Ok heres the report from SDFix and a new hjt log..
SDFix: Version 1.88
Run by Owner on Sat 06/16/2007 at 07:14 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\DOCUME~1\Owner\Desktop\NEWFOL~3\SDFix
Safe Mode:
Checking Services:
Name:
core
ImagePath:
system32\drivers\core.sys
core - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Resetting AppInit_DLLs value
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\SYSTEM32\CBO3UB~1.HTM - Deleted
C:\618795~1 - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\1.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\5.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\6.dllb - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\7.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\1.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\2.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\5.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\6.dllb - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\7.dllb - Deleted
C:\Documents and Settings\Hailey\Local Settings\Temp\stdrun12.exe - Deleted
C:\Documents and Settings\Hailey\Local Settings\Temp\stdrun2.exe - Deleted
C:\Documents and Settings\Hailey\Local Settings\Temp\stdrun3.exe - Deleted
C:\Documents and Settings\Hailey\Local Settings\Temp\stdrun7.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun10.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun11.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun12.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun13.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun14.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun15.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun16.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun17.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun18.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun19.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun2.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun20.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun21.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun22.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun23.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun24.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun25.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun26.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun27.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun28.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun29.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun3.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun30.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun31.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun32.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun33.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun34.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun35.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun36.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun37.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun38.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun39.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun4.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun40.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun41.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun42.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun43.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun44.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun45.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun46.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun47.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun48.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun49.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun5.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun50.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun51.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun52.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun53.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun54.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun55.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun56.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun57.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun58.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun59.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun6.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun60.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun61.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun62.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun63.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun64.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun65.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun66.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun67.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun68.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun69.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun7.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun70.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun71.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun72.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun73.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun74.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun75.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun76.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun77.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun78.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun79.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun8.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun80.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun81.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun82.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun83.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun84.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun85.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun86.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun87.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun88.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun89.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun9.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun90.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun91.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun92.exe - Deleted
C:\Documents and Settings\LocalService\Local Settings\Temp\stdrun93.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun1.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun10.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun100.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun101.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun102.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun103.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun104.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun11.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun12.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun13.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun14.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun15.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun16.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun17.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun18.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun19.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun2.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun20.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun21.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun22.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun23.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun24.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun25.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun26.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun27.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun28.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun29.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun3.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun30.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun31.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun32.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun33.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun34.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun35.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun36.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun37.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun38.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun39.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun4.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun40.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun41.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun42.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun43.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun44.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun45.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun46.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun47.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun48.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun49.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun5.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun50.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun51.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun52.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun53.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun54.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun55.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun56.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun57.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun58.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun59.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun6.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun60.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun61.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun62.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun63.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun64.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun65.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun66.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun67.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun68.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun69.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun7.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun70.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun71.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun72.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun73.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun74.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun75.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun76.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun77.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun78.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun79.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun8.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun80.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun81.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun82.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun83.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun84.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun85.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun86.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun87.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun88.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun89.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun9.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun90.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun91.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun92.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun93.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun94.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun95.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun96.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun97.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun98.exe - Deleted
C:\Documents and Settings\NetworkService\Local Settings\Temp\stdrun99.exe - Deleted
C:\WINDOWS\abc5026def.exe - Deleted
C:\Documents and Settings\Owner\Application Data\Install.dat - Deleted
C:\U.exe - Deleted
C:\WINDOWS\avp.exe - Deleted
C:\WINDOWS\csrss.exe - Deleted
C:\WINDOWS\services.dll - Deleted
C:\WINDOWS\smanager.7.exe - Deleted
C:\WINDOWS\smgr.exe - Deleted
C:\WINDOWS\system32\advvpi32.dll - Deleted
C:\WINDOWS\system32\driver.exe - Deleted
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\drivers\core.sys - Deleted
C:\WINDOWS\system32\drivers\uzcx.exe - Deleted
C:\WINDOWS\system32\ipv6monq.dll - Deleted
C:\WINDOWS\system32\ipv6monr.dll - Deleted
C:\WINDOWS\system32\ipv6mons.dll - Deleted
C:\WINDOWS\system32\ldcore.dll - Deleted
C:\WINDOWS\system32\ldinfo.ldr - Deleted
C:\WINDOWS\system32\sysmon32.exe - Deleted
C:\WINDOWS\update.exe - Deleted
C:\WINDOWS\winhp32.exe - Deleted
C:\WINDOWS\Temp\win*.tmp - Deleted
Removing Temp Files...
ADS Check:
Checking C:\WINDOWS\
C:\WINDOWS
No streams found.
Checking C:\WINDOWS\system32
C:\WINDOWS\system32
No streams found.
