InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 3801. |
Solve : Redirected Google links? |
|
Answer» I am running Windows Vista and I use GOOGLE Chrome. More often than not, when I click on a link on a Google search, it will redirect me to a random website for about half a second, then another one with the search results of my original search on another website. For example, when I search "Sins of a Solar Empire: Diplomacy beta", then click on one of the links, it redirects me to "http://sopranoclarinet.com/result.php?Keywords=Sins+of+a+Solar+Empire:+Diplomacy&r=19a62d05d0c76434e38e49a4a1ecec8b19e5d049d86ffbd91fc1205cb0a9d7edc0dd9aa83a2b3ed1e84eee14de24d78c&Submit=Go", then it directs me to "http://www.lowpriceshopper.com/about-solar/shop?rf=llp". When I hit the "back" button, the browser will either show some "generic" website like "www.Corporatehousingproviders.org" or a site that will say "your page is loading" and then will direct me back to the site that I was on before pressing the "back" button. These problems can be AVOIDED by right-clicking the link on the Google search and OPENING it in a new tab. For the most part, the "major" sites such as Google, Yahoo, Miniclip, Wikipedia, etc. are fine, but the "SMALLER", lesser known sites are affected. I have McAfee (the one Comcast gives out for free) and I have run two full scans, both of which have come back negative. Please advise.Click here, follow the directions and post the logs.Here are the logs |
|
| 3802. |
Solve : Atapi.sys infected by a Trojan Horse Packed.Protector.C? |
|
Answer» Try this.
I'm pretty sure we removed the malware but the damage it did may be more than we can see. You may need to reinstall.Alright. Well thanks a lot for the help! It might take some days till I get it REINSTALLED. |
|
| 3803. |
Solve : Can a virus remain on a graphics card if the card is used in another PC?? |
|
Answer» Hi. I'm ASKING this question for a friend. I think he is running XP. He would like to use a graphics CARD from an old, infected PC. Can a virus REMAIN on the card? |
|
| 3804. |
Solve : Request Help for trojan removal - Combofix Log interpretation? |
|
Answer» Cannot run Viruseffect remover: It is hard to know if one program is dependent upon the first running successfully. They usually are but if one won't run then we're forced to try the next. Good news. I don't see anything wrong. Bad news. I don't see anything wrong.... Try Dial-a-fix. Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.
How is the computer now?During install it Stated "Installer unable to determine your version of Internet explorer, some DLL registrations will be skipped" I ran it anyways. received Multiple error messages #127: for the following files: iesetup.dll imgutil.dll inserg.dll pngfild.dll webcheck.dll inshtml.dll msrating.dll occache.dll After reboot to normal windows mode still no permissions to run programs or startup notifications bar. Nothing changed that can be detected. I ran Avast boot time scan this morning and it showed no infections. Ever since post reply #9 where I attempted to run ESET I have had the issue with the lack permissions and the missing start up notifications bar. In post replay #28 I asked you if we could address this and you did not respond but instead had me run another program. I ASK NOW .... Is it possible that we have cleaned the machine in this process and what is left is some configurations that got screwed up in the process? Can we now directly address why I am not getting permissions in the normal run mode and why the start up notification bar is missing? or do you still feel we need to run more checks for infections?I have searched on my own attempting to fix the configurations but I have had no luck. Any suggestions before I NUKEIT ?Do you have an XP CD? If so, place it in your CD ROM drive and follow the instructions below:
Not sure I understood the proper procedure for running it. It never wanted to go to the CD drive for the file. I tried as you said and it did not run. Did open a window but then hangs, no progress bar indicator. Tried this multiple times. I read up on this SFC and found where it should be located. "D" is my CD drive. I then tried d:\i386\sfc \scannow and that did not work. Guess cause file there is marked as SFC.EX_ I then found that I have two copies of this file on my c drive. One in c:\i386\ and another in c:\windows\system32\ When I point a full path the c:\386 version a window opens too quick to read and closes again. I checked in the registry and the CurrentVersion\setup is pointed to C\... and not the D drive. Any other suggestions? It should be run with the C drive. Post a fresh HijackThis log please.So you directed me to insert the CD just in case the SFC.exe file was not present on the C drive then? I am attaching a new hijack log. [Saving space, attachment deleted by admin]I have not been overly impressed with the help I received here. Realizing that you offer help on your own time and for free I do want to Thank you for trying. I am Nukin it now!There is only so much we can do... |
|
| 3805. |
Solve : my computer crashed? |
|
Answer» I have toshiba satalite laptop A25-s3072. recently while working on my laptop it crashed and shut down. After five minutes when I power up the computer I got the following message: |
|
| 3806. |
Solve : Best subscription Anti-Virus? |
|
Answer» I have tried several free anti-virus programs and have found that most of them just don't cut the mustard. |
|
| 3807. |
Solve : Avast boot scan/ files corrupted? |
|
Answer» Just finished BOOT scan USING avast there was multiple items show up saying files corrupted, the items were registry items is this something to be worried about. Also is there a way to post logs from avast of the boot scan that i can post here? |
|
| 3808. |
Solve : Windows Defender Help!? |
|
Answer» I have Windows Defender and Norton 360, everytime I load the computer Windows Defender says: Windows Defender is not on, would you like to turn it on? So I have to do that everytime. |
|
| 3809. |
Solve : What is a good Viruse protection?? |
|
Answer» link removed , what was wrong with it , i took wot out I prefer AVAST.I'll have to give it a try. Has anyone had trouble getting AVG completely off their pc?Here's the AVG removal tool. On my main PC I use Kaspersky Internet Security and Avast Home on all the others. I wonder if you could advise me then - have used avg in the past, but prefer Avast. I had pondered trying Avira but not tried it yet. My bank are offering Kaspersky (AV only) for free so I wondered whether you FELT it was better, faster & less resource hungry? cheersi have tried avg , macafee , norton and have kept with avira I would say, if you have one antivirus software that you like and it is doing well and updates at least once every 24 hours and has realtime protection, then just stay with it. Kaspersky is a good AV as well, but considering it's free, I'd still go with Avast because it has the antimalware/antispyware components that the free version of Kaspersky OFFERED by your bank does not include. You'd have to pay for a subscription to GET all the other stuff.thanks for that... the version of kaspersky offered is http://www.kaspersky.co.uk/kaspersky_internet_security which i believe does include antimalware / antispyware. avast is ok, but sometimes I feel it is slow. Since the suite offered by my bank includes a firewall too I wonder if my system MAY be improved (no longer run avast & zone alarm).yeah but however, is your bank offering the KAV for life? You'll have to pay for a subscription/key when it expires if you want to continue using it after it expires.well they've renewed it the last few years, but i guess i will cross that bridge when i come to itQuote from: Helpmeh on August 05, 2009, 04:29:33 PM I suggest staying away from Norton (personal experience: very slow and resource greedy).i agree with that norton takes processing power and sometimes not even idle power too McAfee.. However it slows down your computer if you don't have the correct mimimum requirements... AVG is the 2nd best. |
|
| 3810. |
Solve : What's the best operating system?? |
|
Answer» HEY! What operating SYSTEM do YOU like the most? Have a little vote, my best one is: WINDOWS XP On a good day Operating System Poll #150 Initialized.I THINK XP is the best because the hundreds of other polls on this forum say so; without GIVING any reasons to back up their decision. |
|
| 3811. |
Solve : Got a program that keeps wanting to in stall when turning on the computer? |
|
Answer» Every time i turn on my machine i get this program that WANTS to install looks like a EXE that has been download |
|
| 3812. |
Solve : Run other programs while doing an AV scan?? |
|
Answer» Do you know if it's ok to run other PROGRAMS while doing an AV SCAN? |
|
| 3813. |
Solve : Computer shut down it self? |
|
Answer» I have windows xp and it shut down on its own. I restarted ran for half hour then shut down again. This went on two more times and the last time it said window shutting down and cannot restart. Help Carol, |
|
| 3814. |
Solve : CyberDefender. Is this a Scam?? |
|
Answer» but NEVER pay for questionable software |
|
| 3815. |
Solve : Need help with malware? |
|
Answer» I've read the info page and thus far have run Avast, which found three or four trojans. Before coming here I had already tried to run SUPERantispyware (already on my machine) and couldn't. I uninstalled but was unable to reinstall from the site. I was able to download from Cnet but I cannot install it. I have also run Windows Defender and the regular version of Ccleaner which I already had on. I wanted to double check if I need to specifically download the CC slim version, if I am able to download. At the moment I cannot access most antispyware related sites. |
|
| 3816. |
Solve : Windows will not load? |
|
Answer» I recently installed Nortons 360 on my home computer. I received a NOTICE that I had a upgrade to Nortons 2009 which I received. When the program removed my old Nortons and restarted my computer I received a message that Windows could not start because PART was missing. After much trial and error I finally got the computer up using my start up CD. Each time I contacted Nortons and they tried to work the issue a reboot of the system yielded the same message as before. Now my system will not restart even using the start up CD. I now get the message "Window could not CONFIGURE one or more system components. To install Windows, restart the computer and reinstall." Any help would be greatly appreciated. Also I have not tried a total restart from the CD since there is material that I would rather not loose.go to tools , internet options , advanced , reset internet explorer options , reset , and follow through go to tools , internet options , advanced , reset internet explorer options , reset , and follow throughHarry, how is resetting Internet Explorer going to put his computer back to factory settings?Quote from: SuperDave on August 18, 2009, 05:40:56 PM Harry, how is resetting Internet Explorer going to put his computer back to factory settings?That's exactly what I'm wondering too. sorry it puts windows back to when you got it , am i wrong in saying this because this is what i got out of the reading when i do it twice a yearQuote from: harry 48 on August 19, 2009, 12:45:40 PM sorry it puts windows back to when you got it , am i wrong in saying this because this is what i got out of the reading when i do it twice a yearNo, it resets Internet Explorer to the default settings - nothing else.ok , i'll go read it Quote from: harry 48 on August 19, 2009, 01:11:12 PM ok , i'll go read itPlease copy and paste the thing you read. Quote from: Helpmeh on August 19, 2009, 04:06:15 PM Please copy and paste the thing you read.I really don't think there's any point, do you? Clearly he simply didn't understand what he was reading, wouldn't you say?there is more after that but do not want to start it [attachment deleted by admin]I'm not sure what part of that you think refers to the OS as opposed to Internet Explorer, but it certainly seems clear to me.Quote from: ADG on August 19, 2009, 04:23:52 PM I'm not sure what part of that you think refers to the OS as opposed to Internet Explorer, but it certainly seems clear to me.Same here. Either harry reads the hidden text that makes up the background of that message box or he read it wrong. Sorry. ok i must have read it wrong |
|
| 3817. |
Solve : BIOS Virus? |
|
Answer» What is a BIOS Virus? You're probably thinking of a boot sector virus...not as common as they used to be but are going through a resurgence as the newest batch of malicious idiots are cutting their chops in the malware world.No, not thinking of an MBR virus. (Easy fix for those since I had a problem with a Windows 3.0 instalation disk at one point: fdisk /mbr re-writes the Master Boot Record. It can even clear a program like Lilo, so it can be problamatic) After my research, (From GX1_Man's link to Google), I found out that they do exist, and that they can be quite dammaging. I had an uncle who said at one time a long time ago that he had a BIOS virus, and I wanted to do more research on it some day. (now I know) The BIOS are infected through the BIOS Updates (which, on many BIOS chips, can be dissabled to prevent such a virus) Quote from: Zylstra on March 07, 2007, 02:15:36 PM No, not thinking of an MBR virus. Does a rootkit stop an MBR virus, or scan for it? If not, can Avast or Panda scan ONLY the MBR. I'm the guy with the cross partition deal. So, I FIGURE I'd hide partitions, but since the MBR will still be vulnerable I would scan for that before SWITCHING from dirter to clean partion (OS installs) and boot from CD to do the scan. I woudn't get lazy then, hopefully, and blow it off cuz I don't have to do a whole scan _ then dont update the bios i have never heard of a bios virus |
|
| 3818. |
Solve : What are these files?? |
|
Answer» I was doing some general cleanup on my computer and happened to come across some unusual files. I'm HOPING someone here can maybe help me find out what they are and if I should DELETE them. I'm on WinXP, by the way. The files are: |
|
| 3819. |
Solve : Sysvxd.exe? |
|
Answer» I had the Sysvxd.exe virus. I followed all the steps and have the 3 logs attached below. Those programs may have DELETED it, but I just want to make sure that EVERYTHING is gone so I won't have this problem again. Thank you so much for your help. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.
---------- Disable/Enable the System Restore Utility to flush old infected restore points 1) Right click the My Computer icon on the Desktop and click on Properties. 2) Click on the System Restore tab. 3) Put a check mark next to TURN off System Restore on All Drives 4) Click the OK button. 5) You will be prompted to restart the computer. Click the Yes button. Now re-enable System Restore To re-enable the System Restore Utility, follow steps one to five and on step three remove the check mark next to 'Turn off System Restore on All Drives'. 1) Right click the My Computer icon on the Desktop and click on Properties. 2) Click on the System Restore tab. 3) Remove the check mark next to Turn off System Restore on All Drives 4) Click the OK button. ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Awesome. Thanks so much. I know where I'll be coming back to if I have any more computer problems. Your welcome. Safe SURFING...Deleting again.... |
|
| 3820. |
Solve : anti virus/anti spyware programs? |
|
Answer» My computer seems to have slowed down considerably in the past few weeks. The question I have is in regards to ANTI Virus/Anti Spyware programs. |
|
| 3821. |
Solve : Cannot go online in safe mode.? |
|
Answer» Quote like, literally, 7 years ago and not since then. Should I uninstall avast since I cannot find a place to uninstal MCAFEE?Download this removal tool. It should get rid of all TRACES of McAfee. Quote how can I make sure of that?You can check the Winsock file by USING this SYSTEM File Checker. You will probably need your OS Disc.somehow removing mcafee fixed it. thanks! |
|
| 3822. |
Solve : What are these programs for?? |
|
Answer» I opened regedit and went to HKEY_LOCAL_MACHINE. Then went to SOFTWARE. Then I found these programs: C07ft5Y, Codec tweak tool, divxnetworks, gemplus, S3R521, Schlumberger, x-avcsd. Can anyone explain what are these programs for? Thank you very much.Codec tweak tool --> do you have klite codec pack or something? C07ft5Y is made by SecuROM. oh SecuROM. Thank you. Hi, 2x3i5x, helpmeh, BC_programmer: thank you very much for your really helpful answers. I am sorry for wasting your time. Next time i should search on google first before asking. To 2x3i5x : oh, i see. Yes, i think i've just found the programs you mentioned. I'm gonna to follow your ADVICES for sure. Thank you.Hi, again. i've just searched c07ft5y on google several minutes ago. And i only found one link for the keyword: c07ft5y. The link was home.no/nootrreok/c07ft5y.html. I followed the link and came accross this message: warning!!! Your computer contains various SIGNS of viruses and malware programs presence. Your system requires immediate anti viruses check! System security will perform a quick and free scanning of your PC for viruses and malicious programs. My question: is this c07ft5y safe enough to dwell in my registry? Or should i delete it? I know little about computer and I'm just a bit paranoia with this c07ft5y (sorry). Thank you very much. only one hit? I got several thousand: http://www.google.ca/#hl=en&source=hp&q=C07ft5Y&btnG=Google+Search&meta=&aq=f&oq=C07ft5Y&fp=a1047c2a76fad57b Quote from: BC_Programmer on August 26, 2009, 05:41:15 AM only one hit? I got several thousand:yeah, it seems you pinpointed further than me. I'll try it once again myself. Thank you.but... regarding the key; I was actually curious about that key myself, some time ago. it's been present on my XP desktop, as well as Vista laptop and new desktop build running vista. In my case I have several keys underneath it reflecting the games I have installed that use that copy-protection technology, Age of empires 2, quake 4, Halo... etc. while the name they chose CERTAINLY raises an eyebrow, looking past the name, it's really just a few morsels of irrelevant data- nothing to be concerned about. Again- I was quite curious about the key myself, and in fact ran Registry Monitor to find out what was accessing the key, to discover it was accessed when I played some of my games. After much investigation about the games that did and did not TRIGGER the discovery I discovered each game that did access the mystery key had the "secuROM" copy protection. Of course if I had simply done a google search I would have discovered that quite quickly, but I guess I like the thrill of the chase Quote from: BC_Programmer on August 26, 2009, 07:38:26 AM but... regarding the key;oh, i see. Thank you for explain this to me. So i no longer need to worry about this 'lovely key' hehe. Thank you very much. I think I was asking a silly question. Shame on me. |
|
| 3823. |
Solve : Rootkit-pakes.M? |
|
Answer» Hi, I currently run AVG. I also now have sas and MBAM. Do the spybot/adaware/spywareblaster programme slow the machine down much? Why so many programmes that seemingly serev the same function? Or do they all do something alightly different?I'm currently running SpywareBlaster, Spybot S&D and Threatfire as well as Avast AV and there is no SLOWNESS in my computer. Evil once told me that a layered approach was the best way to protect against Viruses and infections. When it comes to AV, 2 is not often better than one. If you find 2 free ones that truly are compatible with each other, tell me!Right. Only one AV at a time but for spyware & malware you can run as many as you want. Plus a good firewall that blocks outgoing as well as incoming.I had the same problem Tried Spybot and Malwarebytes. Neither could clean it up. Tried going back to a restore point (Start -> Accessories -> System Tools -> System Restore). Did not work for me. Finally went to microsoft for help. They SUGGESTED I run the scanner at onecare.live.com. Seems to have worked so far.... |
|
| 3824. |
Solve : Screensavers are trying to take over my pc.? |
|
Answer» My boyfriend wanted a stupid fireplace screensaver because we have our pc conntected to our tv. Well he downloaded something CALLED 'Relevant Knowledge' that was attached to one of the downloads and I did some research and found out its malware.
