processes ... 

                      scanning hidden autostart entries ...

                      scanning hidden files ... 

                      scan completed successfully
                      hidden files: 0

                      **************************************************************************

                      Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
                      Windows 5.1.2600 Disk: ST380011A rev.3.06 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3

                      device: opened successfully
                      user: MBR read successfully

                      Disk trace:
                      called modules: ntoskrnl.exe >>UNKNOWN [0x837A2808]<<
                      _asm { MOV EAX, 0x837a2728; XCHG [ESP], EAX; PUSH EAX; PUSH 0x837cceb4; RET ; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL; ADD [EAX], AL;  }
                      1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x837755E0]
                      \Driver\Disk[0x83770F38] -> IRP_MJ_CREATE -> 0x837A2808
                      kernel: MBR read successfully
                      _asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a;  }
                      detected disk devices:
                      detected hooks:
                      \Driver\Disk -> 0x837a2808
                      user & kernel MBR OK
                      Warning: possible MBR rootkit infection !

                      **************************************************************************
                      .
                      --------------------- LOCKED REGISTRY KEYS ---------------------

                      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                      @Denied: (A 2) (Everyone)
                      @="FlashBroker"
                      "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

                      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                      "Enabled"=dword:00000001

                      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                      @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

                      [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

                      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                      @Denied: (A 2) (Everyone)
                      @="IFlashBroker4"

                      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                      @="{00020424-0000-0000-C000-000000000046}"

                      [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                      @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                      "Version"="1.0"
                      .
                      --------------------- DLLs Loaded Under Running Processes ---------------------

                      - - - - - - - > 'winlogon.exe'(656)
                      c:\documents and settings\Mike\Desktop\SASWINLO.DLL
                      c:\windows\system32\WININET.dll
                      c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll

                      - - - - - - - > 'explorer.exe'(3308)
                      c:\windows\system32\WININET.dll
                      c:\windows\system32\ieframe.dll
                      c:\windows\system32\webcheck.dll
                      c:\windows\system32\WPDShServiceObj.dll
                      c:\windows\system32\PortableDeviceTypes.dll
                      c:\windows\system32\PortableDeviceApi.dll
                      c:\windows\system32\msi.dll
                      .
                      ------------------------ Other Running Processes ------------------------
                      .
                      c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                      c:\program files\Bonjour\mDNSResponder.exe
                      c:\windows\system32\CTsvcCDA.exe
                      c:\program files\Java\jre6\bin\jqs.exe
                      c:\program files\Common Files\Motive\McciCMService.exe
                      c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                      c:\windows\system32\nvsvc32.exe
                      c:\windows\wanmpsvc.exe
                      c:\windows\system32\MsPMSPSv.exe
                      c:\windows\system32\wscntfy.exe
                      c:\windows\Logi_MwX.Exe
                      c:\program files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE
                      c:\program files\iPod\bin\iPodService.exe
                      c:\program files\Logitech\SetPointP\LU\LULnchr.exe
                      c:\program files\Logitech\SetPointP\LU\LogitechUpdate.exe
                      .
                      **************************************************************************
                      .
                      Completion time: 2010-11-25  09:52:47 - machine was rebooted
                      ComboFix-quarantined-files.txt  2010-11-25 14:52

                      Pre-Run: 9,872,470,016 bytes free
                      Post-Run: 11,097,464,832 bytes free

                      WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
                      [boot loader]
                      timeout=2
                      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                      [operating systems]
                      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                      UnsupportedDebug="do not select this" /debug
                      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

                      Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
                      - - End Of File - - A2D31BCAB4C6CD2A7179EEDC2EB8157B

                      SuperDave

                      • Malware Removal Specialist


                      • Genius
                      • Thanked: 1020
                      • Certifications: List
                      • Experience: Expert
                      • OS: Windows 10
                      Re: TR/FakeSpyPro6
                      « Reply #12 on: November 25, 2010, 01:11:22 PM »
                      You have Viewpoint installed.

                      Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

                      More information:

                      * ViewMgr.exe - Useless
                      * Viewpoint to Plunge Into Adware

                      It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present.

                      * Viewpoint
                      * Viewpoint Manager
                      * Viewpoint Media Player
                      * Viewpoint Toolbar
                      * Viewpoint Experience Technology

                      *************************************
                      Please download MBRCheck.exe by a_d_13 from one of the links provided below and save it to your desktop.

