Help Me Please!
New member
Thank you so much for helping me out with my parent's computer. You have the thanks of our family. :rockon:
Initially when I started the computer and logged onto my father's account, there was a Norton PC Checkup. I did not know who installed it and when I asked around no one had touched the computer but me. So i basically just clicked uninstall and for now it seems to be gone.
Here is the log that you have asked for, and may I say again. THANK YOU SO MUCH!
ComboFix 10-01-15.05 - Owner 6/2010 Sat 10:22:34.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.949.82.1033.18.767.409 [GMT -6:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
FILE ::
"C:\Program.exe"
"c:\windows\System32\drivers\etc\hosts"
"c:\windows\system32\drivers\logiflt.iad"
"c:\windows\system32\drivers\lvuvc.hs"
"c:\windows\system32\filokinu.dll"
"c:\windows\system32\fomowipi.dll"
"c:\windows\system32\vuyugije.dll"
"c:\windows\Tasks\PCConfidential.job"
"c:\windows\tasks\wwyzfblp.job"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\b469fcc
c:\documents and settings\All Users\Application Data\b469fcc\BackUp\IMVU.lnk
c:\documents and settings\All Users\Application Data\b469fcc\mozcrt19.dll
c:\documents and settings\All Users\Application Data\b469fcc\sqlite3.dll
c:\documents and settings\All Users\Application Data\b469fcc\WSD_APDM.ico
c:\documents and settings\All Users\Application Data\b469fcc\WSDDSys\vd952342.bd
c:\documents and settings\All Users\Application Data\ESTsoft
c:\documents and settings\All Users\Application Data\ESTsoft\ALCM\ALCMUpdate.exe
c:\documents and settings\All Users\Application Data\ESTsoft\ALToolbar\Common.ini
c:\documents and settings\All Users\Application Data\ESTsoft\ALYac\LicenseInfo.ini
c:\documents and settings\All Users\Application Data\Lavasoft
c:\documents and settings\All Users\Application Data\Lavasoft\License\adaware.da2
c:\documents and settings\All Users\Application Data\Lavasoft\MiniMessage\2
c:\documents and settings\All Users\Application Data\Verizon
c:\documents and settings\All Users\Application Data\Verizon\VSP\SharedProperties.xml
c:\documents and settings\All Users\Application Data\zitakihu
c:\documents and settings\Owner\Application Data\EstSoft
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\0302_pv_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\080609_DefMM02_106.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\081009_seeMaker_default.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090130_seeMakerEnd_default.GIF
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090130_seeMakerIng_default.GIF
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090305_all_cabal.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090306_all_seeWhite.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090313_ftp_aig.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090313_pass_aig1.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090313_see_aig.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090313_zip_aig.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_all_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_ftp_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_pass_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_see_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_zip_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090323_ftp_kimyoung.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090323_pass_kimyoung.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090323_see_kimyoung.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090323_zip_kimyoung.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090324_alpass_hanafos.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090324_alzip_hanafos.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\20090323_all_biz.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\505_90.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\alyacpc_ch_080327.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\log.dat
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091015_pop_toolbarOn1.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091015_pop_toolbarOn2.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091214_pop_hk.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091216_pop_dongyang2.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091218_pop_hcardM.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091221_pop_cabal.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091230_pop_gmarket.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\100104_pop_dongyang2.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\100108_pop_bizhard.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\100108_pop_hs.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\100111_pop_dongyang2.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\pslog.dat
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_alyac23057_ocu.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_alzip23057_ocu.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_yac23057_scau2.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_zip23057_ktshow.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_zip23057_scau2.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_zip23057_sejong.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_zip23057ing_ktshow.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0105_yac23057_scau3.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0105_zip23057_scau3.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0106_zip23057_sejong2.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091015_all23057_toolbarOn4.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091102_all23057_alzip10th.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091217_yac23057_sec002.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091221_yac23057_cabal.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091221_zip23057_cabal.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091230_yac23057_hs.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091230_zip23057_hs.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100107_yac23057_hs_pixed.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100107_zip23057_autoinside.jpg
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100107_zip23057_hs_pixed.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100107_zip23057ing_autoinside.jpg
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100108_all23057_bizhard.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\20100112_yac23057_scau.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\bg_type21.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\CommonInfo1016_93.xml
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_01.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_012.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_02.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_022.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_03.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_032.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_04.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_042.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_05.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_052.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_06.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_062.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_07.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_072.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\KIMYOUNG_091228_ing230_57.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\KIMYOUNG_091228_m230_57.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALCM\cmulog.dat