---------- Download, update and run a-squared Free edition At the main menu, click Scan Now, there will be 4 options, choose Deep Scan and then click Scan * If malware is found, click the button Remove Selected Malware * If malware is found, select all found and click Quarantine selected objects * Click Save Report. Save the report to somewhere convenient, such as your desktop * Add the report as an attachment in your next post. ---------- Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop. Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will open two (2) logs. 1) DDS.txt 2) Attach.txt * Save both logs to your desktop. * Please copy and paste the entire contents of both logs in your next reply. Note: DDS will instruct you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copy and pasting it into the reply.Here are the logs from each as requested. a-squared Free - Version 4.5 Last update: 8/22/2009 4:33:11 PM Scan settings: Scan type: Deep Scan Objects: Memory, Traces, Cookies, C:\, H:\ Scan archives: On Heuristics: Off ADS Scan: On Scan start:8/22/2009 4:33:38 PM c:\program files\bittorrent detected: Trace.Directory.Bittorrent 5.0!A2 c:\documents and settings\all users\start menu\programs\bittorrent detected: Trace.Directory.Bittorrent 5.0!A2 c:\program files\bittorrent\bittorrent.exe detected: Trace.File.Bittorrent 5.0!A2 c:\documents and settings\all users\start menu\programs\bittorrent\bittorrent.lnk detected: Trace.File.Bittorrent 5.0!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638815625005 detected: Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638816265000 detected: Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638816265003 detected: Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638822921000 detected: Trace.TrackingCookie.doubleclick.net!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638869593001 detected: Trace.TrackingCookie.aol.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249490816828004 detected: Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249495168656001 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305500000 detected: Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305625000 detected: Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305718000 detected: Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305718005 detected: Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530306593000 detected: Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530356687000 detected: Trace.TrackingCookie.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530356687001 detected: Trace.TrackingCookie.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530390140000 detected: Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249563719765000 detected: Trace.TrackingCookie.www.buy!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750000 detected: Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750001 detected: Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750002 detected: Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356828006 detected: Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572358843000 detected: Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359015005 detected: Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359562003 detected: Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359562006 detected: Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572412890000 detected: Trace.TrackingCookie.ads.bridgetrack.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249577188921001 detected: Trace.TrackingCookie.adserv!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249691875265000 detected: Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249854774312006 detected: Trace.TrackingCookie.tag.contextweb.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858553140010 detected: Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858699531002 detected: Trace.TrackingCookie.www.burstnet.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858720656000 detected: Trace.TrackingCookie.www.burstbeacon.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249861032687003 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249863405953000 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891109006 detected: Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891187004 detected: Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891187005 detected: Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916091281000 detected: Trace.TrackingCookie.sales.liveperson.n et!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916091328000 detected: Trace.TrackingCookie.sales.liveperson.n et!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187000 detected: Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187001 detected: Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187002 detected: Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187003 detected: Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187004 detected: Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249918138984000 detected: Trace.TrackingCookie.cms!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036490437000 detected: Trace.TrackingCookie.www.googleadservic es.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036969265000 detected: Trace.TrackingCookie.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036969265001 detected: Trace.TrackingCookie.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038191609000 detected: Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038193281003 detected: Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038193296003 detected: Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194656001 detected: Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194656002 detected: Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812000 detected: Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812002 detected: Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812003 detected: Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043655093000 detected: Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043655093001 detected: Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043656718000 detected: Trace.TrackingCookie.adserv!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044174796004 detected: Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859000 detected: Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859001 detected: Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859002 detected: Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044400578000 detected: Trace.TrackingCookie.zedo.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044400578001 detected: Trace.TrackingCookie.zedo.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044401125000 detected: Trace.TrackingCookie.zedo.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250050142031000 detected: Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051116765004 detected: Trace.TrackingCookie.media!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051948937000 detected: Trace.TrackingCookie.stat.onestat!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051948937001 detected: Trace.TrackingCookie.stat.onestat!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051966718000 detected: Trace.TrackingCookie.server.cpmstar.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051966890000 detected: Trace.TrackingCookie.server.cpmstar.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250536247968000 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250538475593000 detected: Trace.TrackingCookie.webtrends!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250538475750000 detected: Trace.TrackingCookie.webtrends!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539111375000 detected: Trace.TrackingCookie.cookie.monster.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539111578000 detected: Trace.TrackingCookie.ads.monster.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539939859001 detected: Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794469125004 detected: Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794472687002 detected: Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794696281000 detected: Trace.TrackingCookie.statse.webtrendsli ve!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250795144796000 detected: Trace.TrackingCookie.ad1.clickhype.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250802085875001 detected: Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250806725546000 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250863260875002 detected: Trace.TrackingCookie.click.cashengines. com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250864211953001 detected: Trace.TrackingCookie.am1.activemeter.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250868467203000 detected: Trace.TrackingCookie.zedo.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914155734002 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914155734004 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914156890000 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250951853750000 detected: Trace.TrackingCookie.m.webtrends.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250956872250000 detected: Trace.TrackingCookie.www.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250972724359003 detected: Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S92N09AN\upgrade[1].cab/seekapp.dll detected: Gen.AdWare!IK C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S92N09AN\upgrade[1].cab/seekappsrch.exe detected: Gen.AdWare!IK C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SHQR8LAR\upgrade[1].cab/seekapp.dll detected: Gen.AdWare!IK C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SHQR8LAR\upgrade[1].cab/seekappsrch.exe detected: Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP18\A0001402.dll detected: Gen.Trojan!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP18\A0001404.dll detected: Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005109.dll detected: Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005110.dll detected: Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005113.dll detected: Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005115.exe detected: Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005148.dll detected: Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005149.exe detected: Adware.PremiumO!IK C:\WINDOWS\Temp\SEE165.tmp\upgrade.exe/seekapp.dll detected: Gen.AdWare!IK C:\WINDOWS\Temp\SEE51.tmp\upgrade.exe/seekapp.dll detected: Gen.AdWare!IK Scanned Files: 74292 Traces: 628846 Cookies: 1441 Processes: 25 Found Files: 14 Traces: 4 Cookies: 102 Processes: 0 Registry keys: 0 Scan end:8/22/2009 5:15:03 PM Scan time:0:41:25 C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005149.exeQuarantined Adware.PremiumO!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP18\A0001402.dllQuarantined Gen.Trojan!IK C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S92N09AN\upgrade[1].cab/seekapp.dllQuarantined Gen.AdWare!IK C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\S92N09AN\upgrade[1].cab/seekappsrch.exeQuarantined Gen.AdWare!IK C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SHQR8LAR\upgrade[1].cab/seekapp.dllQuarantined Gen.AdWare!IK C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\SHQR8LAR\upgrade[1].cab/seekappsrch.exeQuarantined Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP18\A0001404.dllQuarantined Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005109.dllQuarantined Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005110.dllQuarantined Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005113.dllQuarantined Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005115.exeQuarantined Gen.AdWare!IK C:\System Volume Information\_restore{37B38896-87A3-4D37-B41C-FC20135C5D04}\RP25\A0005148.dllQuarantined Gen.AdWare!IK C:\WINDOWS\Temp\SEE165.tmp\upgrade.exe/seekapp.dllQuarantined Gen.AdWare!IK C:\WINDOWS\Temp\SEE51.tmp\upgrade.exe/seekapp.dllQuarantined Gen.AdWare!IK C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250956872250000Quarantined Trace.TrackingCookie.www.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250951853750000Quarantined Trace.TrackingCookie.m.webtrends.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250864211953001Quarantined Trace.TrackingCookie.am1.activemeter.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250863260875002Quarantined Trace.TrackingCookie.click.cashengines. com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250795144796000Quarantined Trace.TrackingCookie.ad1.clickhype.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794696281000Quarantined Trace.TrackingCookie.statse.webtrendsli ve!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539111578000Quarantined Trace.TrackingCookie.ads.monster.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539111375000Quarantined Trace.TrackingCookie.cookie.monster.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250538475593000Quarantined Trace.TrackingCookie.webtrends!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250538475750000Quarantined Trace.TrackingCookie.webtrends!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051966718000Quarantined Trace.TrackingCookie.server.cpmstar.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051966890000Quarantined Trace.TrackingCookie.server.cpmstar.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051948937000Quarantined Trace.TrackingCookie.stat.onestat!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051948937001Quarantined Trace.TrackingCookie.stat.onestat!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250051116765004Quarantined Trace.TrackingCookie.media!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044400578000Quarantined Trace.TrackingCookie.zedo.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044400578001Quarantined Trace.TrackingCookie.zedo.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044401125000Quarantined Trace.TrackingCookie.zedo.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250868467203000Quarantined Trace.TrackingCookie.zedo.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043655093000Quarantined Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043655093001Quarantined Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250050142031000Quarantined Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794469125004Quarantined Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250794472687002Quarantined Trace.TrackingCookie.adbrite.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038191609000Quarantined Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038193281003Quarantined Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038193296003Quarantined Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194656001Quarantined Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194656002Quarantined Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812000Quarantined Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812002Quarantined Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250038194812003Quarantined Trace.TrackingCookie.about.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036490437000Quarantined Trace.TrackingCookie.www.googleadservic es.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249918138984000Quarantined Trace.TrackingCookie.cms!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916091281000Quarantined Trace.TrackingCookie.sales.liveperson.n et!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916091328000Quarantined Trace.TrackingCookie.sales.liveperson.n et!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891187004Quarantined Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891187005Quarantined Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859000Quarantined Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859001Quarantined Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044399859002Quarantined Trace.TrackingCookie.trafficmp.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858720656000Quarantined Trace.TrackingCookie.www.burstbeacon.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858699531002Quarantined Trace.TrackingCookie.www.burstnet.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249854774312006Quarantined Trace.TrackingCookie.tag.contextweb.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249577188921001Quarantined Trace.TrackingCookie.adserv!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250043656718000Quarantined Trace.TrackingCookie.adserv!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572412890000Quarantined Trace.TrackingCookie.ads.bridgetrack.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572358843000Quarantined Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187000Quarantined Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187001Quarantined Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187002Quarantined Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187003Quarantined Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249916917187004Quarantined Trace.TrackingCookie.tribalfusion.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750000Quarantined Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750001Quarantined Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356750002Quarantined Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572356828006Quarantined Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359015005Quarantined Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359562003Quarantined Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249572359562006Quarantined Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249915891109006Quarantined Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250044174796004Quarantined Trace.TrackingCookie.casalemedia.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249563719765000Quarantined Trace.TrackingCookie.www.buy!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530356687000Quarantined Trace.TrackingCookie.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530356687001Quarantined Trace.TrackingCookie.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036969265000Quarantined Trace.TrackingCookie.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250036969265001Quarantined Trace.TrackingCookie.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305500000Quarantined Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305625000Quarantined Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305718000Quarantined Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530305718005Quarantined Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530306593000Quarantined Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249530390140000Quarantined Trace.TrackingCookie.go.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249495168656001Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249861032687003Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249863405953000Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250536247968000Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250806725546000Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914155734002Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914155734004Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250914156890000Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250972724359003Quarantined Trace.TrackingCookie.ad.yieldmanager.co m!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638869593001Quarantined Trace.TrackingCookie.aol.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638822921000Quarantined Trace.TrackingCookie.doubleclick.net!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638815625005Quarantined Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638816265000Quarantined Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1248638816265003Quarantined Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249490816828004Quarantined Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249691875265000Quarantined Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1249858553140010Quarantined Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250539939859001Quarantined Trace.TrackingCookie.myspace.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250802085875001Quarantined Trace.TrackingCookie.myspace.com!A2 c:\program files\bittorrent\bittorrent.exeQuarantined Trace.File.Bittorrent 5.0!A2 c:\documents and settings\all users\start menu\programs\bittorrent\bittorrent.lnkQuarantined Trace.File.Bittorrent 5.0!A2 c:\program files\bittorrentQuarantined Trace.Directory.Bittorrent 5.0!A2 c:\documents and settings\all users\start menu\programs\bittorrentQuarantined Trace.Directory.Bittorrent 5.0!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250956872250000Quarantined Trace.TrackingCookie.www.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250951853750000Quarantined Trace.TrackingCookie.m.webtrends.com!A2 C:\Documents and Settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\cookies.sqlite:1250864211953001Quarantined Trace.TrackingCookie.am1.activemeter.co m!A2 Quarantined Files: 14 Traces: 4 Cookies: 95 _______________________________________ _________ DDS (Ver_09-07-30.01) - NTFSx86 Run by Cassaundra at 17:20:16.85 on Sat 08/22/2009 Internet Explorer: 6.0.2900.5512 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.478.64 [GMT -4:00] AV: Panda Cloud Antivirus *On-access scanning enabled* (Updated) {5AD27692-540A-464E-B625-78275FA38393} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Documents and Settings\All Users\Application Data\SeekappSrch\seekapp147.exe C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe C:\Program Files\SeekappSrch\seekappsrch.exe C:\Program Files\a-squared Free\a2service.exe C:\Program Files\a-squared Free\a2free.exe C:\Program Files\BitTorrent\bittorrent.