| Answer» Logfile of Trend Micro HijackThis v2.0.2Scan saved at 5:59:23 PM, on 09/10/2008
 Platform: Windows XP SP2 (WinNT 5.01.2600)
 MSIE: Internet Explorer v7.00 (7.00.6000.16705)
 BOOT mode: Normal
 
 Running processes:
 C:\WINDOWS\System32\smss.exe
 C:\WINDOWS\system32\winlogon.exe
 C:\WINDOWS\system32\services.exe
 C:\WINDOWS\system32\lsass.exe
 C:\WINDOWS\system32\svchost.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 C:\WINDOWS\Explorer.EXE
 C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 C:\Program Files\Norton Internet Security\ISSVC.exe
 C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 C:\WINDOWS\system32\spoolsv.exe
 C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
 C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 C:\Program Files\Bonjour\mDNSResponder.exe
 C:\WINDOWS\system32\nvsvc32.exe
 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 C:\PROGRA~1\AVG\AVG8\avgrsx.exe
 C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
 C:\PROGRA~1\AVG\AVG8\avgemc.exe
 C:\WINDOWS\system32\wscntfy.exe
 C:\WINDOWS\system32\VTTimer.exe
 C:\WINDOWS\SOUNDMAN.EXE
 C:\Program Files\Common Files\Symantec Shared\ccApp.exe
 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
 C:\Program Files\Winamp\winampa.exe
 C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
 C:\WINDOWS\System32\svchost.exe
 C:\Program Files\iTunes\iTunesHelper.exe
 C:\PROGRA~1\AVG\AVG8\avgtray.exe
 C:\Program Files\MSN Messenger\MsnMsgr.Exe
 C:\WINDOWS\system32\ctfmon.exe
 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 C:\Program Files\Logitech\SetPoint\SetPoint.exe
 C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
 C:\Program Files\iPod\bin\iPodService.exe
 C:\Program Files\MSN Messenger\usnsvc.exe
 C:\Program Files\Internet Explorer\iexplore.exe
 C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
 C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe
 
 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.trivium.org
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50245
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=22028
 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
 O2 - BHO: (no name) - {70BC9B99-5802-4523-8B5E-519F3AF61828} - C:\WINDOWS\system32\hgGvwvWp.dll (file missing)
 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
 O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
 O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
 O3 - Toolbar: (no name) - {6366459B-45A6-489C-9726-429617BB05C2} - (no file)
 O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
 O4 - HKLM\..\RUN: [VTTimer] VTTimer.exe
 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
 O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
 O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
 O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
 O4 - HKLM\..\Run: [Adobe Version Cue CS2] "C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe"
 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
 O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
 O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
 O4 - HKLM\..\Run: [iut75] c:\windows\system32\drivers\uzcx.exe
 O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
 O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
 O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
 O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
 O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
 O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
 O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
 O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
 O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Etomi\Plugins\RazaWebHook.dll/3000
 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
 O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
 O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
 O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
 O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
 O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
 O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://my-remote.johnsoncontrols.com/https/jwimkns9.na.jci.com/iNotes6W.cab
 O16 - DPF: {4C68DACE-E6BC-4650-9C7E-D036720CA729} (Nps Control) - http://kr.gameguard.nprotect.com/inca/onscan//tyscan/nps.cab
 O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
 O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab53083.cab
 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
 O16 - DPF: {F977E961-BC9E-4B91-ACF8-468E1CC224DD} (FixUpdate Class) - http://69.59.149.193:82/enzf/TqUpdate_Release.CAB
 O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
 O20 - AppInit_DLLs: avgrsstx.dll pclgna.dll
 O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
 O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addpf.exe (file missing)
 O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
 O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
 O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
 O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
 O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
 O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
 O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
 O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
 O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
 O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
 O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
 O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
 O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
 O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
 O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
 --
 End of file - 11381 bytes
 Malwarebytes' Anti-Malware 1.28
 Database version: 1248
 Windows 5.1.2600 Service Pack 2
 
 09/10/2008 4:54:55 PM
 mbam-log-2008-10-09 (16-54-55).txt
 
 Scan type: Quick Scan
 Objects scanned: 50590
 Time elapsed: 4 minute(s), 18 second(s)
 
 Memory Processes Infected: 0
 Memory Modules Infected: 1
 Registry Keys Infected: 17
 Registry Values Infected: 22
 Registry Data Items Infected: 14
 Folders Infected: 1
 Files Infected: 23
 
 Memory Processes Infected:
 (No malicious items detected)
 
 Memory Modules Infected:
 C:\WINDOWS\system32\yqcbwter.dll (Trojan.Vundo) -> Delete on reboot.
 
