![]() ![]() |
Nov 8 2008, 02:24 PM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
Hello,
Picked up malware yesterday called tinyproxy.exe that NAV caught and blocked. However, now my google searches are being redirected. I've run Ad-aware with latest definitions, problem is still there. I'm running WinXP, IE 7, Norton AV 2008 Following is current HJT log. Thank you for your help! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:24:54 AM, on 11/8/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\WINDOWS\system32\HPConfig.exe C:\WINDOWS\system32\RadioSvr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE C:\Windows\system32\HpSrvUI.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\essspk.exe C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4nb.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4nb.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://srch-us4nb.hpwis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://srch-us4nb.hpwis.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local> O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll O2 - BHO: 890166 helper - {A48FE9AC-DD02-4FF7-9211-B7BA9A2C8BF2} - C:\WINDOWS\system32\890166\890166.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [CP4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [HPLaptopGamesActiveMenu] C:\Program Files\WildTangent\ActiveMenu\HPLaptop\Games\ActiveMenu.exe O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [VTPreset] VTPreset.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: ORiNOCO Client Manager.lnk = C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/bizcenter-o O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2098F239-F08E-4840-9F81-B758A4971D83} - http://www.batesville.com/us/setup.cab O16 - DPF: {3F807625-B32A-498F-9010-7ABB2BB5D3B3} - http://www.batesville.com/us/install.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.a...meInstaller.exe O16 - DPF: {5A3AD060-E5D9-4DEF-8E77-B44336153FD9} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft Terminal Services Client Control (redist)) - https://ccgfalmouth.dyndns.org/Remote/msrdp.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp.com/rdqna/downloads/msxml4.cab O16 - DPF: {8B2BE470-543C-4662-8536-54D191F82675} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft Terminal Services Client Control (redist)) - http://68.160.177.202:10367/tsweb/msrdp.cab O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com/Apps/WSC/en-us/WscWlanScannerCtrl.cab O16 - DPF: {BB707357-1966-4198-B14B-1F8156D79B98} - http://www.batesville.com/us/setup.cab O16 - DPF: {CFC1C622-8C5B-4683-A64F-5A964EE397E1} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/...ash/swflash.cab O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://webmail.gpjco.com/dwa7W.cab O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Error Reporting Service (ERSvc) - Unknown owner - (no file) O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: WinPPPoverEthernet - Unknown owner - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE (file missing) -- End of file - 10271 bytes |
|
|
|
Nov 8 2008, 04:06 PM
Post
#2
|
|
|
Advanced Member ![]() ![]() ![]() Group: Volunteer Security Advisor Posts: 1,733 Joined: 9-September 08 Member No.: 62,225 |
Hello
Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding. Download SDFix and save it to your Desktop. Double click SDFix.exe and it will extract the files to %systemdrive% (Drive that contains the Windows Directory, typically C:\SDFix) Please then reboot your computer in Safe Mode by doing the following :
Disable resident protections (Antivirus...); you'll re-enable them after the scan Download Lop S&D < here Double-click Lop S&D.exe Choose the language, then choose Option 1 (Search) Wait till the end of the scan Post the log which is created: (%SystemDrive%\lopR.txt) -------------------- By the power of truth, I, while living, have conquered the universe.
~Scratch~ |
|
|
|
Nov 8 2008, 05:31 PM
Post
#3
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
Here is report.txt from SDfix. logfile from Lop S&D will follow shortly. Thanks!
SDFix: Version 1.240 Run by Owner on Sat 11/08/2008 at 10:54 AM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : No Trojan Files Found Folder C:\WINDOWS\system32\890166 - Removed Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-08 11:11:18 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Symantec\\pcAnywhere\\WINAW32.EXE"="C:\\Program Files\\Symantec\\pcAnywhere\\WINAW32.EXE:*:Enabled:pcAnywhere Main Program" "C:\\Program Files\\Symantec\\pcAnywhere\\AWHOST32.EXE"="C:\\Program Files\\Symantec\\pcAnywhere\\AWHOST32.EXE:*:Enabled:pcAnywhere Host Service" "C:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe"="C:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe:*:Enabled:pcAnywhere Remote Service" "C:\\Program Files\\microsoft frontpage\\bin\\fpexplor.exe"="C:\\Program Files\\microsoft frontpage\\bin\\fpexplor.exe:*:Enabled:Microsoft FrontPage Explorer" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Sat 4 Mar 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Fri 7 Nov 2008 8,448 ..SHR --- "C:\RECYCLER\S-1-5-21-3499916212-2805738209-4071888707-1003\Dc517\tinyproxy.exe" Fri 7 Nov 2008 29,696 A..H. --- "C:\System Volume Information\_restore{CBC2C510-007E-49FC-B319-B551940A2A56}\RP929\A0090266.exe" Fri 7 Nov 2008 29,696 A..H. --- "C:\System Volume Information\_restore{CBC2C510-007E-49FC-B319-B551940A2A56}\RP930\A0090267.exe" Thu 15 May 2003 43,008 ...H. --- "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe" Fri 18 Jan 2008 400 A..H. --- "C:\Program Files\Common Files\Symantec Shared\COH\COH32LU.reg" Fri 18 Jan 2008 403 A..H. --- "C:\Program Files\Common Files\Symantec Shared\COH\COHDLU.reg" Sat 4 Mar 2006 4,348 ...H. --- "C:\Documents and Settings\Owner\My Documents\My Music\License Backup\drmv1key.bak" Tue 21 Mar 2006 20 A..H. --- "C:\Documents and Settings\Owner\My Documents\My Music\License Backup\drmv1lic.bak" Sat 4 Mar 2006 400 A.SH. --- "C:\Documents and Settings\Owner\My Documents\My Music\License Backup\drmv2key.bak" Tue 25 Oct 2005 19,456 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Job_Search\~WRL0005.tmp" Tue 25 Oct 2005 20,480 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Job_Search\~WRL0493.tmp" Tue 25 Oct 2005 20,992 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Job_Search\~WRL0551.tmp" Tue 25 Oct 2005 19,456 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Job_Search\~WRL1174.tmp" Tue 25 Oct 2005 20,480 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Job_Search\~WRL1835.tmp" Tue 25 Oct 2005 20,480 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Job_Search\~WRL2066.tmp" Tue 25 Oct 2005 20,480 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Job_Search\~WRL3695.tmp" Tue 25 Oct 2005 20,992 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Job_Search\~WRL3958.tmp" Thu 12 Jul 2001 35,328 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Work\~WRL0004.tmp" Sun 25 Jan 2004 52,736 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Work\~WRL0005.tmp" Thu 12 Jul 2001 35,328 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Work\~WRL1301.tmp" Sun 25 Jan 2004 40,448 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Work\~WRL1321.tmp" Sun 25 Jan 2004 42,496 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Work\~WRL2530.tmp" Sun 25 Jan 2004 48,640 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Work\~WRL2648.tmp" Sun 25 Jan 2004 44,032 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Work\~WRL2938.tmp" Sun 25 Jan 2004 40,960 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Work\~WRL3583.tmp" Thu 12 Jul 2001 35,840 A..H. --- "C:\Documents and Settings\Owner\Desktop\HEY KIM! OLD FILES ARE HERE!\Kim\Work\~WRL3620.tmp" Finished! |
|
|
|
Nov 8 2008, 05:42 PM
Post
#4
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
Here is log from Lop S&D. Thanks again!