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Cassaundra\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://google.com/ BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [SoundMan] SOUNDMAN.EXE mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [PSUNMain] "c:\program files\panda security\panda cloud antivirus\PSUNMain.exe" /Traybar StartupFolder: c:\docume~1\cassau~1\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\cassau~1\applic~1\mozilla\firefox\profiles\23gmjj1q.default\ FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll ---- FIREFOX POLICIES ---- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default _setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_pa ge", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_ enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 PSINKNC;PSINKNC;c:\windows\system32\drivers\PSINKNC.sys [2009-6-23 114056] R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2009-8-22 1864824] R2 NanoServiceMain;NanoServiceMain;c:\program files\panda security\panda cloud antivirus\PSANHost.exe [2009-4-23 95488] R2 PSINAflt;PSINAflt;c:\windows\system32\drivers\PSINAflt.sys [2009-6-23 136072] R2 PSINFile;PSINFile;c:\windows\system32\drivers\PSINFile.sys [2009-6-4 92552] R2 PSINProc;PSINProc;c:\windows\system32\drivers\PSINProc.sys [2009-6-4 98184] R2 SeekappSrch Service;SeekappSrch Service;c:\documents and settings\all users\application data\seekappsrch\seekapp147.exe [2009-8-14 54760] S2 spupdsvc;Windows Service Pack Installer update service;c:\windows\system32\spupdsvc.exe [2009-7-26 26488] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?] =============== Created Last 30 ================ 2009-08-22 16:44--d-----c:\docume~1\cassau~1\applic~1\BitTorrent 2009-08-22 16:25--d-----c:\program files\a-squared Free 2009-08-22 16:15142a-------c:\windows\system32\spupdsvc.inf 2009-08-22 14:19333,952-c------c:\windows\system32\dllcache\srv.sys 2009-08-22 14:18455,296-c------c:\windows\system32\dllcache\mrxsmb.sys 2009-08-22 14:181,106,944a-------c:\windows\system32\SETA9.tmp 2009-08-22 14:181,106,944-c------c:\windows\system32\dllcache\msxml3.dll 2009-08-22 14:18337,408a-------c:\windows\system32\SETA5.tmp 2009-08-22 14:18337,408-c------c:\windows\system32\dllcache\netapi32.dll 2009-08-22 14:18331,776-c------c:\windows\system32\dllcache\msadce.dll 2009-08-22 14:17691,712-c------c:\windows\system32\dllcache\inetcomm.dll 2009-08-22 14:16272,128-c------c:\windows\system32\dllcache\bthport.sys 2009-08-22 14:16203,136-c------c:\windows\system32\dllcache\rmcast.sys 2009-08-22 13:14--d-----c:\windows\system32\scripting 2009-08-22 13:14--d-----c:\windows\l2schemas 2009-08-22 13:14--d-----c:\windows\system32\en 2009-08-22 13:14--d-----c:\windows\system32\bits 2009-08-22 13:12--d-----c:\windows\ServicePackFiles 2009-08-22 13:11--d-----c:\windows\network diagnostic 2009-08-22 13:02129,045--------c:\windows\system32\drivers\cxthsfs2.cty 2009-08-22 12:49--d-----c:\windows\system32\PreInstall 2009-08-22 12:49--d-h---c:\windows\$hf_mig$ 2009-08-22 12:47--ds----c:\documents and settings\cassaundra\UserData 2009-08-22 11:47--d-----c:\docume~1\cassau~1\applic~1\Malwarebytes 2009-08-22 11:47--d-----c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-22 10:28--d-----c:\program files\Trend Micro 2009-08-22 10:08--d-----c:\program files\common files\Wise Installation Wizard 2009-08-22 00:05--d-----c:\windows\system32\appmgmt 2009-08-21 10:09--d-----c:\docume~1\cassau~1\applic~1\Panda Security 2009-08-21 10:06245a-------c:\windows\system32\PSUNCpl.dat 2009-08-21 10:06--d-----c:\program files\Panda Security 2009-08-21 10:06--d-----c:\docume~1\alluse~1\applic~1\Panda Security 2009-08-21 10:05--d-----c:\program files\BitTorrent 2009-08-14 19:11--d-----c:\program files\DivX 2009-08-14 19:11--d-----c:\program files\common files\DivX Shared 2009-08-10 11:11--d-----c:\program files\SeekappSrch 2009-08-10 11:11--d-----c:\docume~1\alluse~1\applic~1\SeekappSrch 2009-08-10 10:593,255a-------c:\windows\system32\wbem\Outlook_01ca19cb36d589a0.mof 2009-08-09 20:32--d-----c:\program files\IrfanView 2009-08-06 12:21139,776a-------c:\windows\system32\CNMLM75.DLL 2009-08-06 12:218,704a-------c:\windows\system32\CNMVS75.DLL 2009-08-06 12:2190,112a-------c:\windows\system32\CNMCP75.exe 2009-08-06 12:0625,856a-------c:\windows\system32\drivers\usbprint.sys 2009-07-26 16:27--d-----c:\program files\Windows Media Connect 2 2009-07-26 16:26--d-----c:\windows\system32\LogFiles 2009-07-26 16:2626,488a-------c:\windows\system32\spupdsvc.exe 2009-07-26 16:2132,592a-------c:\windows\system32\msonpmon.dll 2009-07-26 16:17--d-----c:\program files\Microsoft Visual Studio 8 2009-07-26 16:16--d-----c:\windows\SHELLNEW 2009-07-26 16:09--d-----c:\windows\pss 2009-07-26 16:08--d-----c:\docume~1\alluse~1\applic~1\Viewpoint 2009-07-26 16:08--d-----c:\program files\common files\AOL 2009-07-26 16:08382a---h---C:\IPH.PH 2009-07-26 16:03--d-----c:\program files\CONEXANT 2009-07-26 16:00--d-----c:\program files\Realtek Sound Manager 2009-07-26 16:00--d-----c:\program files\AvRack 2009-07-26 16:00--d-----c:\program files\Realtek AC97 2009-07-26 15:5630,277a-------c:\windows\system32\nvapps.xml 2009-07-26 15:56180,224a-------c:\windows\system32\nvudisp.exe 2009-07-26 15:5615,078a-------c:\windows\system32\nvdisp.nvu 2009-07-26 15:56--d-----c:\windows\nview 2009-07-26 15:53--d-----c:\windows\system32\SoftwareDistribution 2009-07-26 15:51176,128a-------c:\windows\system32\nvuide.exe 2009-07-26 15:511,537a-------c:\windows\system32\nvide.nvu 2009-07-26 15:51176,128a-------c:\windows\system32\nvunrm.exe 2009-07-26 15:51100,480a-------c:\windows\system32\drivers\nvtcp.sys 2009-07-26 15:513,632a-------c:\windows\system32\nvnrm.nvu 2009-07-26 15:51176,128a-------c:\windows\system32\nvusmb.exe 2009-07-26 15:511,391a-------c:\windows\system32\nvsmb.nvu 2009-07-26 15:50--d-----c:\windows\system32\ReinstallBackups 2009-07-26 15:50176,128a-------c:\windows\system32\NVUNINST.EXE ==================== Find3M ==================== 2009-08-22 13:1686,327a-------c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-06-15 21:4621,640a-------c:\windows\system32\emptyregdb.dat ============= FINISH: 17:20:45.40 =============== _______________________________________ ____________ UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 6/15/2009 9:51:20 PM System Uptime: 8/22/2009 1:50:23 PM (4 hours ago) Motherboard: First International Computer, Inc. | | K8MC51G Processor: AMD Sempron(tm) Processor 3400+ | Socket 754 | 2009/201mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 145 GiB total, 136.741 GiB free. D: is Removable E: is Removable F: is Removable G: is Removable H: is FIXED (FAT32) - 4 GiB total, 2.306 GiB free. I: is CDROM (UDF) ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP1: 6/15/2009 9:55:21 PM - System Checkpoint RP2: 6/15/2009 10:44:36 PM - Installed Adobe Reader 7.0 RP3: 6/17/2009 3:16:25 PM - System Checkpoint RP4: 6/17/2009 3:22:25 PM - Installed Windows Installer KB893803v2. RP5: 7/26/2009 4:00:02 PM - Installed Realtek AC'97 Audio RP6: 7/26/2009 4:16:01 PM - Installed Microsoft Office Enterprise 2007 RP7: 7/26/2009 4:21:44 PM - Printer Driver Send To Microsoft OneNote Driver Installed RP8: 7/26/2009 4:25:23 PM - Installed Windows Media Player 11 RP9: 7/26/2009 4:25:52 PM - Software Distribution Service 3.0 RP10: 8/5/2009 1:57:04 PM - System Checkpoint RP11: 8/6/2009 12:21:51 PM - Printer Driver Canon iP1600 Installed RP12: 8/7/2009 12:39:20 PM - System Checkpoint RP13: 8/9/2009 6:30:33 PM - System Checkpoint RP14: 8/9/2009 8:31:43 PM - Printer Driver Canon iP1600 Installed RP15: 8/10/2009 11:03:05 AM - Installed walkway2paradisess RP16: 8/11/2009 11:54:42 AM - System Checkpoint RP17: 8/12/2009 12:54:46 PM - System Checkpoint RP18: 8/13/2009 1:54:44 PM - System Checkpoint RP19: 8/14/2009 4:19:26 PM - System Checkpoint RP20: 8/15/2009 4:46:26 PM - System Checkpoint RP21: 8/17/2009 4:41:59 PM - System Checkpoint RP22: 8/20/2009 11:04:57 PM - System Checkpoint RP23: 8/22/2009 12:05:31 AM - Removed walkway2paradisess RP24: 8/22/2009 12:49:31 PM - Software Distribution Service 3.0 RP25: 8/22/2009 1:05:35 PM - Software Distribution Service 3.0 RP26: 8/22/2009 2:29:11 PM - Software Distribution Service 3.0 ==== Installed Programs ====================== a-squared Free 4.5 Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 7.0 BitTorrent Canon iP1600 DivX Web Player Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) IrfanView (remove only) Microsoft .NET Framework 2.0 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft VC9 runtime libraries Mozilla Firefox (3.5.2) MSXML 4.0 NVIDIA Drivers Panda Cloud Antivirus Realtek AC'97 Audio Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB960225) Seekapp 1.0 build 147 Soft Data Fax Modem with SmartCP Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) VC80CRTRedist - 8.0.50727.762 Visual C++ 8.0 CRT (x86) WinSXS MSM WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 ==== Event Viewer Messages From Past Week ======== 8/22/2009 11:57:06 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 8/22/2009 11:47:03 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046} 8/22/2009 11:46:50 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips IPSec MRxSmb NetBIOS NetBT Processor PSINKNC RasAcd Rdbss Tcpip 8/22/2009 11:46:50 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 8/22/2009 11:46:50 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 8/22/2009 11:46:50 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 8/22/2009 11:46:50 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 8/22/2009 11:46:50 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 8/22/2009 11:46:49 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 8/22/2009 11:46:48 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 8/17/2009 2:25:02 PM, error: Dhcp [1002] - The IP address lease 192.168.2.3 for the Network Card with network address 0040CA9200A0 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). ==== End Of File =========================== Thanks again! Let me know if you foud anything else..Go to Add or Remove Programs and uninstall: Seekapp 1.0 build 147 ---------- Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop DO NOT run it yet! Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Driver:: SeekappSrch Service DDS:: IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe Firefox:: FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll Folder:: c:\docume~1\alluse~1\applic~1\Viewpoint C:\Documents and Settings\All Users\Application Data\SeekappSrch C:\Program Files\SeekappSrch c:\program files\messenger c:\program files\viewpoint File:: c:\windows\system32\SETA9.tmp c:\windows\system32\SETA5.tmp 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze ComboFix 09-08-22.06 - Cassaundra 08/22/2009 17:50.1.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.478.212 [GMT -4:00] Running from: c:\documents and settings\Cassaundra\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Cassaundra\Desktop\CFScript.txt AV: Panda Cloud Antivirus *On-access scanning disabled* (Updated) {5AD27692-540A-464E-B625-78275FA38393} FILE :: "c:\windows\system32\SETA5.tmp" "c:\windows\system32\SETA9.tmp" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\alluse~1\applic~1\Viewpoint c:\program files\messenger c:\program files\messenger\custsat.dll c:\program files\messenger\logowin.gif c:\program files\messenger\lvback.gif c:\program files\messenger\msgsc.dll c:\program files\messenger\msgslang.dll c:\program files\messenger\msmsgs.exe c:\program files\messenger\newalert.wav c:\program files\messenger\newemail.wav c:\program files\messenger\online.wav c:\program files\messenger\type.wav c:\program files\messenger\xpmsgr.chm c:\program files\SeekappSrch c:\program files\SeekappSrch\SeekappSrch_deleted_\seekapp.dll c:\program files\SeekappSrch\SeekappSrch_deleted_\seekappsrch.exe c:\windows\system32\_000006_.tmp.dll c:\windows\system32\SETA5.tmp c:\windows\system32\SETA9.tmp H:\Autorun.inf . ((((((((((((((((((((((((( Files Created from 2009-07-22 to 2009-08-22 ))))))))))))))))))))))))))))))) . 2009-08-22 20:25 . 2009-08-22 21:36--------d-----w-c:\program files\a-squared Free 2009-08-22 18:19 . 2008-12-11 10:57333952-c----w-c:\windows\system32\dllcache\srv.sys 2009-08-22 18:18 . 2008-10-24 11:21455296-c----w-c:\windows\system32\dllcache\mrxsmb.sys 2009-08-22 18:18 . 2008-09-04 17:151106944-c----w-c:\windows\system32\dllcache\msxml3.dll 2009-08-22 18:18 . 2008-10-15 16:34337408-c----w-c:\windows\system32\dllcache\netapi32.dll 2009-08-22 18:18 . 2008-05-01 14:33331776-c----w-c:\windows\system32\dllcache\msadce.dll 2009-08-22 18:17 . 2008-04-11 19:04691712-c----w-c:\windows\system32\dllcache\inetcomm.dll 2009-08-22 18:16 . 2008-06-13 11:05272128-c----w-c:\windows\system32\dllcache\bthport.sys 2009-08-22 18:16 . 2008-05-08 14:02203136-c----w-c:\windows\system32\dllcache\rmcast.sys 2009-08-22 17:14 . 2009-08-22 17:14--------d-----w-c:\windows\system32\scripting 2009-08-22 17:14 . 2009-08-22 17:14--------d-----w-c:\windows\l2schemas 2009-08-22 17:14 . 2009-08-22 17:14--------d-----w-c:\windows\system32\en 2009-08-22 17:14 . 2009-08-22 17:14--------d-----w-c:\windows\system32\bits 2009-08-22 17:12 . 2009-08-22 17:12--------d-----w-c:\windows\ServicePackFiles 2009-08-22 17:01 . 2004-08-04 02:2973216------w-c:\windows\system32\drivers\atintuxx.sys 2009-08-22 16:49 . 2009-08-22 18:31--------d--h--w-c:\windows\$hf_mig$ 2009-08-22 16:47 . 2009-08-22 16:47--------d-s---w-c:\documents and settings\Cassaundra\UserData 2009-08-22 15:47 . 2009-08-22 15:47--------d-----w-c:\documents and settings\Cassaundra\Application Data\Malwarebytes 2009-08-22 15:47 . 2009-08-22 15:47--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2009-08-22 14:28 . 2009-08-22 14:28--------d-----w-c:\program files\Trend Micro 2009-08-22 14:08 . 2009-08-22 14:08--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-08-21 14:09 . 2009-08-21 14:09--------d-----w-c:\documents and settings\Cassaundra\Application Data\Panda Security 2009-08-21 14:06 . 2009-08-21 14:06245----a-w-c:\windows\system32\PSUNCpl.dat 2009-08-21 14:06 . 2009-08-21 14:06--------d-----w-c:\program files\Panda Security 2009-08-21 14:06 . 2009-08-21 14:06--------d-----w-c:\documents and settings\All Users\Application Data\Panda Security 2009-08-14 23:11 . 2009-08-14 23:11--------d-----w-c:\program files\DivX 2009-08-14 23:11 . 2009-08-14 23:11--------d-----w-c:\program files\Common Files\DivX Shared 2009-08-12 02:39 . 2004-08-04 06:5625600----a-w-c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll 2009-08-10 00:32 . 2009-08-10 00:32--------d-----w-c:\program files\IrfanView 2009-08-06 16:23 . 2006-07-11 09:0090624----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0409\CNMlr75.dll 2009-08-06 16:23 . 2006-07-11 09:0069632----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0409\CNMsr75.dll 2009-08-06 16:23 . 2006-07-11 09:0054272----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0411\CNMlr75.dll 2009-08-06 16:23 . 2006-07-11 09:0040448----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0411\CNMsr75.dll 2009-08-06 16:23 . 2006-07-11 09:00254464----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0409\CNMur75.dll 2009-08-06 16:23 . 2006-07-11 09:00192512----a-w-c:\documents and settings\All Users\Application Data\CanonBJ\IJPrinter\CNMWINDOWS\Canon iP1600\LanguageModules\0411\CNMur75.dll 2009-08-06 16:06 . 2008-04-13 18:4725856----a-w-c:\windows\system32\drivers\usbprint.sys 2009-07-26 20:27 . 2009-07-26 20:27--------d-----w-c:\program files\Windows Media Connect 2 2009-07-26 20:26 . 2009-07-26 20:26--------d-----w-c:\windows\system32\drivers\UMDF 2009-07-26 20:26 . 2009-07-26 20:26--------d-----w-c:\windows\system32\LogFiles 2009-07-26 20:26 . 2007-08-11 00:4626488----a-w-c:\windows\system32\spupdsvc.exe 2009-07-26 20:21 . 2006-10-27 02:5632592----a-w-c:\windows\system32\msonpmon.dll 2009-07-26 20:20 . 2009-07-26 20:20--------d-----w-c:\program files\Microsoft Works 2009-07-26 20:20 . 2009-07-26 20:20--------d-----w-c:\program files\MSBuild 2009-07-26 20:19 . 2009-07-26 20:19--------d-----w-c:\program files\Microsoft.NET 2009-07-26 20:17 . 2009-07-26 20:17--------d-----w-c:\program files\Microsoft Visual Studio 8 2009-07-26 20:16 . 2009-07-26 20:20--------d-----w-c:\windows\SHELLNEW 2009-07-26 20:16 . 2009-07-26 20:16--------d-----w-c:\documents and settings\Cassaundra\Local Settings\Application Data\Microsoft Help 2009-07-26 20:16 . 2009-07-26 20:22--------d-----w-c:\documents and settings\All Users\Application Data\Microsoft Help 2009-07-26 20:16 . 2009-07-26 20:16--------d--h--r-C:\MSOCache 2009-07-26 20:08 . 2009-07-26 20:08--------d-----w-c:\documents and settings\Cassaundra\Local Settings\Application Data\AOL 2009-07-26 20:08 . 2009-07-26 20:08--------d-----w-c:\documents and settings\All Users\Application Data\AOL OCP 2009-07-26 20:08 . 2009-07-26 20:08--------d-----w-c:\documents and settings\All Users\Application Data\AOL 2009-07-26 20:08 . 2009-08-22 17:23--------d-----w-c:\program files\Common Files\AOL 2009-07-26 20:06 . 2009-07-26 20:060----a-w-c:\windows\nsreg.dat 2009-07-26 20:06 . 2009-07-26 20:06--------d-----w-c:\documents and settings\Cassaundra\Local Settings\Application Data\Mozilla 2009-07-26 20:03 . 2009-07-26 20:03--------d-----w-c:\program files\CONEXANT 2009-07-26 19:56 . 2009-07-26 20:04--------d-----w-c:\windows\nview 2009-07-26 19:56 . 2005-09-18 15:32180224----a-w-c:\windows\system32\nvudisp.exe 2009-07-26 19:51 . 2005-09-09 20:51176128----a-w-c:\windows\system32\nvuide.exe 2009-07-26 19:51 . 2005-09-09 20:51176128----a-w-c:\windows\system32\nvunrm.exe 2009-07-26 19:51 . 2005-07-30 02:10100480----a-w-c:\windows\system32\drivers\nvtcp.sys 2009-07-26 19:51 . 2005-09-09 22:51176128----a-w-c:\windows\system32\nvusmb.exe 2009-07-26 19:50 . 2005-09-09 20:51176128----a-w-c:\windows\system32\NVUNINST.EXE 2009-07-26 19:50 . 2009-07-26 19:50--------d-----w-c:\program files\Common Files\InstallShield 2009-07-26 19:47 . 2006-05-24 01:04110592----a-w-c:\documents and settings\Cassaundra\Application Data\U3\temp\cleanup.exe 2009-07-26 19:46 . 2009-07-26 19:49--------d-----w-c:\documents and settings\Cassaundra\Application Data\U3 . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-08-22 17:16 . 2009-06-16 01:4886327----a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-08-06 16:21 . 2009-08-06 16:21--------d--h--w-c:\documents and settings\All Users\Application Data\CanonBJ 2009-07-26 20:00 . 2009-07-26 20:00--------d-----w-c:\program files\Realtek Sound Manager 2009-07-26 20:00 . 2009-07-26 20:00--------d-----w-c:\program files\AvRack 2009-07-26 20:00 . 2009-07-26 20:00--------d-----w-c:\program files\Realtek AC97 2009-07-26 20:00 . 2009-07-26 20:00--------d--h--w-c:\program files\InstallShield Installation Information 2009-06-23 14:04 . 2009-06-23 14:04136072----a-w-c:\windows\system32\drivers\PSINAflt.sys 2009-06-23 14:04 . 2009-06-23 14:04114056----a-w-c:\windows\system32\drivers\PSINKNC.sys 2009-06-16 01:55 . 2009-06-16 01:5512328----a-w-c:\documents and settings\Cassaundra\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-16 01:46 . 2009-06-16 01:4621640----a-w-c:\windows\system32\emptyregdb.dat 2009-06-04 20:16 . 2009-06-04 20:1698184----a-w-c:\windows\system32\drivers\PSINProc.sys 2009-06-04 20:16 . 2009-06-04 20:1692552----a-w-c:\windows\system32\drivers\PSINFile.sys 2009-05-01 21:02 . 2009-05-01 21:021044480----a-w-c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02200704----a-w-c:\program files\mozilla firefox\plugins\ssldivx.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Malware Icon] @="{E309578C-8EDE-4731-99FA-6810B408B1BC}" [HKEY_CLASSES_ROOT\CLSID\{E309578C-8EDE-4731-99FA-6810B408B1BC}] 2009-06-18 21:51283904----a-w-c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Pending Delete Icon] @="{1D0B2E83-D473-4E1F-B213-AA7BC759DE20}" [HKEY_CLASSES_ROOT\CLSID\{1D0B2E83-D473-4E1F-B213-AA7BC759DE20}] 2009-06-18 21:51283904----a-w-c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Panda Suspect Icon] @="{B26DA910-F1DE-426A-8282-5B55958E11B6}" [HKEY_CLASSES_ROOT\CLSID\{B26DA910-F1DE-426A-8282-5B55958E11B6}] 2009-06-18 21:51283904----a-w-c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-09-18 7204864] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-09-18 86016] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "PSUNMain"="c:\program files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" [2009-06-04 353536] "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-09-18 1519616] "SoundMan"="SOUNDMAN.EXE" - c:\windows\soundman.exe [2005-12-15 577536] c:\documents and settings\Cassaundra\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696] [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= R1 PSINKNC;PSINKNC;c:\windows\system32\drivers\PSINKNC.sys [6/23/2009 10:04 AM 114056] R2 NanoServiceMain;NanoServiceMain;c:\program files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [4/23/2009 8:14 PM 95488] R2 PSINAflt;PSINAflt;c:\windows\system32\drivers\PSINAflt.sys [6/23/2009 10:04 AM 136072] R2 PSINFile;PSINFile;c:\windows\system32\drivers\PSINFile.sys [6/4/2009 4:16 PM 92552] R2 PSINProc;PSINProc;c:\windows\system32\drivers\PSINProc.sys [6/4/2009 4:16 PM 98184] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys --> c:\windows\system32\drivers\mbamswissarmy.sys [?] . . ------- Supplementary Scan ------- . uStart Page = hxxp://google.com/ IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Cassaundra\Application Data\Mozilla\Firefox\Profiles\23gmjj1q.default\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default _setting", true); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_pa ge", "certerror"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_ enter", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-08-22 17:55 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(3004) c:\program files\Panda Security\Panda Cloud Antivirus\PSUNShell.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\nvsvc32.exe c:\windows\system32\rundll32.exe . ************************************************************************** . Completion time: 2009-08-22 17:58 - machine was rebooted ComboFix-quarantined-files.txt 2009-08-22 21:58 Pre-Run: 146,827,730,944 bytes free Post-Run: 147,095,777,280 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect /TUTag=1CVMII /Kernel=TUKernel.exe multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition (TuneUp Backup)" /noexecute=optin /fastdetect /TUTag=1CVMII-BAK 253 Looks a lot better. Is the computer running OK now? * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. |
|
| 3825. |
Solve : vulnerabilities? |
|
Answer» I checked my SECURITY centre and my Windows is already up to date. Java still failed to be installed, with the same message.
Java still failed to be installed. Would you recommend "System Restore"? I have been able to update both Adobe and Java in April 2009.It's worth a try.I wanted to go back to April 2009, but the restore points shown in System Restore only go back to 5/8/2009. Is there any way I can go back to April 2009?If it isn't there then no you can't.Sorry to report that System Restore couldn't solve the problem either. Though I'm still out on a limb, i want to thank you very much for the trouble and time you took. Is it going to have to be the final drastic measure of product recovery for my computer?why didnt you remove it from the control panel i think because you just deleted it now it wont install You can try POSTING in the Computer Help section. Someone there will have some ideas.Ok. I'll post it in Computer Help section. |
|
| 3826. |
Solve : Trojan Horse Clicker ZGZ Infected file too large for archives? |
|
Answer» Hello: I use an XP service pack 3 and I have the free AVG Anti-virus completely updated. After updating I did a scan and found two infected files, both infected with Trojan Horse Clicker.ZGZ When I try to REMOVE the infected files, I GET the message from AVG: "Moved OBJECT is bigger than the ARCHIVE size limit" and so it doesn't remove the infected file. What can I do to get RID of this? |
|
| 3827. |
Solve : Running Windows Vista Firewall in Tandem with Comodo? |
|
Answer» Hi, Is it necessary/efficient to run another firewall such as Commodo or Zonealarm - or is the whole idea of Vista to be self sufficient?No. You should only have one firewall running on your PC. Stick with Comodo, and TURN off Windows Firewall. |
|
| 3828. |
Solve : Debilitating typing/clicking errors? |
|
Answer» I had posted a topic in the the Windows XP section of the forum previously, but nothing suggested seemed to clear up my problem, so I was told to post here. |
|
| 3829. |
Solve : computer acting funny and lots of ads-do i have spyware?? |
|