 Registry Keys Infected:
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{498d8d78-8573-4253-be8c-2ca89b464b8d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\rqrhxvwq (Trojan.Vundo.H) -> Quarantined and deleted successfully.
 HKEY_CLASSES_ROOT\CLSID\{498d8d78-8573-4253-be8c-2ca89b464b8d} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8792432c-f034-4f85-990c-b6d3cc1c51ac} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
 HKEY_CLASSES_ROOT\CLSID\{8792432c-f034-4f85-990c-b6d3cc1c51ac} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
 HKEY_CLASSES_ROOT\qaccess.tchongabho (Trojan.BHO) -> Quarantined and deleted successfully.
 HKEY_CLASSES_ROOT\CLSID\{a34fa88d-8437-4634-8a60-e913011ef2e5} (Trojan.BHO) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\VAV (Rogue.VistaAntivirus2008) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.
 HKEY_CLASSES_ROOT\olnmraew.baok (Trojan.FakeAlert) -> Quarantined and deleted successfully.
 HKEY_CLASSES_ROOT\olnmraew.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
 
 Registry Values Infected:
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\c8651dc6 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ehceb1atnj (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rs32net (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur54.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur55.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur56.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur57.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur4.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur54.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur55.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur56.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur57.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur1.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur4.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\lfstbwvd (Trojan.FakeAlert) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\qmafxprs (Trojan.FakeAlert) -> Quarantined and deleted successfully.
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ANTIVIRUS (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
 
 Registry Data Items Infected:
 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductId (Trojan.FakeAlert) -> Bad: (VIRUS ALERT!) Good: (76477-OEM-0011903-00133) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\Control Panel\International\sTimeFormat (Trojan.FakeAlert) -> Bad: (HH:mm: VIRUS ALERT!) Good: (h:mm:ss tt) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowControlPanel (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowRun (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyDocs (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoStartMenuMorePrograms (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\StartMenuLogOff (Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoToolbarCustomize (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetFolders (Hijack.Explorer) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
 HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispCPL (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
 
 Folders Infected:
 C:\Program Files\Microsoft Common (Trojan.Agent) -> Quarantined and deleted successfully.
 
 Files Infected:
 C:\WINDOWS\system32\rqRHxvWQ.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
 C:\WINDOWS\system32\pclgna.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
 C:\WINDOWS\system32\yqcbwter.dll (Trojan.Vundo.H) -> Delete on reboot.
 C:\WINDOWS\system32\retwbcqy.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
 C:\Documents and Settings\All Users\Application Data\jkrwpezq\nqrmfole.exe (Trojan.FakeAlert.H) -> Delete on reboot.
 C:\WINDOWS\ealf.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
 C:\WINDOWS\system32\ide21201.vxd (Adware.Winad) -> Quarantined and deleted successfully.
 C:\WINDOWS\system32\dlds1.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
 C:\WINDOWS\system32\dlds8.exe (Trojan.Agent) -> Quarantined and deleted successfully.
 C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
 C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> Quarantined and deleted successfully.
 C:\WINDOWS\system32\sysem.exe (Worm.SdBot) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Application Data\TmpRecentIcons\Vista Antivirus 2008.lnk (Rogue.Link) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Desktop\BEST BDSM PORN.url (Rogue.Link) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Desktop\GAY FETISH SEX.url (Rogue.Link) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Desktop\Protect Your Privacy.url (Rogue.Link) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Desktop\Malware Defender.url (Rogue.Link) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Desktop\System Error Fixer.url (Rogue.Link) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Favorites\Malware Defender.url (Rogue.Link) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Favorites\Protect Your Privacy.url (Rogue.Link) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Favorites\System Error Fixer.url (Rogue.Link) -> Quarantined and deleted successfully.
 C:\Documents and Settings\Ash Lattanzi\Local Settings\Temp\smchk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
 C:\WINDOWS\system32\TDSSerrors.log (Trojan.TDSS) -> Quarantined and deleted successfully.SUPERAntiSpyware Scan Log
 http://www.superantispyware.com
 
 Generated 10/09/2008 at 04:32 PM
 
 Application Version : 4.21.1004
 
 Core Rules Database Version : 3593
 Trace Rules Database Version: 1580
 
 Scan type       : Complete Scan
 Total Scan Time : 00:44:43
 
 Memory items scanned      : 465
 Memory threats detected   : 0
 Registry items scanned    : 5819
 Registry threats detected : 94
 File items scanned        : 33510
 File threats detected     : 46
 