                      Link 1
                      Link 2
                      Link 3

                      •Double-click on MBRCheck.exe to run it.

                      •It will open a black window...please do not fix anything (if it gives you an option).

                      •When complete, you should see Done! Press ENTER to exit.... Press Enter on the keyboard.

                      •A log named MBRCheck_date_time.txt (i.e. MBRCheck_07.21.10_10.22.51.txt) will appear on the desktop.
                      •Please copy and paste the contents of that log in your next reply.
                      Windows 8 and Windows 10 dual boot with two SSD's

                      Mikex79

                        Topic Starter


                        Rookie

                        • Computer: Specs
                        • Experience: Familiar
                        • OS: Windows XP
                        Re: TR/FakeSpyPro6
                        « Reply #13 on: November 26, 2010, 12:04:16 AM »
                        MBRCheck, version 1.2.3
                        (c) 2010, AD

                        Command-line:         
                        Windows Version:      Windows XP Professional
                        Windows Information:      Service Pack 3 (build 2600)
                        Logical Drives Mask:      0x0000001d

                        Kernel Drivers (total 154):
                          0x804D7000 \WINDOWS\system32\ntoskrnl.exe
                          0x806EE000 \WINDOWS\system32\hal.dll
                          0xF7AA9000 \WINDOWS\system32\KDCOM.DLL
                          0xF79B9000 \WINDOWS\system32\BOOTVID.dll
                          0xF74B8000 sptd.sys
                          0xF7AAB000 \WINDOWS\System32\Drivers\WMILIB.SYS
                          0xF74A0000 \WINDOWS\System32\Drivers\SPTD6749.SYS
                          0xF7472000 ACPI.sys
                          0xF7461000 pci.sys
                          0xF75A9000 isapnp.sys
                          0xF7AAD000 intelide.sys
                          0xF7829000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS
                          0xF75B9000 MountMgr.sys
                          0xF7442000 ftdisk.sys
                          0xF7AAF000 dmload.sys
                          0xF741C000 dmio.sys
                          0xF7831000 PartMgr.sys
                          0xF75C9000 VolSnap.sys
                          0xF7404000 atapi.sys
                          0xF75D9000 disk.sys
                          0xF75E9000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
                          0xF73E4000 fltmgr.sys
                          0xF73D2000 sr.sys
                          0xF75F9000 PxHelp20.sys
                          0xF73BB000 KSecDD.sys
                          0xF73A8000 WudfPf.sys
                          0xF731B000 Ntfs.sys
                          0xF72EE000 NDIS.sys
                          0xF72D4000 Mup.sys
                          0xF7609000 agp440.sys
                          0xF76F9000 \SystemRoot\System32\DRIVERS\p3.sys
                          0xF6C13000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
                          0xF6BFF000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
                          0xF7971000 \SystemRoot\system32\DRIVERS\RTL8139.SYS
                          0xF6B90000 \SystemRoot\system32\drivers\ctaud2k.sys
                          0xF6B6C000 \SystemRoot\system32\drivers\portcls.sys
                          0xF7709000 \SystemRoot\system32\drivers\drmk.sys
                          0xF6B49000 \SystemRoot\system32\drivers\ks.sys
                          0xF6B30000 \SystemRoot\system32\drivers\ctoss2k.sys
                          0xF7ADD000 \SystemRoot\System32\drivers\ctprxy2k.sys
                          0xF7278000 \SystemRoot\System32\DRIVERS\gameenum.sys
                          0xF6A5B000 \SystemRoot\System32\DRIVERS\BCMDM.sys
                          0xF7979000 \SystemRoot\System32\Drivers\Modem.SYS
                          0xF7729000 \SystemRoot\System32\DRIVERS\i8042prt.sys
                          0xF7739000 \SystemRoot\System32\Drivers\l8042pr2.sys
                          0xF7749000 \SystemRoot\System32\Drivers\LMouFlt2.sys
                          0xF7981000 \SystemRoot\System32\DRIVERS\mouclass.sys
                          0xF7274000 \SystemRoot\system32\DRIVERS\itchfltr.sys
                          0xF7989000 \SystemRoot\System32\DRIVERS\kbdclass.sys
                          0xF7991000 \SystemRoot\System32\DRIVERS\fdc.sys
                          0xF7759000 \SystemRoot\System32\DRIVERS\serial.sys
                          0xF7270000 \SystemRoot\System32\DRIVERS\serenum.sys
                          0xF6A47000 \SystemRoot\System32\DRIVERS\parport.sys
                          0xF7769000 \SystemRoot\system32\drivers\Imapi.sys
                          0xF7779000 \SystemRoot\System32\DRIVERS\cdrom.sys
                          0xF7789000 \SystemRoot\System32\DRIVERS\redbook.sys
                          0xF7999000 \SystemRoot\System32\DRIVERS\InCDPass.sys
                          0xF79A1000 \SystemRoot\System32\Drivers\incdrm.SYS
                          0xF79A9000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
                          0xF79B1000 \SystemRoot\System32\DRIVERS\usbuhci.sys
                          0xF69C1000 \SystemRoot\System32\DRIVERS\USBPORT.SYS
                          0xF7C75000 \SystemRoot\System32\DRIVERS\audstub.sys
                          0xF7799000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
                          0xF7A6D000 \SystemRoot\System32\DRIVERS\ndistapi.sys
                          0xF69AA000 \SystemRoot\System32\DRIVERS\ndiswan.sys
                          0xF77A9000 \SystemRoot\System32\DRIVERS\raspppoe.sys
                          0xF77B9000 \SystemRoot\System32\DRIVERS\raspptp.sys
                          0xF7849000 \SystemRoot\System32\DRIVERS\TDI.SYS
                          0xF68F9000 \SystemRoot\System32\DRIVERS\psched.sys
                          0xF77C9000 \SystemRoot\System32\DRIVERS\msgpc.sys
                          0xF7851000 \SystemRoot\System32\DRIVERS\ptilink.sys
                          0xF7859000 \SystemRoot\System32\DRIVERS\raspti.sys