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20081230.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20081231.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090102.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090103.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090104.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090105.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090109.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090110.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090112.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090113.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090116.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090122.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090123.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090124.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090130.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090203.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090206.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090207.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090215.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090220.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090224.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090227.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090228.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090304.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090305.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090306.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090313.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090315.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090316.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090318.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090320.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090321.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090322.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090323.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090324.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090325.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090326.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090327.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090328.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090329.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090403.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090404.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090405.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090408.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090410.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090411.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090412.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090413.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090414.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090415.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090416.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090417.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090419.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090420.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090421.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090425.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090426.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090427.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090428.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090429.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090502.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090503.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090505.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090506.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090507.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090510.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090511.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090512.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090513.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090515.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090516.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090517.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090523.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090524.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090525.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090527.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090528.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090530.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090531.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090602.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090603.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090605.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090606.log
c:\documents and settings\Owner\Application Data\EstSoft\ALX\alxupdate.exe
c:\program files\Ad-Aware
c:\program files\Ad-Aware\AAWAdmin.exe
c:\program files\Ad-Aware\aawapi.dll
c:\program files\Ad-Aware\AAWService.exe
c:\program files\Ad-Aware\AAWTray.exe
c:\program files\Ad-Aware\AAWWSC.exe
c:\program files\Ad-Aware\Ad-Aware.exe
c:\program files\Ad-Aware\Ad-Aware_manual_DE.chm
c:\program files\Ad-Aware\Ad-Aware_manual_EN.chm
c:\program files\Ad-Aware\Ad-Aware_manual_FR.chm
c:\program files\Ad-Aware\Ad-Aware_manual_JA.chm
c:\program files\Ad-Aware\Ad-AwareAdmin.exe
c:\program files\Ad-Aware\Ad-AwareAdmin.exe.14086.aawbak
c:\program files\Ad-Aware\Ad-AwareCommand.exe
c:\program files\Ad-Aware\aebb.dll
c:\program files\Ad-Aware\aecore.dll
c:\program files\Ad-Aware\aeemu.dll
c:\program files\Ad-Aware\aegen.dll
c:\program files\Ad-Aware\aehelp.dll
c:\program files\Ad-Aware\aeheur.dll
c:\program files\Ad-Aware\aeoffice.dll
c:\program files\Ad-Aware\aepack.dll
c:\program files\Ad-Aware\aerdl.dll
c:\program files\Ad-Aware\aescn.dll
c:\program files\Ad-Aware\aescript.dll
c:\program files\Ad-Aware\aeset.dat
c:\program files\Ad-Aware\aevdf.dll
c:\program files\Ad-Aware\AutoLaunch.exe
c:\program files\Ad-Aware\avpal.dll
c:\program files\Ad-Aware\CEAPI.dll
c:\program files\Ad-Aware\dbghelp.dll
c:\program files\Ad-Aware\Download Guard for Internet Explorer.exe
c:\program files\Ad-Aware\Drivers\32\AAWDriverTool.exe
c:\program files\Ad-Aware\Drivers\32\DIFxAPI.dll
c:\program files\Ad-Aware\Drivers\32\lbd.cat
c:\program files\Ad-Aware\Drivers\32\lbd.inf
c:\program files\Ad-Aware\Drivers\32\lbd.sys
c:\program files\Ad-Aware\Drivers\64\AAWDriverTool.exe
c:\program files\Ad-Aware\Drivers\64\DIFxAPI.dll
c:\program files\Ad-Aware\Drivers\64\lbd.cat
c:\program files\Ad-Aware\Drivers\64\lbd.inf
c:\program files\Ad-Aware\Drivers\64\lbd.sys
c:\program files\Ad-Aware\Drivers\AAWDriverTool.exe
c:\program files\Ad-Aware\Drivers\DIFxAPI.dll
c:\program files\Ad-Aware\Drivers\lbd.cat
c:\program files\Ad-Aware\Drivers\lbd.inf
c:\program files\Ad-Aware\Drivers\lbd.sys
c:\program files\Ad-Aware\Drivers\sbapifs.cat
c:\program files\Ad-Aware\Drivers\sbapifsl.cat
c:\program files\Ad-Aware\Drivers\sbapx64.cat
c:\program files\Ad-Aware\Extras\Threat Work\ThreatWork.exe
c:\program files\Ad-Aware\GenoType.ows
c:\program files\Ad-Aware\hbedv.key
c:\program files\Ad-Aware\Languages\resource_de-DE.xml
c:\program files\Ad-Aware\Languages\resource_en-US.xml
c:\program files\Ad-Aware\Languages\resource_es-ES.xml
c:\program files\Ad-Aware\Languages\resource_fr-FR.xml
c:\program files\Ad-Aware\Languages\resource_it-IT.xml
c:\program files\Ad-Aware\Languages\resource_ja-JP.xml
c:\program files\Ad-Aware\Languages\resource_nl-NL.xml
c:\program files\Ad-Aware\Languages\resource_pt-PT.xml
c:\program files\Ad-Aware\Languages\resource_sv-SE.xml
c:\program files\Ad-Aware\Languages\resource_zh-CN.xml
c:\program files\Ad-Aware\Languages\resource_zh-TW.xml