 Parasite.CoolWebSearch Variant
 HKLM\Software\Classes\CLSID\{9D3DCB85-C38C-2CD8-1768-75E8BDB64A72}
 HKLM\Software\Classes\CLSID\{AF451484-05EA-655A-4EE7-4B4F9A677388}
 HKLM\Software\Classes\CLSID\{B03430E3-E090-8CBB-E139-B55E6B313D07}
 HKLM\Software\Classes\CLSID\{B8E989AC-570B-BFD4-F982-B6FA8BC18348}
 HKLM\Software\Classes\CLSID\{E18E7A68-3ADC-95BD-23E5-697B5C7438E7}
 HKLM\Software\Classes\CLSID\{EFBFBA2F-CC59-CEAD-D6D0-CD413F205910}
 HKLM\Software\Classes\CLSID\{F01F499F-477F-58D2-D5A4-5627210822BF}
 HKCR\CLSID\{9D3DCB85-C38C-2CD8-1768-75E8BDB64A72}
 HKCR\CLSID\{9D3DCB85-C38C-2CD8-1768-75E8BDB64A72}\Data
 HKCR\CLSID\{AF451484-05EA-655A-4EE7-4B4F9A677388}
 HKCR\CLSID\{AF451484-05EA-655A-4EE7-4B4F9A677388}\Data
 HKCR\CLSID\{B03430E3-E090-8CBB-E139-B55E6B313D07}
 HKCR\CLSID\{B03430E3-E090-8CBB-E139-B55E6B313D07}\Data
 HKCR\CLSID\{B8E989AC-570B-BFD4-F982-B6FA8BC18348}
 HKCR\CLSID\{B8E989AC-570B-BFD4-F982-B6FA8BC18348}\Data
 HKCR\CLSID\{E18E7A68-3ADC-95BD-23E5-697B5C7438E7}
 HKCR\CLSID\{E18E7A68-3ADC-95BD-23E5-697B5C7438E7}\Data
 HKCR\CLSID\{EFBFBA2F-CC59-CEAD-D6D0-CD413F205910}
 HKCR\CLSID\{EFBFBA2F-CC59-CEAD-D6D0-CD413F205910}\Data
 HKCR\CLSID\{F01F499F-477F-58D2-D5A4-5627210822BF}
 HKCR\CLSID\{F01F499F-477F-58D2-D5A4-5627210822BF}\Data
 
 Unclassified.Unknown Origin
 HKLM\Software\Classes\CLSID\{B89A9C19-6168-604D-2FF8-CB8455B6D319}
 HKLM\Software\Classes\CLSID\{D9E4FCE9-DD60-AD26-B07D-BFB00720C50B}
 HKLM\Software\Classes\CLSID\{E20A03B0-E8BF-E901-3BC0-4FA42916EF31}
 HKLM\Software\Classes\CLSID\{FC97DD7A-EAF3-5C15-ED04-6CBD8788DF3C}
 HKCR\CLSID\{E20A03B0-E8BF-E901-3BC0-4FA42916EF31}
 HKCR\CLSID\{E20A03B0-E8BF-E901-3BC0-4FA42916EF31}\Data
 HKCR\CLSID\{B89A9C19-6168-604D-2FF8-CB8455B6D319}
 HKCR\CLSID\{B89A9C19-6168-604D-2FF8-CB8455B6D319}\Data
 HKCR\CLSID\{D9E4FCE9-DD60-AD26-B07D-BFB00720C50B}
 HKCR\CLSID\{D9E4FCE9-DD60-AD26-B07D-BFB00720C50B}\Data
 HKCR\CLSID\{FC97DD7A-EAF3-5C15-ED04-6CBD8788DF3C}
 HKCR\CLSID\{FC97DD7A-EAF3-5C15-ED04-6CBD8788DF3C}\Data
 
 Spyware.WebSearch (WinTools/HuntBar)
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87766247-311C-43B4-8499-3D5FEC94A183}
 C:\Program Files\Common Files\WinTools\rmhgxlmu.wzg
 C:\Program Files\Common Files\WinTools\WToolsC.cfg
 C:\Program Files\Common Files\WinTools\WToolsD.cfg
 C:\Program Files\Common Files\WinTools\WToolsP.cfg
 C:\Program Files\Common Files\WinTools\WToolsR.cfg
 C:\Program Files\Common Files\WinTools\WToolsU.cfg
 C:\Program Files\Common Files\WinTools
 HKU\S-1-5-21-3513752564-1149034596-958856376-1005\Software\WinTools
 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC
 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC#NextInstance
 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000
 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#Service
 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#Legacy
 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#ConfigFlags
 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#Class
 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#ClassGUID
 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000#DeviceDesc
 