Answer» i will remove one after this is fixed i will remove one after this is fixed Yes they do conflict. At the very LEAST they are interupting each others processes to scan what the other is doing. Do what ADG suggests there, get rid of McAfee.here is my avira log Code: [Select] Avira AntiVir Personal Report file DATE: Sunday, August 23, 2009 11:05 Scanning for 1651917 virus strains and unwanted programs. Licensee : Avira AntiVir Personal - FREE Antivirus Serial number : 0000149996-ADJIE-0000001 Platform : Windows Vista Windows version : (Service Pack 1) [6.0.6001] Boot mode : Normally booted Username : SYSTEM Computer name : JOHN-PC Version information: BUILD.DAT : 9.0.0.407 17961 Bytes 7/29/2009 10:34:00 AVSCAN.EXE : 9.0.3.7 466689 Bytes 7/21/2009 21:36:14 AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 18:58:24 LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 19:35:49 LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 18:58:52 ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 20:30:36 ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 6/24/2009 17:21:42 ANTIVIR2.VDF : 7.1.5.146 3087360 Bytes 8/21/2009 00:36:58 ANTIVIR3.VDF : 7.1.5.149 9728 Bytes 8/21/2009 00:36:59 Engineversion : 8.2.1.3 AEVDF.DLL : 8.1.1.1 106868 Bytes 7/28/2009 21:31:50 AESCRIPT.DLL : 8.1.2.25 459130 Bytes 8/23/2009 00:37:12 AESCN.DLL : 8.1.2.4 127348 Bytes 7/23/2009 17:59:39 AERDL.DLL : 8.1.2.4 430452 Bytes 7/23/2009 17:59:39 AEPACK.DLL : 8.1.3.18 401783 Bytes 7/28/2009 21:31:50 AEOFFICE.DLL : 8.1.0.38 196987 Bytes 7/23/2009 17:59:39 AEHEUR.DLL : 8.1.0.155 1921400 Bytes 8/23/2009 00:37:10 AEHELP.DLL : 8.1.6.0 233846 Bytes 8/23/2009 00:37:03 AEGEN.DLL : 8.1.1.57 356725 Bytes 8/23/2009 00:37:01 AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 22:32:40 AECORE.DLL : 8.1.7.6 184694 Bytes 7/23/2009 17:59:39 AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 22:32:40 AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 16:47:59 AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 18:32:15 AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 22:34:28 AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 18:32:09 AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 23:05:41 AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 18:37:08 SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 23:03:49 SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 16:21:33 NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 18:32:10 RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 23:39:58 RCTEXT.DLL : 9.0.37.0 86785 Bytes 4/17/2009 18:19:48 Configuration settings for the scan: Jobname.............................: Complete system scan Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp Logging.............................: low Primary action......................: interactive Secondary action....................: ignore Scan master boot sector.............: on Scan boot sector....................: on Boot SECTORS........................: C:, D:, M:, O:, Process scan........................: on Scan registry.......................: on Search for rootkits.................: on Integrity checking of system files..: off Scan all files......................: All files Scan archives.......................: on Recursion depth.....................: 20 Smart extensions....................: on Macro heuristic.....................: on File heuristic......................: medium Deviating risk categories...........: +JOKE, Start of the scan: Sunday, August 23, 2009 11:05 Starting search for hidden objects. '222294' objects were checked, '0' hidden objects were found. The scan of running processes will be started Scan process 'taskeng.exe' - '1' Module(s) have been scanned Scan process 'iexplore.exe' - '1' Module(s) have been scanned Scan process 'speedfan.exe' - '1' Module(s) have been scanned Scan process 'dllhost.exe' - '1' Module(s) have been scanned Scan process '3DMark03.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'sdclt.exe' - '1' Module(s) have been scanned Scan process 'mcupdate.exe' - '1' Module(s) have been scanned Scan process 'taskeng.exe' - '1' Module(s) have been scanned Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'mcuimgr.exe' - '1' Module(s) have been scanned Scan process 'McNASvc.exe' - '1' Module(s) have been scanned Scan process 'mcsysmon.exe' - '1' Module(s) have been scanned Scan process 'RtkBtMnt.exe' - '1' Module(s) have been scanned Scan process 'unsecapp.exe' - '1' Module(s) have been scanned Scan process 'winThrottle.exe' - '1' Module(s) have been scanned Scan process 'taskeng.exe' - '1' Module(s) have been scanned Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned Scan process 'ehmsas.exe' - '1' Module(s) have been scanned Scan process 'igfxext.exe' - '1' Module(s) have been scanned Scan process 'BTTray.exe' - '1' Module(s) have been scanned Scan process 'SUPERAntiSpyware.exe' - '1' Module(s) have been scanned Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned Scan process 'ApntEx.exe' - '1' Module(s) have been scanned Scan process 'vivaty.exe' - '1' Module(s) have been scanned Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned Scan process 'ehtray.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'MC.exe' - '1' Module(s) have been scanned Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned Scan process 'igfxpers.exe' - '1' Module(s) have been scanned Scan process 'hkcmd.exe' - '1' Module(s) have been scanned Scan process 'realsched.exe' - '1' Module(s) have been scanned Scan process 'winampa.exe' - '1' Module(s) have been scanned Scan process 'jusched.exe' - '1' Module(s) have been scanned Scan process 'ApMsgFwd.exe' - '1' Module(s) have been scanned Scan process 'ePower_DMC.exe' - '1' Module(s) have been scanned Scan process 'GoogleDesktop.exe' - '1' Module(s) have been scanned Scan process 'Apoint.exe' - '1' Module(s) have been scanned Scan process 'BkupTray.exe' - '1' Module(s) have been scanned Scan process 'LManager.exe' - '1' Module(s) have been scanned Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned Scan process 'MSASCui.exe' - '1' Module(s) have been scanned Scan process 'mcagent.exe' - '1' Module(s) have been scanned Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned Scan process 'mcmscsvc.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'dwm.exe' - '1' Module(s) have been scanned Scan process 'XAudio.exe' - '1' Module(s) have been scanned Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'sqlwriter.exe' - '1' Module(s) have been scanned Scan process 'sqlbrowser.exe' - '1' Module(s) have been scanned Scan process 'PsiService_2.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'SchedulerSvc.exe' - '1' Module(s) have been scanned Scan process 'BackupSvc.exe' - '1' Module(s) have been scanned Scan process 'SMSvcHost.exe' - '1' Module(s) have been scanned Scan process 'sqlservr.exe' - '1' Module(s) have been scanned Scan process 'msksrver.exe' - '1' Module(s) have been scanned Scan process 'MpfSrv.exe' - '1' Module(s) have been scanned Scan process 'MobilityService.exe' - '1' Module(s) have been scanned Scan process 'Mcshield.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'McProxy.exe' - '1' Module(s) have been scanned Scan process 'McSACore.exe' - '1' Module(s) have been scanned Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned Scan process 'iviRegMgr.exe' - '1' Module(s) have been scanned Scan process 'ETService.exe' - '1' Module(s) have been scanned Scan process 'Agentsvc.exe' - '1' Module(s) have been scanned Scan process 'btwdins.exe' - '1' Module(s) have been scanned Scan process 'BcmSqlStartupSvc.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'taskeng.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'SLsvc.exe' - '1' Module(s) have been scanned Scan process 'audiodg.exe' - '0' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'lsm.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'wininit.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 98 processes with 98 modules were scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Boot sector 'D:\' [INFO] No virus was found! Boot sector 'M:\' [INFO] No virus was found! Boot sector 'O:\' [INFO] No virus was found! Starting to scan executable files (registry). The registry was scanned ( '95' files ). Starting the file scan: Begin scan in 'C:\' <ACER> C:\pagefile.sys [WARNING] The file could not be opened! [NOTE] This file is a Windows system file. [NOTE] This file cannot be opened for scanning. C:\blackcat\TEST\DDTEST.EXE [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan C:\blackcat\TEST\SDLTEST.EXE [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan C:\cygnew\bin\camlp4.exe [WARNING] The file could not be opened! C:\cygnew\bin\camlp4o.exe [WARNING] The file could not be opened! C:\cygnew\bin\camlp4o.opt.exe [WARNING] The file could not be opened! C:\cygnew\bin\camlp4r.exe [WARNING] The file could not be opened! C:\cygnew\bin\camlp4r.opt.exe [WARNING] The file could not be opened! C:\cygnew\bin\lyx.exe [WARNING] The file could not be opened! C:\cygnew\bin\lyxclient.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocaml.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamlbrowser.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamlc.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamlc.opt.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamlcp.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamldebug.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamldep.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamldep.opt.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamldoc.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamldoc.opt.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamllex.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamllex.opt.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamlopt.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamlopt.opt.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamlprof.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamlrun.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocamlyacc.exe [WARNING] The file could not be opened! C:\cygnew\bin\ocpp.exe [WARNING] The file could not be opened! C:\cygnew\bin\tex2lyx.exe [WARNING] The file could not be opened! C:\cygnew\lib\ocaml\camlheader [DETECTION] Is the TR/Dropper.Gen Trojan C:\cygnew\lib\ocaml\camlheader_ur [DETECTION] Is the TR/Dropper.Gen Trojan C:\cygnew\lib\ocaml\expunge.exe [WARNING] The file could not be opened! C:\MinGW\bin\mklinkstub.exe [DETECTION] Is the TR/Dropper.Gen Trojan C:\Program Files\Cain\Abel.exe [DETECTION] Is the TR/Crypt.ULPM.Gen Trojan C:\Program Files\Silicon Pixels\CPIX\CPIX16.EXE [DETECTION] Is the TR/Dropper.Gen Trojan C:\tc\TCC\NONP.EXE [DETECTION] Contains recognition pattern of the DOS/Candy DOS virus C:\tc\TCC\PARSE.EXE [DETECTION] Contains recognition pattern of the DOS/Candy DOS virus C:\windows\system32\eula.txt [DETECTION] Is the TR/Dropper.Gen Trojan C:\windows\system32\_joker123.bin [DETECTION] Contains recognition pattern of the DOS/Candy DOS virus Begin scan in 'D:\' <DATA> D:\pagefile.sys [WARNING] The file could not be opened! D:\snf.exe [DETECTION] Is the TR/Dldr.Small.ewd.2 Trojan D:\Bouncey ball\snf.exe [DETECTION] Is the TR/Dldr.Small.ewd.2 Trojan D:\Bouncey ball\snf2.exe [DETECTION] Is the TR/Dldr.Small.ewd.2 Trojan D:\devkitadv\bin\mklinkstub.exe [DETECTION] Is the TR/Dropper.Gen Trojan D:\dosex\TEST\DDTEST.EXE [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan D:\dosex\TEST\SDLTEST.EXE [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan D:\doxex\TEST\DDTEST.EXE [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan D:\gbadev\devkitadv\bin\mklinkstub.exe [DETECTION] Is the TR/Dropper.Gen Trojan D:\hx\TEST\DDTEST.EXE [DETECTION] Is the TR/Crypt.XPACK.Gen Trojan D:\reactos\ReactOS-0.3.9\output-i386\base\applications\network\dwnl\dwnl.exe [DETECTION] Is the TR/Dropper.Gen Trojan D:\reactos\ReactOS-0.3.9\output-i386\livecd\reactos\system32\dwnl.exe [DETECTION] Is the TR/Dropper.Gen Trojan Begin scan in 'M:\' <PQSERVICE> M:\pagefile.sys [WARNING] The file could not be opened! Begin scan in 'O:\' Quote from: SuperDave on August 21, 2009, 07:24:18 PM Smeezekitty, you should run SuperAntispyware and Malwarebytes-Antimalware programs found here and post the logs. Also run HJT again and post the log. |
|
| 3830. |
Solve : My MBAM says that I have a worm, but I can't get rid of it. Any help?? |
|
Answer» I ATTACHED my logs. I don't know if it is something I should worry about. Just THOUGHT I would GET some advice. My MBAM says I have a worm, but I think it could be wrong. Thanks in ADVANCE for any help. |
|
| 3831. |
Solve : Antivirus 2010,,,,,,,,,,,,,,? |
|
Answer» I got rid of limewire and windows messenger alsoyou have a few things that a malware expert will help you with so wait for one to get in touch please |
|
| 3832. |
Solve : help with security center malware? |
|
Answer» Morning SD, |
|
| 3833. |
Solve : Re: "Your System is Infected" is virus leeching my computer - help please! :)? |
|
Answer» Hi, first post coming here but I had the exact same problem from a rogue anto-virus software called internet security2010, i got RID of the anti-virus with SPYWARE DOCTOR, and fixed the obviously FAKE background with the file suggested on the first page of this thread, and it worked! So I hope you can fix yours soonPlease go to this link and follow the DIRECTIONS and post the required logs. |
|
| 3834. |
Solve : Administrator Problem? |
|
Answer» HI everyone, my boyfriend and I have a computer and his sister set it up for us. She has him as the "ADMINISTRATOR" and me I guess as a regular user. She is on vacation, so I can't ask her and I know the computer has a virsus because it didn't have any protection when my bf started to use it and it is really, really slow. I brought Norton anti-virus and want to install it, but it will not let me install it because I am not the administrator. How do I make myself an administrator??? thank you. I want to install it but my bf thinks we don't need it so that is why he is not installing it, so I have to do it!You have to be an administrator to change user account rights. Sorry, but you'll have to ask your boyfriend to either install it or make you an administrator too.okay thank you I will try!That, or log in as your bf. |
|
| 3835. |
Solve : strange things happening again? |
|
Answer» latest update |
|
| 3836. |
Solve : Painfully Slow Computer? |
|
Answer» My friend has a computer that runs ultra slow. |
|
| 3837. |
Solve : Double the fun!? |
|
Answer» Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and PRESSING Ctrl+C Code: [Select]KillAll:: Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"=- "57086:TCP"=- "57086:UDP"=- RegLockDel:: [HKEY_LOCAL_MACHINE\software\Classes\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{15FD8424-D12A-4C51-8C6C-D5D57B80F781}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{40CA90F3-4098-4877-AE87-23EB612B18C7}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{40CA90F3-4098-4877-AE87-23EB612B18C7}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{40CA90F3-4098-4877-AE87-23EB612B18C7}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C3B62AF-CA25-4FBA-8405-32E44F83BB6F}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C3B62AF-CA25-4FBA-8405-32E44F83BB6F}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{4C3B62AF-CA25-4FBA-8405-32E44F83BB6F}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{5A635A91-C303-45C9-8DB9-F759D98A3B9D}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{5A635A91-C303-45C9-8DB9-F759D98A3B9D}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{5A635A91-C303-45C9-8DB9-F759D98A3B9D}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{67B3BECF-7B6F-42B2-99F0-F7656F89CFFA}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{715FFD42-4E05-4EAB-9513-C8DAA5395AE2}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{759D6F7C-8D30-45B6-ABEA-FA51C190EED5}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{7E335D04-2E6E-4D0E-A921-C3D9192E7121}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{7E335D04-2E6E-4D0E-A921-C3D9192E7121}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{7E335D04-2E6E-4D0E-A921-C3D9192E7121}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{99CCFB8C-6380-4A14-8FDD-EF3E7E95335D}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{99CCFB8C-6380-4A14-8FDD-EF3E7E95335D}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{99CCFB8C-6380-4A14-8FDD-EF3E7E95335D}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{9A4A64A4-A2FB-48FA-9BBA-1AC50267695D}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{B20D7ADD-989C-4BC0-A797-F6FE7998EFD7}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{B20D7ADD-989C-4BC0-A797-F6FE7998EFD7}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{B20D7ADD-989C-4BC0-A797-F6FE7998EFD7}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{BFC20A15-B0AC-44CC-A25A-A7039014BA9F}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{BFC20A15-B0AC-44CC-A25A-A7039014BA9F}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{BFC20A15-B0AC-44CC-A25A-A7039014BA9F}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{F019AEC4-4C95-46DE-A107-E302473E3B9A}\ProxyStubClsid] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{F019AEC4-4C95-46DE-A107-E302473E3B9A}\ProxyStubClsid32] [HKEY_LOCAL_MACHINE\software\Classes\Interface\{F019AEC4-4C95-46DE-A107-E302473E3B9A}\TypeLib] [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{0729F461-8054-47DC-8D39-A31B61CC0119}\1.0] [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{C62A9E79-2B52-439B-AF57-2E60BB06E86C}\1.0] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > SAVE 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeAs requested: ComboFix 09-06-26.02 - Dad 06/27/2009 19:56.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1007.572 [GMT -7:00] Running from: c:\documents and settings\Dad\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Dad\Desktop\CFScript.txt AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} . ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-28 ))))))))))))))))))))))))))))))) . 2009-06-28 02:02 . 2009-06-28 02:02--------d-----w-c:\windows\system32\dllcache\cache 2009-06-27 21:03 . 2009-06-27 21:03--------d--h--w-c:\windows\PIF 2009-06-27 06:55 . 2009-06-27 06:55--------d-----w-c:\documents and settings\Dad\Application Data\Malwarebytes 2009-06-27 06:50 . 2009-06-27 06:54--------d-----w-c:\program files\SUPERAntiSpyware 2009-06-27 06:27 . 2009-06-27 18:06117760----a-w-c:\documents and settings\Dad\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-27 06:27 . 2009-06-27 06:27--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-06-27 06:20 . 2009-06-27 06:20--------d-----w-c:\documents and settings\Dad\Application Data\SUPERAntiSpyware.com 2009-06-27 05:46 . 2009-06-27 05:46--------d-----w-c:\program files\Trend Micro 2009-06-27 05:40 . 2009-06-27 05:39410984----a-w-c:\windows\system32\deploytk.dll 2009-06-26 07:45 . 2009-03-30 17:3396104----a-w-c:\windows\system32\drivers\avipbb.sys 2009-06-26 07:45 . 2009-03-24 23:0855640----a-w-c:\windows\system32\drivers\avgntflt.sys 2009-06-26 07:45 . 2009-02-13 19:2922360----a-w-c:\windows\system32\drivers\avgntmgr.sys 2009-06-26 07:45 . 2009-02-13 19:1745416----a-w-c:\windows\system32\drivers\avgntdd.sys 2009-06-26 07:44 . 2009-06-26 07:44--------d-----w-c:\program files\Avira 2009-06-26 07:44 . 2009-06-26 07:44--------d-----w-c:\documents and settings\All Users\Application Data\Avira 2009-06-26 07:36 . 2009-06-17 18:2738160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-26 07:36 . 2009-06-26 07:36--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-26 07:36 . 2009-06-17 18:2719096----a-w-c:\windows\system32\drivers\mbam.sys 2009-06-22 00:48 . 2009-06-22 00:48--------d-----w-c:\program files\iPod 2009-06-22 00:48 . 2009-06-22 00:48--------d-----w-c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-06-22 00:46 . 2009-06-22 00:46--------d-----w-c:\program files\Bonjour 2009-06-22 00:45 . 2009-06-22 00:45--------d-----w-c:\program files\QuickTime 2009-06-22 00:43 . 2009-06-22 00:43--------d-----w-c:\program files\Apple Software Update 2009-06-21 22:50 . 2009-06-21 22:50--------d-----w-c:\documents and settings\Dad\Local Settings\Application Data\AOL 2009-06-05 20:57 . 2009-06-05 20:5775048----a-w-c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-27 23:55 . 2009-04-10 18:27--------d-----w-c:\documents and settings\All Users\Application Data\Viewpoint 2009-06-27 06:49 . 2002-01-04 09:43--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-06-27 05:39 . 2002-01-02 07:20--------d-----w-c:\program files\Java 2009-06-27 04:41 . 2007-07-22 04:02--------d-----w-c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-06-26 06:04 . 2007-03-25 15:4951936----a-w-c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-26 06:02 . 2002-01-02 07:21--------d-----w-c:\program files\OpenOffice.org 2.2 2009-06-26 05:56 . 2003-07-31 11:52--------d--h--w-c:\program files\InstallShield Installation Information 2009-06-26 05:52 . 2002-01-02 08:35--------d-----w-c:\documents and settings\Dad\Application Data\OpenOffice.org2 2009-06-26 05:52 . 2008-10-08 06:27--------d-----w-c:\documents and settings\Dad\Application Data\stickies 2009-06-26 05:20 . 2002-01-04 09:37--------d-----w-c:\program files\Common Files\Panda Software 2009-06-26 05:12 . 2008-11-25 19:33--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater 2009-06-22 00:48 . 2008-09-15 04:37--------d-----w-c:\program files\Common Files\Apple 2009-06-21 22:51 . 2009-04-10 18:24--------d-----w-c:\program files\Common Files\AOL 2009-06-09 17:09 . 2007-09-17 05:02--------d-----w-c:\documents and settings\Samuel.OAKTREE3\Application Data\OpenOffice.org2 2009-05-11 22:48 . 2009-05-11 22:2034----a-w-c:\documents and settings\Samuel.OAKTREE3\jagex_runescape_preferences.dat 2009-04-10 18:29 . 2009-04-10 18:291144808----a-w-c:\documents and settings\All Users\Application Data\AOL Downloads\aimtunes\AIMTunes.exe 2008-01-15 18:50 . 2007-10-21 07:101004--sha-w-c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((( [emailprotected]_01.59.41 ))))))))))))))))))))))))))))))))))))))))) . + 2009-06-28 03:02 . 2009-06-28 03:0216384 c:\windows\temp\Perflib_Perfdata_294.dat + 2009-06-28 02:02 . 2008-10-16 22:0951224 c:\windows\system32\dllcache\cache\wuauclt.exe + 2009-06-28 02:02 . 2004-08-04 07:5682944 c:\windows\system32\dllcache\cache\ws2_32.dll + 2009-06-28 02:02 . 2004-08-04 07:5624576 c:\windows\system32\dllcache\cache\userinit.exe + 2009-06-28 02:02 . 2004-08-04 07:5614336 c:\windows\system32\dllcache\cache\svchost.exe + 2009-06-28 02:02 . 2005-06-10 23:5357856 c:\windows\system32\dllcache\cache\spoolsv.exe + 2009-06-28 02:02 . 2004-08-04 07:5617408 c:\windows\system32\dllcache\cache\powrprof.dll + 2009-06-28 02:02 . 2004-08-04 07:5613312 c:\windows\system32\dllcache\cache\lsass.exe + 2009-06-28 02:02 . 2004-08-04 05:5824576 c:\windows\system32\dllcache\cache\kbdclass.sys + 2009-06-28 02:02 . 2004-08-04 06:0029056 c:\windows\system32\dllcache\cache\ip6fw.sys + 2009-06-28 02:02 . 2004-08-04 07:5615360 c:\windows\system32\dllcache\cache\ctfmon.exe + 2009-06-28 02:02 . 2004-08-04 07:56502272 c:\windows\system32\dllcache\cache\winlogon.exe + 2009-06-28 02:02 . 2008-10-16 10:37659456 c:\windows\system32\dllcache\cache\wininet.dll + 2009-06-28 02:02 . 2007-03-08 15:36577536 c:\windows\system32\dllcache\cache\user32.dll + 2009-06-28 02:02 . 2004-08-04 07:56295424 c:\windows\system32\dllcache\cache\termsrv.dll + 2009-06-28 02:02 . 2008-06-20 10:45360320 c:\windows\system32\dllcache\cache\tcpip.sys + 2009-06-28 02:02 . 2004-08-04 07:56108032 c:\windows\system32\dllcache\cache\services.exe + 2009-06-28 02:02 . 2004-08-04 06:14182912 c:\windows\system32\dllcache\cache\ndis.sys + 2009-06-28 02:02 . 2007-04-16 15:52984576 c:\windows\system32\dllcache\cache\kernel32.dll + 2009-06-28 02:02 . 2004-08-04 07:56110080 c:\windows\system32\dllcache\cache\imm32.dll + 2009-06-28 02:02 . 2004-08-04 07:56167936 c:\windows\system32\dllcache\cache\appmgmts.dll + 2009-06-28 02:02 . 2004-08-04 07:561580544 c:\windows\system32\dllcache\cache\sfcfiles.dll + 2009-06-28 02:02 . 2008-08-14 09:582136064 c:\windows\system32\dllcache\cache\ntoskrnl.exe + 2009-06-28 02:02 . 2008-08-14 09:222015744 c:\windows\system32\dllcache\cache\ntkrnlpa.exe + 2009-06-28 02:02 . 2007-06-13 10:231033216 c:\windows\system32\dllcache\cache\explorer.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}] 2009-04-21 00:181883672----a-w-c:\program files\Freecorder\tbFre1.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sony Ericsson PC Suite"="e:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-06-19 393216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544] "Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-04 143360] "AdaptecDirectCD"="c:\program files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2003-09-19 684032] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-27 148888] "AAWTray"="c:\program files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 88024] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "MBM 5"="c:\program files\Motherboard Monitor 5\MBM5.EXE" [2004-06-12 594944] "Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696] "iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 19:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "c:\\Documents and Settings\\Samuel.OAKTREE3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\Samuel.OAKTREE3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "e:\\Program Files\\iTunes\\iTunes.exe"= "e:\\Program Files\\Stickies\\stickies.exe"= R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/26/2009 12:45 AM 108289] S1 Multicam;MultiCam for Picolo;c:\windows\system32\Drivers\multicam.sys --> c:\windows\system32\Drivers\multicam.sys [?] S1 SASKUTIL;SASKUTIL;\??\e:\program files\SUPERAntiSpyware\SASKUTIL.sys --> e:\program files\SUPERAntiSpyware\SASKUTIL.sys [?] S3 AtomSync;AtomSync;e:\program files\AtomSync\service.exe [9/23/2008 10:34 PM 159744] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [5/20/2008 10:47 PM 13224] S3 SASENUM;SASENUM;\??\e:\program files\SUPERAntiSpyware\SASENUM.SYS --> e:\program files\SUPERAntiSpyware\SASENUM.SYS [?] . Contents of the 'Scheduled Tasks' folder 2009-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] 2009-06-28 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-02 01:16] 2009-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4265909289-2111342016-2801439982-1016.job - c:\documents and settings\Samuel.OAKTREE3\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-18 07:05] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.gbcph.org/ uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\b9k9d87q.default\ FF - prefs.js: browser.startup.homepage - www.gbcph.org FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: e:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll FF - plugin: e:\program files\iTunes\Mozilla Plugins\npitunes.dll FF - plugin: e:\program files\Mozilla Firefox\plugins\npmusicn.dll FF - plugin: e:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-27 20:03 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{0729F461-8054-47DC-8D39-A31B61CC0119}\1.0\0\win32] @DACL=(02 0000) @="c:\\Program Files\\Zango\\bin\\10.3.75.0\\CoreSrv.dll" [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{C62A9E79-2B52-439B-AF57-2E60BB06E86C}\1.0\0\win32] @DACL=(02 0000) @="c:\\Program Files\\Zango\\bin\\10.3.75.0\\Toolbar.dll" . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(856) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(1440) c:\progra~1\WINDOW~2\wmpband.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\HPZipm12.exe c:\program files\Analog Devices\SoundMAX\SMAgent.exe c:\windows\system32\MsPMSPSv.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-06-28 20:08 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-28 03:08 ComboFix2.txt 2009-06-28 02:04 Pre-Run: 108,959,559,680 bytes free Post-Run: 108,944,457,728 bytes free 214 Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Folder:: c:\Program Files\Zango RegLockDel:: [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{0729F461-8054-47DC-8D39-A31B61CC0119}\1.0\0\win32] [HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{C62A9E79-2B52-439B-AF57-2E60BB06E86C}\1.0\0\win32] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeComboFix 09-06-26.02 - Dad 06/27/2009 22:42.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1007.579 [GMT -7:00] Running from: c:\documents and settings\Dad\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Dad\Desktop\cfscript.txt AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} . ((((((((((((((((((((((((( Files Created from 2009-05-28 to 2009-06-28 ))))))))))))))))))))))))))))))) . 2009-06-28 02:02 . 2009-06-28 02:02--------d-----w-c:\windows\system32\dllcache\cache 2009-06-27 21:03 . 2009-06-27 21:03--------d--h--w-c:\windows\PIF 2009-06-27 06:55 . 2009-06-27 06:55--------d-----w-c:\documents and settings\Dad\Application Data\Malwarebytes 2009-06-27 06:50 . 2009-06-27 06:54--------d-----w-c:\program files\SUPERAntiSpyware 2009-06-27 06:27 . 2009-06-27 18:06117760----a-w-c:\documents and settings\Dad\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-06-27 06:27 . 2009-06-27 06:27--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-06-27 06:20 . 2009-06-27 06:20--------d-----w-c:\documents and settings\Dad\Application Data\SUPERAntiSpyware.com 2009-06-27 05:46 . 2009-06-27 05:46--------d-----w-c:\program files\Trend Micro 2009-06-27 05:40 . 2009-06-27 05:39410984----a-w-c:\windows\system32\deploytk.dll 2009-06-26 07:45 . 2009-03-30 17:3396104----a-w-c:\windows\system32\drivers\avipbb.sys 2009-06-26 07:45 . 2009-03-24 23:0855640----a-w-c:\windows\system32\drivers\avgntflt.sys 2009-06-26 07:45 . 2009-02-13 19:2922360----a-w-c:\windows\system32\drivers\avgntmgr.sys 2009-06-26 07:45 . 2009-02-13 19:1745416----a-w-c:\windows\system32\drivers\avgntdd.sys 2009-06-26 07:44 . 2009-06-26 07:44--------d-----w-c:\program files\Avira 2009-06-26 07:44 . 2009-06-26 07:44--------d-----w-c:\documents and settings\All Users\Application Data\Avira 2009-06-26 07:36 . 2009-06-17 18:2738160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-26 07:36 . 2009-06-26 07:36--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2009-06-26 07:36 . 2009-06-17 18:2719096----a-w-c:\windows\system32\drivers\mbam.sys 2009-06-22 00:48 . 2009-06-22 00:48--------d-----w-c:\program files\iPod 2009-06-22 00:48 . 2009-06-22 00:48--------d-----w-c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-06-22 00:46 . 2009-06-22 00:46--------d-----w-c:\program files\Bonjour 2009-06-22 00:45 . 2009-06-22 00:45--------d-----w-c:\program files\QuickTime 2009-06-22 00:43 . 2009-06-22 00:43--------d-----w-c:\program files\Apple Software Update 2009-06-21 22:50 . 2009-06-21 22:50--------d-----w-c:\documents and settings\Dad\Local Settings\Application Data\AOL 2009-06-05 20:57 . 2009-06-05 20:5775048----a-w-c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.0.23\SetupAdmin.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-27 23:55 . 2009-04-10 18:27--------d-----w-c:\documents and settings\All Users\Application Data\Viewpoint 2009-06-27 06:49 . 2002-01-04 09:43--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-06-27 05:39 . 2002-01-02 07:20--------d-----w-c:\program files\Java 2009-06-27 04:41 . 2007-07-22 04:02--------d-----w-c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-06-26 06:04 . 2007-03-25 15:4951936----a-w-c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-26 06:02 . 2002-01-02 07:21--------d-----w-c:\program files\OpenOffice.org 2.2 2009-06-26 05:56 . 2003-07-31 11:52--------d--h--w-c:\program files\InstallShield Installation Information 2009-06-26 05:52 . 2002-01-02 08:35--------d-----w-c:\documents and settings\Dad\Application Data\OpenOffice.org2 2009-06-26 05:52 . 2008-10-08 06:27--------d-----w-c:\documents and settings\Dad\Application Data\stickies 2009-06-26 05:20 . 2002-01-04 09:37--------d-----w-c:\program files\Common Files\Panda Software 2009-06-26 05:12 . 2008-11-25 19:33--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater 2009-06-22 00:48 . 2008-09-15 04:37--------d-----w-c:\program files\Common Files\Apple 2009-06-21 22:51 . 2009-04-10 18:24--------d-----w-c:\program files\Common Files\AOL 2009-06-09 17:09 . 2007-09-17 05:02--------d-----w-c:\documents and settings\Samuel.OAKTREE3\Application Data\OpenOffice.org2 2009-05-11 22:48 . 2009-05-11 22:2034----a-w-c:\documents and settings\Samuel.OAKTREE3\jagex_runescape_preferences.dat 2009-04-10 18:29 . 2009-04-10 18:291144808----a-w-c:\documents and settings\All Users\Application Data\AOL Downloads\aimtunes\AIMTunes.exe 2008-01-15 18:50 . 2007-10-21 07:101004--sha-w-c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((( [emailprotected]_01.59.41 ))))))))))))))))))))))))))))))))))))))))) . + 2009-06-28 05:48 . 2009-06-28 05:4816384 c:\windows\temp\Perflib_Perfdata_244.dat + 2009-06-28 02:02 . 2008-10-16 22:0951224 c:\windows\system32\dllcache\cache\wuauclt.exe + 2009-06-28 02:02 . 2004-08-04 07:5682944 c:\windows\system32\dllcache\cache\ws2_32.dll + 2009-06-28 02:02 . 2004-08-04 07:5624576 c:\windows\system32\dllcache\cache\userinit.exe + 2009-06-28 02:02 . 2004-08-04 07:5614336 c:\windows\system32\dllcache\cache\svchost.exe + 2009-06-28 02:02 . 2005-06-10 23:5357856 c:\windows\system32\dllcache\cache\spoolsv.exe + 2009-06-28 02:02 . 2004-08-04 07:5617408 c:\windows\system32\dllcache\cache\powrprof.dll + 2009-06-28 02:02 . 2004-08-04 07:5613312 c:\windows\system32\dllcache\cache\lsass.exe + 2009-06-28 02:02 . 2004-08-04 05:5824576 c:\windows\system32\dllcache\cache\kbdclass.sys + 2009-06-28 02:02 . 2004-08-04 06:0029056 c:\windows\system32\dllcache\cache\ip6fw.sys + 2009-06-28 02:02 . 2004-08-04 07:5615360 c:\windows\system32\dllcache\cache\ctfmon.exe + 2009-06-28 02:02 . 2004-08-04 07:56502272 c:\windows\system32\dllcache\cache\winlogon.exe + 2009-06-28 02:02 . 2008-10-16 10:37659456 c:\windows\system32\dllcache\cache\wininet.dll + 2009-06-28 02:02 . 2007-03-08 15:36577536 c:\windows\system32\dllcache\cache\user32.dll + 2009-06-28 02:02 . 2004-08-04 07:56295424 c:\windows\system32\dllcache\cache\termsrv.dll + 2009-06-28 02:02 . 2008-06-20 10:45360320 c:\windows\system32\dllcache\cache\tcpip.sys + 2009-06-28 02:02 . 2004-08-04 07:56108032 c:\windows\system32\dllcache\cache\services.exe + 2009-06-28 02:02 . 2004-08-04 06:14182912 c:\windows\system32\dllcache\cache\ndis.sys + 2009-06-28 02:02 . 2007-04-16 15:52984576 c:\windows\system32\dllcache\cache\kernel32.dll + 2009-06-28 02:02 . 2004-08-04 07:56110080 c:\windows\system32\dllcache\cache\imm32.dll + 2009-06-28 02:02 . 2004-08-04 07:56167936 c:\windows\system32\dllcache\cache\appmgmts.dll + 2009-06-28 02:02 . 2004-08-04 07:561580544 c:\windows\system32\dllcache\cache\sfcfiles.dll + 2009-06-28 02:02 . 2008-08-14 09:582136064 c:\windows\system32\dllcache\cache\ntoskrnl.exe + 2009-06-28 02:02 . 2008-08-14 09:222015744 c:\windows\system32\dllcache\cache\ntkrnlpa.exe + 2009-06-28 02:02 . 2007-06-13 10:231033216 c:\windows\system32\dllcache\cache\explorer.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1392b8d2-5c05-419f-a8f6-b9f15a596612}] 2009-04-21 00:181883672----a-w-c:\program files\Freecorder\tbFre1.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sony Ericsson PC Suite"="e:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-06-19 393216] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 1388544] "Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-04 143360] "AdaptecDirectCD"="c:\program files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [2003-09-19 684032] "igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-27 148888] "AAWTray"="c:\program files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 88024] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "MBM 5"="c:\program files\Motherboard Monitor 5\MBM5.EXE" [2004-06-12 594944] "Adobe Reader Speed Launcher"="e:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696] "iTunesHelper"="e:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 19:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Google\\Google Talk\\googletalk.exe"= "c:\\Documents and Settings\\Samuel.OAKTREE3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\Samuel.OAKTREE3\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "e:\\Program Files\\iTunes\\iTunes.exe"= "e:\\Program Files\\Stickies\\stickies.exe"= R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/26/2009 12:45 AM 108289] S1 Multicam;MultiCam for Picolo;c:\windows\system32\Drivers\multicam.sys --> c:\windows\system32\Drivers\multicam.sys [?] S1 SASKUTIL;SASKUTIL;\??\e:\program files\SUPERAntiSpyware\SASKUTIL.sys --> e:\program files\SUPERAntiSpyware\SASKUTIL.sys [?] S3 AtomSync;AtomSync;e:\program files\AtomSync\service.exe [9/23/2008 10:34 PM 159744] S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [5/20/2008 10:47 PM 13224] S3 SASENUM;SASENUM;\??\e:\program files\SUPERAntiSpyware\SASENUM.SYS --> e:\program files\SUPERAntiSpyware\SASENUM.SYS [?] . Contents of the 'Scheduled Tasks' folder 2009-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34] 2009-06-28 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-02 01:16] 2009-06-28 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4265909289-2111342016-2801439982-1016.job - c:\documents and settings\Samuel.OAKTREE3\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-18 07:05] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.gbcph.org/ uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab FF - ProfilePath - c:\documents and settings\Dad\Application Data\Mozilla\Firefox\Profiles\b9k9d87q.default\ FF - prefs.js: browser.startup.homepage - www.gbcph.org FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll FF - plugin: e:\program files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll FF - plugin: e:\program files\iTunes\Mozilla Plugins\npitunes.dll FF - plugin: e:\program files\Mozilla Firefox\plugins\npmusicn.dll FF - plugin: e:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - e:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-27 22:51 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(860) c:\program files\SUPERAntiSpyware\SASWINLO.dll - - - - - - - > 'explorer.exe'(1456) c:\progra~1\WINDOW~2\wmpband.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Belkin\Belkin Wireless Network Utility\WLService.exe c:\program files\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\windows\system32\HPZipm12.exe c:\program files\Analog Devices\SoundMAX\SMAgent.exe c:\windows\system32\MsPMSPSv.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-06-28 22:56 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-28 05:56 ComboFix2.txt 2009-06-28 03:08 ComboFix3.txt 2009-06-28 02:04 Pre-Run: 108,956,647,424 bytes free Post-Run: 108,939,886,592 bytes free 207
---------- Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- Use the ESET Online Antivirus Scanner This scanner requires Internet Explorer 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. WAIT for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.[emailprotected] as CAB hook log: OnlineScanner.ocx - delete file error:The process cannot access the file because it is being used by another process. OnlineScanner.ocx - copy file error :The process cannot access the file because it is being used by another process. OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) # OnlineScanner.ocx=1.0.0.5863 # api_version=3.0.2 # EOSSerial=f8635a3504fa9c4583e41c03195de3f1 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2009-06-29 09:53:45 # local_time=2009-06-29 02:53:45 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=1797 21 100 100 76642968750 # scanned=46189 # found=0 # cleaned=0 # scan_time=1490 Looks good. Is the computer running OK now? Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, SPYWARE, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky WEBSITE. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. Ahhh...much better! My thanks to all of the CH players who invested time in helping me resolve this problem. This has been a long but rewarding and educational process. Thanks also for the final "tools" recommendations to help safeguard my future computing experiences. Kudos to the team! (Now it's time to run off to the XP thread and see how my other machine is doing!) |
|
| 3838. |
Solve : Hijack this log.? |
|
Answer» Can you please check through this log to see if there is anything bad on ym system? thanks. |
|
| 3839. |
Solve : from internet browsers - IE disappearing - scan logs? |
|
Answer» Ok, I got the laptop and sure enough the application for IE was missing from c:\program files\Internet Explorer. I tried to load IE6 but got a message that a later VERSION was already loaded. I tried to load IE7 but for some strange reason got a Proxy timeout from the DOE. I tried to load IE8, but part of the install process is updating, and with no working IE that failed. Finally installed the latest Firefox and made that default, now the laptop can get online. |
|
| 3840. |
Solve : system security 2009 - can't run programs and can't start in safe mode? |
|
Answer» I have RESTARTED and run MBAM and HJT a few more times and seem to have gotten the last of the evidence of the INFECTION... THANKS for your HELP, we're very very busy right now so DEALING with a stubborn computer problem was not high on my list... |
|
| 3841. |
Solve : Re: Firefox & IE search results go to wrong page. Can't run HijackThis. HELP Please? |
|
Answer» Hello,
---------- Looking at the ComboFix log now.... Sorry, I keep forgetting to finish what I start. I sometimes know what I'm doing. Before we continue download and install a free antivirus. Remember to only install one antivirus! 1) Avast! Home Free Edition 2) AVG Free Edition 3) Avira AntiVir Personal Be back with more instructions after finishing the ComboFix log. OK. Here we go. Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: RegLock:: [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze ---------- If you already have Malwarebytes be sure to update it before running the scan! Download Malwarebytes' Anti-Malware (MBAM) Alternate MBAM download link
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. ---------- Also let me know how the computer is running now. .Hi Here is the new ComboFix log. ComboFix 09-07-01.01 - Guillaume 02-07-2009 10:37.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.91.1033.18.3069.2003 [GMT 2:00] Running from: c:\users\Guillaume\Desktop\ComboFix1.exe Command switches used :: c:\users\Guillaume\Desktop\CFScript.txt SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((( Files Created from 2009-06-02 to 2009-07-02 ))))))))))))))))))))))))))))))) . 2009-07-02 08:41 . 2009-07-02 08:43--------d-----w-c:\users\Guillaume\AppData\Local\temp 2009-07-01 22:30 . 2009-07-01 22:30--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-07-01 22:17 . 2009-07-01 22:17--------d-----w-c:\program files\Trend Micro 2009-07-01 21:58 . 2009-01-18 21:3515688----a-w-c:\windows\system32\lsdelete.exe 2009-07-01 19:17 . 2009-01-18 21:3064160----a-w-c:\windows\system32\drivers\Lbd.sys 2009-07-01 19:17 . 2009-07-01 19:17--------dc-h--w-c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800} 2009-07-01 19:17 . 2009-01-18 21:432892112-c--a-w-c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe 2009-07-01 19:17 . 2009-07-01 19:17--------d-----w-c:\program files\Lavasoft 2009-07-01 11:42 . 2009-07-01 11:48--------d-----w-c:\users\Guillaume\AppData\Roaming\.clamwin 2009-07-01 11:41 . 2009-07-01 11:41--------d-----w-c:\programdata\.clamwin 2009-07-01 11:41 . 2009-07-01 11:41--------d-----w-c:\program files\ClamWin 2009-06-30 12:57 . 2008-04-17 11:1215464----a-w-c:\windows\system32\drivers\GEARAspiWDM.sys 2009-06-30 12:57 . 2008-04-17 11:12107368----a-w-c:\windows\system32\GEARAspi.dll 2009-06-30 12:57 . 2009-06-30 12:57--------d-----w-c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6} 2009-06-30 10:57 . 2009-07-02 08:23--------d-----w-c:\users\Guillaume\AppData\Roaming\Symantec 2009-06-30 10:49 . 2009-07-02 08:23--------d-----w-c:\program files\Common Files\Symantec Shared 2009-06-30 09:08 . 2009-06-30 09:08--------d-----w-c:\users\Public\InOut 2009-06-29 21:20 . 2009-06-29 21:20680----a-w-c:\users\Guillaume\AppData\Local\d3d9caps.dat 2009-06-25 15:15 . 2009-06-25 15:15--------d-----w-c:\programdata\AVS4YOU 2009-06-25 15:15 . 2009-06-25 15:15--------d-----w-c:\users\Guillaume\AppData\Roaming\AVS4YOU 2009-06-25 15:12 . 2009-07-01 19:11--------d-----w-c:\program files\Common Files\AVSMedia 2009-06-25 15:12 . 2003-05-21 21:50344064----a-w-c:\windows\system32\msvcr70.dll 2009-06-25 15:12 . 2002-01-05 12:48974848----a-w-c:\windows\system32\mfc70.dll 2009-06-25 15:12 . 2002-01-05 11:40487424----a-w-c:\windows\system32\msvcp70.dll 2009-06-25 15:12 . 2009-07-01 19:11--------d-----w-c:\program files\AVS4YOU 2009-06-25 15:12 . 2008-07-11 09:521700352----a-w-c:\windows\system32\GdiPlus.dll 2009-06-25 15:12 . 2003-05-21 21:5024576----a-w-c:\windows\system32\msxml3a.dll 2009-06-24 08:36 . 2009-06-25 11:14--------d-----w-c:\users\Guillaume\group 2009-06-21 14:43 . 2009-06-21 14:43--------d-----w-C:\mwdumper 2009-06-17 20:34 . 2009-06-22 17:55--------d-----w-c:\users\Guillaume\AppData\Roaming\Mozilla Embedded Browser 2009-06-17 16:12 . 2009-06-24 15:20--------d-----w-C:\Downloads 2009-06-15 12:58 . 2009-06-15 12:58--------d-----w-c:\users\Guillaume\AppData\Local\Quest Software 2009-06-14 11:59 . 2009-04-09 06:2586096----a-w-c:\windows\system32\php_mysqli.dll 2009-06-14 11:59 . 2009-04-09 06:2545135----a-w-c:\windows\system32\php_mysql.dll 2009-06-09 14:01 . 2009-06-09 14:01--------d-----w-C:\php5 2009-06-08 21:03 . 2009-06-08 21:03--------d-----w-c:\program files\Microsoft Works 2009-06-08 21:00 . 2009-06-08 21:00--------d-----w-c:\program files\Microsoft Visual Studio 8 2009-06-08 20:59 . 2009-06-08 20:59--------d-----w-c:\users\Guillaume\AppData\Local\Microsoft Help 2009-06-08 20:58 . 2009-06-08 20:58--------d--h--r-C:\MSOCache 2009-06-08 20:39 . 2009-06-08 20:39--------d-----w-c:\users\Guillaume\AppData\Local\Seven Zip 2009-06-07 14:38 . 2009-07-01 19:17--------d-----w-c:\programdata\Lavasoft 2009-06-07 14:32 . 2009-06-07 14:32--------d-----w-c:\windows\Sun 2009-06-07 11:48 . 2009-06-07 11:53--------d-----w-c:\users\Guillaume\Grupo 2009-06-06 09:23 . 2009-06-06 09:233584----a-r-c:\users\Guillaume\AppData\Roaming\Microsoft\Installer\{D58340FF-57D2-4AF3-81DB-073DDD4FAEA9}\IconTmpl7.15B59236_99D3_4DBB_BC63_B5BF7D73F468.exe 2009-06-06 09:23 . 2009-06-06 09:23244224----a-r-c:\users\Guillaume\AppData\Roaming\Microsoft\Installer\{D58340FF-57D2-4AF3-81DB-073DDD4FAEA9}\Icon8EEA8E04.exe 2009-06-06 09:23 . 2009-06-06 09:23--------d-----w-c:\users\Guillaume\AppData\Roaming\Software 2009-06-06 09:23 . 2009-06-06 09:23--------d-----w-c:\program files\Common Files\Quest Shared 2009-06-06 09:23 . 2009-06-06 09:23--------d-----w-c:\program files\Quest Software 2009-06-05 18:43 . 2009-06-09 15:50--------d-----w-C:\wamp 2009-06-04 09:52 . 