                          0xF7861000 \SystemRoot\System32\DRIVERS\VWan2k.SYS
                          0xF7869000 \SystemRoot\system32\DRIVERS\wanatw4.sys
                          0xF68C9000 \SystemRoot\System32\DRIVERS\rdpdr.sys
                          0xF77D9000 \SystemRoot\System32\DRIVERS\termdd.sys
                          0xF7ADF000 \SystemRoot\System32\DRIVERS\swenum.sys
                          0xF6843000 \SystemRoot\System32\DRIVERS\update.sys
                          0xF6FA3000 \SystemRoot\System32\DRIVERS\mssmbios.sys
                          0xF6F9F000 \SystemRoot\system32\drivers\WmBEnum.sys
                          0xF77E9000 \SystemRoot\system32\drivers\WmXlCore.sys
                          0xF7809000 \SystemRoot\System32\DRIVERS\usbhub.sys
                          0xF7AE1000 \SystemRoot\System32\DRIVERS\USBD.SYS
                          0xF7819000 \SystemRoot\System32\Drivers\NDProxy.SYS
                          0xF482F000 \SystemRoot\System32\drivers\ha10kx2k.sys
                          0xF480E000 \SystemRoot\System32\drivers\ctac32k.sys
                          0xF47EC000 \SystemRoot\System32\drivers\emupia2k.sys
                          0xF47CD000 \SystemRoot\System32\drivers\ctsfm2k.sys
                          0xF7A99000 \SystemRoot\system32\drivers\MODEMCSA.sys
                          0xF7879000 \SystemRoot\System32\DRIVERS\flpydisk.sys
                          0xF7AE5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
                          0xF7C2B000 \SystemRoot\System32\Drivers\Null.SYS
                          0xF7AE7000 \SystemRoot\System32\Drivers\Beep.SYS
                          0xF7C2C000 \SystemRoot\System32\DRIVERS\papycpu2.sys
                          0xF7C2D000 \SystemRoot\System32\DRIVERS\papyjoy.sys
                          0xF7889000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
                          0xF7891000 \SystemRoot\System32\drivers\vga.sys
                          0xF7AE9000 \SystemRoot\System32\Drivers\mnmdd.SYS
                          0xF7AEB000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
                          0xF7AA5000 \SystemRoot\System32\Drivers\InCDrec.SYS
                          0xF4794000 \SystemRoot\System32\Drivers\InCDfs.SYS
                          0xF7899000 \SystemRoot\System32\Drivers\Msfs.SYS
                          0xF78A1000 \SystemRoot\System32\Drivers\Npfs.SYS
                          0xF72B0000 \SystemRoot\System32\DRIVERS\rasacd.sys
                          0xF4781000 \SystemRoot\System32\DRIVERS\ipsec.sys
                          0xF4728000 \SystemRoot\System32\DRIVERS\tcpip.sys
                          0xF4700000 \SystemRoot\System32\DRIVERS\netbt.sys
                          0xF46DE000 \SystemRoot\System32\drivers\afd.sys
                          0xF7659000 \SystemRoot\System32\DRIVERS\netbios.sys
                          0xF46BC000 \??\C:\Documents and Settings\Mike\Desktop\SASKUTIL.SYS
                          0xF78A9000 \??\C:\Documents and Settings\Mike\Desktop\SASDIFSV.SYS
                          0xF4691000 \SystemRoot\System32\DRIVERS\rdbss.sys
                          0xF45F9000 \SystemRoot\System32\DRIVERS\mrxsmb.sys
                          0xF7669000 \SystemRoot\System32\Drivers\Fips.SYS
                          0xF4533000 \SystemRoot\System32\DRIVERS\ipnat.sys
                          0xF7679000 \SystemRoot\System32\DRIVERS\wanarp.sys
                          0xF78B1000 \SystemRoot\System32\DRIVERS\usbprint.sys
                          0xF78B9000 \SystemRoot\System32\Drivers\LUsbFilt.Sys
                          0xF7689000 \SystemRoot\System32\Drivers\WDFLDR.SYS
                          0xF44C2000 \SystemRoot\System32\Drivers\wdf01000.sys
                          0xF7290000 \SystemRoot\System32\DRIVERS\hidusb.sys
                          0xF7699000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS
                          0xF76A9000 \SystemRoot\System32\Drivers\btwusb.sys
                          0xF78C1000 \SystemRoot\system32\DRIVERS\LHidFilt.Sys
                          0xF68C5000 \SystemRoot\System32\DRIVERS\mouhid.sys
                          0xF78C9000 \SystemRoot\system32\DRIVERS\LMouFilt.Sys
                          0xF68BD000 \SystemRoot\system32\DRIVERS\kbdhid.sys
                          0xF76D9000 \SystemRoot\System32\Drivers\Cdfs.SYS
                          0xF44AA000 \SystemRoot\System32\Drivers\dump_atapi.sys
                          0xF7AFD000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
                          0xBF800000 \SystemRoot\System32\win32k.sys
                          0xF66AB000 \SystemRoot\System32\drivers\Dxapi.sys
                          0xF78E9000 \SystemRoot\System32\watchdog.sys
                          0xBF000000 \SystemRoot\System32\drivers\dxg.sys
                          0xF7C26000 \SystemRoot\System32\drivers\dxgthk.sys
                          0xBF012000 \SystemRoot\System32\nv4_disp.dll
                          0xBFFA0000 \SystemRoot\System32\ATMFD.DLL
                          0xBA6C0000 \SystemRoot\system32\DRIVERS\fssfltr_tdi.sys
                          0xBA5D8000 \SystemRoot\System32\DRIVERS\ndisuio.sys
                          0xBA5D4000 \SystemRoot\System32\DRIVERS\VProt2k.SYS
                          0xB9F63000 \SystemRoot\System32\DRIVERS\mrxdav.sys
                          0xF7B23000 \SystemRoot\System32\Drivers\ParVdm.SYS
                          0xF78D9000 \SystemRoot\System32\drivers\aspi32.sys
                          0xB9D04000 \SystemRoot\System32\DRIVERS\srv.sys
                          0xF7B43000 \SystemRoot\System32\Drivers\MCSTRM.SYS
                          0xB9FAC000 \??\C:\WINDOWS\system32\drivers\PfModNT.sys
                          0xB9EAB000 \SystemRoot\System32\DRIVERS\secdrv.sys
                          0xB9907000 \SystemRoot\system32\drivers\wdmaud.sys
                          0xB9A6C000 \SystemRoot\system32\drivers\sysaudio.sys
                          0xB7EB8000 \SystemRoot\system32\drivers\kmixer.sys
                          0xB7A94000 \SystemRoot\system32\DRIVERS\avipbb.sys
                          0xF7AB9000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys
                          0xB7A7F000 \SystemRoot\system32\DRIVERS\avgntflt.sys
                          0x7C900000 \WINDOWS\system32\ntdll.dll