c:\program files\Ad-Aware\Languages\ResourceAdmin.xml
c:\program files\Ad-Aware\lavalicense.dll
c:\program files\Ad-Aware\lavamessage.dll
c:\program files\Ad-Aware\Lavasoft Homepage.url
c:\program files\Ad-Aware\libapr-1.dll
c:\program files\Ad-Aware\libaprutil-1.dll
c:\program files\Ad-Aware\libavll.dll
c:\program files\Ad-Aware\lsdelete.exe
c:\program files\Ad-Aware\msvcp71.dll
c:\program files\Ad-Aware\msvcr71.dll
c:\program files\Ad-Aware\Neutralize.dll
c:\program files\Ad-Aware\pcre.dll
c:\program files\Ad-Aware\PrivacyClean.dll
c:\program files\Ad-Aware\Rebrand.dat
c:\program files\Ad-Aware\Resources.dll
c:\program files\Ad-Aware\Resources.dll.11281.aawbak
c:\program files\Ad-Aware\Resources\aa11.efp
c:\program files\Ad-Aware\Resources\aa14.efp
c:\program files\Ad-Aware\Resources\Carbon.eGL
c:\program files\Ad-Aware\Resources\Default.eGL
c:\program files\Ad-Aware\Resources\Gold.eGL
c:\program files\Ad-Aware\Resources\Orange.eGL
c:\program files\Ad-Aware\Resources\Sedona.eGL
c:\program files\Ad-Aware\Resources\wa11.efp
c:\program files\Ad-Aware\Resources\wa11b.efp
c:\program files\Ad-Aware\Resources\wa12.efp
c:\program files\Ad-Aware\Resources\wa12b.efp
c:\program files\Ad-Aware\Resources\wa14b.efp
c:\program files\Ad-Aware\Resources\wa14i.efp
c:\program files\Ad-Aware\Resources\wt12.efp
c:\program files\Ad-Aware\Resources\wt12b.efp
c:\program files\Ad-Aware\Resources\wt16b.efp
c:\program files\Ad-Aware\Resources\wt16bi.efp
c:\program files\Ad-Aware\Resources\wt20b.efp
c:\program files\Ad-Aware\Resources\wt20bi.efp
c:\program files\Ad-Aware\RPAPI.dll
c:\program files\Ad-Aware\savapi3.dll
c:\program files\Ad-Aware\savapi3client.dll
c:\program files\Ad-Aware\Savapibridge.dll
c:\program files\Ad-Aware\ShellExt.dll
c:\program files\Ad-Aware\threatwork.exe
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\AutoStart Manager.exe
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Settings.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gbottompic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gbottompicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gtoppic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gtoppicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\skin.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\Thumbs.db
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\SO.dll
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\de.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\en.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\english.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\es.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\fr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\it.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\ja.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\nl.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\pr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\russian.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\zh-cmn-Hans.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\zh-cmn-Hant.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\AutoStart Manager.exe
c:\program files\Ad-Aware\ToolBox\AutoStart\de.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\en.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\english.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\es.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\fr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\gbottompic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\gbottompicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\gbottompic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\gbottompicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\gtoppic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\gtoppicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\skin.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\Thumbs.db
c:\program files\Ad-Aware\ToolBox\AutoStart\gtoppic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\gtoppicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\it.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\ja.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\nl.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\pr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\russian.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Settings.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\skin.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\gbottompic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\gbottompicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\gtoppic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\gtoppicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\skin.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\Thumbs.db
c:\program files\Ad-Aware\ToolBox\AutoStart\SO.dll
c:\program files\Ad-Aware\ToolBox\AutoStart\Thumbs.db
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\de.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\en.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\english.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\es.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\fr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\it.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\ja.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\nl.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\pr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\russian.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\zh-cmn-Hans.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\zh-cmn-Hant.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\zh-cmn-Hans.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\zh-cmn-Hant.xml
c:\program files\Ad-Aware\ToolBox\LT\Extras.LGFF
c:\program files\Ad-Aware\ToolBox\LT\HostFileEditor.exe
c:\program files\Ad-Aware\ToolBox\LT\Lang\DE.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\EN.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\ES.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\FL.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\FR.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\IT.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\NL.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\PT.lslang
c:\program files\Ad-Aware\ToolBox\LT\ProcessWatch.dll
c:\program files\Ad-Aware\ToolBox\LT\ProcessWatch.exe
c:\program files\Ad-Aware\unacev2.dll
c:\program files\Ad-Aware\unrar.dll
c:\program files\Ad-Aware\UpdateManager.dll
c:\program files\Ad-Aware\UpdateManager.dll.18090.aawbak
c:\program files\Ad-Aware\WSCUpdate.dll
c:\program files\ESTsoft
c:\program files\ESTsoft\Common\ALBNCollector.exe
c:\program files\ESTsoft\Common\ALSTSCollector.exe
c:\program files\Winferno
c:\program files\Winferno\PC Confidential\DeleteIndex.exe
c:\program files\Winferno\PC Confidential\Graphics\HandPoint.ico
c:\program files\Winferno\PC Confidential\PCCBHO.dll
c:\program files\Winferno\PC Confidential\PCCL.DLL
c:\program files\Winferno\PC Confidential\PCConfidential.chm
c:\program files\Winferno\PC Confidential\PCConfidential.exe
c:\program files\Winferno\PC Confidential\PCCST.exe
c:\program files\Winferno\PC Confidential\unins000.dat
c:\program files\Winferno\PC Confidential\unins000.exe
c:\program files\Winferno\PC Confidential\WinCMR.dll
c:\program files\Winferno\PC Confidential\WinfernoSoftware.url
c:\windows\System32\drivers\etc\hosts
c:\windows\system32\drivers\logiflt.iad
c:\windows\system32\drivers\lvuvc.hs
c:\windows\Tasks\PCConfidential.job
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
--------------- FCopy ---------------
c:\windows\system32\dllcache\atapi.sys --> c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_LVUVC
((((((((((((((((((((((((( Files Created from 2009-12-16 to 2010-01-16 )))))))))))))))))))))))))))))))
.