--------------------\\ Lop S&D 4.2.4-9c XP/Vista Microsoft Windows XP Home Edition ( v5.1.2600 ) Service Pack 2 X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 Mobile CPU 1.40GHz ) BIOS : Insyde Software MobilePRO BIOS Version 4.00.01 USER : Owner ( Administrator ) BOOT : Normal boot Antivirus : Norton AntiVirus 15.5.0.23 (Not Activated) Firewall : Norton AntiVirus 15.5.0.23 (Activated) C:\ (Local Disk) - NTFS - Total:27 Go (Free:9 Go) D:\ (USB) E:\ (CD or DVD) "C:\Lop SD" ( MAJ : 01-11-2008|16:30 ) Option : [1] ( Sat 11/08/2008|11:41 ) --------------------\\ Listing folders in APPLIC~1 [02/09/2008|07:44] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Adobe [05/14/2006|11:25] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> BVRP Software [06/06/2005|06:21] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> InstallShield [08/06/2007|07:07] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Intuit [11/07/2008|09:17] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Lavasoft [03/12/2007|09:16] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Microsoft [04/04/2007|08:21] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Nero [11/21/2002|10:11] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> QuickTime [04/11/2002|09:16] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> SBSI [03/21/2006|09:34] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy [08/31/2008|07:16] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Symantec [03/09/2007|09:25] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Viewpoint [10/06/2002|05:09] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Visual Networks [02/04/2006|09:13] C:\DOCUME~2\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage [04/11/2002|08:43] C:\DOCUME~2\DEFAUL~1\APPLIC~1\<DIR> Adobe [04/11/2002|08:28] C:\DOCUME~2\DEFAUL~1\APPLIC~1\<DIR> Identities [04/11/2002|08:43] C:\DOCUME~2\DEFAUL~1\APPLIC~1\<DIR> InterTrust [04/11/2002|08:13] C:\DOCUME~2\DEFAUL~1\APPLIC~1\<DIR> Microsoft [04/11/2002|09:19] C:\DOCUME~2\DEFAUL~1\APPLIC~1\<DIR> Symantec [04/11/2002|08:43] C:\DOCUME~2\Guest\APPLIC~1\<DIR> Adobe [04/11/2002|08:28] C:\DOCUME~2\Guest\APPLIC~1\<DIR> Identities [04/11/2002|08:43] C:\DOCUME~2\Guest\APPLIC~1\<DIR> InterTrust [03/24/2008|02:31] C:\DOCUME~2\Guest\APPLIC~1\<DIR> Microsoft [04/11/2002|09:19] C:\DOCUME~2\Guest\APPLIC~1\<DIR> Symantec [06/08/2002|01:00] C:\DOCUME~2\LOCALS~1\APPLIC~1\<DIR> Microsoft [04/11/2002|08:13] C:\DOCUME~2\NETWOR~1\APPLIC~1\<DIR> Microsoft [07/18/2008|01:09] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Adobe [12/09/2007|12:38] C:\DOCUME~2\Owner\APPLIC~1\<DIR> AdobeUM [04/04/2007|08:42] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Ahead [04/05/2006|03:23] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Allume Systems [08/12/2002|06:06] C:\DOCUME~2\Owner\APPLIC~1\<DIR> CyberLink [07/01/2002|11:01] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Help [04/11/2002|08:28] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Identities [08/12/2002|07:21] C:\DOCUME~2\Owner\APPLIC~1\<DIR> InterVideo [08/06/2007|07:00] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Intuit [02/28/2006|09:28] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Lavasoft [04/04/2007|05:03] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Leadertech [01/15/2004|08:38] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Macromedia [12/09/2007|01:03] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Microsoft [06/19/2006|09:01] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Sun [02/24/2007|12:32] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Symantec [08/06/2002|11:16] C:\DOCUME~2\Owner\APPLIC~1\<DIR> VERITAS [03/09/2007|09:25] C:\DOCUME~2\Owner\APPLIC~1\<DIR> Viewpoint --------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks [11/04/2008 07:10 AM][--a------] C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Owner.job [11/08/2008 11:04 AM][--ah-----] C:\WINDOWS\tasks\SA.DAT [08/18/2001 07:00 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini --------------------\\ Listing Folders in C:\Program Files [11/13/2006|08:47] C:\Program Files\<DIR> 3DGroove [07/03/2008|01:53] C:\Program Files\<DIR> Adobe [10/02/2002|07:57] C:\Program Files\<DIR> Adobe Type Manager [04/05/2006|03:21] C:\Program Files\<DIR> Allume Systems [09/01/2002|04:49] C:\Program Files\<DIR> ArcSoft [03/15/2004|03:51] C:\Program Files\<DIR> Batesville [05/14/2006|10:07] C:\Program Files\<DIR> Burncdcc [08/23/2002|01:39] C:\Program Files\<DIR> Canon [10/05/2003|10:53] C:\Program Files\<DIR> CDCheck [11/07/2008|09:14] C:\Program Files\<DIR> Common Files [04/11/2002|08:20] C:\Program Files\<DIR> ComPlus Applications [03/21/2006|09:36] C:\Program Files\<DIR> CyberLink [10/25/2005|06:50] C:\Program Files\<DIR> Directors Tribute Creator [04/11/2002|09:00] C:\Program Files\<DIR> Games [11/07/2007|07:52] C:\Program Files\<DIR> Hewlett-Packard [04/21/2008|07:36] C:\Program Files\<DIR> Hooked on Phonics Learning [04/11/2002|08:33] C:\Program Files\<DIR> HP [12/26/2002|09:06] C:\Program Files\<DIR> HP DLA [02/06/2004|03:30] C:\Program Files\<DIR> HP RecordNow [09/02/2007|08:51] C:\Program Files\<DIR> InstallShield Installation Information [01/01/2004|02:54] C:\Program Files\<DIR> InterActual [10/15/2008|02:08] C:\Program Files\<DIR> Internet Explorer [04/11/2002|08:44] C:\Program Files\<DIR> InterVideo [06/19/2006|08:57] C:\Program Files\<DIR> Java [11/07/2008|09:15] C:\Program Files\<DIR> Lavasoft [05/14/2006|10:39] C:\Program Files\<DIR> LiveUpdate [06/07/2002|05:31] C:\Program Files\<DIR> MapInfo MapX [08/16/2008|02:14] C:\Program Files\<DIR> Messenger [04/12/2002|12:39] C:\Program Files\<DIR> Microsoft ActiveSync [09/14/2002|01:20] C:\Program Files\<DIR> microsoft frontpage [11/24/2006|01:42] C:\Program Files\<DIR> Microsoft IntelliPoint [10/28/2008|01:22] C:\Program Files\<DIR> Microsoft Office [05/14/2006|10:51] C:\Program Files\<DIR> mobile PhoneTools [10/06/2002|05:07] C:\Program Files\<DIR> Motive [04/23/2006|07:51] C:\Program Files\<DIR> Motorola [03/12/2007|08:00] C:\Program Files\<DIR> Movie Maker [10/28/2008|01:21] C:\Program Files\<DIR> MSECache [12/24/2005|10:04] C:\Program Files\<DIR> MSN Apps [04/11/2002|08:19] C:\Program Files\<DIR> MSN Gaming Zone [12/24/2005|10:02] C:\Program Files\<DIR> MSN Messenger [03/07/2005|07:29] C:\Program Files\<DIR> MsnMusic [03/30/2007|02:32] C:\Program Files\<DIR> MSXML 4.0 [04/11/2002|08:59] C:\Program Files\<DIR> MusicMatch [04/04/2007|08:21] C:\Program Files\<DIR> Nero [03/12/2007|07:53] C:\Program Files\<DIR> NetMeeting [05/13/2008|02:31] C:\Program Files\<DIR> Norton AntiVirus [04/15/2006|02:58] C:\Program Files\<DIR> NoteWorthy Composer [02/24/2004|07:49] C:\Program Files\<DIR> OfficeUpdate11 [06/10/2002|10:25] C:\Program Files\<DIR> ORiNOCO [06/02/2008|06:27] C:\Program Files\<DIR> Outlook Express [05/08/2006|10:08] C:\Program Files\<DIR> Outlook Express Backup Wizard [04/19/2004|08:16] C:\Program Files\<DIR> PowerPoint Viewer [04/11/2002|09:05] C:\Program Files\<DIR> QuickenFC [10/26/2008|07:41] C:\Program Files\<DIR> QUICKENW [11/05/2004|07:00] C:\Program Files\<DIR> QuickTime [08/28/2007|09:47] C:\Program Files\<DIR> S3 [08/29/2004|07:18] C:\Program Files\<DIR> Samsung [07/05/2002|05:44] C:\Program Files\<DIR> Seagate Software [10/22/2004|06:50] C:\Program Files\<DIR> Snapshot Viewer [03/21/2006|09:34] C:\Program Files\<DIR> Spybot - Search & Destroy [08/23/2008|06:08] C:\Program Files\<DIR> Symantec [11/08/2008|12:01] C:\Program Files\<DIR> Trend Micro [07/17/2003|09:39] C:\Program Files\<DIR> Uninstall Information [12/16/2005|11:32] C:\Program Files\<DIR> Verizon Wireless [03/07/2005|12:10] C:\Program Files\<DIR> Viewpoint [07/19/2008|02:37] C:\Program Files\<DIR> Virtools [07/19/2008|02:35] C:\Program Files\<DIR> Virtools Web Player 3.5 [09/02/2007|08:51] C:\Program Files\<DIR> VTech [04/23/2006|07:51] C:\Program Files\<DIR> WIBUKEY [04/23/2006|07:51] C:\Program Files\<DIR> WIBU-SYSTEMS [03/30/2007|02:19] C:\Program Files\<DIR> Windows Media Player [03/12/2007|07:52] C:\Program Files\<DIR> Windows NT [05/13/2008|07:33] C:\Program Files\<DIR> Windows Sidebar [02/04/2006|08:57] C:\Program Files\<DIR> WindowsUpdate [07/21/2007|01:23] C:\Program Files\<DIR> WinZip [04/11/2002|08:24] C:\Program Files\<DIR> xerox [04/05/2006|03:27] C:\Program Files\<DIR> X-Fonter --------------------\\ Listing Folders in C:\Program Files\Common Files [02/09/2008|07:44] C:\Program Files\Common Files\<DIR> Adobe [04/04/2007|08:24] C:\Program Files\Common Files\<DIR> Ahead [04/12/2002|12:38] C:\Program Files\Common Files\<DIR> Designer [04/23/2006|07:50] C:\Program Files\Common Files\<DIR> InstallShield [08/06/2007|07:03] C:\Program Files\Common Files\<DIR> Intuit [06/19/2006|08:55] C:\Program Files\Common Files\<DIR> Java [10/28/2008|01:22] C:\Program Files\Common Files\<DIR> Microsoft Shared [10/06/2002|05:06] C:\Program Files\Common Files\<DIR> Motive [04/11/2002|08:21] C:\Program Files\Common Files\<DIR> MSSoap [04/11/2002|08:14] C:\Program Files\Common Files\<DIR> ODBC [08/06/2007|07:03] C:\Program Files\Common Files\<DIR> Palo Alto Software [08/21/2002|06:08] C:\Program Files\Common Files\<DIR> Pervasive Software [04/11/2002|08:21] C:\Program Files\Common Files\<DIR> Services [04/11/2002|08:14] C:\Program Files\Common Files\<DIR> SpeechEngines [11/07/2008|12:19] C:\Program Files\Common Files\<DIR> Symantec Shared [06/02/2008|06:27] C:\Program Files\Common Files\<DIR> System [07/02/2002|07:55] C:\Program Files\Common Files\<DIR> Vbox [11/07/2008|09:14] C:\Program Files\Common Files\<DIR> Wise Installation Wizard --------------------\\ Process ( 40 Processes ) ... OK ! --------------------\\ Searching with S_Lop No Lop folder found ! --------------------\\ Searching for Lop Files - Folders C:\DOCUME~2\Owner\Cookies\owner@greatermediaboston.advertserve[1].txt C:\DOCUME~2\Owner\Cookies\owner@jra.advertserve[1].txt C:\DOCUME~2\Owner\Cookies\owner@advertising[2].txt C:\DOCUME~2\Owner\Cookies\owner@lasvegassun[2].txt --------------------\\ Searching within the Registry ..... OK ! --------------------\\ Checking the Hosts file Hosts file CLEAN --------------------\\ Searching for hidden files with Catchme catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-08 11:43:55 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden files: 0 --------------------\\ Searching for other infections --------------------\\ KoobFace ! C:\WINDOWS\fmark2.dat --------------------\\ Cracks & Keygens .. C:\DOCUME~2\Owner\Cookies\owner@crackberry[1].txt C:\DOCUME~2\Owner\Cookies\owner@forums.crackberry[1].txt C:\DOCUME~2\Owner\Local Settings\Temporary Internet Files\Content.IE5\GCJGQGRP\crackberry-logo-wall-on[1].jpg C:\DOCUME~2\Owner\Local Settings\Temporary Internet Files\Content.IE5\YVQ9CX1N\crackberry-logo-forums-on[1].jpg [F:17][D:268]-> C:\DOCUME~2\Owner\LOCALS~1\Temp [F:1713][D:0]-> C:\DOCUME~2\Owner\Cookies [F:17887][D:29]-> C:\DOCUME~2\Owner\LOCALS~1\TEMPOR~1\content.IE5 1 - "C:\Lop SD\LopR_1.txt" - Sat 11/08/2008|11:46 - Option : [1] --------------------\\ Scan completed at 11:46:15 |
|
|
|
Nov 8 2008, 06:04 PM
Post
#5
|
|
|
Advanced Member ![]() ![]() ![]() Group: Volunteer Security Advisor Posts: 1,733 Joined: 9-September 08 Member No.: 62,225 |
Hello
Please download the OTMoveIt3 by OldTimer or from here.