                        Processes (total 47):
                               0 System Idle Process
                               4 System
                             580 C:\WINDOWS\system32\smss.exe
                             632 csrss.exe
                             656 C:\WINDOWS\system32\winlogon.exe
                             704 C:\WINDOWS\system32\services.exe
                             716 C:\WINDOWS\system32\lsass.exe
                             884 C:\WINDOWS\system32\svchost.exe
                             932 svchost.exe
                            1000 C:\WINDOWS\system32\svchost.exe
                            1056 C:\WINDOWS\system32\svchost.exe
                            1148 svchost.exe
                            1276 svchost.exe
                            1404 C:\WINDOWS\system32\spoolsv.exe
                            1504 svchost.exe
                            1552 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                            1564 C:\Program Files\Bonjour\mDNSResponder.exe
                            1588 C:\WINDOWS\system32\CTSVCCDA.EXE
                            1712 C:\Program Files\Java\jre6\bin\jqs.exe
                            1796 C:\Program Files\Common Files\Motive\McciCMService.exe
                            1868 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                            1892 C:\WINDOWS\system32\nvsvc32.exe
                            1944 C:\WINDOWS\system32\svchost.exe
                            1964 C:\WINDOWS\wanmpsvc.exe
                            1988 C:\WINDOWS\system32\MsPMSPSv.exe
                             256 C:\Program Files\Xobni\XobniService.exe
                            1204 alg.exe
                            2120 C:\WINDOWS\explorer.exe
                            2400 C:\WINDOWS\system32\wscntfy.exe
                            2608 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                            2680 C:\WINDOWS\LOGI_MWX.EXE
                            2696 C:\WINDOWS\system32\CTHELPER.EXE
                            2744 C:\Program Files\Logitech\SetPointP\SetPoint.exe
                            2796 C:\Program Files\iTunes\iTunesHelper.exe
                            2804 C:\Program Files\Common Files\Java\Java Update\jusched.exe
                            2824 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            3124 C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
                            3360 C:\Program Files\iPod\bin\iPodService.exe
                            3464 C:\Program Files\Logitech\SetPointP\LU\LULnchr.exe
                            3480 C:\Program Files\Logitech\SetPointP\LU\LogitechUpdate.exe
                            2900 C:\Program Files\Creative\MediaSource5\CTDetctu.exe
                            2220 C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                            3556 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
                            3860 C:\Program Files\Avira\AntiVir Desktop\sched.exe
                            1084 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                             596 C:\Program Files\Mozilla Firefox\firefox.exe
                            1344 C:\Documents and Settings\Smoking Guns BBQ\Desktop\MBRCheck.exe