2010-01-16 02:39 . 2010-01-16 02:39 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-14 01:07 . 2010-01-14 01:08 -------- d-----w- c:\program files\trend micro
2010-01-14 01:07 . 2010-01-14 01:08 -------- d-----w- C:\rsit
2010-01-13 03:25 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-10 00:39 . 2010-01-10 01:13 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-08 19:04 . 2010-01-08 19:04 -------- d-----w- c:\program files\TrendMicro
2010-01-08 19:02 . 2010-01-15 14:42 -------- d-----w- c:\program files\ERUNT
2010-01-05 02:26 . 2010-01-05 02:26 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-05 01:34 . 2010-01-05 01:34 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-01-05 01:30 . 2010-01-05 01:30 -------- d-sh--w- c:\documents and settings\All Users\Application Data\WSPTNVD_APDM
2009-12-19 01:02 . 2009-12-19 01:02 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Mozilla
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-16 16:35 . 2009-09-04 04:58 -------- d-----w- c:\documents and settings\Owner\Application Data\Skype
2010-01-13 22:29 . 2009-03-23 03:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-08 19:04 . 2010-01-08 19:04 388096 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-08 04:19 . 2008-12-25 22:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-08 04:19 . 2005-05-14 14:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-07 22:07 . 2009-03-23 03:53 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2009-03-23 03:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 19:19 . 2010-01-05 19:19 5061519 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-05 02:24 . 2009-09-04 05:05 -------- d-----w- c:\documents and settings\Owner\Application Data\skypePM
2009-12-18 23:38 . 2009-04-27 20:23 -------- d-----w- c:\program files\VideoLAN
2009-12-18 23:37 . 2007-08-27 03:07 -------- d-----w- c:\program files\Google
2009-12-13 02:26 . 2009-12-13 02:26 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-12-13 01:25 . 2009-12-13 01:23 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2009-12-13 01:23 . 2009-12-13 01:23 -------- d-----w- c:\program files\Pando Networks
2009-12-13 00:56 . 2009-11-14 00:20 -------- d-----w- c:\program files\Microsoft Silverlight
2009-12-02 15:13 . 2009-12-02 15:13 -------- d-----w- c:\program files\Common Files\Logitech
2009-11-29 02:45 . 2008-03-08 22:24 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-21 15:51 . 2002-09-03 16:26 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-04 18:46 . 2009-11-04 18:46 1421449 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_Monopoly\IAF.dll
2009-10-29 07:45 . 2005-02-18 21:19 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ------w- c:\windows\system32\drivers\http.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-04 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-12-11 267048]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCTAVSvc]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^TrueAssistant.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\TrueAssistant.lnk
backup=c:\windows\pss\TrueAssistant.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/17/2007 10:05 AM 24652]
S2 GdFsHook;McAfee Privacy Service File Guardian;\??\c:\windows\System32\Drivers\GDFSHK.SYS --> c:\windows\System32\Drivers\GDFSHK.SYS [?]
S2 GdTdi;McAfee Privacy Service Transport Filter;\??\c:\windows\System32\Drivers\GDTDI.SYS --> c:\windows\System32\Drivers\GDTDI.SYS [?]
S3 cpuz128;cpuz128;\??\c:\docume~1\Owner\LOCALS~1\Temp\cpuz_x32.sys --> c:\docume~1\Owner\LOCALS~1\Temp\cpuz_x32.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-12-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:57]
2009-01-05 c:\windows\Tasks\NSSstub.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2008-12-25 20:59]
2010-01-16 c:\windows\Tasks\User_Feed_Synchronization-{297CA128-8625-40F0-866D-756308C4F29F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
2010-01-16 c:\windows\Tasks\User_Feed_Synchronization-{B71AB70B-D1B1-4C62-A30B-C37ED636C629}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} - hxxp://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} - hxxp://player.bugs.co.kr/install/mv/XTools.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\em47iz8j.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
.
- - - - ORPHANS REMOVED - - - -
AddRemove-PCConfidential_is1 - c:\program files\Winferno\PC Confidential\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-16 10:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(6628)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\Ink\PENUSA.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\conime.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2010-01-16 10:41:49 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-16 16:41
ComboFix2.txt 2010-01-15 17:41
Pre-Run: 18,141,184,000 bytes free
Post-Run: 18,037,776,384 bytes free
- - End Of File - - 682E08C44FFACA750E4FAF36F991E20A
Initially when I started the computer and logged onto my father's account, there was a Norton PC Checkup. I did not know who installed it and when I asked around no one had touched the computer but me. So i basically just clicked uninstall and for now it seems to be gone.
Here is the log that you have asked for, and may I say again. THANK YOU SO MUCH!