 Trojan.Net-MSV/VPS-Variant
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F8DE4182-0328-438E-B5EC-0A5F5E57FA2E}
 HKCR\CLSID\{F8DE4182-0328-438E-B5EC-0A5F5E57FA2E}
 HKCR\CLSID\{F8DE4182-0328-438E-B5EC-0A5F5E57FA2E}
 HKCR\CLSID\{F8DE4182-0328-438E-B5EC-0A5F5E57FA2E}\InprocServer32
 HKCR\CLSID\{F8DE4182-0328-438E-B5EC-0A5F5E57FA2E}\InprocServer32#ThreadingModel
 HKCR\CLSID\{F8DE4182-0328-438E-B5EC-0A5F5E57FA2E}\ProgID
 HKCR\CLSID\{F8DE4182-0328-438E-B5EC-0A5F5E57FA2E}\Programmable
 HKCR\CLSID\{F8DE4182-0328-438E-B5EC-0A5F5E57FA2E}\TypeLib
 HKCR\CLSID\{F8DE4182-0328-438E-B5EC-0A5F5E57FA2E}\VersionIndependentProgID
 HKCR\QXK.Olive
 HKCR\TypeLib\{FEC11AA8-D826-4562-9223-A9A901A06B56}
 HKCR\TypeLib\{FEC11AA8-D826-4562-9223-A9A901A06B56}\1.0
 HKCR\TypeLib\{FEC11AA8-D826-4562-9223-A9A901A06B56}\1.0\0
 HKCR\TypeLib\{FEC11AA8-D826-4562-9223-A9A901A06B56}\1.0\0\win32
 HKCR\TypeLib\{FEC11AA8-D826-4562-9223-A9A901A06B56}\1.0\FLAGS
 HKCR\TypeLib\{FEC11AA8-D826-4562-9223-A9A901A06B56}\1.0\HELPDIR
 C:\WINDOWS\VORTSGBQTPR.DLL
 HKCR\Interface\{73E37705-8560-4541-A9DB-C8DE64D7CD00}
 HKCR\Interface\{73E37705-8560-4541-A9DB-C8DE64D7CD00}\ProxyStubClsid
 HKCR\Interface\{73E37705-8560-4541-A9DB-C8DE64D7CD00}\ProxyStubClsid32
 HKCR\Interface\{73E37705-8560-4541-A9DB-C8DE64D7CD00}\TypeLib
 HKCR\Interface\{73E37705-8560-4541-A9DB-C8DE64D7CD00}\TypeLib#Version
 HKCR\Interface\{AFE3DAB2-8795-45E5-BF5B-89F21F7FEBA0}
 HKCR\Interface\{AFE3DAB2-8795-45E5-BF5B-89F21F7FEBA0}\ProxyStubClsid
 HKCR\Interface\{AFE3DAB2-8795-45E5-BF5B-89F21F7FEBA0}\ProxyStubClsid32
 HKCR\Interface\{AFE3DAB2-8795-45E5-BF5B-89F21F7FEBA0}\TypeLib
 HKCR\Interface\{AFE3DAB2-8795-45E5-BF5B-89F21F7FEBA0}\TypeLib#Version
 
 Adware.Tracking Cookie
 C:\Documents and Settings\Ash Lattanzi\Cookies\[email protected][2].txt
 C:\Documents and Settings\Ash Lattanzi\Cookies\[email protected][1].txt
 
 Adware.WhenU
 HKCR\WUSN.1
 HKCR\WUSN.1#WUSN_Id
 HKU\S-1-5-21-3513752564-1149034596-958856376-1005\Software\WhenU
 C:\Documents and Settings\Ash Lattanzi\Start Menu\Programs\WhenU\Learn More About Save!.url
 C:\Documents and Settings\Ash Lattanzi\Start Menu\Programs\WhenU\Learn More About SaveNow.url
 C:\Documents and Settings\Ash Lattanzi\Start Menu\Programs\WhenU\WhenU.com Website.url
 C:\Documents and Settings\Ash Lattanzi\Start Menu\Programs\WhenU
 