2009-06-04 09:52--------d-----w-c:\programdata\muvee Technologies 2009-06-04 09:51 . 2009-06-04 09:52--------d-----w-c:\users\Guillaume\AppData\Roaming\muvee Technologies 2009-06-02 13:09 . 2009-06-29 11:41--------d-----w-c:\users\Guillaume\Divers 2009-06-02 11:38 . 2009-06-02 11:38--------d-----w-c:\program files\Common Files\Adobe AIR 2009-06-02 10:09 . 2009-06-02 11:37--------d-----w-c:\program files\Common Files\Adobe 2009-06-02 09:54 . 2009-06-02 09:54--------d-----w-c:\users\Guillaume\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2009-06-02 08:46 . 2009-06-02 08:50--------d-----w-c:\users\Guillaume\AppData\Roaming\SolidDocuments 2009-06-02 08:45 . 2008-08-01 16:3213560----a-w-c:\windows\system32\solidlocalui.dll 2009-06-02 08:45 . 2008-08-01 16:3221240----a-w-c:\windows\system32\solidlocalmon.dll 2009-06-02 08:44 . 2009-06-02 08:44--------d-----w-c:\programdata\SolidDocuments . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-02 08:41 . 2009-01-21 10:1812----a-w-c:\windows\bthservsdp.dat 2009-07-02 08:23 . 2009-02-19 09:35--------d-----w-c:\programdata\Symantec 2009-07-02 08:21 . 2009-02-19 09:34--------d-----w-c:\programdata\NortonInstaller 2009-07-02 08:18 . 2009-02-19 11:40--------d-----w-c:\program files\Java 2009-07-02 08:15 . 2009-02-19 10:21--------d-----w-c:\programdata\Microsoft Help 2009-07-02 00:29 . 2009-07-01 23:41410984----a-w-c:\windows\system32\deploytk.dll 2009-06-29 22:28 . 2009-02-19 10:26--------d-----w-c:\program files\Microsoft SQL Server 2009-06-29 22:24 . 2009-02-19 10:23--------d-----w-c:\program files\Microsoft.NET 2009-06-29 22:12 . 2009-05-26 17:09--------d-----w-c:\users\Guillaume\AppData\Roaming\NuSphere 2009-06-29 22:09 . 2009-02-19 10:02--------d-----w-c:\programdata\WildTangent 2009-06-29 22:09 . 2009-02-19 10:02--------d-----w-c:\program files\HP Games 2009-06-23 16:00 . 2009-05-22 11:29--------d-----w-c:\users\Guillaume\AppData\Roaming\CyberLink 2009-06-20 18:12 . 2009-05-26 11:00--------d-----w-c:\users\Guillaume\AppData\Roaming\DBDesigner4 2009-06-19 13:00 . 2009-05-18 12:02--------d-----w-c:\program files\PHP 2009-06-17 19:54 . 2009-06-01 08:32--------d-----w-c:\users\Guillaume\AppData\Roaming\Skype 2009-06-17 19:40 . 2009-06-01 08:45--------d-----w-c:\users\Guillaume\AppData\Roaming\skypePM 2009-06-08 21:45 . 2009-05-14 02:20104560----a-w-c:\users\Guillaume\AppData\Local\GDIPFONTCACHEV1.DAT 2009-06-08 21:03 . 2006-11-02 12:37--------d-----w-c:\program files\MSBuild 2009-06-08 08:26 . 2009-05-14 02:52--------d-----w-c:\users\Guillaume\AppData\Roaming\Hewlett-Packard 2009-06-08 08:25 . 2009-02-19 09:33--------d-----w-c:\programdata\Hewlett-Packard 2009-06-07 17:07 . 2009-05-31 20:18--------d-----w-c:\users\Guillaume\AppData\Roaming\FileZilla 2009-06-03 13:47 . 2009-02-19 09:32--------d--h--w-c:\program files\InstallShield Installation Information 2009-06-02 10:25 . 2009-05-19 19:41--------d-----w-c:\program files\File Recover 2009-06-01 08:45 . 2009-06-01 08:4556---ha-w-c:\windows\system32\ezsidmv.dat 2009-06-01 08:32 . 2009-06-01 08:32--------d-----w-c:\program files\Common Files\Skype 2009-06-01 08:32 . 2009-06-01 08:32--------d-----r-c:\program files\Skype 2009-06-01 08:32 . 2009-06-01 08:32--------d-----w-c:\programdata\Skype 2009-05-31 20:18 . 2009-05-31 20:18--------d-----w-c:\program files\FileZilla FTP Client 2009-05-30 21:18 . 2009-05-15 03:52--------d-----w-c:\program files\Google 2009-05-28 20:00 . 2009-05-28 20:00--------d-----w-c:\program files\EASEUS 2009-05-28 18:02 . 2009-02-19 12:35--------d-----w-c:\program files\SMINST 2009-05-26 10:53 . 2009-05-26 10:53--------d-----w-c:\program files\Common Files\fabFORCE 2009-05-26 10:53 . 2009-05-26 10:53--------d-----w-c:\program files\fabFORCE 2009-05-26 10:03 . 2009-05-26 10:03--------d-----w-c:\programdata\MySQL 2009-05-26 09:12 . 2009-05-26 09:12--------d-----w-c:\program files\Opera 2009-05-25 23:40 . 2009-05-25 22:13--------d-----w-c:\users\Guillaume\AppData\Roaming\vlc 2009-05-25 22:12 . 2009-05-25 22:12--------d-----w-c:\program files\VideoLAN 2009-05-20 21:09 . 2009-02-19 09:35--------d-----w-c:\programdata\Norton 2009-05-19 19:34 . 2009-05-19 19:34--------d-----w-c:\programdata\ParetoLogic 2009-05-19 19:33 . 2009-05-19 19:33--------d-----w-c:\programdata\Cached Installations 2009-05-19 19:19 . 2009-05-19 19:19--------d-----w-c:\program files\AVG 2009-05-19 09:06 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail 2009-05-18 19:26 . 2009-05-18 19:26--------d-----w-c:\program files\MSXML 4.0 2009-05-18 17:49 . 2009-05-18 17:49--------d-----w-c:\programdata\NOS 2009-05-18 17:49 . 2009-05-18 17:49--------d-----w-c:\program files\NOS 2009-05-18 15:34 . 2009-05-18 15:34--------d-----w-c:\users\Guillaume\AppData\Roaming\Nvu 2009-05-18 15:34 . 2009-05-18 15:34--------d-----w-c:\program files\Nvu 2009-05-18 12:18 . 2009-05-29 10:152076672----a-w-c:\windows\system32\libmysql.dll 2009-05-17 06:24 . 2009-05-17 06:24--------d-----w-c:\program files\Western Digital Corporation 2009-05-16 15:39 . 2009-05-16 15:390----a-w-c:\windows\nsreg.dat 2009-05-16 08:25 . 2009-05-16 08:25--------d--h--r-c:\users\Guillaume\AppData\Roaming\SecuROM 2009-05-16 08:25 . 2009-05-16 08:2598304----a-w-c:\windows\system32\CmdLineExt.dll 2009-05-16 08:14 . 2009-05-16 08:14--------d-----w-c:\program files\Sierra 2009-05-16 08:11 . 2009-05-16 08:11--------d-----w-c:\users\Guillaume\AppData\Roaming\InstallShield 2009-05-15 03:53 . 2009-05-15 03:53--------d-----w-c:\program files\Common Files\PX Storage Engine 2009-05-14 02:55 . 2009-05-14 02:55--------d-----w-c:\users\Guillaume\AppData\Roaming\WildTangent 2009-05-14 02:52 . 2009-05-14 02:52--------d-----w-c:\users\Guillaume\AppData\Roaming\Macrovision 2009-05-14 02:52 . 2009-05-14 02:52--------d-----w-c:\users\Guillaume\AppData\Roaming\ATI 2009-05-14 02:51 . 2009-05-14 02:51--------d-----w-c:\users\Guillaume\AppData\Roaming\DigitalPersona 2009-05-14 02:18 . 2009-05-14 02:18--------d-----w-c:\users\Guillaume\AppData\Roaming\HP TCS 2009-05-14 02:18 . 2006-11-02 12:37--------d-----w-c:\program files\Windows Sidebar 2009-05-14 02:16 . 2009-05-14 02:160--sha-r-c:\windows\system32\drivers\103C_HP_cNB_Pavilion dv5 Notebook PC_Y5335KV_0U_QCNF9143YJF_E517901-371_4A_I3600_SHP_V98.32_F.23_T090105_WV3-1_L409_M3069_J320_7AMD_8F31_92.20_#090121_N10EC8168;168C001C_(NU324PA#ACJ)_XMOBILE_CN10_Z_2Rev 1.MRK 2009-05-01 18:30 . 2009-05-01 18:303366912----a-w-c:\windows\system32\GPhotos.scr 2009-03-25 12:13 . 2009-05-15 03:357100928----a-w-c:\program files\PocketDivXEncoder_0.3.96.exe 2009-02-19 10:47 . 2009-02-19 10:338192--sha-w-c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((( [emailprotected]_00.18.35 ))))))))))))))))))))))))))))))))))))))))) . + 2006-11-02 07:33 . 2006-11-02 07:3348128 c:\windows\winsxs\x86_microsoft-windows-ie-htmleditingsupport_31bf3856ad364e35_6.0.6001.18248_none_f34a4cecba3fd10b\mshtmler.dll + 2008-01-21 02:23 . 2008-01-21 02:2372704 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18248_none_ae0ee83906df1e56\admparse.dll + 2009-02-19 10:37 . 2009-02-19 10:3764512 c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18248_none_01c5b9e9a1ec46b0\WininetPlugin.dll + 2008-01-21 01:58 . 2009-07-02 08:3251680 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2009-05-14 02:18 . 2009-07-02 08:4316384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-05-14 02:18 . 2009-07-01 23:5816384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2009-05-14 02:18 . 2009-07-01 23:5832768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-05-14 02:18 . 2009-07-02 08:4332768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2009-05-14 02:18 . 2009-07-02 08:4316384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2009-05-14 02:18 . 2009-07-01 23:5816384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-01-21 02:25 . 2008-01-21 02:256656 c:\windows\winsxs\x86_microsoft-windows-ehome-devices-mcrmgr_31bf3856ad364e35_6.0.6001.18254_none_33f7ddc1da1f1d8a\McrMgr.dll + 2009-05-17 07:56 . 2009-07-02 00:307588 c:\windows\System32\WDI\ERCQueuedResolutions.dat + 2009-05-14 02:17 . 2009-07-02 08:329578 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3809033370-1981303550-699846253-1003_UserData.bin - 2009-07-01 23:57 . 2009-07-01 23:572048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-07-02 08:42 . 2009-07-02 08:422048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2008-01-21 02:24 . 2008-01-21 02:24180736 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18248_none_647f330bae383e13\ieui.dll + 2008-01-21 02:24 . 2008-01-21 02:24129536 c:\windows\winsxs\x86_microsoft-windows-ie-runtimeutilities_31bf3856ad364e35_6.0.6001.18248_none_478070c58c9d650d\sqmapi.dll + 2006-11-02 07:27 . 2006-11-02 09:39161792 c:\windows\winsxs\x86_microsoft-windows-ie-adminkitmostfiles_31bf3856ad364e35_6.0.6001.18248_none_ae0ee83906df1e56\ieakui.dll + 2006-11-02 13:05 . 2009-07-02 08:32110090 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin + 2006-11-02 10:33 . 2009-07-02 08:15663196 c:\windows\System32\perfh009.dat - 2006-11-02 10:33 . 2009-07-02 00:05663196 c:\windows\System32\perfh009.dat + 2006-11-02 10:33 . 2009-07-02 08:15127404 c:\windows\System32\perfc009.dat - 2006-11-02 10:33 . 2009-07-02 00:05127404 c:\windows\System32\perfc009.dat - 2009-02-19 11:41 . 2009-07-01 23:41148888 c:\windows\System32\javaws.exe + 2009-07-02 00:29 . 2009-07-02 00:29148888 c:\windows\System32\javaws.exe - 2009-02-19 11:41 . 2009-07-01 23:41144792 c:\windows\System32\javaw.exe + 2009-07-02 00:29 . 2009-07-02 00:29144792 c:\windows\System32\javaw.exe - 2009-02-19 11:41 . 2009-07-01 23:41144792 c:\windows\System32\java.exe + 2009-07-02 00:29 . 2009-07-02 00:29144792 c:\windows\System32\java.exe + 2009-05-18 11:58 . 2009-04-14 07:032409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22435_none_f2f64e4f84abbcec\OESpamFilter.dat + 2009-05-18 11:58 . 2009-04-14 07:032409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18259_none_f25b10ee6b9abd39\OESpamFilter.dat + 2009-05-18 11:58 . 2009-04-14 07:032409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21056_none_f0fb46578794b34f\OESpamFilter.dat + 2009-05-18 11:58 . 2009-04-14 07:032409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16860_none_f060ffc26e84642a\OESpamFilter.dat + 2008-01-21 02:24 . 2008-01-21 02:242455488 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.21046_none_fa10127687d0d070\ieapfltr.dat + 2008-01-21 02:24 . 2008-01-21 02:242455488 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16851_none_f976cc2b6ebf9aa2\ieapfltr.dat + 2006-11-02 10:22 . 2009-07-02 08:296553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT - 2006-11-02 10:22 . 2009-07-01 11:106553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT + 2008-06-06 17:27 . 2009-07-02 08:28131780406 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DpAgent"="c:\program files\DigitalPersona\Bin\dpagent.exe" [2008-12-11 842816] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1316136] "ClamWin"="c:\program files\ClamWin\bin\ClamTray.exe" [2009-06-11 86016] "Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-02 148888] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification PackagesREG_MULTI_SZ scecli DPPWDFLT [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk backup=c:\windows\pss\Bluetooth.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Monitor Apache Servers.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Apache Servers.lnk backup=c:\windows\pss\Monitor Apache Servers.lnk.CommonStartup backupExtension=.CommonStartup [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{E6DB3961-07E4-45A0-AA3C-F3B3B7F4F9F7}"= c:\program files\CyberLink\PowerDirector\PDR.EXE:CyberLink PowerDirector "{353CF60D-E2AD-4F09-B76F-C1CDD3478789}"= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartMusic.exe:HP TouchSmart Music "{4AA41B04-FF93-4B2D-A7A8-6DA731383642}"= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartPhoto.exe:HP TouchSmart Photo "{3A5169F5-3859-4E6E-BB92-5B35B8C6911B}"= c:\program files\Hewlett-Packard\Media\DVD\HPTouchSmartVideo.exe:HP TouchSmart Video "{BC92971A-983D-4974-88A3-576F943534BC}"= c:\program files\Hewlett-Packard\Media\DVD\TSMAgent.exe:HP TouchSmart Media Resident Program "{A7467990-D655-4E94-80E7-FA9E8BA1E3FA}"= c:\program files\Hewlett-Packard\Media\DVD\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service "{A00F1E0E-FBE5-4BB6-97FB-380E719F92E5}"= c:\program files\Hewlett-Packard\Media\DVD\HPDVDSmart.exe:HP MediaSmart DVD "{6F13DC25-28CE-42DB-ABD0-5682B2024A79}"= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartMusic.exe:HP TouchSmart Music "{67D587A5-DEB8-4A93-B3B1-3226CAB96983}"= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartPhoto.exe:HP TouchSmart Photo "{94801C04-866B-4BF4-A902-F4195C37EA9B}"= c:\program files\Hewlett-Packard\TouchSmart\Media\HPTouchSmartVideo.exe:HP TouchSmart Video "{8B4BBE2F-DFEB-4EA4-BCC8-2734E5E8A9FB}"= c:\program files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe:HP TouchSmart Media Resident Program "{92E60A91-51C1-4153-914B-020EE33F6C60}"= c:\program files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe:CyberLink Media Service "{535552D7-2F2E-457A-A653-B94E417C029B}"= c:\program files\Hewlett-Packard\Media\TV\QP.exe:Quick Play "{445E2C51-CF0E-4F90-83EB-C1903B572927}"= c:\program files\Hewlett-Packard\Media\TV\QPService.exe:Quick Play Resident Program "TCP Query User{6B46CD09-8566-434F-A3FF-CBDA4B0B7331}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows "UDP Query User{C11FEE4C-5B54-453A-83D4-25941667E24E}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows "TCP Query User{844E49C1-FDE0-4617-8D07-9CE36D1BF429}c:\\program files\\ares\\ares.exe"= UDP:c:\program files\ares\ares.exe:Ares p2p for windows "UDP Query User{EB116974-69E3-4B3F-8A6A-A7CCDB2A6FCA}c:\\program files\\ares\\ares.exe"= TCP:c:\program files\ares\ares.exe:Ares p2p for windows "{8F9629FE-2EC6-4DB4-B73F-DE5398BD5FA1}"= UDP:c:\program files\nusphere\phped\Srv.exe:NuSphere PhpED SRV web server "{809437AF-EDE8-42B0-AB49-89B0183A1352}"= TCP:c:\program files\nusphere\phped\Srv.exe:NuSphere PhpED SRV web server "{9D1960D7-5A1C-451F-9530-A2A63A482EE7}"= UDP:c:\program files\nusphere\phped\debugger\DbgListener.exe:NuSphere PhpED Dbg Listener "{125EECFC-463C-41F6-99FD-F26D456CF288}"= TCP:c:\program files\nusphere\phped\debugger\DbgListener.exe:NuSphere PhpED Dbg Listener "{C420771C-6514-4124-9253-5143600D9699}"= UDP:c:\program files\nusphere\phped\phped.exe:NuSphere PhpED Embedded browser "{4C5C4A73-C523-4639-AA30-079FF741791B}"= TCP:c:\program files\nusphere\phped\phped.exe:NuSphere PhpED Embedded browser "{0858C917-6AE0-47FD-9220-529AC026C79A}"= c:\program files\Skype\Phone\Skype.exe:Skype "{2ABB040C-C949-4C0A-99A1-698D45CF9014}"= c:\program files\Skype\Phone\Skype.exe:Skype "{0F855C04-E7EE-4B44-AE86-C5E8541D7566}"= c:\program files\Skype\Phone\Skype.exe:Skype "TCP Query User{640C01A5-F4AC-47DF-8372-C676D3CE567E}c:\\program files\\nusphere\\phped\\debugger\\dbglistener.exe"= UDP:c:\program files\nusphere\phped\debugger\dbglistener.exe:Listener for php debugger DBG "UDP Query User{29EC753F-84F2-48F1-8170-B813D5537431}c:\\program files\\nusphere\\phped\\debugger\\dbglistener.exe"= TCP:c:\program files\nusphere\phped\debugger\dbglistener.exe:Listener for php debugger DBG "TCP Query User{79D3A5C4-4E33-4AF6-BF9E-375EC79BEB93}c:\\program files\\nusphere\\phped\\srv.exe"= UDP:c:\program files\nusphere\phped\srv.exe:SRV Local WEB server "UDP Query User{08869455-D764-4AAD-823E-A744B1FDA516}c:\\program files\\nusphere\\phped\\srv.exe"= TCP:c:\program files\nusphere\phped\srv.exe:SRV Local WEB server "{1B779A5F-1F93-4A92-8729-18090A1ECBA2}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C16D5914-BA67-4BE6-B6E9-E7790E83F72C}"= c:\program files\Skype\Phone\Skype.exe:Skype "{6797A88C-F4AD-4568-A9B5-5B435E0C06E8}"= c:\program files\Skype\Phone\Skype.exe:Skype "{E278D605-6FAC-43B7-A46F-9FDD26CCD134}"= UDP:c:\users\Guillaume\AppData\Local\temp\7zSEB67.tmp\SymNRT.exe:Norton Removal Tool "{879ABAC5-CD45-490F-BB81-F33B9AD48DA6}"= TCP:c:\users\Guillaume\AppData\Local\temp\7zSEB67.tmp\SymNRT.exe:Norton Removal Tool R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [01-07-2009 21:17 64160] R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2009/01/21 03:06];c:\program files\Hewlett-Packard\Media\DVD\000.fcl [29-11-2008 04:04 87536] R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\AEstSrv.exe [21-01-2009 12:29 77824] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18-01-2009 23:34 921936] R2 Recovery Service for Windows;Recovery Service for Windows;c:\program files\SMINST\BLService.exe [19-02-2009 14:35 365952] R2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [27-11-2008 03:13 296320] R2 TVSched;TV Task Scheduler (TVTS);c:\program files\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [27-11-2008 03:13 116096] R2 vfsFPService;Validity Fingerprint Service;c:\windows\System32\vfsFPService.exe [18-11-2008 16:09 599344] R3 enecir;ENE CIR Receiver;c:\windows\System32\drivers\enecir.sys [04-09-2008 19:47 54784] R3 usbfilter;AMD USB Filter Driver;c:\windows\System32\drivers\usbfilter.sys [21-01-2009 12:33 22072] S2 gupdate1c9e16bff8dc080;Google Update Service (gupdate1c9e16bff8dc080);c:\program files\Google\Update\GoogleUpdate.exe [30-05-2009 23:17 133104] S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [19-02-2009 11:49 222512] S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [18-05-2009 19:49 33176] S3 hpsrv;HP Service;c:\windows\System32\hpservice.exe [19-03-2008 02:24 19456] S3 JMCR;JMCR;c:\windows\System32\drivers\jmcr.sys [23-10-2008 11:42 107360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcsREG_MULTI_SZ BthServ [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "c:\program files\Common Files\LightScribe\LSRunOnce.exe" . Contents of the 'Scheduled Tasks' folder 2009-07-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 21:34] 2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 21:16] 2009-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-05-30 21:16] 2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809033370-1981303550-699846253-1003Core.job - c:\users\Guillaume\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-29 21:16] 2009-07-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3809033370-1981303550-699846253-1003UA.job - c:\users\Guillaume\AppData\Local\Google\Update\GoogleUpdate.exe [2009-06-29 21:16] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_in&c=91&bd=Pavilion&pf=cnnb IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm FF - ProfilePath - c:\users\Guillaume\AppData\Roaming\Mozilla\Firefox\Profiles\7epg4avp.default\ FF - component: c:\program files\DigitalPersona\Bin\firefoxext\components\dpffcli.dll FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\users\Guillaume\AppData\Local\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-02 10:43 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MySQL] "ImagePath"="\"c:\mysql\bin\mysqld\" --defaults-file=\"c:\mysql\my.ini\" MySQL" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}] "ImagePath"="\??\c:\program files\Hewlett-Packard\Media\DVD\000.fcl" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\S-1-5-21-3809033370-1981303550-699846253-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:a5,c6,03,b0,fe,da,19,0e,13,6f,1d,be,81,54,7e,02,98,7a,e5,db,eb,9e,6e, b8,0d,f4,3e,c1,a9,b2,25,b3,df,5f,35,0d,bb,d1,a9,20,18,46,31,f0,11,60,81,fe,\ "??"=hex:03,ed,aa,f5,c2,c1,45,25,6f,40,71,e2,b3,45,2f,79 . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'lsass.exe'(712) c:\windows\system32\DPPWDFLT.dll - - - - - - - > 'Explorer.exe'(3040) c:\program files\DigitalPersona\Bin\DpoFeedb.dll c:\program files\DigitalPersona\Bin\DpoSet.dll c:\windows\system32\btncopy.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\Ati2evxx.exe c:\windows\System32\DriverStore\FileRepository\stwrt.inf_805f33de\stacsv.exe c:\windows\System32\audiodg.exe c:\windows\System32\Ati2evxx.exe c:\windows\System32\wlanext.exe c:\program files\DigitalPersona\Bin\DpHostW.exe c:\windows\System32\agrsmsvc.exe c:\program files\Common Files\LightScribe\LSSrvc.exe c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe c:\program files\CyberLink\Shared files\RichVideo.exe c:\windows\System32\wbem\unsecapp.exe c:\windows\System32\conime.exe c:\program files\Windows Media Player\wmpnscfg.exe c:\windows\System32\wbem\unsecapp.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\program files\Synaptics\SynTP\SynTPHelper.exe c:\windows\System32\wbem\WMIADAP.exe . ************************************************************************** . Completion time: 2009-07-02 10:47 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-02 08:47 ComboFix2.txt 2009-07-02 00:20 Pre-Run: 95,925,760,000 bytes free Post-Run: 95,698,595,840 bytes free 350--- E O F ---2009-07-02 08:28 .... and the Malwarebytes log: Malwarebytes' Anti-Malware 1.38 Database version: 2362 Windows 6.0.6001 Service Pack 1 02-07-2009 10:54:54 mbam-log-2009-07-02 (10-54-54).txt Scan type: Quick Scan Objects scanned: 82864 Time elapsed: 3 minute(s), 25 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Thanks for helping me out. I'm going to see how it is running now. Cheers What is the status of the new antivirus?I am using Avira now. It has updated the last version. I ran a scan and it found and healed 3 threats. So far it's doing ok. * Click START then RUN * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ---------- Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ---------- How is the computer running now? .The computer seems to be running ok. I'll keep you informed in the next few days. Thank you anyway for the great help you gave me. Sounds good. Here are a few more suggestions. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thanks for the suggestions. I'll have a look at this too. Cheers |
|
| 3842. |
Solve : DEP Error preventing access to computer.? |
|
Answer» Hello, not to sure of the reason for the error but having read some previous posts it seems like the right forum to post. Yesterday evening after turning on my computer I got a "DEP userinit login app" message on my computer, blank screen but for message and background image. I managed to get my browser up, searched the web for the message, and came to this site. Read some more and came to the sticky on malware removal help. I've downloaded all programs listed, my java is upto date, and I'm running AVG Free with an upto date database by 1 day. |
|
| 3843. |
Solve : Microsoft Updates will not scan my computer for updates? |
|
Answer» When I go to Windows Updates and click for the express scan for updates I get an error message. The number of the error message is 0x80248011. I have tried a couple of the solutions that Microsoft recommends on its Update site, but have not been successful in completing them. For one it asks me to rename a file, but it won't let me change the name. |
|
| 3844. |
Solve : Malware removal procedures completed? |
|
Answer» Hello |
|
| 3845. |
Solve : Good decoration of free security softwares? |
|
Answer» I bought a new computer few days ago.I have installed the following softwares for protection: |
|
| 3846. |
Solve : Virus is not letting execute any program? |
|
Answer» My system is ATTACKED by some malware. its automatically opening all porn websites and not letting me to run any virus program. i have followed the thread on the cool website and run as you guys said. i am pasting the logs below. please advise me what should i do next.
Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. ---------- Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Driver:: lich File:: C:\WINDOWS\system32\lich.exe 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeI have runned the combofix. here is the log. THanks a bunch. ComboFix 09-07-04.04 - OM 07/04/2009 23:48.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1169 [GMT -5:00] Running from: c:\documents and settings\OM\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\OM\Desktop\CFScript.txt AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} * Created a new restore point FILE :: "c:\windows\system32\lich.exe" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\-1124205267 c:\windows\Installer\105b0428.msp c:\windows\Installer\105b0496.msp c:\windows\Installer\3f1184.msi c:\windows\Installer\55e09e.msp c:\windows\Installer\acc93ef.msi c:\windows\system32\drivers\4289843a.sys c:\windows\system32\prsgrc.dll c:\windows\system32\ssprs.dll c:\windows\system32\wbem\proquota.exe F:\AUTORUN.INF c:\windows\system32\proquota.exe was missing Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_6to4 -------\Legacy_lich -------\Legacy_pcmstub -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED} -------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE} -------\Service_4289843a -------\Service_6to4 -------\Service_lich ((((((((((((((((((((((((( Files Created from 2009-06-05 to 2009-07-05 ))))))))))))))))))))))))))))))) . 2010-07-15 02:42 . 2009-06-04 22:31--------d-----w-c:\documents and settings\OM\Application Data\dvdcss 2010-07-15 02:42 . 2010-07-15 02:42--------d-----w-c:\documents and settings\OM\Application Data\vlc 2010-07-15 02:41 . 2010-07-15 02:41--------d-----w-c:\program files\VideoLAN 2010-07-13 21:48 . 2009-04-05 00:3373784----a-w-c:\documents and settings\OM\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-07-03 21:19 . 2009-07-03 21:19--------d-----w-c:\program files\Trend Micro 2009-07-03 20:59 . 2009-07-03 20:59152576----a-w-c:\documents and settings\OM\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\documents and settings\OM\Application Data\Malwarebytes 2009-07-03 20:34 . 2009-06-17 16:2738160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-03 20:34 . 2009-06-17 16:2719096----a-w-c:\windows\system32\drivers\mbam.sys 2009-07-03 16:14 . 2009-07-03 21:39117760----a-w-c:\documents and settings\OM\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-07-03 16:14 . 2009-07-03 16:14--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\program files\SUPERAntiSpyware 2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\documents and settings\OM\Application Data\SUPERAntiSpyware.com 2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-C:\MSId8962.tmp 2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-07-03 16:02 . 2009-07-03 16:02--------d-----w-c:\program files\CCleaner 2009-07-03 04:12 . 2009-07-03 23:39--------d-----w-c:\documents and settings\OM\Application Data\Lavasoft 2009-07-02 19:15 . 2009-07-02 19:154656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP7.sys 2009-07-02 19:12 . 2009-07-02 19:124656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP6.sys 2009-07-02 19:12 . 2009-07-02 19:124656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP5.sys 2009-07-02 19:11 . 2009-07-02 19:114656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP4.sys 2009-07-02 18:27 . 2009-07-02 18:274656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP3.sys 2009-07-02 18:27 . 2009-07-02 18:274656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP2.sys 2009-07-02 18:26 . 2009-07-02 18:264656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP1.sys 2009-07-02 18:26 . 2009-07-02 18:264656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP0.sys 2009-07-02 18:26 . 2009-07-03 03:12--------d-----w-c:\documents and settings\All Users\Application Data\12080624 2009-07-02 18:26 . 2009-07-02 18:26--------d-sh--w-c:\windows\System Volume Information 2009-06-29 03:13 . 2009-06-29 03:13--------d-----w-c:\program files\MediaMelon 2009-06-22 02:45 . 2009-06-22 02:45--------d-----w-c:\program files\Common Files\xing shared 2009-06-09 03:53 . 2009-06-09 03:53--------d-----w-c:\documents and settings\All Users\Application Data\McAfee 2009-06-05 13:30 . 2009-05-21 16:33410984----a-w-c:\windows\system32\deploytk.dll 2009-06-05 13:29 . 2009-06-05 13:29152576----a-w-c:\documents and settings\OM\Application Data\Sun\Java\jre1.6.0_13\lzma.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-15 03:11 . 2007-07-13 04:5086327----a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-07-05 04:32 . 2008-06-17 01:01--------d-----w-c:\documents and settings\OM\Application Data\HPAppData 2009-07-04 04:40 . 2009-04-03 14:36--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater 2009-07-03 21:03 . 2008-04-23 00:50--------d-----w-c:\program files\Java 2009-07-03 16:07 . 2009-03-31 00:50--------d-----w-c:\documents and settings\OM\Application Data\Azureus 2009-07-03 13:05 . 2008-06-19 03:4511952----a-w-c:\windows\system32\avgrsstx.dll 2009-07-03 13:05 . 2008-06-19 03:45327688----a-w-c:\windows\system32\drivers\avgldx86.sys 2009-07-03 13:05 . 2007-03-03 08:0127784----a-w-c:\windows\system32\drivers\avgmfx86.sys 2009-07-03 13:05 . 2008-06-19 03:45108552----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-07-03 02:52 . 2008-06-19 03:45--------d-----w-c:\documents and settings\All Users\Application Data\avg8 2009-07-02 18:55 . 2009-04-11 11:22--------d-----w-c:\documents and settings\OM\Application Data\Amazon 2009-07-02 18:55 . 2009-04-11 11:21--------d-----w-c:\program files\Amazon 2009-07-02 18:27 . 2009-07-02 18:27327---h--w-c:\windows\Fonts\mlog 2009-07-02 18:25 . 2007-01-16 18:01--------d-----w-c:\documents and settings\OM\Application Data\AdobeUM 2009-06-30 00:58 . 2009-04-17 16:59--------d-----w-c:\documents and settings\OM\Application Data\U3 2009-06-22 02:45 . 2008-07-17 01:21--------d-----w-c:\program files\Common Files\Real 2009-06-20 01:19 . 2009-02-03 04:21--------d-----w-c:\program files\Google 2009-06-03 04:41 . 2009-06-03 04:41--------d-----w-c:\documents and settings\OM\Application Data\ATI 2009-06-03 03:14 . 2009-06-03 03:14708608----a-w-c:\windows\system32\Resecure60.dll 2009-06-03 03:14 . 2009-06-03 03:146536----a-w-c:\windows\system32\WinGPDrv.dat 2009-06-03 03:14 . 2009-06-03 03:146533----a-w-c:\windows\system32\NGWinDrv.dat 2009-06-03 03:14 . 2009-06-03 03:14458752----a-w-c:\windows\system32\LiveUpdate.dll 2009-06-03 03:14 . 2009-06-03 03:141290240----a-w-c:\windows\system32\NGWinSys.dll 2009-06-03 03:14 . 2004-08-04 12:001025----a-w-c:\windows\system32\y1vz87p.dll 2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\grcauth2.dll 2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\grcauth1.dll 2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\clauth2.dll 2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\clauth1.dll 2009-06-03 03:12 . 2009-06-03 03:12--------d-----w-c:\program files\Common Files\RAM Common 2009-06-03 03:11 . 2009-06-03 03:11--------d-----w-c:\program files\VectorDraw 2009-06-03 03:11 . 2009-06-03 03:11--------d-----w-c:\program files\Common Files\Bentley 2009-06-03 03:09 . 2009-06-03 03:0910134----a-r-c:\documents and settings\OM\Application Data\Microsoft\Installer\{D4A33E08-4FE7-40C4-BF5E-5853C56ADD7C}\ARPPRODUCTICON.exe 2009-06-03 03:09 . 2009-03-31 01:57--------d-----w-c:\program files\Common Files\Bentley Shared 2009-06-01 15:56 . 2008-07-20 03:46--------d-----w-c:\documents and settings\Guest\Application Data\HPAppData 2009-05-31 12:26 . 2009-05-31 12:2673784----a-w-c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-10 03:04 . 2009-02-06 01:22--------d-----w-c:\documents and settings\OM\Application Data\ZoomBrowser EX 2009-05-10 03:03 . 2009-02-06 01:14--------d-----w-c:\documents and settings\All Users\Application Data\ZoomBrowser 2009-05-07 15:32 . 2004-08-04 12:00345600----a-w-c:\windows\system32\localspl.dll 2009-05-01 18:30 . 2009-05-01 18:303366912----a-w-c:\windows\system32\GPhotos.scr 2009-04-17 12:26 . 2004-08-04 12:001847168----a-w-c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-08-04 12:00585216----a-w-c:\windows\system32\rpcrt4.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232] "Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-13 3660848] "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-02-24 3558136] "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856] "Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-03 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947] "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-02-20 1191936] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920] "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-03 1948440] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-22 198160] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360] ImageMixer 3 SE Camera Monitor.lnk - c:\program files\PIXELA\ImageMixer 3 SE\CameraMonitor.exe [2009-2-14 253952] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon] 2008-12-22 17:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-07-03 13:0511952----a-w-c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "Themes"=2 (0x2) "TapiSrv"=3 (0x3) "Symantec AntiVirus"=2 (0x2) "SNDSrvc"=3 (0x3) "SavRoam"=3 (0x3) "HPSLPSVC"=2 (0x2) "hpqddsvc"=2 (0x2) "helpsvc"=2 (0x2) "FastUserSwitchingCompatibility"=3 (0x3) "ERSvc"=2 (0x2) "DefWatch"=2 (0x2) "ccSetMgr"=2 (0x2) "ccPwdSvc"=3 (0x3) "ccEvtMgr"=2 (0x2) "BITS"=2 (0x2) "avg8emc"=2 (0x2) "Ati HotKey Poller"=2 (0x2) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"= "c:\\Program Files\\Vuze\\Azureus.exe"= "c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"= "c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"= "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "c:\\Program Files\\MediaMelon\\bin\\wrapper.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "11:TCP"= 11:TCP:INTERNET "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009 R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2008 10:45 PM 327688] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/18/2008 10:45 PM 108552] R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968] R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2009 8:05 AM 906520] R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/4/2008 9:06 AM 298776] R2 MediaMelon Client;MediaMelon Client 1.0;c:\program files\MediaMelon\bin\wrapper.exe [4/16/2009 3:30 PM 217088] S2 gupdate1c98fbdcfb083d4;Google Update Service (gupdate1c98fbdcfb083d4);c:\program files\Google\Update\GoogleUpdate.exe [2/15/2009 5:36 PM 133104] S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [7/2/2009 2:09 PM 1252474] S3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408] S4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [3/12/2004 4:48 AM 169192] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPServiceREG_MULTI_SZ HPSLPSVC hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-07-04 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 18:34] 2009-07-05 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-03 14:36] 2009-07-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 22:35] 2009-07-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 22:35] . - - - - ORPHANS REMOVED - - - - HKCU-Run-SpeedItUpEX - c:\program files\Speeditup Free\SpeedItUp.exe HKCU-Run-SmartVoip - c:\program files\SmartVoip.com\SmartVoip\SmartVoip.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-04 23:55 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(888) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(2836) c:\windows\system32\webcheck.dll c:\windows\system32\IEFRAME.dll c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL c:\windows\system32\msls31.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\WLTRYSVC.EXE c:\windows\system32\BCMWLTRY.EXE c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\drivers\CDAC11BA.EXE c:\program files\Java\jre6\bin\jqs.exe c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe c:\windows\system32\java.exe c:\program files\Canon\CAL\CALMAIN.exe c:\program files\AVG\AVG8\avgrsx.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\program files\AVG\AVG8\avgcsrvx.exe c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe c:\program files\iPod\bin\iPodService.exe c:\windows\system32\wscntfy.exe c:\program files\HP\Digital Imaging\bin\hpqste08.exe c:\program files\HP\Digital Imaging\bin\hpqbam08.exe c:\windows\system32\msiexec.exe c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe . ************************************************************************** . Completion time: 2009-07-05 23:59 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-05 04:59 Pre-Run: 3,585,925,120 bytes free Post-Run: 4,511,961,088 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [OPERATING systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows Server 2003, Enterprise" /noexecute=optout /fastdetect multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 306--- E O F ---2009-06-11 08:03 Download OTM by OldTimer to your desktop. Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator. * Save it to your Desktop. * Double-click OTM.exe to run it. * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy) Code: [Select]:Processes explorer.exe :services :reg :files c:\documents and settings\All Users\Application Data\Symantec :Commands [purity] [emptytemp] [start explorer] * Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste. * Click the red Moveit! button. * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply. Close OTM Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. ---------- Download DDS from |HERE| or |HERE| or |HERE| and save it to your desktop. Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will open two (2) logs. 1) DDS.txt 2) Attach.txt * Save both logs to your desktop. * Please copy and paste the entire contents of both logs in your next reply. Note: DDS will instruct you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copy and pasting it into the reply. ---------- Also let me know how the computer is running now. .hI evilfantasy, THANK FOR YOUR HELP. I ran programs as you told me. when i ran OTM by Oldtimer, after clicking on "Move It" there is a message in the green box "it killed all" and screen went blank. I can see only desktop background. then I waited for 30 mins and restarted the system forcefully. It ran fine. then I ran DDS program. the logs are as follows. DDS.txt DDS (Ver_09-06-26.01) - NTFSx86 Run by OM at 8:54:36.78 on Sun 07/05/2009 Internet Explorer: 8.0.6001.18372 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1324 [GMT -5:00] AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\drivers\CDAC11BA.EXE C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\WINDOWS\system32\svchost.exe -k HPService C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe C:\Program Files\MediaMelon\bin\wrapper.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\java.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\WINDOWS\stsystra.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\WLTRAY.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Veoh Networks\Veoh\VeohClient.exe C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe C:\Program Files\PIXELA\ImageMixer 3 SE\CameraMonitor.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe C:\Documents and Settings\OM\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.23.0\gears.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll uRun: [Yahoo! Pager] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Veoh] "c:\program files\veoh networks\veoh\VeohClient.exe" /VeohHide uRun: [VeohPlugin] "c:\program files\veoh networks\veohwebplayer\veohwebplayer.exe" uRun: [YSearchProtection] c:\program files\yahoo!\search protection\SearchProtection.exe uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\imagem~1.lnk - c:\program files\pixela\imagemixer 3 se\CameraMonitor.exe IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.23.0\gears.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204 DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} - hxxp://dl.tvunetworks.com/TVUAx.cab DPF: {474F00F5-3853-492C-AC3A-476512BBC336} - hxxp://picasaweb.google.com/s/v/45.11/uploader2.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab DPF: {8ad9c840-044e-11d1-b3e9-00805f499d93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {cafeefac-0016-0000-0014-abcdeffedcba} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {cafeefac-ffff-ffff-ffff-abcdeffedcba} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: !saswinlogon - c:\program files\superantispyware\SASWINLO.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-6-18 327688] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2007-3-3 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-6-18 108552] R1 sasdifsv;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968] R1 saskutil;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 72944] R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2004-2-9 301200] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-3 906520] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-7-4 298776] R2 MediaMelon Client;MediaMelon Client 1.0;c:\program files\mediamelon\bin\wrapper.exe [2009-4-16 217088] R2 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2004-2-9 37008] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20080613.003\naveng.sys [2008-6-14 89936] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20080613.003\navex15.sys [2008-6-14 856336] S2 gupdate1c98fbdcfb083d4;Google Update Service (gupdate1c98fbdcfb083d4);c:\program files\google\update\GoogleUpdate.exe [2009-2-15 133104] S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [2009-7-2 1252474] S3 sasenum;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408] S4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2004-2-29 255096] S4 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2004-2-29 87160] S4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2004-2-29 242808] S4 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2004-3-12 169192] S4 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2004-3-12 1221864] =============== Created Last 30 ================ 2009-07-05 08:10--d-----C:\_OTM 2009-07-04 23:58-cd-----c:\windows\system32\dllcache\cache 2009-07-04 23:5050,176ac------c:\windows\system32\dllcache\proquota.exe 2009-07-04 23:5050,176a-------c:\windows\system32\proquota.exe 2009-07-04 23:46a-dshr--C:\cmdcons 2009-07-04 23:44161,792a-------c:\windows\SWREG.exe 2009-07-04 23:44155,136a-------c:\windows\PEV.exe 2009-07-04 23:4498,816a-------c:\windows\sed.exe 2009-07-04 23:44--ds----C:\ComboFix 2009-07-03 16:19--d-----c:\program files\Trend Micro 2009-07-03 15:34--d-----c:\docume~1\om\applic~1\Malwarebytes 2009-07-03 15:3438,160a-------c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-03 15:3419,096a-------c:\windows\system32\drivers\mbam.sys 2009-07-03 15:34--d-----c:\program files\Malwarebytes' Anti-Malware 2009-07-03 15:34--d-----c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-03 11:14--d-----c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-07-03 11:13--d-----c:\program files\SUPERAntiSpyware 2009-07-03 11:13--d-----c:\docume~1\om\applic~1\SUPERAntiSpyware.com 2009-07-03 11:13--d-----C:\MSId8962.tmp 2009-07-03 11:13--d-----c:\program files\common files\Wise Installation Wizard 2009-07-03 11:02--d-----c:\program files\CCleaner 2009-07-02 13:26--d-----c:\docume~1\alluse~1\applic~1\12080624 2009-07-02 13:26--dsh---c:\windows\System Volume Information 2009-06-28 22:13--d-----c:\program files\MediaMelon 2009-06-21 21:45--d-----c:\program files\common files\xing shared 2009-06-14 20:120a-------c:\windows\mtstack16.INI ==================== Find3M ==================== 2009-07-03 08:05327,688a-------c:\windows\system32\drivers\avgldx86.sys 2009-07-03 08:0511,952a-------c:\windows\system32\avgrsstx.dll 2009-07-03 08:05108,552a-------c:\windows\system32\drivers\avgtdix.sys 2009-07-02 13:27327----h---c:\windows\fonts\mlog 2009-06-02 22:141,290,240a-------c:\windows\system32\NGWinSys.dll 2009-06-02 22:14708,608a-------c:\windows\system32\Resecure60.dll 2009-06-02 22:14458,752a-------c:\windows\system32\LiveUpdate.dll 2009-06-02 22:146,536a-------c:\windows\system32\WinGPDrv.dat 2009-06-02 22:146,533a-------c:\windows\system32\NGWinDrv.dat 2009-05-21 11:33410,984a-------c:\windows\system32\deploytk.dll 2009-05-07 10:32345,600a-------c:\windows\system32\localspl.dll 2009-05-01 13:303,366,912a-------c:\windows\system32\GPhotos.scr 2009-04-17 07:261,847,168a-------c:\windows\system32\win32k.sys 2009-04-15 09:51585,216a-------c:\windows\system32\rpcrt4.dll 2009-03-14 19:0860,744a-------c:\documents and settings\om\g2mdlhlpx.exe 2008-02-22 20:0032a----r--c:\documents and settings\all users\hash.dat ============= FINISH: 8:54:54.70 =============== Attach.txt UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 7/12/2007 11:53:14 PM System Uptime: 7/5/2009 8:41:08 AM (0 hours ago) Motherboard: Dell Inc. | | 0XD720 Processor: Intel(R) Core(TM)2 CPU T7200 @ 2.00GHz | Microprocessor | 1995/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 24 GiB total, 4.19 GiB free. D: is CDROM () E: is FIXED (NTFS) - 10 GiB total, 5.547 GiB free. F: is FIXED (NTFS) - 78 GiB total, 11.013 GiB free. ==== Disabled Device Manager Items ============= Class GUID: Description: BCM2045 Device ID: USB\VID_413C&PID_8126\5&2CD8A58F&0&2 Manufacturer: Name: BCM2045 PNP Device ID: USB\VID_413C&PID_8126\5&2CD8A58F&0&2 Service: Class GUID: {4D36E971-E325-11CE-BFC1-08002BE10318} Description: Officejet J6400 series Device ID: ROOT\MULTIFUNCTION\0000 Manufacturer: HP Name: Officejet J6400 series PNP Device ID: ROOT\MULTIFUNCTION\0000 Service: Class GUID: {4D36E979-E325-11CE-BFC1-08002BE10318} Description: Officejet J6400 series Device ID: ROOT\PRINTER\0000 Manufacturer: HP Name: Officejet J6400 series PNP Device ID: ROOT\PRINTER\0000 Service: Class GUID: {EEC5AD98-8080-425F-922A-DABF3DE3F69A} Description: Nokia N75 Device ID: ROOT\WPD\0000 Manufacturer: Nokia Name: Nokia N75 PNP Device ID: ROOT\WPD\0000 Service: WUDFRd ==== System Restore Points =================== RP451: 7/4/2009 11:50:21 PM - ComboFix created restore point RP452: 7/5/2009 8:29:04 AM - System Checkpoint ==== Installed Programs ====================== 32 Bit HP CIO Components Installer 4Media HD Video Converter 6400_Help Adobe Acrobat 6.0 Professional Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player Plugin Aide PDF to DXF Converter 9.5 AirXonix version 1.41 Any Video Converter 2.7.1 Ap PDF to IMAGE Apple Mobile Device Support Apple Software Update ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver AutoCAD 2004 Autodesk Express Viewer AVG 8.5 Bentley IEG License Service Bentley MicroStation (V 08.05.01.25) - 1 Bonjour bpd_scan BPDSoftware BPDSoftware_Ini Broadcom 440x 10/100 Integrated Controller BufferChm Canon Camera Access Library Canon Camera Support Core Library Canon RAW Image Task for ZoomBrowser EX Canon Utilities CameraWindow Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities EOS Utility Canon Utilities MyCamera Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility Cards_Calendar_OrderGift_DoMorePlugout CCleaner (remove only) Conexant HDA D110 MDC V.92 Modem Creative WebCam NX Ultra Driver (1.01.03.0112) Critical Update for Windows Media Player 11 (KB959772) CustomerResearchQFolder Dell Wireless WLAN Card Destination Component DeviceDiscovery DeviceManagementQFolder DivX Web Player DocProc DocProcQFolder eSupportQFolder Fax Free DWG Viewer 6.2 Google Earth Google Gears Google Update Helper Google Updater GoToMeeting 4.0.0.320 GPBaseService High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) HP Customer Participation Program 10.0 HP Imaging Device Functions 10.0 HP Officejet J6400 Series HP Photosmart Essential 2.5 HP Photosmart Essential 3.0 HP Smart Web Printing HP Solution Center 10.0 HP Update HPPhotoSmartPhotobookWebPack1 HPProductAssistant HPSSupply ImageMixer 3 SE iTunes J6400 Java(TM) 6 Update 14 LiveUpdate 2.0 (Symantec Corporation) Malwarebytes' Anti-Malware MarketResearch MediaMelon Client MetaFrame Presentation Server Web Client for Win32 Microsoft .NET Framework 2.0 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Professional Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.5 Microsoft Visual C++ 2005 Redistributable MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) NetDeviceManager Nokia Connectivity Cable Driver OCR Software by I.R.I.S. 10.0 PC Connectivity Solution Picasa 3 ProductContext PSSWCORE QuickSet QuickTime RealPlayer RedistSysFiles SafeCast Shared Components Scan Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Shop for HP Supplies SigmaTel Audio SmartWebPrintingOC SolutionCenter Sound Blaster ADVANCED MB Drivers STAAD.Pro V8i Status SUPERAntiSpyware Free Edition Symantec AntiVirus Synaptics Pointing Device Driver Toolbox TrayApp UnloadSupport Update for Windows Internet Explorer 8 (KB961813) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) VBA (2627.01) Veoh Web Player Beta VeohTV BETA VideoLAN VLC media player 0.8.6b VideoToolkit01 Vuze WebFldrs XP WebReg Windows Driver Package - Nokia (WUDFRd) WPD (03/19/2007 6.83.31.1) Windows Driver Package - Nokia Modem (02/15/2007 3.1) Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04) Windows Genuine Advantage Notifications (KB905474) Windows Internet Explorer 8 Release Candidate 1 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinRAR archiver WinStorm30 Yahoo! Messenger Yahoo! Search Protection ==== End Of File =========================== Thanks, SreeGo to Add or Remove Programs and uninstall:
Download the Norton Removal Tool (SymNRT) to your desktop. Once downloaded please close ALL open browsers, also save any work because this may require a restart.