ComboFix 10-01-15.05 - Owner 6/2010 Sat 10:22:34.5.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.949.82.1033.18.767.409 [GMT -6:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
FILE ::
"C:\Program.exe"
"c:\windows\System32\drivers\etc\hosts"
"c:\windows\system32\drivers\logiflt.iad"
"c:\windows\system32\drivers\lvuvc.hs"
"c:\windows\system32\filokinu.dll"
"c:\windows\system32\fomowipi.dll"
"c:\windows\system32\vuyugije.dll"
"c:\windows\Tasks\PCConfidential.job"
"c:\windows\tasks\wwyzfblp.job"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\b469fcc
c:\documents and settings\All Users\Application Data\b469fcc\BackUp\IMVU.lnk
c:\documents and settings\All Users\Application Data\b469fcc\mozcrt19.dll
c:\documents and settings\All Users\Application Data\b469fcc\sqlite3.dll
c:\documents and settings\All Users\Application Data\b469fcc\WSD_APDM.ico
c:\documents and settings\All Users\Application Data\b469fcc\WSDDSys\vd952342.bd
c:\documents and settings\All Users\Application Data\ESTsoft
c:\documents and settings\All Users\Application Data\ESTsoft\ALCM\ALCMUpdate.exe
c:\documents and settings\All Users\Application Data\ESTsoft\ALToolbar\Common.ini
c:\documents and settings\All Users\Application Data\ESTsoft\ALYac\LicenseInfo.ini
c:\documents and settings\All Users\Application Data\Lavasoft
c:\documents and settings\All Users\Application Data\Lavasoft\License\adaware.da2
c:\documents and settings\All Users\Application Data\Lavasoft\MiniMessage\2
c:\documents and settings\All Users\Application Data\Verizon
c:\documents and settings\All Users\Application Data\Verizon\VSP\SharedProperties.xml
c:\documents and settings\All Users\Application Data\zitakihu
c:\documents and settings\Owner\Application Data\EstSoft
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\0302_pv_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\080609_DefMM02_106.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\081009_seeMaker_default.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090130_seeMakerEnd_default.GIF
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090130_seeMakerIng_default.GIF
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090305_all_cabal.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090306_all_seeWhite.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090313_ftp_aig.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090313_pass_aig1.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090313_see_aig.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090313_zip_aig.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_all_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_ftp_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_pass_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_see_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090316_zip_pudding.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090323_ftp_kimyoung.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090323_pass_kimyoung.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090323_see_kimyoung.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090323_zip_kimyoung.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090324_alpass_hanafos.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\090324_alzip_hanafos.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\20090323_all_biz.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\505_90.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\alyacpc_ch_080327.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\log.dat
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091015_pop_toolbarOn1.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091015_pop_toolbarOn2.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091214_pop_hk.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091216_pop_dongyang2.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091218_pop_hcardM.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091221_pop_cabal.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\091230_pop_gmarket.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\100104_pop_dongyang2.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\100108_pop_bizhard.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\100108_pop_hs.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\100111_pop_dongyang2.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\PopSkin\pslog.dat
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_alyac23057_ocu.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_alzip23057_ocu.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_yac23057_scau2.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_zip23057_ktshow.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_zip23057_scau2.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_zip23057_sejong.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0104_zip23057ing_ktshow.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0105_yac23057_scau3.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0105_zip23057_scau3.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\0106_zip23057_sejong2.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091015_all23057_toolbarOn4.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091102_all23057_alzip10th.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091217_yac23057_sec002.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091221_yac23057_cabal.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091221_zip23057_cabal.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091230_yac23057_hs.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\091230_zip23057_hs.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100107_yac23057_hs_pixed.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100107_zip23057_autoinside.jpg
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100107_zip23057_hs_pixed.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100107_zip23057ing_autoinside.jpg
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\100108_all23057_bizhard.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\20100112_yac23057_scau.gif
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\bg_type21.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\CommonInfo1016_93.xml
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_01.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_012.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_02.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_022.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_03.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_032.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_04.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_042.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_05.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_052.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_06.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_062.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_07.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\img_072.bmp
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\KIMYOUNG_091228_ing230_57.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALBanner\ver6\KIMYOUNG_091228_m230_57.swf
c:\documents and settings\Owner\Application Data\EstSoft\ALCM\cmulog.dat