Download ComboFix from one of these locations: Link 1 Link 2 Link 3 * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. -------------------- By the power of truth, I, while living, have conquered the universe.
~Scratch~ |
|
|
|
Nov 8 2008, 07:46 PM
Post
#6
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
OTMoveIt3 log:
========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\RECYCLER\S-1-5-21-3499916212-2805738209-4071888707-1003\Dc517\tinyproxy.exe moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~2\Owner\LOCALS~1\Temp\~DFBF36.tmp scheduled to be deleted on reboot. File delete failed. C:\DOCUME~2\Owner\LOCALS~1\Temp\~DFBF55.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\JETEDB9.tmp scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11082008_131725 Files moved on Reboot... File C:\DOCUME~2\Owner\LOCALS~1\Temp\~DFBF36.tmp not found! File C:\DOCUME~2\Owner\LOCALS~1\Temp\~DFBF55.tmp not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\JETEDB9.tmp not found! Combofix log: ComboFix 08-11-07.01 - Owner 2008-11-08 13:40:01.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.470 [GMT -5:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Downloaded Program Files\setup.inf c:\windows\fmark2.dat . ((((((((((((((((((((((((( Files Created from 2008-10-08 to 2008-11-08 ))))))))))))))))))))))))))))))) . 2008-11-08 13:14 . 2008-11-08 13:14 <DIR> d-------- C:\_OTMoveIt 2008-11-08 11:40 . 2008-11-08 11:46 <DIR> d-------- C:\Lop SD 2008-11-08 10:45 . 2008-11-08 10:46 <DIR> d-------- c:\windows\ERUNT 2008-11-08 10:38 . 2008-11-08 11:30 <DIR> d-------- C:\SDFix 2008-11-08 00:01 . 2008-11-08 00:01 <DIR> d-------- c:\program files\Trend Micro 2008-11-07 21:15 . 2008-11-07 21:15 <DIR> d-------- c:\program files\Lavasoft 2008-11-07 21:15 . 2008-11-07 21:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft 2008-11-07 21:14 . 2008-11-07 21:14 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard 2008-11-07 12:18 . 2008-11-07 14:00 1 ---h----- c:\windows\f49f4daa.dat 2008-10-28 13:21 . 2008-10-28 13:21 <DIR> d-------- c:\program files\MSECache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-07 17:19 --------- d-----w c:\program files\Common Files\Symantec Shared 2008-10-27 00:41 --------- d-----w c:\program files\QUICKENW 2008-10-15 16:57 332,800 ------w c:\windows\system32\dllcache\netapi32.dll 2008-10-03 17:41 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll 2008-09-15 11:57 1,846,016 ----a-w c:\windows\system32\win32k.sys 2008-09-15 11:57 1,846,016 ------w c:\windows\system32\dllcache\win32k.sys 2008-08-28 10:04 333,056 ------w c:\windows\system32\dllcache\srv.sys 2008-08-27 08:24 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll 2008-08-25 08:38 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe 2008-08-25 08:37 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe 2008-08-23 23:08 60,800 ----a-w c:\windows\system32\S32EVNT1.DLL 2008-08-23 05:56 635,848 ------w c:\windows\system32\dllcache\iexplore.exe 2008-08-23 05:54 161,792 ------w c:\windows\system32\dllcache\ieakui.dll 2008-08-14 10:00 2,180,352 ----a-w c:\windows\system32\ntoskrnl.exe 2008-08-14 10:00 2,180,352 ------w c:\windows\system32\dllcache\ntoskrnl.exe 2008-08-14 09:58 2,136,064 ------w c:\windows\system32\dllcache\ntkrnlmp.exe 2008-08-14 09:51 138,368 ------w c:\windows\system32\dllcache\afd.sys 2008-08-14 09:22 2,057,728 ----a-w c:\windows\system32\ntkrnlpa.exe 2008-08-14 09:22 2,057,728 ------w c:\windows\system32\dllcache\ntkrnlpa.exe 2008-08-14 09:22 2,015,744 ------w c:\windows\system32\dllcache\ntkrpamp.exe 2007-11-25 01:38 66,808 ----a-w c:\documents and settings\Owner\Application Data\GDIPFONTCACHEV1.DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP TV Now"="c:\program files\Hewlett-Packard\HP TV Now\HpTvNow.exe" [2002-03-14 237568] "HP Display Settings"="c:\program files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe" [2002-03-07 61440] "CP4HPOT"="c:\progra~1\HEWLET~1\ONE-TO~1\OneTouch.EXE" [2002-02-22 90112] "hp Silent Service"="c:\windows\system32\HpSrvUI.exe" [2001-11-29 32768] "hpScannerFirstBoot"="c:\hp\drivers\scanners\scannerfb.exe" [2001-12-13 20480] "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [2001-07-19 52736] "Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-04 143360] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2002-03-14 102455] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-11-05 98304] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920] "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 36975] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048] "osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2008-02-07 718704] "S3TRAY2"="S3tray2.exe" [2003-09-09 c:\windows\system32\S3tray2.exe] "EssSpkPhone"="essspk.exe" [2002-05-31 c:\windows\essspk.exe] "VTPreset"="VTPreset.exe" [2004-02-24 c:\windows\system32\VTPreset.exe] c:\documents and settings\All Users\Start Menu\Programs\Startup\ ORiNOCO Client Manager.lnk - c:\program files\ORiNOCO\Client Manager\CmLUC.exe [2002-07-22 339968] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify] 2002-02-15 09:51 24638 c:\windows\system32\PCANotify.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Symantec\\pcAnywhere\\WINAW32.EXE"= "c:\\Program Files\\Symantec\\pcAnywhere\\AWHOST32.EXE"= "c:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe"= "c:\\Program Files\\microsoft frontpage\\bin\\fpexplor.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352] R2 MLPTDR_J;MLPTDR_J;c:\windows\System32\MLPTDR_J.sys [2003-01-30 19904] R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\Drivers\WBSD.SYS [2002-03-31 24320] R3 wlluc48b;ORINOCO PC Card Driver;c:\windows\system32\DRIVERS\wlluc48b.sys [2002-07-15 156672] S3 BW2NDIS5;BW2NDIS5 NDIS Protocol Driver;c:\windows\system32\Drivers\BW2NDIS5.sys [ ] S3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888] S3 S3chipid;S3chipid;c:\windows\TEMP\_ISTMP0.DIR\S3chipid.sys [ ] S3 wlags48b;Agere Wireless PCCard Driver;c:\windows\system32\DRIVERS\wlags48b.sys [2003-01-09 163328] S3 WrKPoET2000;WrKPoET2000;c:\program files\Verizon Online\WinPoET\WrKPoET2000.sys [ ] *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder 2008-11-04 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Owner.job - c:\program files\Norton AntiVirus\Navw32.exe [2008-02-07 09:05] . - - - - ORPHANS REMOVED - - - - HKLM-Run-HPLaptopGamesActiveMenu - c:\program files\WildTangent\ActiveMenu\HPLaptop\Games\ActiveMenu.exe . ------- Supplementary Scan ------- . R0 -: HKCU-Main,Default_Search_URL = hxxp://srch-us4nb.hpwis.com/ R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/ R0 -: HKLM-Main,Search Bar = hxxp://srch-us4nb.hpwis.com/ R1 -: HKCU-Internet Settings,ProxyOverride = *.local;<local> R1 -: HKCU-Internet Settings,ProxyServer = http=127.0.0.1:9090 O8 -: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd O16 -: {2098F239-F08E-4840-9F81-B758A4971D83} - hxxp://www.batesville.com/us/setup.cab c:\windows\Downloaded Program Files\Setup.inf O16 -: {3F807625-B32A-498F-9010-7ABB2BB5D3B3} - hxxp://www.batesville.com/us/install.cab c:\windows\Downloaded Program Files\Setup.inf O16 -: {5A3AD060-E5D9-4DEF-8E77-B44336153FD9} - hxxp://www.batesville.com/dlb/setup.cab c:\windows\Downloaded Program Files\Setup.inf O16 -: {8B2BE470-543C-4662-8536-54D191F82675} - hxxp://www.batesville.com/dlb/setup.cab c:\windows\Downloaded Program Files\Setup.inf O16 -: {BB707357-1966-4198-B14B-1F8156D79B98} - hxxp://www.batesville.com/us/setup.cab c:\windows\Downloaded Program Files\Setup.inf O16 -: {CFC1C622-8C5B-4683-A64F-5A964EE397E1} - hxxp://www.batesville.com/dlb/setup.cab c:\windows\Downloaded Program Files\Setup.inf . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-08 13:44:38 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Error Reporting Service (ERSvc) ] "ImagePath"="" . Completion time: 2008-11-08 13:49:42 ComboFix-quarantined-files.txt 2008-11-08 18:48:31 Pre-Run: 12,637,306,880 bytes free Post-Run: 12,735,676,416 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn 157 --- E O F --- 2008-10-29 07:05:26 |
|
|
|
Nov 8 2008, 08:43 PM
Post
#7
|
|
|
Advanced Member ![]() ![]() ![]() Group: Volunteer Security Advisor Posts: 1,733 Joined: 9-September 08 Member No.: 62,225 |
Hello
1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: QUOTE File:: c:\windows\f49f4daa.dat Folder:: Registry:: Driver:: "Error Reporting Service (ERSvc) " Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. -------------------- By the power of truth, I, while living, have conquered the universe.
~Scratch~ |
|
|
|
Nov 9 2008, 01:44 AM
Post
#8
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
Hello 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. Rorschach112, Had to go to in-laws for dinner. Will have the Combofix log for you ASAP. Thanks! |
|
|
|
Nov 9 2008, 02:24 PM
Post
#9
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
Hello 1. Close any open browsers. 2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. 3. Open notepad and copy/paste the text in the quotebox below into it: Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply. Second Combofix log. Sorry for the delay. ComboFix 08-11-07.01 - Owner 2008-11-08 14:58:50.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.446 [GMT -5:00] Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt * Created a new restore point FILE :: c:\windows\f49f4daa.dat . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\f49f4daa.dat . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_ERROR_REPORTING_SERVICE_(ERSVC)_ -------\Service_Error Reporting Service (ERSvc) ((((((((((((((((((((((((( Files Created from 2008-10-08 to 2008-11-08 ))))))))))))))))))))))))))))))) . 2008-11-08 13:14 . 2008-11-08 13:14 <DIR> d-------- C:\_OTMoveIt 2008-11-08 11:40 . 2008-11-08 11:46 <DIR> d-------- C:\Lop SD 2008-11-08 10:45 . 2008-11-08 10:46 <DIR> d-------- c:\windows\ERUNT 2008-11-08 10:38 . 2008-11-08 11:30 <DIR> d-------- C:\SDFix 2008-11-08 00:01 . 2008-11-08 00:01 <DIR> d-------- c:\program files\Trend Micro 2008-11-07 21:15 . 2008-11-07 21:15 <DIR> d-------- c:\program files\Lavasoft 2008-11-07 21:15 . 2008-11-07 21:17 <DIR> d-------- c:\documents and settings\All Users\Application Data\Lavasoft 2008-11-07 21:14 . 2008-11-07 21:14 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard 2008-10-28 13:21 . 2008-10-28 13:21 <DIR> d-------- c:\program files\MSECache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-11-07 17:19 --------- d-----w c:\program files\Common Files\Symantec Shared 2008-10-27 00:41 --------- d-----w c:\program files\QUICKENW 2007-11-25 01:38 66,808 ----a-w c:\documents and settings\Owner\Application Data\GDIPFONTCACHEV1.DAT . ((((((((((((((((((((((((((((( snapshot@2008-11-08_13.47.42.12 ))))))))))))))))))))))))))))))))))))))))) . + 2005-10-21 01:02:28 163,328 ----a-w c:\windows\ERDNT\subs\ERDNT.EXE . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HP TV Now"="c:\program files\Hewlett-Packard\HP TV Now\HpTvNow.exe" [2002-03-14 237568] "HP Display Settings"="c:\program files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe" [2002-03-07 61440] "CP4HPOT"="c:\progra~1\HEWLET~1\ONE-TO~1\OneTouch.EXE" [2002-02-22 90112] "hp Silent Service"="c:\windows\system32\HpSrvUI.exe" [2001-11-29 32768] "hpScannerFirstBoot"="c:\hp\drivers\scanners\scannerfb.exe" [2001-12-13 20480] "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [2001-07-19 52736] "Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-04 143360] "dla"="c:\windows\system32\dla\tfswctrl.exe" [2002-03-14 102455] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2004-11-05 98304] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 221184] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920] "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 36975] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2005-03-23 217088] "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048] "osCheck"="c:\program files\Norton AntiVirus\osCheck.exe" [2008-02-07 718704] "S3TRAY2"="S3tray2.exe" [2003-09-09 c:\windows\system32\S3tray2.exe] "EssSpkPhone"="essspk.exe" [2002-05-31 c:\windows\essspk.exe] "VTPreset"="VTPreset.exe" [2004-02-24 c:\windows\system32\VTPreset.exe] c:\documents and settings\All Users\Start Menu\Programs\Startup\ ORiNOCO Client Manager.lnk - c:\program files\ORiNOCO\Client Manager\CmLUC.exe [2002-07-22 339968] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify] 2002-02-15 09:51 24638 c:\windows\system32\PCANotify.dll [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Symantec\\pcAnywhere\\WINAW32.EXE"= "c:\\Program Files\\Symantec\\pcAnywhere\\AWHOST32.EXE"= "c:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe"= "c:\\Program Files\\microsoft frontpage\\bin\\fpexplor.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352] R2 MLPTDR_J;MLPTDR_J;c:\windows\System32\MLPTDR_J.sys [2003-01-30 19904] R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\Drivers\WBSD.SYS [2002-03-31 24320] S3 BW2NDIS5;BW2NDIS5 NDIS Protocol Driver;c:\windows\system32\Drivers\BW2NDIS5.sys [ ] S3 COH_Mon;COH_Mon;c:\windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888] S3 S3chipid;S3chipid;c:\windows\TEMP\_ISTMP0.DIR\S3chipid.sys [ ] S3 wlags48b;Agere Wireless PCCard Driver;c:\windows\system32\DRIVERS\wlags48b.sys [2003-01-09 163328] S3 wlluc48b;ORINOCO PC Card Driver;c:\windows\system32\DRIVERS\wlluc48b.sys [2002-07-15 156672] S3 WrKPoET2000;WrKPoET2000;c:\program files\Verizon Online\WinPoET\WrKPoET2000.sys [ ] *Newly Created Service* - ERROR_REPORTING_SERVICE_(ERSVC)_ . Contents of the 'Scheduled Tasks' folder 2008-11-04 c:\windows\Tasks\Norton AntiVirus - Run Full System Scan - Owner.job - c:\program files\Norton AntiVirus\Navw32.exe [2008-02-07 09:05] . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-11-08 15:11:55 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Error Reporting Service (ERSvc) ] "ImagePath"="" . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe c:\program files\Lavasoft\Ad-Aware\aawservice.exe c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe c:\windows\system32\HPConfig.exe c:\windows\system32\RadioSvr.exe c:\windows\system32\wdfmgr.exe . ************************************************************************** . Completion time: 2008-11-08 15:21:23 - machine was rebooted ComboFix-quarantined-files.txt 2008-11-08 20:21:11 ComboFix2.txt 2008-11-08 18:49:44 Pre-Run: 12,723,879,936 bytes free Post-Run: 12,658,851,840 bytes free 129 --- E O F --- 2008-10-29 07:05:26 |
|
|
|
Nov 9 2008, 07:14 PM
Post
#10
|
|
|
Advanced Member ![]() ![]() ![]() Group: Volunteer Security Advisor Posts: 1,733 Joined: 9-September 08 Member No.: 62,225 |
Hello
Please download Malwarebytes' Anti-Malware from Here or Here Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Go to Kaspersky website and perform an online antivirus scan.
-------------------- By the power of truth, I, while living, have conquered the universe.
~Scratch~ |
|
|
|
Nov 9 2008, 10:43 PM
Post
#11
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
Hello Rorschach112,
The following is Malwarebytes log. Running Kaspersky scan now. Thanks! Malwarebytes' Anti-Malware 1.30 Database version: 1378 Windows 5.1.2600 Service Pack 2 11/9/2008 4:50:40 PM mbam-log-2008-11-09 (16-50-40).txt Scan type: Quick Scan Objects scanned: 49425 Time elapsed: 6 minute(s), 57 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
Nov 10 2008, 12:09 AM
Post
#12
|
|
|
Advanced Member ![]() ![]() ![]() Group: Volunteer Security Advisor Posts: 1,733 Joined: 9-September 08 Member No.: 62,225 |
Post a new HJT log with the Kaspersky one
-------------------- By the power of truth, I, while living, have conquered the universe.
~Scratch~ |
|
|
|
Nov 10 2008, 01:55 AM
Post
#13
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
Post a new HJT log with the Kaspersky one Here is Kasperky log: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Sunday, November 9, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Sunday, November 09, 2008 10:09:15 Records in database: 1376472 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 70983 Threat name: 2 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 02:41:30 File name / Threat name / Threats count C:\SDFix\backups\890166\890166.dll Infected: not-a-virus:AdWare.Win32.E404.iy 1 C:\_OTMoveIt\MovedFiles\11082008_131725\RECYCLER\S-1-5-21-3499916212-2805738209-4071888707-1003\Dc517\tinyproxy.exe Infected: Trojan-Proxy.Win32.Agent.bcw 1 The selected area was scanned. and here is HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:05:44 PM, on 11/9/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\WINDOWS\system32\HPConfig.exe C:\WINDOWS\system32\RadioSvr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE C:\Windows\system32\HpSrvUI.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\essspk.exe C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe C:\Program Files\internet explorer\iexplore.exe C:\Documents and Settings\Owner\Local Settings\temp\jkos-Owner\binaries\ScanningProcess.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4nb.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local> O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [CP4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [VTPreset] VTPreset.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: ORiNOCO Client Manager.lnk = C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/bizcenter-o O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2098F239-F08E-4840-9F81-B758A4971D83} - http://www.batesville.com/us/setup.cab O16 - DPF: {3F807625-B32A-498F-9010-7ABB2BB5D3B3} - http://www.batesville.com/us/install.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.a...meInstaller.exe O16 - DPF: {5A3AD060-E5D9-4DEF-8E77-B44336153FD9} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft Terminal Services Client Control (redist)) - https://ccgfalmouth.dyndns.org/Remote/msrdp.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp.com/rdqna/downloads/msxml4.cab O16 - DPF: {8B2BE470-543C-4662-8536-54D191F82675} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft Terminal Services Client Control (redist)) - http://68.160.177.202:10367/tsweb/msrdp.cab O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com/Apps/WSC/en-us/WscWlanScannerCtrl.cab O16 - DPF: {BB707357-1966-4198-B14B-1F8156D79B98} - http://www.batesville.com/us/setup.cab O16 - DPF: {CFC1C622-8C5B-4683-A64F-5A964EE397E1} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/...ash/swflash.cab O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://webmail.gpjco.com/dwa7W.cab O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Error Reporting Service (ERSvc) - Unknown owner - (no file) O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: WinPPPoverEthernet - Unknown owner - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE (file missing) -- End of file - 9812 bytes |
|
|
|
Nov 10 2008, 02:02 AM
Post
#14
|
|
|
Advanced Member ![]() ![]() ![]() Group: Volunteer Security Advisor Posts: 1,733 Joined: 9-September 08 Member No.: 62,225 |
Hello
-------------------- By the power of truth, I, while living, have conquered the universe.
~Scratch~ |
|
|
|
Nov 10 2008, 02:50 AM
Post
#15
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
Hello
Here is log.txt Logfile of random's system information tool 1.04 (written by random/random) Run by Owner at 2008-11-09 20:59:35 Microsoft Windows XP Home Edition Service Pack 2 System drive C: has 12 GB (42%) free of 29 GB Total RAM: 751 MB (65% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:59:39 PM, on 11/9/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\WINDOWS\system32\HPConfig.exe C:\WINDOWS\system32\RadioSvr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE C:\Windows\system32\HpSrvUI.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\essspk.exe C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe C:\Program Files\internet explorer\iexplore.exe C:\Documents and Settings\Owner\Local Settings\temp\jkos-Owner\binaries\ScanningProcess.exe C:\Documents and Settings\Owner\Desktop\RSIT.exe C:\Program Files\Trend Micro\HijackThis\Owner.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4nb.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local> O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [CP4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [VTPreset] VTPreset.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: ORiNOCO Client Manager.lnk = C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/bizcenter-o O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2098F239-F08E-4840-9F81-B758A4971D83} - http://www.batesville.com/us/setup.cab O16 - DPF: {3F807625-B32A-498F-9010-7ABB2BB5D3B3} - http://www.batesville.com/us/install.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.a...meInstaller.exe O16 - DPF: {5A3AD060-E5D9-4DEF-8E77-B44336153FD9} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft Terminal Services Client Control (redist)) - https://ccgfalmouth.dyndns.org/Remote/msrdp.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp.com/rdqna/downloads/msxml4.cab O16 - DPF: {8B2BE470-543C-4662-8536-54D191F82675} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft Terminal Services Client Control (redist)) - http://68.160.177.202:10367/tsweb/msrdp.cab O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com/Apps/WSC/en-us/WscWlanScannerCtrl.cab O16 - DPF: {BB707357-1966-4198-B14B-1F8156D79B98} - http://www.batesville.com/us/setup.cab O16 - DPF: {CFC1C622-8C5B-4683-A64F-5A964EE397E1} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/...ash/swflash.cab O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://webmail.gpjco.com/dwa7W.cab O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Error Reporting Service (ERSvc) - Unknown owner - (no file) O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: WinPPPoverEthernet - Unknown owner - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE (file missing) -- End of file - 9857 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Owner.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}] Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2008-05-13 116088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}] SSVHelper Class - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll [2006-05-03 434279] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}] ST - C:\Program Files\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll [2004-08-13 155648] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}] MSNToolBandBHO - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll [2006-01-17 282624] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - MSN - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll [2006-01-17 282624] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "S3TRAY2"=C:\WINDOWS\system32\S3tray2.exe [2003-09-09 77824] "HP TV Now"=C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe [2002-03-14 237568] "HP Display Settings"=C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe [2002-03-07 61440] "CP4HPOT"=C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE [2002-02-22 90112] "hp Silent Service"=C:\Windows\system32\HpSrvUI.exe [2001-11-29 32768] "hpScannerFirstBoot"=c:\hp\drivers\scanners\scannerfb.exe [2001-12-13 20480] "hpsysdrv"=c:\windows\system\hpsysdrv.exe [2001-07-19 52736] "Synchronization Manager"=C:\WINDOWS\system32\mobsync.exe [2004-08-04 143360] "dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2002-03-14 102455] "EssSpkPhone"=C:\WINDOWS\essspk.exe [2002-05-31 167936] "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2004-11-05 98304] "ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2005-02-16 221184] "ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-02-16 81920] "VTPreset"=C:\WINDOWS\system32\VTPreset.exe [2004-02-24 45056] "SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe [2006-05-03 36975] "IntelliPoint"=C:\Program Files\Microsoft IntelliPoint\point32.exe [2005-03-23 217088] "NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792] "ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2008-10-17 51048] "osCheck"=C:\Program Files\Norton AntiVirus\osCheck.exe [2008-02-07 718704] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2008-10-22 399504] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360] C:\Documents and Settings\All Users\Start Menu\Programs\Startup ORiNOCO Client Manager.lnk - C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PCANotify] C:\WINDOWS\system32\PCANotify.dll [2002-02-15 24638] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SYMTDI] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"= "NoDrives"= "NoDriveAutoRun"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\Symantec\pcAnywhere\WINAW32.EXE"="C:\Program Files\Symantec\pcAnywhere\WINAW32.EXE:*:Enabled:pcAnywhere Main Program" "C:\Program Files\Symantec\pcAnywhere\AWHOST32.EXE"="C:\Program Files\Symantec\pcAnywhere\AWHOST32.EXE:*:Enabled:pcAnywhere Host Service" "C:\Program Files\Symantec\pcAnywhere\awrem32.exe"="C:\Program Files\Symantec\pcAnywhere\awrem32.exe:*:Enabled:pcAnywhere Remote Service" "C:\Program Files\microsoft frontpage\bin\fpexplor.exe"="C:\Program Files\microsoft frontpage\bin\fpexplor.exe:*:Enabled:Microsoft FrontPage Explorer" "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:MSN Messenger 7.5" ======List of files/folders created in the last 1 months====== 2008-11-09 20:59:35 ----D---- C:\rsit 2008-11-09 16:42:39 ----D---- C:\Documents and Settings\Owner\Application Data\Malwarebytes 2008-11-09 16:42:31 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2008-11-09 16:42:31 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2008-11-08 15:21:27 ----A---- C:\ComboFix.txt 2008-11-08 13:35:39 ----A---- C:\Boot.bak 2008-11-08 13:35:19 ----RASHD---- C:\cmdcons 2008-11-08 13:32:42 ----A---- C:\WINDOWS\zip.exe 2008-11-08 13:32:42 ----A---- C:\WINDOWS\VFIND.exe 2008-11-08 13:32:42 ----A---- C:\WINDOWS\SWXCACLS.exe 2008-11-08 13:32:42 ----A---- C:\WINDOWS\SWSC.exe 2008-11-08 13:32:42 ----A---- C:\WINDOWS\SWREG.exe 2008-11-08 13:32:42 ----A---- C:\WINDOWS\sed.exe 2008-11-08 13:32:42 ----A---- C:\WINDOWS\NIRCMD.exe 2008-11-08 13:32:42 ----A---- C:\WINDOWS\grep.exe 2008-11-08 13:32:42 ----A---- C:\WINDOWS\fdsv.exe 2008-11-08 13:32:35 ----D---- C:\WINDOWS\ERDNT 2008-11-08 13:32:35 ----D---- C:\Qoobox 2008-11-08 13:14:58 ----D---- C:\_OTMoveIt 2008-11-08 11:41:14 ----A---- C:\lopR.txt 2008-11-08 11:40:49 ----D---- C:\Lop SD 2008-11-08 10:45:59 ----D---- C:\WINDOWS\ERUNT 2008-11-08 10:43:35 ----A---- C:\WINDOWS\ntbtlog.txt 2008-11-08 10:38:44 ----D---- C:\SDFix 2008-11-08 00:01:46 ----D---- C:\Program Files\Trend Micro 2008-11-07 21:15:23 ----D---- C:\Program Files\Lavasoft 2008-11-07 21:15:21 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-11-07 21:14:08 ----D---- C:\Program Files\Common Files\Wise Installation Wizard 2008-10-28 13:21:41 ----D---- C:\Program Files\MSECache 2008-10-24 02:01:51 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$ 2008-10-15 02:09:49 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$ 2008-10-15 02:09:26 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$ 2008-10-15 02:09:02 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$ 2008-10-15 02:07:02 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$ 2008-10-15 02:05:18 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$ ======List of files/folders modified in the last 1 months====== 2008-11-09 20:59:24 ----D---- C:\WINDOWS\Prefetch 2008-11-09 16:55:28 ----D---- C:\WINDOWS\Temp 2008-11-09 16:42:35 ----D---- C:\WINDOWS\system32\drivers 2008-11-09 16:42:31 ----AD---- C:\Program Files 2008-11-09 16:37:21 ----D---- C:\WINDOWS\system32\CatRoot2 2008-11-09 16:37:13 ----A---- C:\WINDOWS\ModemLog_ESS SuperLink-M Data Fax Voice Modem.txt 2008-11-09 12:45:50 ----A---- C:\WINDOWS\SchedLgU.Txt 2008-11-09 09:28:23 ----A---- C:\WINDOWS\hpbafd.ini 2008-11-08 15:21:35 ----AD---- C:\WINDOWS\system32 2008-11-08 15:21:30 ----AD---- C:\WINDOWS 2008-11-08 15:10:00 ----A---- C:\WINDOWS\system.ini 2008-11-08 15:05:52 ----D---- C:\WINDOWS\system32\config 2008-11-08 15:03:40 ----D---- C:\Program Files\Common Files 2008-11-08 15:03:39 ----D---- C:\WINDOWS\AppPatch 2008-11-08 13:40:34 ----SD---- C:\WINDOWS\Downloaded Program Files 2008-11-08 13:35:39 ----RASH---- C:\boot.ini 2008-11-07 21:16:34 ----SHD---- C:\WINDOWS\Installer 2008-11-07 21:16:32 ----D---- C:\Config.Msi 2008-11-07 13:59:20 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2008-11-07 12:19:29 ----D---- C:\Program Files\Common Files\Symantec Shared 2008-10-31 20:18:56 ----HD---- C:\WINDOWS\inf 2008-10-28 13:22:31 ----D---- C:\Program Files\Common Files\Microsoft Shared 2008-10-28 13:22:30 ----D---- C:\WINDOWS\WinSxS 2008-10-28 13:22:27 ----RSD---- C:\WINDOWS\Fonts 2008-10-28 13:22:14 ----D---- C:\Program Files\Microsoft Office 2008-10-26 19:41:08 ----D---- C:\Program Files\QUICKENW 2008-10-24 02:01:56 ----RSHD---- C:\WINDOWS\system32\dllcache 2008-10-24 02:00:36 ----HD---- C:\WINDOWS\$hf_mig$ 2008-10-15 11:57:55 ----A---- C:\WINDOWS\system32\netapi32.dll 2008-10-15 02:09:59 ----A---- C:\WINDOWS\imsins.BAK 2008-10-15 02:08:12 ----D---- C:\Program Files\Internet Explorer ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 AW_HOST;AW_HOST; C:\WINDOWS\system32\drivers\aw_host5.sys [2002-02-11 33496] R1 awlegacy;awlegacy; C:\WINDOWS\System32\Drivers\awlegacy.sys [2000-09-11 10816] R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [] R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2004-08-04 36096] R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [] R1 SRTSPX;SRTSPX; C:\WINDOWS\System32\Drivers\SRTSPX.SYS [2008-01-31 43696] R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2002-01-28 5589] R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2002-01-28 22963] R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2008-06-13 184240] R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2002-02-12 40096] R2 HPGate;HPGate; C:\WINDOWS\System32\Drivers\HPGate.sys [2001-05-03 6848] R2 irda;IrDA Protocol; C:\WINDOWS\System32\DRIVERS\irda.sys [2004-08-04 87424] R2 MLPTDR_J;MLPTDR_J; \??\C:\WINDOWS\System32\MLPTDR_J.sys [] R2 MxlW2k;MxlW2k; C:\WINDOWS\system32\drivers\MxlW2k.sys [2002-04-11 27924] R2 symlcbrd;symlcbrd; \??\C:\WINDOWS\System32\drivers\symlcbrd.sys [] R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2002-03-14 23607] R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2002-03-14 34743] R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2002-03-14 4119] R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2002-03-14 2203] R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2002-03-14 52758] R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2002-03-14 13847] R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2002-03-14 6327] R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2002-03-14 88758] R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2002-03-14 94679] R2 WIBUKEY;WIBU-KEY Kernel Driver; C:\WINDOWS\SYSTEM32\DRIVERS\Wibukey.sys [2001-12-27 67072] R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2004-08-04 60800] R3 CmBatt;Microsoft AC Adapter Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2004-08-04 14080] R3 Edspport;EDSP Port Driver; C:\WINDOWS\System32\DRIVERS\es56hpi.sys [2003-03-24 702188] R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [] R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-08-17 9600] R3 HPCI;HP Configuration Interface; C:\WINDOWS\System32\DRIVERS\hpci.sys [2002-01-30 14472] R3 KBFiltr;Dritek HotKey Keyboard Filter Driver; C:\WINDOWS\System32\Drivers\KBFiltr.sys [2001-11-05 14474] R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128] R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160] R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081109.003\NAVENG.SYS [] R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20081109.003\NAVEX15.SYS [] R3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2004-08-04 61824] R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2001-06-28 13780] R3 Point32;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\System32\DRIVERS\point32.sys [2005-03-15 20352] R3 Rasirda;WAN Miniport (IrDA); C:\WINDOWS\System32\DRIVERS\rasirda.sys [2001-08-17 19584] R3 rtl8139;Realtek RTL8139/810X Family PCI Fast Ethernet NIC NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992] R3 S3Psddr;S3Psddr; C:\WINDOWS\System32\DRIVERS\s3gnbm.sys [2004-08-13 167168] R3 SRTSP;SRTSP; C:\WINDOWS\System32\Drivers\SRTSP.SYS [2008-01-31 279088] R3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2008-06-13 13616] R3 SymEvent;SymEvent; \??\C:\WINDOWS\System32\Drivers\SYMEVENT.SYS [] R3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2008-06-13 96432] R3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2008-06-13 38576] R3 SYMIDSCO;SYMIDSCO; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\ipsdefs\20081108.004\SymIDSCo.sys [] R3 SymIMMP;SymIMMP; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280] R3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2008-06-13 37424] R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2008-06-13 22320] R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-08-04 57600] R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-08-04 20480] R3 VIAIRDA;VIA Infrared Device Driver; C:\WINDOWS\System32\DRIVERS\viairda.sys [2002-01-04 24244] R3 VIAudio;VIA AC'97 Enhanced Audio Controller (WDM); C:\WINDOWS\system32\drivers\viaudio.sys [2002-03-12 43776] R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver; C:\WINDOWS\System32\Drivers\WBSD.SYS [2002-03-31 24320] R3 wlluc48b;ORINOCO PC Card Driver; C:\WINDOWS\System32\DRIVERS\wlluc48b.sys [2002-07-15 156672] S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848] S3 BT3CSer;3Com Bluetooth Serial Driver; C:\WINDOWS\System32\DRIVERS\BT3CSer.sys [2001-06-05 6237] S3 bt3cusb;bt3cusb; C:\WINDOWS\system32\drivers\bt3cusb.sys [2001-11-20 41261] S3 BW2NDIS5;BW2NDIS5 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\BW2NDIS5.sys [] S3 catchme;catchme; \??\C:\ComboFix\catchme.sys [] S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-08-04 17024] S3 COH_Mon;COH_Mon; \??\C:\WINDOWS\system32\Drivers\COH_Mon.sys [] S3 dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2004-08-04 207360] S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys [2001-08-17 12928] S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2001-08-17 23808] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-04 5504] S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-08-04 85376] S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-08-04 10880] S3 P2k;Motorola USB Device; C:\WINDOWS\System32\DRIVERS\P2k.sys [2004-08-19 38016] S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\VERIZO~1\QUICKL~1\PCAMPR5.SYS [] S3 QCDonner;Logitech QuickCam Express; C:\WINDOWS\System32\DRIVERS\OVCD.sys [2001-08-17 28032] S3 S3chipid;S3chipid; \??\C:\WINDOWS\TEMP\_ISTMP0.DIR\S3chipid.sys [] S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-08-04 11136] S3 SMNDIS5;SMNDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\VERIZO~1\QUICKL~1\SMNDIS5.SYS [] S3 SRTSPL;SRTSPL; C:\WINDOWS\System32\Drivers\SRTSPL.SYS [2008-01-31 317616] S3 sscdbus;SAMSUNG USB Composite Device driver (WDM); C:\WINDOWS\System32\DRIVERS\sscdbus.sys [2002-12-12 43248] S3 sscdmdfl;SAMSUNG CDMA Modem Filter; C:\WINDOWS\System32\DRIVERS\sscdmdfl.sys [2002-12-12 6000] S3 sscdmdm;SAMSUNG CDMA Modem Drivers; C:\WINDOWS\System32\DRIVERS\sscdmdm.sys [2002-12-12 78144] S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-08-04 15360] S3 SymIM;Symantec Network Security Intermediate Filter Service; C:\WINDOWS\system32\DRIVERS\SymIM.sys [2008-06-13 31280] S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-08-04 31616] S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2004-08-04 25856] S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2004-08-04 15104] S3 usbser;Motorola USB Modem Driver; C:\WINDOWS\System32\DRIVERS\usbser.sys [2004-08-04 25600] S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2004-08-04 26496] S3 wlags48b;Agere Wireless PCCard Driver; C:\WINDOWS\System32\DRIVERS\wlags48b.sys [2003-01-09 163328] S3 wlluc48;Wireless LAN PC Card Driver; C:\WINDOWS\System32\DRIVERS\wlluc48.sys [2002-08-29 154624] S3 WrKPoET2000;WrKPoET2000; \??\C:\Program Files\Verizon Online\WinPoET\WrKPoET2000.sys [] S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-08-04 19328] S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-10 611664] R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2008-02-09 238968] R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352] R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352] R2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352] R2 HPConfig;HP Configuration Interface Service; C:\WINDOWS\system32\HPConfig.exe [2002-03-14 151552] R2 Irmon;Infrared Monitor; C:\WINDOWS\System32\svchost.exe [2004-08-04 14336] R2 LiveUpdate Notice;LiveUpdate Notice; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352] R2 Symantec Core LC;Symantec Core LC; C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe [2008-05-13 1245064] R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2005-01-28 38912] R3 RadioSvr;RadioSvr; C:\WINDOWS\system32\RadioSvr.exe [2002-01-18 122880] S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776] S2 HpRfDev;HP RF Device Service; C:\WINDOWS\system32\HpRfDev.exe [2002-01-18 69632] S2 WinPPPoverEthernet;WinPPPoverEthernet; C:\Program Files\Verizon Online\WinPoET\WrOS.EXE [] S3 awhost32;pcAnywhere Host Service; C:\Program Files\Symantec\pcAnywhere\awhost32.exe [2002-02-15 114749] S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2008-08-04 3220856] S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920] S4 ATMsrvc;ATM Service; C:\WINDOWS\System32\ATMsrvc.exe [2000-05-24 15360] -----------------EOF----------------- Here is info.txt info.txt logfile of random's system information tool 1.04 2008-11-09 20:59:50 ======Uninstall list====== -->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U -->C:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL -->C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu -->C:\WINDOWS\System32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6} -->C:\WINDOWS\System32\\MSIEXEC.EXE /x {8214CC02-6271-4DC8-B8DD-779933450264} -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf 3D Groove Playback Engine-->RunDll32 C:\WINDOWS\DOWNLO~1\GrooveAX.dll,_RemoveGroove@16 3DVIA Player 4.1-->MsiExec.exe /X{4E868D3D-6EEB-4273-926C-2287236B5B79} Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF} Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)-->MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7} Adobe Atmosphere Player for Acrobat and Adobe Reader-->C:\WINDOWS\atmoUn.exe Adobe Download Manager 1.2 (Remove Only)-->"C:\Program Files\Common Files\Adobe\ESD\uninst.exe" Adobe Flash Player 9 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlock Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Reader 8.1.2-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003} Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~2\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~2\Install.log Adobe Type Manager 4.1-->C:\WINDOWS\uninst.exe -f"C:\Program Files\Adobe Type Manager\DeIsL1.isu" -c"C:\Program Files\Adobe Type Manager\UNINST.DLL" AppCore-->MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B} ArcSoft Camera Suite-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ArcSoft\Camera Suite\Uninst.isu" Atomic Pop-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6FAA3A53-F51F-4E18-B4D5-CE339F46E2C3}\setup.exe" Batesville Digital Litho Book 2004-->MsiExec.exe /I{B009AD06-DF8C-4F2E-AF36-98495155666C} Batesville Digital Litho Book April 2005-->MsiExec.exe /I{1520E194-3DB2-41DD-8C11-5F4A00FC046B} Batesville Digital Litho Book Update 2005 US-->MsiExec.exe /I{60FD7EDC-E15A-419D-9A24-F8F6DD20E1C7} Batesville Digital Litho Book Update Spring 2004 US-->MsiExec.exe /I{7313F452-4D11-4E4E-9DA7-DFB28D4E87FB} Batesville Digital Litho Book, Winter 2004 US Update-->MsiExec.exe /I{B7FBE84E-2D97-44E0-96C3-95FBEF9575E2} Batesville Digital Litho Book-->MsiExec.exe /I{28AB0980-D2D2-453D-8202-B16D7150108D} Batesville Digital Litho Book-->MsiExec.exe /I{88973158-6F2D-4EA5-B09A-044CC7F6B2D6} BlasterBall Wild-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F9576535-5077-4EF1-887D-71D249C6ADE1}\setup.exe" Canon IXY 200a, PowerShot S200, IXUS v2 WIA Driver-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\IXY200A PSS200 IXUSV2 WIA\Uninst.isu" -c"C:\Program Files\Canon\IXY200A PSS200 IXUSV2 WIA\UNSTE116.dll" Canon PhotoRecord-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\PhotoRecord\Uninst.isu" -c"C:\Program Files\Canon\PhotoRecord\Program\uninstdll.dll" Canon Utilities PhotoStitch 3.1-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\PhotoStitch\Uninst.isu" Canon Utilities RAW Image Converter2-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\RAW Image Converter2\Uninst.isu" Canon Utilities RemoteCapture 2.4-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\RemoteCapture\Uninst.isu" Canon Utilities ZoomBrowser EX-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Canon\ZoomBrowser EX\Uninst.isu" -c"C:\Program Files\Canon\ZoomBrowser EX\Program\uninstallutilities.dll" CasePrinter-->C:\WINDOWS\uninst.exe -fc:\cpwin\DeIsL1.isu -cc:\cpwin\_ISREG32.DLL ccCommon-->MsiExec.exe /I{B24E05CC-46FF-4787-BBB8-5CD516AFB118} CDCheck (remove only)-->"C:\Program Files\CDCheck\uninst.exe" Checkers-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{87446305-AF82-462F-9939-2A4A6349C6F6}\setup.exe" Compatibility Pack for the 2007 Office system-->MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE} Component Framework-->MsiExec.exe /I{31478BE1-CDE5-4753-A8B2-F6D4BC1FBE09} DarkOrbit-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2ED5402B-695D-11D5-A8E1-00A0CC663B7C}\setup.exe" Directors Tribute Creator version 3.0.0.615-->"C:\Program Files\Directors Tribute Creator\unins000.exe" Easy Internet Sign-up-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2B5DDB2C-0807-47FD-9C11-80EA761902C0}\Setup.exe" -l0x9 e-DiagTools for Windows-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{38E71FA0-59B0-11D4-BB75-00500478B0F5}\Setup.exe" FDMS Memorial Maker for Word2002-->C:\WINDOWS\IsUninst.exe -fC:\Winword\Memorial\Uninmm2k2.isu FDMS2000 for Windows v6-->C:\WINDOWS\IsUninst.exe -fC:\FD\Uninst.isu FDMS2000 for Windows v7-->C:\WINDOWS\IsUninst.exe -fC:\FD\Uninst.isu GemMaster-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BA6DB07B-696D-11D5-A8E1-00A0CC663B7C}\setup.exe" HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall Hooked on Phonics Learn to Read-->C:\WINDOWS\uninst.exe -f"C:\Program Files\Hooked on Phonics Learning\Hooked on Phonics Learn to Read\DeIsL1.isu" Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe" Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe" HP Desktop Zoom-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D0604F35-314C-4341-A05E-3FEABCFDD470}\SETUP.EXE" HP DLA-->MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6} HP LaserJet 2200 Uninstaller-->C:\Program Files\Hewlett-Packard\LaserJet All-in-one\Uninstall\2200\setup.exe uninst22.ini HP Notebook Utilities-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A8F2DCDE-AE4E-4AC9-BECD-496FB80FBF6A}\Setup.exe" -l0x9 HP One-Touch Buttons-->C:\WINDOWS\UnInst32.exe CP4HPOT.UNI HP Photo-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B23F9FE-C25F-40BF-88B2-5F8E32E8B261}\setup.exe" HP RecordNow-->MsiExec.exe /I{8214CC02-6271-4DC8-B8DD-779933450264} HP Wireless LAN-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6E1D54D7-47EB-11D5-AE90-00D0590FFE27}\setup.exe" Hpsetup-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A6792A59-15B3-4FD4-BE35-45F1E00A51AF}\SETUP.EXE" InterVideo WinDVD-->"C:\Program Files\InstallShield Installation Information\{C1939820-A945-11D4-86F6-0001031E5712}\setup.exe" REMOVEALL J2SE Runtime Environment 5.0 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150070} Lernout & Hauspie TruVoice American English TTS Engine-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\tv_enua.inf, Uninstall LiveReg (Symantec Corporation)-->C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVE LiveUpdate (Symantec Corporation)-->MsiExec.exe /x {E80F62FF-5D3C-4A19-8409-9721F2928206} /l*v "C:\Documents and Settings\All Users\Application Data\LuUninstall.LiveUpdate" LiveUpdate (Symantec Corporation)-->MsiExec.exe /X{E80F62FF-5D3C-4A19-8409-9721F2928206} LiveUpdate BVRP Software-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -l0x9 LiveUpdate Notice (Symantec Corporation)-->MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8} Macromedia Shockwave Player-->MsiExec.exe /X{7D1D6A24-65D4-454C-8815-4F08A5FFF12C} magicolor 2300W-->MUINST_J.EXE /PRN:"magicolor 2300W" Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" Medi@Show-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\CyberLink\MediaShow\Uninst.isu" Microsoft FrontPage 98-->"C:\Program Files\Microsoft FrontPage\bin\fpuninst.exe" C:\WINDOWS\UNINST.EXE -f"C:\Program Files\Microsoft FrontPage\DeIsL1.isu" Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe" Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe" Microsoft Office 2000 SR-1 Professional-->MsiExec.exe /I{00010409-78E1-11D2-B60F-006097C998E7} Microsoft Office XP Small Business-->MsiExec.exe /I{91130409-6000-11D3-8CFE-0050048383C9} Microsoft PowerPoint Viewer 97-->C:\Program Files\PowerPoint Viewer\setup\setup.exe Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} mobile PhoneTools-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F18E8A0F-BE99-4305-96A5-6C0FD9D7D999}\setup.exe" -l0x9 Motorola PST-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8CC5BF82-4DD4-11D4-A39F-00C04F05E3F0}\Setup.exe" -l0x9 anything MSN Messenger 7.5-->MsiExec.exe /I{CEB3A11A-03EA-11DA-BFBD-00065BBDC0B5} MSN Music Assistant-->rundll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msninst.inf,Uninstall MSN Toolbar-->C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\mtbs.exe c MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F} MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} MUSICMATCH Jukebox-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MusicMatch\MusicMatch Jukebox\Uninst.isu" -cC:\PROGRA~1\MUSICM~1\MUSICM~1\unmatch.dll MyFonts Order M518625-->MsiExec.exe /I{EE139451-19E1-88A5-5354-20E60D8D9472} Nero 7-->MsiExec.exe /I{43FFE159-3199-4188-A1CD-629166AD1033} neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} Norton AntiVirus (Symantec Corporation)-->"C:\Program Files\Common Files\Symantec Shared\SymSetup\{77FFBA7E-0973-4F39-BBDB-AC2F537578D2}_15_5_0_23\Setup.exe" /X Norton AntiVirus Help-->MsiExec.exe /I{34EEB1F5-E939-40A1-A6BA-957282A4B2C8} Norton AntiVirus-->MsiExec.exe /X{77FFBA7E-0973-4F39-BBDB-AC2F537578D2} Norton Protection Center-->MsiExec.exe /I{62120008-8E1E-4807-860D-A8B48F8552DB} NoteWorthy Composer-->C:\PROGRA~1\NOTEWO~1\UNINSTAL.EXE C:\PROGRA~1\NOTEWO~1\INSTALL.LOG ORiNOCO Client Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{82425B27-1E96-11D4-95C9-0060B0FBF2F6}\Setup.exe" -l0x9 -a Outlook Express Backup Wizard version 1.1-->"C:\Program Files\Outlook Express Backup Wizard\unins000.exe" ProSavageDDR and Utilities-->C:\PROGRA~1\S3\P4M266\s3setvga.exe -s -fC:\PROGRA~1\S3\P4M266\P4M266.uns Quicken 2005-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{2DBE41DD-2129-4C65-A3D3-5647236A60F3} anything Quicken Financial Center-->C:\PROGRA~1\QUICKE~1\rem\UNWISE.EXE /s C:\PROGRA~1\QUICKE~1\rem\INSTALL.LOG QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\System32\QuickTime\Uninstall.log Reversi-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4E0F57C-6BC4-4B53-AE6C-E455F1A43A0D}\setup.exe" S3Display-->s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Display' S3Gamma2-->s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Gamma2' S3Info2-->s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Info2' S3Overlay-->s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Overlay' SabreWing 2-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{07F45C50-6693-4D53-9A6C-1F5B39BA2A16}\setup.exe" Samsung USB Driver (MCCI 3.40)-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{7D8367E4-9EF5-40F5-BECD-32615B0FE215} Security Update for Step By Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe" Security Update for Step By Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe" Security Update for Windows Media Player (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe" Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe" Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe" Security Update for Windows Media Player 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe" Security Update for Windows XP (KB890046)-->"C:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe" Security Update for Windows XP (KB893066)-->"C:\WINDOWS\$NtUninstallKB893066$\spuninst\spuninst.exe" Security Update for Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe" Security Update for Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe" Security Update for Windows XP (KB896422)-->"C:\WINDOWS\$NtUninstallKB896422$\spuninst\spuninst.exe" Security Update for Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe" Security Update for Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe" Security Update for Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe" Security Update for Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe" Security Update for Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe" Security Update for Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe" Security Update for Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe" Security Update for Windows XP (KB901190)-->"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe" Security Update for Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe" Security Update for Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe" Security Update for Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe" Security Update for Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe" Security Update for Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe" Security Update for Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe" Security Update for Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe" Security Update for Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe" Security Update for Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe" Security Update for Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe" Security Update for Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe" Security Update for Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe" Security Update for Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe" Security Update for Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe" Security Update for Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe" Security Update for Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe" Security Update for Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe" Security Update for Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe" Security Update for Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe" Security Update for Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe" Security Update for Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe" Security Update for Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe" Security Update for Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe" Security Update for Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe" Security Update for Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe" Security Update for Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe" Security Update for Windows XP (KB923694)-->"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe" Security Update for Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe" Security Update for Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe" Security Update for Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe" Security Update for Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe" Security Update for Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe" Security Update for Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe" Security Update for Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe" Security Update for Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe" Security Update for Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe" Security Update for Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe" Security Update for Windows XP (KB928090)-->"C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe" Security Update for Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe" Security Update for Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe" Security Update for Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe" Security Update for Windows XP (KB929969)-->"C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.exe" Security Update for Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe" Security Update for Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe" Security Update for Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe" Security Update for Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe" Security Update for Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe" Security Update for Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe" Security Update for Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe" Security Update for Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe" Security Update for Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe" Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe" Security Update for Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe" Security Update for Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe" Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe" Security Update for Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe" Security Update for Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe" Security Update for Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe" Security Update for Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe" Security