 Adware.Avenue Media/Internet Optimizer
 HKU\S-1-5-21-3513752564-1149034596-958856376-1005\Software\Avenue Media
 HKLM\Software\Avenue Media
 HKLM\Software\Avenue Media\Internet Optimizer
 HKLM\Software\Avenue Media\Internet Optimizer#TargetDir
 HKLM\Software\Avenue Media\Internet Optimizer#CLS
 HKLM\Software\Avenue Media\Internet Optimizer#RID
 HKLM\Software\Avenue Media\Internet Optimizer#Version
 HKLM\Software\Avenue Media\Internet Optimizer#TAC
 HKLM\Software\Avenue Media\Internet Optimizer#ServerVisited
 HKLM\Software\Avenue Media\Internet Optimizer#PendingRemoval
 HKU\S-1-5-21-3513752564-1149034596-958856376-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\AMeOpt
 HKU\S-1-5-21-3513752564-1149034596-958856376-1005\SOFTWARE\Policies\Avenue Media
 HKLM\SOFTWARE\Policies\Avenue Media
 
 Trojan.Unknown Origin
 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A34FA88D-8437-4634-8A60-E913011EF2E5}
 C:\WINDOWS\SYSTEM32\1.ICO
 C:\WINDOWS\SYSTEM32\2.ICO
 C:\X
 
 Trojan.Media-Codec
 C:\Program Files\PCHealthCenter\0.exe
 C:\Program Files\PCHealthCenter\0.gif
 C:\Program Files\PCHealthCenter\1.exe
 C:\Program Files\PCHealthCenter\1.gif
 C:\Program Files\PCHealthCenter\1.ico
 C:\Program Files\PCHealthCenter\2.exe
 C:\Program Files\PCHealthCenter\2.gif
 C:\Program Files\PCHealthCenter\2.ico
 C:\Program Files\PCHealthCenter\3.exe
 C:\Program Files\PCHealthCenter\3.gif
 C:\Program Files\PCHealthCenter\4.exe
 C:\Program Files\PCHealthCenter\5.exe
 C:\Program Files\PCHealthCenter\7.exe
 C:\Program Files\PCHealthCenter\sc.html
 C:\Program Files\PCHealthCenter
 
 Trojan.DNSChanger-Codec
 HKU\S-1-5-21-3513752564-1149034596-958856376-1005\Software\uninstall
 
 Trojan.Net-MU/Gen
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#uninstallString
 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WebVideo#DisplayName
 
 Rootkit.Unclassified/KR_Done
 C:\WINDOWS\system32\vx.tll
 
 Rogue.AntiVirus 2008
 HKU\S-1-5-21-3513752564-1149034596-958856376-1005\Software\Microsoft\Windows\CurrentVersion\Run#Antivirus [ C:\Program Files\VAV\vav.exe ]
 
 Adware.Vundo Variant/Rel
 HKLM\SOFTWARE\Microsoft\FCOVM
 HKLM\SOFTWARE\Microsoft\RemoveRP
 
 Rogue.UltimateAntiVirus
 C:\Program Files\VAV\vav.ooo
 C:\Program Files\VAV\vav0.dat
 C:\Program Files\VAV\vav1.dat
 C:\Program Files\VAV
 
 Trojan.Unclassified/GTS
 C:\SYSTEM VOLUME INFORMATION\_RESTORE{C1BA3EC0-6DD3-4C77-9BE2-2E0F8E04EC34}\RP1117\A0266193.DLL
 
 Trojan.Dropper/Gen
 C:\WINDOWS\QKEFTMXN.EXE
 
 Unclassified.Unknown Origin/System
 C:\WINDOWS\SYSTEM32\ATLEB.EXE
 C:\WINDOWS\SYSTEM32\CRSN32.EXE
 C:\WINDOWS\SYSTEM32\D3QW.EXE
 C:\WINDOWS\SYSTEM32\MSNQ32.EXE
 
 Adware.Vundo/Variant
 C:\WINDOWS\SYSTEM32\CKAPVAPA.DLL
 C:\WINDOWS\SYSTEM32\JLKKKXXB.DLL
 C:\WINDOWS\SYSTEM32\TTRGII.DLLOpen HijackThis and select Do a system scan only.
 
 Place a check mark next to the following entries: (if there)
 
 - R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50245
 - O2 - BHO: (no name) - {70BC9B99-5802-4523-8B5E-519F3AF61828} - C:\WINDOWS\system32\hgGvwvWp.dll (file missing)
 - O3 - Toolbar: (no name) - {6366459B-45A6-489C-9726-429617BB05C2} - (no file)
 - O4 - HKLM\..\Run: [iut75] c:\windows\system32\drivers\uzcx.exe
 - O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
 - O20 - AppInit_DLLs: avgrsstx.dll pclgna.dll
 - O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addpf.exe (file missing)
 
 Important: Close all windows except for HijackThis and then click Fix checked.
 
 Exit HijackThis.
 