                        \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00  (NTFS)

                        PhysicalDrive0 Model Number: ST380011A, Rev: 3.06   

                              Size  Device Name          MBR Status
                          --------------------------------------------
                             74 GB  \\.\PhysicalDrive0   Windows XP MBR code detected
                                    SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644 A


                        Done!

                        SuperDave

                        • Malware Removal Specialist


                        • Genius
                        • Thanked: 1020
                        • Certifications: List
                        • Experience: Expert
                        • OS: Windows 10
                        Re: TR/FakeSpyPro6
                        « Reply #14 on: November 26, 2010, 04:53:31 PM »
                        SysProt Antirootkit

                        Download
                        SysProt Antirootkit from the link below (you will find it at the bottom
                        of the page under attachments, or you can get it from one of the
                        mirrors).

                        http://sites.google.com/site/sysprotantirootkit/

                        Unzip it into a folder on your desktop.
                        • Double click Sysprot.exe to start the program.
                        • Click on the Log tab.
                        • In the Write to log box select the following items.
                          • Process << Selected
                          • Kernel Modules << Selected
                          • SSDT << Selected
                          • Kernel Hooks << Selected
                          • IRP Hooks << NOT Selected
                          • Ports << NOT Selected
                          • Hidden Files << Selected
                        • At the bottom of the page
                          • Hidden Objects Only << Selected
                        • Click on the Create Log button on the bottom right.
                        • After a few seconds a new window should appear.
                        • Select Scan Root Drive. Click on the Start button.
                        • When it is complete a new window will appear to indicate that the scan is finished.
                        • The log will be saved automatically in the same folder Sysprot.exe was

                        extracted to. Open the text file and copy/paste the log here.
                        [/list]
                        Windows 8 and Windows 10 dual boot with two SSD's