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20081230.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20081231.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090102.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090103.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090104.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090105.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090109.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090110.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090112.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090113.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090116.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090122.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090123.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090124.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090130.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090203.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090206.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090207.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090215.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090220.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090224.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090227.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090228.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090304.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090305.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090306.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090313.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090315.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090316.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090318.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090320.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090321.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090322.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090323.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090324.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090325.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090326.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090327.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090328.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090329.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090403.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090404.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090405.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090408.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090410.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090411.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090412.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090413.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090414.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090415.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090416.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090417.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090419.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090420.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090421.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090425.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090426.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090427.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090428.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090429.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090502.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090503.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090505.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090506.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090507.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090510.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090511.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090512.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090513.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090515.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090516.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090517.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090523.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090524.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090525.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090527.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090528.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090530.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090531.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090602.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090603.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090605.log
c:\documents and settings\Owner\Application Data\EstSoft\ALToolBar\Log\20090606.log
c:\documents and settings\Owner\Application Data\EstSoft\ALX\alxupdate.exe
c:\program files\Ad-Aware
c:\program files\Ad-Aware\AAWAdmin.exe
c:\program files\Ad-Aware\aawapi.dll
c:\program files\Ad-Aware\AAWService.exe
c:\program files\Ad-Aware\AAWTray.exe
c:\program files\Ad-Aware\AAWWSC.exe
c:\program files\Ad-Aware\Ad-Aware.exe
c:\program files\Ad-Aware\Ad-Aware_manual_DE.chm
c:\program files\Ad-Aware\Ad-Aware_manual_EN.chm
c:\program files\Ad-Aware\Ad-Aware_manual_FR.chm
c:\program files\Ad-Aware\Ad-Aware_manual_JA.chm
c:\program files\Ad-Aware\Ad-AwareAdmin.exe
c:\program files\Ad-Aware\Ad-AwareAdmin.exe.14086.aawbak
c:\program files\Ad-Aware\Ad-AwareCommand.exe
c:\program files\Ad-Aware\aebb.dll
c:\program files\Ad-Aware\aecore.dll
c:\program files\Ad-Aware\aeemu.dll
c:\program files\Ad-Aware\aegen.dll
c:\program files\Ad-Aware\aehelp.dll
c:\program files\Ad-Aware\aeheur.dll
c:\program files\Ad-Aware\aeoffice.dll
c:\program files\Ad-Aware\aepack.dll
c:\program files\Ad-Aware\aerdl.dll
c:\program files\Ad-Aware\aescn.dll
c:\program files\Ad-Aware\aescript.dll
c:\program files\Ad-Aware\aeset.dat
c:\program files\Ad-Aware\aevdf.dll
c:\program files\Ad-Aware\AutoLaunch.exe
c:\program files\Ad-Aware\avpal.dll
c:\program files\Ad-Aware\CEAPI.dll
c:\program files\Ad-Aware\dbghelp.dll
c:\program files\Ad-Aware\Download Guard for Internet Explorer.exe
c:\program files\Ad-Aware\Drivers\32\AAWDriverTool.exe
c:\program files\Ad-Aware\Drivers\32\DIFxAPI.dll
c:\program files\Ad-Aware\Drivers\32\lbd.cat
c:\program files\Ad-Aware\Drivers\32\lbd.inf
c:\program files\Ad-Aware\Drivers\32\lbd.sys
c:\program files\Ad-Aware\Drivers\64\AAWDriverTool.exe
c:\program files\Ad-Aware\Drivers\64\DIFxAPI.dll
c:\program files\Ad-Aware\Drivers\64\lbd.cat
c:\program files\Ad-Aware\Drivers\64\lbd.inf
c:\program files\Ad-Aware\Drivers\64\lbd.sys
c:\program files\Ad-Aware\Drivers\AAWDriverTool.exe
c:\program files\Ad-Aware\Drivers\DIFxAPI.dll
c:\program files\Ad-Aware\Drivers\lbd.cat
c:\program files\Ad-Aware\Drivers\lbd.inf
c:\program files\Ad-Aware\Drivers\lbd.sys
c:\program files\Ad-Aware\Drivers\sbapifs.cat
c:\program files\Ad-Aware\Drivers\sbapifsl.cat
c:\program files\Ad-Aware\Drivers\sbapx64.cat
c:\program files\Ad-Aware\Extras\Threat Work\ThreatWork.exe
c:\program files\Ad-Aware\GenoType.ows
c:\program files\Ad-Aware\hbedv.key
c:\program files\Ad-Aware\Languages\resource_de-DE.xml
c:\program files\Ad-Aware\Languages\resource_en-US.xml
c:\program files\Ad-Aware\Languages\resource_es-ES.xml
c:\program files\Ad-Aware\Languages\resource_fr-FR.xml
c:\program files\Ad-Aware\Languages\resource_it-IT.xml
c:\program files\Ad-Aware\Languages\resource_ja-JP.xml
c:\program files\Ad-Aware\Languages\resource_nl-NL.xml
c:\program files\Ad-Aware\Languages\resource_pt-PT.xml
c:\program files\Ad-Aware\Languages\resource_sv-SE.xml
c:\program files\Ad-Aware\Languages\resource_zh-CN.xml
c:\program files\Ad-Aware\Languages\resource_zh-TW.xml
c:\program files\Ad-Aware\Languages\ResourceAdmin.xml
c:\program files\Ad-Aware\lavalicense.dll
c:\program files\Ad-Aware\lavamessage.dll
c:\program files\Ad-Aware\Lavasoft Homepage.url
c:\program files\Ad-Aware\libapr-1.dll
c:\program files\Ad-Aware\libaprutil-1.dll
c:\program files\Ad-Aware\libavll.dll
c:\program files\Ad-Aware\lsdelete.exe
c:\program files\Ad-Aware\msvcp71.dll
c:\program files\Ad-Aware\msvcr71.dll
c:\program files\Ad-Aware\Neutralize.dll
c:\program files\Ad-Aware\pcre.dll
c:\program files\Ad-Aware\PrivacyClean.dll
c:\program files\Ad-Aware\Rebrand.dat
c:\program files\Ad-Aware\Resources.dll
c:\program files\Ad-Aware\Resources.dll.11281.aawbak
c:\program files\Ad-Aware\Resources\aa11.efp
c:\program files\Ad-Aware\Resources\aa14.efp
c:\program files\Ad-Aware\Resources\Carbon.eGL
c:\program files\Ad-Aware\Resources\Default.eGL
c:\program files\Ad-Aware\Resources\Gold.eGL
c:\program files\Ad-Aware\Resources\Orange.eGL
c:\program files\Ad-Aware\Resources\Sedona.eGL
c:\program files\Ad-Aware\Resources\wa11.efp
c:\program files\Ad-Aware\Resources\wa11b.efp
c:\program files\Ad-Aware\Resources\wa12.efp
c:\program files\Ad-Aware\Resources\wa12b.efp
c:\program files\Ad-Aware\Resources\wa14b.efp
c:\program files\Ad-Aware\Resources\wa14i.efp
c:\program files\Ad-Aware\Resources\wt12.efp
c:\program files\Ad-Aware\Resources\wt12b.efp
c:\program files\Ad-Aware\Resources\wt16b.efp
c:\program files\Ad-Aware\Resources\wt16bi.efp
c:\program files\Ad-Aware\Resources\wt20b.efp
c:\program files\Ad-Aware\Resources\wt20bi.efp
c:\program files\Ad-Aware\RPAPI.dll
c:\program files\Ad-Aware\savapi3.dll
c:\program files\Ad-Aware\savapi3client.dll
c:\program files\Ad-Aware\Savapibridge.dll
c:\program files\Ad-Aware\ShellExt.dll
c:\program files\Ad-Aware\threatwork.exe
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\AutoStart Manager.exe
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Settings.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gbottompic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gbottompicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gtoppic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\gtoppicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\skin.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Skins\grey\Thumbs.db
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\SO.dll
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\de.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\en.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\english.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\es.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\fr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\it.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\ja.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\nl.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\pr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\russian.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\zh-cmn-Hans.xml
c:\program files\Ad-Aware\ToolBox\AutoStart Manager\Translations\zh-cmn-Hant.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\AutoStart Manager.exe
c:\program files\Ad-Aware\ToolBox\AutoStart\de.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\en.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\english.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\es.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\fr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\gbottompic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\gbottompicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\gbottompic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\gbottompicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\gtoppic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\gtoppicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\skin.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\grey\Thumbs.db
c:\program files\Ad-Aware\ToolBox\AutoStart\gtoppic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\gtoppicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\it.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\ja.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\nl.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\pr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\russian.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Settings.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\skin.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\gbottompic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\gbottompicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\gtoppic.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\gtoppicp.bmp
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\skin.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Skins\grey\Thumbs.db
c:\program files\Ad-Aware\ToolBox\AutoStart\SO.dll
c:\program files\Ad-Aware\ToolBox\AutoStart\Thumbs.db
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\de.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\en.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\english.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\es.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\fr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\it.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\ja.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\nl.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\pr.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\russian.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\zh-cmn-Hans.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\Translations\zh-cmn-Hant.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\zh-cmn-Hans.xml
c:\program files\Ad-Aware\ToolBox\AutoStart\zh-cmn-Hant.xml
c:\program files\Ad-Aware\ToolBox\LT\Extras.LGFF
c:\program files\Ad-Aware\ToolBox\LT\HostFileEditor.exe
c:\program files\Ad-Aware\ToolBox\LT\Lang\DE.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\EN.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\ES.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\FL.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\FR.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\IT.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\NL.lslang
c:\program files\Ad-Aware\ToolBox\LT\Lang\PT.lslang
c:\program files\Ad-Aware\ToolBox\LT\ProcessWatch.dll
c:\program files\Ad-Aware\ToolBox\LT\ProcessWatch.exe
c:\program files\Ad-Aware\unacev2.dll
c:\program files\Ad-Aware\unrar.dll
c:\program files\Ad-Aware\UpdateManager.dll
c:\program files\Ad-Aware\UpdateManager.dll.18090.aawbak
c:\program files\Ad-Aware\WSCUpdate.dll
c:\program files\ESTsoft
c:\program files\ESTsoft\Common\ALBNCollector.exe
c:\program files\ESTsoft\Common\ALSTSCollector.exe
c:\program files\Winferno
c:\program files\Winferno\PC Confidential\DeleteIndex.exe
c:\program files\Winferno\PC Confidential\Graphics\HandPoint.ico
c:\program files\Winferno\PC Confidential\PCCBHO.dll
c:\program files\Winferno\PC Confidential\PCCL.DLL
c:\program files\Winferno\PC Confidential\PCConfidential.chm
c:\program files\Winferno\PC Confidential\PCConfidential.exe
c:\program files\Winferno\PC Confidential\PCCST.exe
c:\program files\Winferno\PC Confidential\unins000.dat
c:\program files\Winferno\PC Confidential\unins000.exe
c:\program files\Winferno\PC Confidential\WinCMR.dll
c:\program files\Winferno\PC Confidential\WinfernoSoftware.url
c:\windows\System32\drivers\etc\hosts
c:\windows\system32\drivers\logiflt.iad
c:\windows\system32\drivers\lvuvc.hs
c:\windows\Tasks\PCConfidential.job
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
--------------- FCopy ---------------
c:\windows\system32\dllcache\atapi.sys --> c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_LVUVC
((((((((((((((((((((((((( Files Created from 2009-12-16 to 2010-01-16 )))))))))))))))))))))))))))))))
.