 ----------
 
 Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.
 http://download.bleepingcomputer.com/sUBs/ComboFix.exe
 
 Note: the below instructions were CREATED specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system
 
 Delete these files/folders, as follows:
 
 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
 It must be Notepad, not Wordpad.
 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C
 
 Code: [Select]KillAll::
 
 File::
 C:\WINDOWS\system32\addpf.exe
 C:\WINDOWS\system32\hgGvwvWp.dll
 c:\windows\system32\drivers\uzcx.exe
 3. Go to the Notepad window and click Edit > Paste
 4. Then click File > Save
 5. Name the file CFScript.txt - Save the file to your Desktop
 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!
 
 
 
 ComboFix will begin to execute, just follow the prompts.
 After reboot (in case it asks to reboot), it will produce a log for you.
 Post that log (Combofix.txt) in your next reply.
 
 Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeOk, I ran HJT and fixed those files you listed.
 
 I saved ComboFix to my desktop and created the notepad file exactly as stated.
 When I drag the notepad file onto ComboFix and release, I get a Run / Cancel prompt window saying that the publisher could not be verfied. I click Run and the progress bar for ComboFix starts and completes but I get no log file or anything else when it is done.Go to Start > Run and then type combofix.txt and click OK
 
 If a log pops up then post it here.
 
 Let me know...Nothing comes up except a window saying Windows cannot find the file.
 I also ran a search for combofix.txt and no results came up.OK just run ComboFix then.
 
 Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.
 
 Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
 
 Double click combofix.exe & follow the prompts.
 When finished ComboFix will produce a log for you.
 Post the ComboFix log and a new HijackThis log in your next reply.
 
 Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.
 
 Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.
 
 Ok I disabled my antivrus programs and tried running combofix again and still I get nothing.
 
 I followed the instructionds here: http://www.bleepingcomputer.com/combofix/how-to-use-combofix
 and got as far as Windows Open File Security Warning. After I hit Run a progress bar starts on my screen and then nothing. Those blue prompt screens never show up.
 
 Am I missing something? I tried re downloading it from all 3 of the links provided in that thread as well but that didn't change anything.Try this.
 
 Go to Start > Run and copy/paste in the following:
 
 "%userprofile%\desktop\combofix.exe" /killall
 
 Press Enter and Combofix will begin to run.
 
 When finished, it will produce a log file located at C:\ComboFix.txt
 
 Post the contents of that log in your next reply.
 
 Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall.
 Same thing. Maybe there is something wrong with combofix.
 
 I clicked on the link, saved it to my desktop then proceeded to run it.OK forget ComboFix for now, we will use another tool instead.
 
 Download random's system information tool (RSIT) by random/random from and save it to your Desktop.
 
 
 info.txt logfile of random's system information tool 1.04 2008-10-09 22:39:35Double click on RSIT.exe to run.
Click Continue at the disclaimer screen.
Once it has finished, two logs will open.log.txt <will be maximized and info.txt <will be minimized
Please post the contents of both logs in the next reply.
 
 ======Uninstall list======
 
 -->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
 -->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D}
 -->msiexec /i {46548E80-0409-0000-7E8A-45000F855001}
 -->msiexec /I {B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}
 -->msiexec /I{7F4C8163-F259-49A0-A018-2857A90578BC}
 -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
 Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-1033-0000-0000-000000000001}
 Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39}
 Adobe Creative Suite 2-->C:\PROGRA~1\INSTAL~1\{0134A~1\setup.exe /relaunched/rootloc=d:\adobe creative suite 2.0/lang=0409
 Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
 Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
 Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001}
 Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
 Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
 Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001}
 Adobe SVG Viewer 3.0-->C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log
 Ahead InCD EasyWrite Reader-->C:\WINDOWS\unmrw.exe /UNINSTALL
 Apple Mobile Device Support-->MsiExec.exe /I{44734179-8A79-4DEE-BB08-73037F065543}
 Apple Software Update-->MsiExec.exe /I{02DFF6B1-1654-411C-8D7B-FD6052EF016F}
 AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
 BitComet 0.70-->C:\Program Files\BitComet\uninst.exe
 Bonjour-->MsiExec.exe /I{47BF1BD6-DCAC-468F-A0AD-E5DECC2211C3}
 CC_ccProxyExt-->MsiExec.exe /I{DA42FDCA-7C5A-43EF-9A05-CCE148ADF919}
 ccCommon-->MsiExec.exe /I{DC367608-64A7-4BF7-92F4-8BAA25BA02DB}
 CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
 ccPxyCore-->MsiExec.exe /I{FC08587A-4F01-4188-819F-F55880022917}
 CDDRV_Installer-->MsiExec.exe /I{0C826C5B-B131-423A-A229-C71B3CACCD6A}
 Conquer 2.0-->C:\Program Files\InstallShield Installation Information\{B6060381-5C28-4F86-A31A-B5ADA7A1BD8D}\setup.exe -runfromtemp -l0x0009 -removeonly
 DAO 3.5-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Your Company\DAO 3.5\Uninst.isu"
 DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
 DivX Pro Trial-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
 DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
 Google Earth-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9  -removeonly
 Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar3.dll"
 HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
 Hotfix for Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
 Hotfix for Windows XP (KB914440)-->"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
 Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
 Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
 iTunes-->MsiExec.exe /I{9F70BF98-003C-491D-81FC-FF9792206AF0}
 Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
 KhalInstallWrapper-->MsiExec.exe /I{3101CB58-3482-4D21-AF1A-7057FC935355}
 LiveReg (Symantec Corporation)-->C:\Program Files\Common Files\Symantec Shared\LiveReg\VCSetup.exe /REMOVE
 Logitech SetPoint-->C:\Program Files\InstallShield Installation Information\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}\setup.exe -runfromtemp -l0x0009 -removeonly
 Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
 Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
 Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
 Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
 Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
 Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
 Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
 Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
 Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
 MSRedist-->MsiExec.exe /I{B7C61755-DB48-4003-948F-3D34DB8EAF69}
 Nero 6-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
 Nero Media Player-->C:\WINDOWS\UNNMP.exe /UNINSTALL
 NeroVision Express 2-->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
 Norton AntiSpam-->MsiExec.exe /I{3B29A786-5803-4e9e-9B58-3014A5B4E519}
 Norton AntiSpam-->MsiExec.exe /I{5677563D-0CB1-485f-9E18-C5025306BB3F}
 Norton Internet Security 2005 (Symantec Corporation)-->C:\Program Files\Common Files\Symantec Shared\SymSetup\{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe /X
 Norton Internet Security-->MsiExec.exe /I{12E2B9E9-05B1-407d-B0FD-B5F350535125}
 Norton Internet Security-->MsiExec.exe /I{449F3A9E-9903-4a0d-A209-08030D45A935}
 Norton Internet Security-->MsiExec.exe /I{48185814-A224-447a-81DA-71BD20580E1B}
 Norton Internet Security-->MsiExec.exe /I{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}
 Norton Internet Security-->MsiExec.exe /I{A93C9E60-29B6-49da-BA21-F70AC6AADE20}
 Norton Internet Security-->MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
 Norton Internet Security-->MsiExec.exe /I{FC2C0536-583C-46c0-844A-62CECAE01F22}
 Norton WMI Update-->MsiExec.exe /X{E85FA9A1-C241-4698-893B-DD99509B8DB0}
 NTI DVD Player-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D31612BB-C6D7-4142-96AE-16DB062354CF}\Setup.exe" -l0x9
 NTI DVD-Maker Gold-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{C438B7C4-B4F8-49C5-A4DF-FF6F1F242778} /l1033 AnyText
 NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
 PartyPokerNet-->"C:\Program Files\PartyGaming.Net\PartyPokerNet\Uninstall.exe" "C:\Program Files\PartyGaming.Net\PartyPokerNet\install.log"
 Power Tab Editor 1.7-->MsiExec.exe /I{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}
 QuickTime-->MsiExec.exe /I{08CA9554-B5FE-4313-938F-D4A417B81175}
 RealPlayer-->C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
 Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
 Risk II (remove only)-->"C:\Program Files\Games\Risk II\Uninstall.exe"
 S3 S3Display-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Display'
 S3 S3Gamma2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Gamma2'
 S3 S3Info2-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Info2'
 S3 S3Overlay-->vtuninst.exe -reg 5 'HKLM\Software\S3\VT\S3Uninst\S3Overlay'
 Security Update for Windows Internet Explorer 7 (KB928090)-->"C:\WINDOWS\ie7updates\KB928090-IE7\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB929969)-->"C:\WINDOWS\ie7updates\KB929969\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB931768)-->"C:\WINDOWS\ie7updates\KB931768-IE7\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB933566)-->"C:\WINDOWS\ie7updates\KB933566-IE7\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB937143)-->"C:\WINDOWS\ie7updates\KB937143-IE7\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
 Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
 Security Update for Windows Media Player (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
 Security Update for Windows Media Player 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
 Security Update for Windows Media Player 9 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
 Security Update for Windows Media Player 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
 Security Update for Windows Media Player 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB883939)-->"C:\WINDOWS\$NtUninstallKB883939$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB896422)-->"C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB896688)-->"C:\WINDOWS\$NtUninstallKB896688$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB899588)-->"C:\WINDOWS\$NtUninstallKB899588$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB901190)-->"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB903235)-->"C:\WINDOWS\$NtUninstallKB903235$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB905915)-->"C:\WINDOWS\$NtUninstallKB905915$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB911567)-->"C:\WINDOWS\$NtUninstallKB911567$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB912812)-->"C:\WINDOWS\$NtUninstallKB912812$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB913446)-->"C:\WINDOWS\$NtUninstallKB913446$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB916281)-->"C:\WINDOWS\$NtUninstallKB916281$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB917159)-->"C:\WINDOWS\$NtUninstallKB917159$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB918899)-->"C:\WINDOWS\$NtUninstallKB918899$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB920214)-->"C:\WINDOWS\$NtUninstallKB920214$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB921883)-->"C:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB922760)-->"C:\WINDOWS\$NtUninstallKB922760$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB923694)-->"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB925486)-->"C:\WINDOWS\$NtUninstallKB925486$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
 Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
 SPBBC-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
 Starcraft-->C:\WINDOWS\SCunin.exe C:\WINDOWS\SCunin.dat
 Suite Specific-->MsiExec.exe /I{C49DAA9C-5BA8-459A-8244-E57B69DF0F04}
 SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
 Symantec Technical Support Web Controls-->MsiExec.exe /X{C4868E88-F5B5-4E45-9592-C7062BD97441}
 Update for Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
 Update for Windows XP (KB896727)-->"C:\WINDOWS\$NtUninstallKB896727$\spuninst\spuninst.exe"
 Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
 Update for Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
 Update for Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
 Update for Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
 Update for Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
 Update for Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
 Update for Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
 Update for Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
 Update for Windows XP (KB929338)-->"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
 Update for Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
 Update for Windows XP (KB931836)-->"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
 Update for Windows XP (KB932823-v3)-->"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
 Update for Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
 Update for Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
 Update for Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
 Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
 Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
 VIA Rhine-Family Fast Ethernet Adapter-->Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
 Winamp (remove only)-->"C:\Program Files\Winamp\UninstWA.exe"
 Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803$\spuninst\spuninst.exe"
 Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
 Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
 Windows Live Messenger-->MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
 Windows XP Hotfix - KB834707-->C:\WINDOWS\$NtUninstallKB834707$\spuninst\spuninst.exe
 Windows XP Hotfix - KB867282-->C:\WINDOWS\$NtUninstallKB867282$\spuninst\spuninst.exe
 Windows XP Hotfix - KB873333-->C:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
 Windows XP Hotfix - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
 Windows XP Hotfix - KB885250-->C:\WINDOWS\$NtUninstallKB885250$\spuninst\spuninst.exe
 Windows XP Hotfix - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
 Windows XP Hotfix - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
 Windows XP Hotfix - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
 Windows XP Hotfix - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
 Windows XP Hotfix - KB887742-->C:\WINDOWS\$NtUninstallKB887742$\spuninst\spuninst.exe
 Windows XP Hotfix - KB888113-->C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe
 Windows XP Hotfix - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
 Windows XP Hotfix - KB890047-->C:\WINDOWS\$NtUninstallKB890047$\spuninst\spuninst.exe
 Windows XP Hotfix - KB890175-->C:\WINDOWS\$NtUninstallKB890175$\spuninst\spuninst.exe
 Windows XP Hotfix - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
 Windows XP Hotfix - KB890923-->"C:\WINDOWS\$NtUninstallKB890923$\spuninst\spuninst.exe"
 Windows XP Hotfix - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
 Windows XP Hotfix - KB893066-->"C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe"
 Windows XP Hotfix - KB893086-->"C:\WINDOWS\$NtUninstallKB893086$\spuninst\spuninst.exe"
 WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
 World of Warcraft-->C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft (2)\Uninstall.exe
 Wrath of the Lich KING Beta-->C:\Program Files\Common Files\Blizzard Entertainment\Wrath of the Lich King\Uninstall.exe
 
 =====HijackThis Backups=====
 
 O4 - HKLM\..\Run: [iut75] c:\windows\system32\drivers\uzcx.exe
 O2 - BHO: (no name) - {70BC9B99-5802-4523-8B5E-519F3AF61828} - C:\WINDOWS\system32\hgGvwvWp.dll (file missing)
 O20 - AppInit_DLLs: avgrsstx.dll pclgna.dll
 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50245
 O3 - Toolbar: (no name) - {6366459B-45A6-489C-9726-429617BB05C2} - (no file)
 O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\addpf.exe (file missing)
 
 Hosts File Missing
 Gonna take about 4 posts or so to get the log file in so give me a couple mins.
 |