Update for Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe" Security Update for Windows XP (KB944338)-->"C:\WINDOWS\$NtUninstallKB944338$\spuninst\spuninst.exe" Security Update for Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe" Security Update for Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe" Security Update for Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe" Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe" Security Update for Windows XP (KB947864)-->"C:\WINDOWS\$NtUninstallKB947864$\spuninst\spuninst.exe" Security Update for Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe" Security Update for Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe" Security Update for Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe" Security Update for Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe" Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe" Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe" Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe" Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe" Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe" Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe" Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe" Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe" Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe" Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe" Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe" Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe" Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe" Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe" Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe" Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe" Shockwave-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log Snapshot Viewer-->C:\Program Files\Snapshot Viewer\Setup\Setup.exe /T snap90.stf SPBBC 32bit-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56} Speedway-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A3892EB-696D-11D5-A8E1-00A0CC663B7C}\setup.exe" StuffIt Standard-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\10\INTEL3~1\IDriver.exe /M{40ABF1E0-8B6F-4D32-B343-E19FA2F04B3C} Symantec KB-DocID:2003093015493306-->MsiExec.exe /I{08C5815C-2C6E-44f8-8748-0E61BC9AFB68} Symantec pcAnywhere-->MsiExec.exe /I{D05E8183-866A-11D3-97DF-0000F8D8F2E9} Symantec Real Time Storage Protection Component-->MsiExec.exe /I{D6E6FA4A-5445-4850-8365-CF216C1CBB7A} Uninstall ESS Modem-->C:\WINDOWS\remvess Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe" Update for Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe" Update for Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe" Update for Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe" Update for Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe" Update for Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe" Update for Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe" Update for Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe" Update for Windows XP (KB925876)-->"C:\WINDOWS\$NtUninstallKB925876$\spuninst\spuninst.exe" Update for Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe" Update for Windows XP (KB929338)-->"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe" Update for Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe" Update for Windows XP (KB931836)-->"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe" Update for Windows XP (KB932823-v3)-->"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe" Update for Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe" Update for Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe" Update for Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe" Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe" Virtual Warfare Demo-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{626F20B3-01A5-4942-89F7-C59B4237A581}\setup.exe" VTech® Photo Editor-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{43D2A1DD-69C9-4E86-8F51-4890A6263863}\setup.exe" WIBU-KEY Setup (WIBU-KEY Remove)-->C:\Program Files\WIBUKEY\Setup\SETUP32.EXE /R:{00060000-0000-1004-8002-0000C06B5161} Windows Genuine Advantage v1.3.0254.0-->MsiExec.exe /I{63569CE9-FA00-469C-AF5C-E5D4D93ACF91} Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe" Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe" Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall Windows XP Hotfix - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe Windows XP Hotfix - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe Windows XP Hotfix - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe Windows XP Hotfix - KB885884-->C:\WINDOWS\$NtUninstallKB885884$\spuninst\spuninst.exe Windows XP Hotfix - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe Windows XP Hotfix - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe Windows XP Hotfix - KB888113-->C:\WINDOWS\$NtUninstallKB888113$\spuninst\spuninst.exe Windows XP Hotfix - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe Windows XP Hotfix - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe" Windows XP Hotfix - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe Windows XP Service Pack 2-->C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall X-Fonter 5.5-->"C:\Program Files\X-Fonter\unins000.exe" ======Security center information====== AV: Norton AntiVirus (disabled) FW: Norton AntiVirus ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\Symantec\pcAnywhere "windir"=%SystemRoot% "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 4, GenuineIntel "PROCESSOR_REVISION"=0204 "NUMBER_OF_PROCESSORS"=1 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "CI_HOLOS_CLI"=C:\Program Files\Seagate Software\Open OLAP "VSL"=C:\PVSW\BIN "FP_NO_HOST_CHECK"=NO -----------------EOF----------------- |
|
|
|
Nov 10 2008, 03:54 PM
Post
#16
|
|
|
Advanced Member ![]() ![]() ![]() Group: Volunteer Security Advisor Posts: 1,733 Joined: 9-September 08 Member No.: 62,225 |
Hello
Please download the OTMoveIt3 by OldTimer or from here.
Also post a new HJT log and tell me how your PC is running -------------------- By the power of truth, I, while living, have conquered the universe.
~Scratch~ |
|
|
|
Nov 10 2008, 11:44 PM
Post
#17
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
Hello Rorschach112,
My PC is running better. Google searches now go where they are supposed to. Here is OTMoveIt3 log: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== Unable to stop service "Error Reporting Service (ERSvc) " . ========== REGISTRY ========== Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm\\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys\\ deleted successfully. ========== FILES ========== ========== COMMANDS ========== User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\JETFBA6.tmp scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.0 log created on 11102008_174353 Files moved on Reboot... File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File C:\WINDOWS\temp\JETFBA6.tmp not found! ---- EOF ----- Here is HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:55:50 PM, on 11/10/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\WINDOWS\system32\HPConfig.exe C:\WINDOWS\system32\RadioSvr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE C:\Windows\system32\HpSrvUI.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\essspk.exe C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe C:\Program Files\Microsoft IntelliPoint\point32.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Java\jre1.5.0_07\bin\jucheck.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4nb.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4nb.hpwis.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local> O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST1.03.0000.1005\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar1.02.5000.1021\en-us\msntb.dll O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe O4 - HKLM\..\Run: [HP TV Now] C:\Program Files\Hewlett-Packard\HP TV Now\HpTvNow.exe /RK O4 - HKLM\..\Run: [HP Display Settings] C:\Program Files\Hewlett-Packard\HP Notebook Utilities\hptasks.exe /s O4 - HKLM\..\Run: [CP4HPOT] C:\PROGRA~1\HEWLET~1\ONE-TO~1\OneTouch.EXE O4 - HKLM\..\Run: [hp Silent Service] C:\Windows\system32\HpSrvUI.exe O4 - HKLM\..\Run: [hpScannerFirstBoot] c:\hp\drivers\scanners\scannerfb.exe O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [VTPreset] VTPreset.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: ORiNOCO Client Manager.lnk = C:\Program Files\ORiNOCO\Client Manager\CmLUC.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com/info/bizcenter-o O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2098F239-F08E-4840-9F81-B758A4971D83} - http://www.batesville.com/us/setup.cab O16 - DPF: {3F807625-B32A-498F-9010-7ABB2BB5D3B3} - http://www.batesville.com/us/install.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.a...meInstaller.exe O16 - DPF: {5A3AD060-E5D9-4DEF-8E77-B44336153FD9} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft Terminal Services Client Control (redist)) - https://ccgfalmouth.dyndns.org/Remote/msrdp.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://ipgweb.cce.hp.com/rdqna/downloads/msxml4.cab O16 - DPF: {8B2BE470-543C-4662-8536-54D191F82675} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft Terminal Services Client Control (redist)) - http://68.160.177.202:10367/tsweb/msrdp.cab O16 - DPF: {9C024426-7859-4B2D-AB4C-B1E370AE7549} - http://us.mcafee.com/Apps/WSC/en-us/WscWlanScannerCtrl.cab O16 - DPF: {BB707357-1966-4198-B14B-1F8156D79B98} - http://www.batesville.com/us/setup.cab O16 - DPF: {CFC1C622-8C5B-4683-A64F-5A964EE397E1} - http://www.batesville.com/dlb/setup.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.adobe.com/pub/shockwave/...ash/swflash.cab O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir...5/installer.exe O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://webmail.gpjco.com/dwa7W.cab O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} - https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Error Reporting Service (ERSvc) - Unknown owner - (no file) O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe O23 - Service: HP RF Device Service (HpRfDev) - Hewlett-Packard - C:\WINDOWS\system32\HpRfDev.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: RadioSvr - Hewlett-Packard - C:\WINDOWS\system32\RadioSvr.exe O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: WinPPPoverEthernet - Unknown owner - C:\Program Files\Verizon Online\WinPoET\WrOS.EXE (file missing) -- End of file - 9646 bytes Looks like we're there. |
|
|
|
Nov 10 2008, 11:56 PM
Post
#18
|
|
|
Advanced Member ![]() ![]() ![]() Group: Volunteer Security Advisor Posts: 1,733 Joined: 9-September 08 Member No.: 62,225 |
One final thing
Download OTScanIt2.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt2 on your desktop.
Make sure you attach the report in your reply. If it is too big to upload, then zip the text file and upload it that way -------------------- By the power of truth, I, while living, have conquered the universe.
~Scratch~ |
|
|
|
Nov 11 2008, 02:44 AM
Post
#19
|
|
|
Member ![]() ![]() Group: Members Posts: 14 Joined: 8-November 08 Member No.: 63,950 |
|
|
|
|
Nov 11 2008, 02:01 PM
Post
#20
|
|
|
Advanced Member ![]() ![]() ![]() Group: Volunteer Security Advisor Posts: 1,733 Joined: 9-September 08 Member No.: 62,225 |
Sorry but can I get you to post it here instead of attaching it, or host it at a site like mediafire.com
It gets messed up attaching it here -------------------- By the power of truth, I, while living, have conquered the universe.
~Scratch~ |
|
|
|
![]() ![]() |
|
Lo-Fi Version | Time is now: 21st November 2009 - 03:16 PM |