2010-01-16 02:39 . 2010-01-16 02:39 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-14 01:07 . 2010-01-14 01:08 -------- d-----w- c:\program files\trend micro
2010-01-14 01:07 . 2010-01-14 01:08 -------- d-----w- C:\rsit
2010-01-13 03:25 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-10 00:39 . 2010-01-10 01:13 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-08 19:04 . 2010-01-08 19:04 -------- d-----w- c:\program files\TrendMicro
2010-01-08 19:02 . 2010-01-15 14:42 -------- d-----w- c:\program files\ERUNT
2010-01-05 02:26 . 2010-01-05 02:26 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-01-05 01:34 . 2010-01-05 01:34 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-01-05 01:30 . 2010-01-05 01:30 -------- d-sh--w- c:\documents and settings\All Users\Application Data\WSPTNVD_APDM
2009-12-19 01:02 . 2009-12-19 01:02 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Mozilla
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-16 16:35 . 2009-09-04 04:58 -------- d-----w- c:\documents and settings\Owner\Application Data\Skype
2010-01-13 22:29 . 2009-03-23 03:53 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-08 19:04 . 2010-01-08 19:04 388096 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-08 04:19 . 2008-12-25 22:05 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-08 04:19 . 2005-05-14 14:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-07 22:07 . 2009-03-23 03:53 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-07 22:07 . 2009-03-23 03:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-05 19:19 . 2010-01-05 19:19 5061519 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-05 02:24 . 2009-09-04 05:05 -------- d-----w- c:\documents and settings\Owner\Application Data\skypePM
2009-12-18 23:38 . 2009-04-27 20:23 -------- d-----w- c:\program files\VideoLAN
2009-12-18 23:37 . 2007-08-27 03:07 -------- d-----w- c:\program files\Google
2009-12-13 02:26 . 2009-12-13 02:26 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-12-13 01:25 . 2009-12-13 01:23 -------- d-----w- c:\documents and settings\All Users\Application Data\PMB Files
2009-12-13 01:23 . 2009-12-13 01:23 -------- d-----w- c:\program files\Pando Networks
2009-12-13 00:56 . 2009-11-14 00:20 -------- d-----w- c:\program files\Microsoft Silverlight
2009-12-02 15:13 . 2009-12-02 15:13 -------- d-----w- c:\program files\Common Files\Logitech
2009-11-29 02:45 . 2008-03-08 22:24 1324 ----a-w- c:\windows\system32\d3d9caps.dat
2009-11-21 15:51 . 2002-09-03 16:26 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
2009-11-04 18:46 . 2009-11-04 18:46 1421449 ----a-w- c:\documents and settings\All Users\Application Data\NeoEdge Networks\Yahoo_Monopoly\IAF.dll
2009-10-29 07:45 . 2005-02-18 21:19 916480 ------w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 ------w- c:\windows\system32\drivers\http.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-04 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2003-10-06 5058560]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2007-12-11 267048]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PCTAVSvc]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^TrueAssistant.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\TrueAssistant.lnk
backup=c:\windows\pss\TrueAssistant.lnkStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [1/17/2007 10:05 AM 24652]
S2 GdFsHook;McAfee Privacy Service File Guardian;\??\c:\windows\System32\Drivers\GDFSHK.SYS --> c:\windows\System32\Drivers\GDFSHK.SYS [?]
S2 GdTdi;McAfee Privacy Service Transport Filter;\??\c:\windows\System32\Drivers\GDTDI.SYS --> c:\windows\System32\Drivers\GDTDI.SYS [?]
S3 cpuz128;cpuz128;\??\c:\docume~1\Owner\LOCALS~1\Temp\cpuz_x32.sys --> c:\docume~1\Owner\LOCALS~1\Temp\cpuz_x32.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-12-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 20:57]
2009-01-05 c:\windows\Tasks\NSSstub.job
- c:\windows\system32\Adobe\Shockwave 11\nssstub.exe [2008-12-25 20:59]
2010-01-16 c:\windows\Tasks\User_Feed_Synchronization-{297CA128-8625-40F0-866D-756308C4F29F}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
2010-01-16 c:\windows\Tasks\User_Feed_Synchronization-{B71AB70B-D1B1-4C62-A30B-C37ED636C629}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:31]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {1DE9BB01-B121-401D-8877-BCD5ED5B7EE5} - hxxp://www.crezio.com/test/leeyunho/AlwaysOn/AlwaysOn.CAB
DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} - hxxp://player.bugs.co.kr/install/mv/XTools.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\em47iz8j.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
.
- - - - ORPHANS REMOVED - - - -
AddRemove-PCConfidential_is1 - c:\program files\Winferno\PC Confidential\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-16 10:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(6628)
c:\windows\system32\WININET.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\IME\SPGRMR.DLL
c:\program files\Common Files\Microsoft Shared\Ink\PENUSA.DLL
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\conime.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2010-01-16 10:41:49 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-16 16:41
ComboFix2.txt 2010-01-15 17:41
Pre-Run: 18,141,184,000 bytes free
Post-Run: 18,037,776,384 bytes free
- - End Of File - - 682E08C44FFACA750E4FAF36F991E20A