---------- Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: DDS:: TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeHI, I ran the combofix. Here is the log. Thanks. ComboFix 09-07-05.01 - OM 07/05/2009 19:38.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1467 [GMT -5:00] Running from: c:\documents and settings\OM\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\OM\Desktop\CFScript.txt AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\messenger\msmsgs.exe . ((((((((((((((((((((((((( Files Created from 2009-06-06 to 2009-07-06 ))))))))))))))))))))))))))))))) . 2010-07-15 02:42 . 2009-06-04 22:31--------d-----w-c:\documents and settings\OM\Application Data\dvdcss 2010-07-15 02:42 . 2010-07-15 02:42--------d-----w-c:\documents and settings\OM\Application Data\vlc 2010-07-15 02:41 . 2010-07-15 02:41--------d-----w-c:\program files\VideoLAN 2010-07-13 21:48 . 2009-04-05 00:3373784----a-w-c:\documents and settings\OM\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-07-05 13:10 . 2009-07-05 13:10--------d-----w-C:\_OTM 2009-07-05 04:50 . 2008-04-14 00:1250176-c--a-w-c:\windows\system32\dllcache\proquota.exe 2009-07-05 04:50 . 2008-04-14 00:1250176----a-w-c:\windows\system32\proquota.exe 2009-07-03 21:19 . 2009-07-03 21:19--------d-----w-c:\program files\Trend Micro 2009-07-03 20:59 . 2009-07-03 20:59152576----a-w-c:\documents and settings\OM\Application Data\Sun\Java\jre1.6.0_14\lzma.dll 2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\documents and settings\OM\Application Data\Malwarebytes 2009-07-03 20:34 . 2009-06-17 16:2738160----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2009-07-03 20:34 . 2009-07-03 20:34--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes 2009-07-03 20:34 . 2009-06-17 16:2719096----a-w-c:\windows\system32\drivers\mbam.sys 2009-07-03 16:14 . 2009-07-03 21:39117760----a-w-c:\documents and settings\OM\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2009-07-03 16:14 . 2009-07-03 16:14--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\program files\SUPERAntiSpyware 2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\documents and settings\OM\Application Data\SUPERAntiSpyware.com 2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-C:\MSId8962.tmp 2009-07-03 16:13 . 2009-07-03 16:13--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2009-07-03 16:02 . 2009-07-03 16:02--------d-----w-c:\program files\CCleaner 2009-07-03 04:12 . 2009-07-03 23:39--------d-----w-c:\documents and settings\OM\Application Data\Lavasoft 2009-07-02 19:15 . 2009-07-02 19:154656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP7.sys 2009-07-02 19:12 . 2009-07-02 19:124656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP6.sys 2009-07-02 19:12 . 2009-07-02 19:124656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP5.sys 2009-07-02 19:11 . 2009-07-02 19:114656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP4.sys 2009-07-02 18:27 . 2009-07-02 18:274656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP3.sys 2009-07-02 18:27 . 2009-07-02 18:274656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP2.sys 2009-07-02 18:26 . 2009-07-02 18:264656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP1.sys 2009-07-02 18:26 . 2009-07-02 18:264656----a-w-c:\documents and settings\All Users\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\APTemp\AP0.sys 2009-07-02 18:26 . 2009-07-03 03:12--------d-----w-c:\documents and settings\All Users\Application Data\12080624 2009-07-02 18:26 . 2009-07-02 18:26--------d-sh--w-c:\windows\System Volume Information 2009-06-29 03:13 . 2009-06-29 03:13--------d-----w-c:\program files\MediaMelon 2009-06-22 02:45 . 2009-06-22 02:45--------d-----w-c:\program files\Common Files\xing shared 2009-06-09 03:53 . 2009-06-09 03:53--------d-----w-c:\documents and settings\All Users\Application Data\McAfee . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-15 03:11 . 2007-07-13 04:5086327----a-w-c:\windows\pchealth\helpctr\OfflineCache\index.dat 2009-07-06 00:35 . 2008-06-17 01:01--------d-----w-c:\documents and settings\OM\Application Data\HPAppData 2009-07-06 00:25 . 2007-03-27 11:27--------d-----w-c:\program files\Common Files\Symantec Shared 2009-07-06 00:25 . 2007-03-27 11:27--------d-----w-c:\program files\Symantec 2009-07-06 00:25 . 2007-03-27 11:27--------d-----w-c:\documents and settings\All Users\Application Data\Symantec 2009-07-05 13:02 . 2009-04-03 14:36--------d-----w-c:\documents and settings\All Users\Application Data\Google Updater 2009-07-03 21:03 . 2008-04-23 00:50--------d-----w-c:\program files\Java 2009-07-03 16:07 . 2009-03-31 00:50--------d-----w-c:\documents and settings\OM\Application Data\Azureus 2009-07-03 13:05 . 2008-06-19 03:4511952----a-w-c:\windows\system32\avgrsstx.dll 2009-07-03 13:05 . 2008-06-19 03:45327688----a-w-c:\windows\system32\drivers\avgldx86.sys 2009-07-03 13:05 . 2007-03-03 08:0127784----a-w-c:\windows\system32\drivers\avgmfx86.sys 2009-07-03 13:05 . 2008-06-19 03:45108552----a-w-c:\windows\system32\drivers\avgtdix.sys 2009-07-03 02:52 . 2008-06-19 03:45--------d-----w-c:\documents and settings\All Users\Application Data\avg8 2009-07-02 18:55 . 2009-04-11 11:22--------d-----w-c:\documents and settings\OM\Application Data\Amazon 2009-07-02 18:55 . 2009-04-11 11:21--------d-----w-c:\program files\Amazon 2009-07-02 18:27 . 2009-07-02 18:27327---h--w-c:\windows\Fonts\mlog 2009-07-02 18:25 . 2007-01-16 18:01--------d-----w-c:\documents and settings\OM\Application Data\AdobeUM 2009-06-30 00:58 . 2009-04-17 16:59--------d-----w-c:\documents and settings\OM\Application Data\U3 2009-06-22 02:45 . 2008-07-17 01:21--------d-----w-c:\program files\Common Files\Real 2009-06-20 01:19 . 2009-02-03 04:21--------d-----w-c:\program files\Google 2009-06-05 13:29 . 2009-06-05 13:29152576----a-w-c:\documents and settings\OM\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-06-03 04:41 . 2009-06-03 04:41--------d-----w-c:\documents and settings\OM\Application Data\ATI 2009-06-03 03:14 . 2009-06-03 03:14708608----a-w-c:\windows\system32\Resecure60.dll 2009-06-03 03:14 . 2009-06-03 03:146536----a-w-c:\windows\system32\WinGPDrv.dat 2009-06-03 03:14 . 2009-06-03 03:146533----a-w-c:\windows\system32\NGWinDrv.dat 2009-06-03 03:14 . 2009-06-03 03:14458752----a-w-c:\windows\system32\LiveUpdate.dll 2009-06-03 03:14 . 2009-06-03 03:141290240----a-w-c:\windows\system32\NGWinSys.dll 2009-06-03 03:14 . 2004-08-04 12:001025----a-w-c:\windows\system32\y1vz87p.dll 2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\grcauth2.dll 2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\grcauth1.dll 2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\clauth2.dll 2009-06-03 03:14 . 2004-08-04 12:001024----a-w-c:\windows\system32\clauth1.dll 2009-06-03 03:12 . 2009-06-03 03:12--------d-----w-c:\program files\Common Files\RAM Common 2009-06-03 03:11 . 2009-06-03 03:11--------d-----w-c:\program files\VectorDraw 2009-06-03 03:11 . 2009-06-03 03:11--------d-----w-c:\program files\Common Files\Bentley 2009-06-03 03:09 . 2009-06-03 03:0910134----a-r-c:\documents and settings\OM\Application Data\Microsoft\Installer\{D4A33E08-4FE7-40C4-BF5E-5853C56ADD7C}\ARPPRODUCTICON.exe 2009-06-03 03:09 . 2009-03-31 01:57--------d-----w-c:\program files\Common Files\Bentley Shared 2009-06-01 15:56 . 2008-07-20 03:46--------d-----w-c:\documents and settings\Guest\Application Data\HPAppData 2009-05-31 12:26 . 2009-05-31 12:2673784----a-w-c:\documents and settings\Guest\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-21 16:33 . 2009-06-05 13:30410984----a-w-c:\windows\system32\deploytk.dll 2009-05-10 03:04 . 2009-02-06 01:22--------d-----w-c:\documents and settings\OM\Application Data\ZoomBrowser EX 2009-05-10 03:03 . 2009-02-06 01:14--------d-----w-c:\documents and settings\All Users\Application Data\ZoomBrowser 2009-05-07 15:32 . 2004-08-04 12:00345600----a-w-c:\windows\system32\localspl.dll 2009-05-01 18:30 . 2009-05-01 18:303366912----a-w-c:\windows\system32\GPhotos.scr 2009-04-17 12:26 . 2004-08-04 12:001847168----a-w-c:\windows\system32\win32k.sys 2009-04-15 14:51 . 2004-08-04 12:00585216----a-w-c:\windows\system32\rpcrt4.dll . ((((((((((((((((((((((((((((( [emailprotected]_04.55.54 ))))))))))))))))))))))))))))))))))))))))) . + 2009-07-06 00:43 . 2009-07-06 00:4316384 c:\windows\Temp\Perflib_Perfdata_fc.dat - 2004-08-04 12:00 . 2009-07-03 03:4258998 c:\windows\system32\perfc009.dat + 2004-08-04 12:00 . 2009-07-05 04:5858998 c:\windows\system32\perfc009.dat + 2004-08-04 12:00 . 2009-07-05 04:58392864 c:\windows\system32\perfh009.dat - 2004-08-04 12:00 . 2009-07-03 03:42392864 c:\windows\system32\perfh009.dat + 2007-01-16 16:51 . 2009-07-05 18:133817984 c:\windows\Installer\1073be.msi - 2007-01-16 16:51 . 2009-07-03 23:383817984 c:\windows\Installer\1073be.msi . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704] "Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-13 3660848] "VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2009-02-24 3558136] "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856] "Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-03 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947] "Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-02-20 1191936] "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-15 49152] "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-03-13 81920] "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-17 1392640] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-03 1948440] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-22 198160] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-21 148888] "SigmatelSysTrayApp"="stsystra.exe" - c:\windows\stsystra.exe [2006-03-24 282624] c:\documents and settings\All Users\Start Menu\Programs\Startup\ HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360] ImageMixer 3 SE Camera Monitor.lnk - c:\program files\PIXELA\ImageMixer 3 SE\CameraMonitor.exe [2009-2-14 253952] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!saswinlogon] 2008-12-22 17:05356352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-07-03 13:0511952----a-w-c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "Themes"=2 (0x2) "TapiSrv"=3 (0x3) "Symantec AntiVirus"=2 (0x2) "SNDSrvc"=3 (0x3) "SavRoam"=3 (0x3) "HPSLPSVC"=2 (0x2) "hpqddsvc"=2 (0x2) "helpsvc"=2 (0x2) "FastUserSwitchingCompatibility"=3 (0x3) "ERSvc"=2 (0x2) "DefWatch"=2 (0x2) "ccSetMgr"=2 (0x2) "ccPwdSvc"=3 (0x3) "ccEvtMgr"=2 (0x2) "BITS"=2 (0x2) "avg8emc"=2 (0x2) "Ati HotKey Poller"=2 (0x2) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\AVG\\AVG8\\avgemc.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"= "c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"= "c:\\Program Files\\Vuze\\Azureus.exe"= "c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"= "c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"= "c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"= "c:\\Program Files\\MediaMelon\\bin\\wrapper.exe"= "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "11:TCP"= 11:TCP:INTERNET "3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009 R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/18/2008 10:45 PM 327688] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/18/2008 10:45 PM 108552] R1 sasdifsv;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [6/23/2009 11:01 AM 9968] R1 saskutil;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [6/23/2009 11:01 AM 72944] R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/3/2009 8:05 AM 906520] R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/4/2008 9:06 AM 298776] R2 MediaMelon Client;MediaMelon Client 1.0;c:\program files\MediaMelon\bin\wrapper.exe [4/16/2009 3:30 PM 217088] S2 gupdate1c98fbdcfb083d4;Google Update Service (gupdate1c98fbdcfb083d4);c:\program files\Google\Update\GoogleUpdate.exe [2/15/2009 5:36 PM 133104] S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [7/2/2009 2:09 PM 1252474] S3 sasenum;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [6/23/2009 11:01 AM 7408] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPServiceREG_MULTI_SZ HPSLPSVC hpdevmgmtREG_MULTI_SZ hpqcxs08 hpqddsvc [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-07-04 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 18:34] 2009-07-06 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-03 14:36] 2009-07-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 22:35] 2009-07-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-15 22:35] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-05 19:45 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(892) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\Ati2evxx.dll - - - - - - - > 'explorer.exe'(3104) c:\windows\system32\webcheck.dll c:\windows\system32\IEFRAME.dll c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL c:\progra~1\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL c:\windows\system32\msls31.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\windows\system32\WLTRYSVC.EXE c:\windows\system32\BCMWLTRY.EXE c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\drivers\CDAC11BA.EXE c:\program files\Google\Update\1.2.183.7\GoogleCrashHandler.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\AVG\AVG8\avgrsx.exe c:\progra~1\AVG\AVG8\avgnsx.exe c:\windows\system32\java.exe c:\program files\Canon\CAL\CALMAIN.exe c:\program files\AVG\AVG8\avgcsrvx.exe c:\program files\Yahoo!\Messenger\Ymsgr_tray.exe c:\program files\iPod\bin\iPodService.exe c:\windows\system32\wscntfy.exe c:\program files\HP\Digital Imaging\bin\hpqste08.exe c:\program files\HP\Digital Imaging\bin\hpqbam08.exe c:\windows\system32\msiexec.exe c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe . ************************************************************************** . Completion time: 2009-07-06 19:47 - machine was rebooted ComboFix-quarantined-files.txt 2009-07-06 00:47 ComboFix2.txt 2009-07-05 04:59 Pre-Run: 4,735,184,896 bytes free Post-Run: 4,738,347,008 bytes free 284--- E O F ---2009-06-11 08:03 How is the computer running now?
. The above procedure will:
---------- 1. Double click OTM to launch it. Vista users right click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTM will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTM. HI, My computer is running Normal now. Thank you very much. Do I need to do anything else? Thanks a million, SreeFinal suggestions. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 3847. |
Solve : Cant install Micr. office xp installer patch?? |
|
Answer» I have 1GB of RAM and 9.76g on my C drive and 269 on my e drive. Is that normal. My motherboard is ASUS p4s333 and for some reason my bios says it incorrect. OK i installed microsoft OFFICE xp professional with frontpage on my comp and for some reason its not showing or coming up and when i put the disk in to set it up it says SOMETHING about the installer PATCH. I have xp home edition sp 3. When I go to add and remove and try to uninstall it and it says the source does not exist. Very confusing. it cant FIND the installer patch. even with the cd. Thank you in advance whomever replies. if you need any other info please don't hesitate to ask. |
|
| 3848. |
Solve : HJT Log for perusal before l submit another post? |
|
Answer» I'm having terrible problems with my pc at the MOMENT but before l send a POST to the right forum, could someone take a look at my HJT log to see if anything is dodgy. |
|
| 3849. |
Solve : loading issues? |
|
Answer» Logfile of TREND Micro HijackThis v2.0.2 |
|
| 3850. |
Solve : Virus Combo? |
|
Answer» I was cruising some unscrupulous sites (my fault, so I partially deserve his) and clearly picked up something that was quite strong. |
|