Checking C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Checking C:\WINDOWS\system32\ntoskrnl.exe
C:\WINDOWS\system32\ntoskrnl.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\standard profile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yah oo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Progra m Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Ya hoo! FT Server"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Dynamix\\TRIBES\\Tribes.exe"="C:\\Dynamix\\TR IBES\\Tribes.exe:*:Enabled:Starsiege TRIBES"
"C:\\[eX]MIRC\\mirc.exe"="C:\\[eX]MIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\TMD-Recruit\\mirc.exe"="C:\\TMD-Recruit\\mirc.exe:*:Enabled:mIRC"
"C:\\Program Files\\StreamCast\\Morpheus\\MorphEXE.exe"="C:\\
Pr ogram Files\\StreamCast\\Morpheus\\MorphEXE.exe:*:Enable d:Morpheus"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Program Files\\Morpheus\\Morpheus.exe"="C:\\Program Files\\Morpheus\\Morpheus.exe:*:Enabled:M5Shell"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\ \Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Ena bled:Yahoo! Messenger"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1159663210\\ee\\aolsoftware.exe"="C:\\ Program Files\\Common Files\\AOL\\1159663210\\ee\\aolsoftware.exe:*:Enab led:AOL Services"
"C:\\Program Files\\Common Files\\AOL\\1159663210\\ee\\aim6.exe"="C:\\Program Files\\Common Files\\AOL\\1159663210\\ee\\aim6.exe:*:Enabled:AIM "
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"="C:\\Program Files\\FlashFXP\\FlashFXP.exe:*:Enabled:FlashFXP v3"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\WINDOWS\\explorer.exe"="C:\\WINDOWS\\explorer .exe:*:Enabled:Internet Explorer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\servic es\sharedaccess\parameters\firewallpolicy\domainpr ofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\syste m32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\Program Files\\FlashFXP\\FlashFXP.exe"="C:\\Program Files\\FlashFXP\\FlashFXP.exe:*:Enabled:FlashFXP v3"
Remaining Files:
---------------
Backups Folder: - C:\DOCUME~1\Owner\Desktop\NEWFOL~3\SDFix\backups\b ackups.zip
Listing Files with Hidden Attributes:
C:\WINDOWS\SYSTEM32\jkhhe.dll
C:\WINDOWS\SYSTEM32\ssqpp.dll
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch2\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch3\lock.tmp
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch4\lock.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@R1A08.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@R1A0A.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@R1A0C.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@R1A0E.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@R1A10.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@R1A12.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@R1A14.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@R1A17.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@R1A19.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@S1A09.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@S1A0B.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@S1A0D.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@S1A0F.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@S1A11.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@S1A13.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@S1A15.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@S1A18.tmp
C:\Documents and Settings\Hailey\Local Settings\Temp\Z@S1A1A.tmp
C:\WINDOWS\SYSTEM32\csnpimev.tmp
C:\WINDOWS\SYSTEM32\ppqss.tmp
C:\WINDOWS\SYSTEM32\ututv.tmp
HJT Log..
Logfile of HijackThis v1.99.1
Scan saved at 10:48:08 PM, on 6/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Hailey\Desktop\foolyou.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://red.clientapps.yahoo.com/cust.../www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/...ch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://as.starware.com/dp/search?x=w...fT7JuLjEDRZ58v
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/.../www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1600BDFA-8C02-4F06-A20C-3B9AEA26BE22} - C:\WINDOWS\system32\ugluonyv.dll
O2 - BHO: (no name) - {2252CC30-2908-4697-B044-79865A700FBE} - C:\WINDOWS\system32\ssqpp.dll
O2 - BHO: bho3 Class - {58FB2CBB-C874-45FC-A1C9-B62CC9E3BED9} - C:\Documents and Settings\Hailey\52383811.dll
O2 - BHO: (no name) - {5ADF3862-9E2E-4ad3-86F7-4510E6550CD0} - C:\WINDOWS\system32\pgmvamec.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll (file missing)
O2 - BHO: (no name) - {A0697931-CCD5-4EA3-8CCD-743608DF7F20} - C:\WINDOWS\system32\rqrooon.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (file missing)
O2 - BHO: Freeze.com Helper - {D6A99B1F-FAB9-4FA5-9C9D-D0D0CF846C05} - C:\Program Files\YourScreen\Freeze.DesktopManager.BrowserHelp er.dll (file missing)
O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\jkumaarb.dll
O2 - BHO: (no name) - {E4749367-DEEC-4BAC-9D1A-BA8703BDE1B0} - C:\WINDOWS\system32\vtutu.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll (file missing)
O3 - Toolbar: (no name) - {D49E9D35-254C-4c6a-9D17-95018D228FF5} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [GPLv3] rundll32.exe "C:\WINDOWS\system32\hbvcnooi.dll",realset
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [csrss] C:\WINDOWS\csrss.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplanet.com/fpdlmgr/ca...C_1_0_0_44.cab
O16 - DPF: {E856B973-45FD-4559-8F82-EAB539144667} -
O17 - HKLM\System\CCS\Services\Tcpip\..\{7B34E699-3C62-4074-9350-AC324996B627}: NameServer = 68.12.16.25,68.12.16.30
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: c:\windows\system32\ldcore.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: rqrooon - C:\WINDOWS\SYSTEM32\rqrooon.dll
O20 - Winlogon Notify: ssqpp - C:\WINDOWS\system32\ssqpp.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wineil32 - C:\WINDOWS\SYSTEM32\wineil32.dll
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: Network DDE DSDM NetDDEdsdmxmlprov (NetDDEdsdmxmlprov) - Unknown owner - c:\squix.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe