View Full Version : My spyware won against 4 antiviruses
Hello from France!
My problem:
A spyware opens an Internet Explorer window and connects to a real estate website. If Internet Explorer was already open, it adds a tab. And keeps adding tabs every few minutes. When the bug acts up the window comes on top of everything and I have to wait for it to load to continue with what I was doing.
My laptop is also slower...
I had Norton on and updated when it hit.
I downloaded Avast which sorted my last spyware problem, but it didn't help this time (even upgraded to Pro).
So I downloaded Ad-Aware and tried my luck... Nothing more.
So I got Spybot, which did find malwares on my PC but not the one that keeps opening my browser.
Should I get AVG next? lol... :eek:
I check updates for all 4 softwares everyday and run scans but they don't find anything anymore. And my bug is still there! Doing very well thank you!
PLEASE SOMEBODY!!
WHAT CAN I DO??
Please give a helpless woman a hand boys... :p:
Thanks in advance...
Hi
I guess you missed this:
BEFORE you POST
(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288) ;)
Download and install TrendMicro HijackThis (http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe)
* Once installed open HijackThis by clicking Start > Programs > HijackThis and click the button labeled
Do a system scan only
* Click the scan button in the lower left hand corner of the interface and HijackThis will quickly scan your system.
* Once the scan is complete the scan button will now read save log. Click this button to save the log file to your PC. Once you select where you would like to save the file it will open in your systems default text editor. Typically this application is Notepad. Post the log here.
All done :laugh:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:37:07, on 04.11.2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ppcbooster\ppcb_32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\Hewlett-Packard\HP Health Check\HPHC.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NO&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NO&c=73&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mondrv411] C:\Windows\mondrv411.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - HKCU\..\Run: [VnrBlock21] "C:\Program Files\VnrBlock\VnrBlock21.exe"
O4 - HKCU\..\Run: [mondrv411] C:\WINDOWS\mondrv411.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: ppcb_32.lnk = C:\Program Files\ppcbooster\ppcb_32.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 12504 bytes
Hi
Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:
Run Spybot-S&D in Advanced Mode
If it is not already set to do this, go to the Mode menu
select
Advanced Mode
On the left hand side, click on Tools
Then click on the Resident icon in the list
Uncheck
Resident TeaTimer
and OK any prompts.
Restart your computer
Download ResetTeaTimer.bat to the Desktop
http://downloads.subratam.org/ResetTeaTimer.bat
Double click ResetTeaTimer.bat to remove all entries set by TeaTimer (and preventing TeaTimer to restore them upon reactivation).
Please visit this webpage for download links, and instructions for running ComboFix tool:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Please continue as follows:
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix, link (http://www.bleepingcomputer.com/forums/topic114351.html)
Remember to re-enable them afterwards.
Click Yes to allow ComboFix to continue scanning for malware.
When the tool is finished, it will produce a report for you.
Please include the following reports for further review, and so we may continue cleansing the system:
C:\ComboFix.txt
New HijackThis log.
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix. This tool is not a toy and not for everyday use.
The tutorial says Combofix might fix the issue, it didn't. Just so you know... :red:
Here's the log.
ComboFix 08-11-03.06 - Isabelle 2008-11-04 18:31:58.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1124 [GMT 1:00]
Running from: c:\users\Isabelle\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-04 to 2008-11-04 )))))))))))))))))))))))))))))))
.
2008-11-04 13:35 . 2008-11-04 13:35 <DIR> d-------- c:\program files\Trend Micro
2008-11-01 21:06 . 2008-11-02 10:33 <DIR> d-------- c:\users\All Users\Spybot - Search & Destroy
2008-11-01 21:06 . 2008-11-02 10:33 <DIR> d-------- c:\programdata\Spybot - Search & Destroy
2008-11-01 21:06 . 2008-11-01 21:10 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-01 14:00 . 2008-07-30 17:42 23,888 --a------ c:\windows\System32\drivers\COH_Mon.sys
2008-11-01 14:00 . 2008-07-30 17:28 10,537 --a------ c:\windows\System32\drivers\COH_Mon.cat
2008-11-01 14:00 . 2008-07-30 17:28 706 --a------ c:\windows\System32\drivers\COH_Mon.inf
2008-10-31 23:39 . 2008-10-31 23:39 <DIR> d-------- c:\program files\Lavasoft
2008-10-31 23:38 . 2008-10-31 23:38 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-10-31 20:24 . 2008-10-31 20:26 <DIR> d-------- c:\users\All Users\Lavasoft
2008-10-31 20:24 . 2008-10-31 20:26 <DIR> d-------- c:\programdata\Lavasoft
2008-10-31 09:23 . 2008-10-31 09:23 <DIR> d-------- c:\program files\Alwil Software
2008-10-31 09:23 . 2008-07-19 16:36 51,280 --a------ c:\windows\System32\drivers\aswMonFlt.sys
2008-10-30 17:52 . 2008-10-30 17:52 <DIR> d-------- c:\program files\ppcbooster
2008-10-30 17:52 . 2008-10-30 17:52 71,135 --a------ c:\windows\pptb1948.exe
2008-10-30 17:40 . 2008-10-30 17:40 <DIR> d-------- c:\users\All Users\TomTom
2008-10-30 17:40 . 2008-10-30 17:40 <DIR> d-------- c:\programdata\TomTom
2008-10-30 17:39 . 2008-10-30 17:39 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\TomTom
2008-10-30 17:37 . 2008-10-30 17:37 <DIR> d-------- c:\program files\TomTom HOME 2
2008-10-30 17:34 . 2008-10-30 17:34 <DIR> d-------- c:\program files\TomTom DesktopSuite
2008-10-30 17:34 . 2008-10-30 17:34 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-10-30 17:18 . 2008-10-30 17:18 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\Apple Computer
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d----c--- c:\windows\System32\DRVSTORE
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d-------- c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d-------- c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d-------- c:\program files\iTunes
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d-------- c:\program files\iPod
2008-10-30 17:17 . 2008-04-17 13:12 107,368 --a------ c:\windows\System32\GEARAspi.dll
2008-10-30 17:17 . 2008-04-17 13:12 15,464 --a------ c:\windows\System32\drivers\GEARAspiWDM.sys
2008-10-30 17:15 . 2008-10-30 17:15 <DIR> d-------- c:\program files\Bonjour
2008-10-30 17:14 . 2008-10-30 17:17 <DIR> d-------- c:\users\All Users\Apple Computer
2008-10-30 17:14 . 2008-10-30 17:17 <DIR> d-------- c:\programdata\Apple Computer
2008-10-30 17:14 . 2008-10-30 17:15 <DIR> d-------- c:\program files\QuickTime
2008-10-30 17:12 . 2008-10-30 17:12 <DIR> d-------- c:\program files\Apple Software Update
2008-10-30 17:11 . 2008-10-30 17:11 <DIR> d-------- c:\users\All Users\Apple
2008-10-30 17:11 . 2008-10-30 17:11 <DIR> d-------- c:\programdata\Apple
2008-10-30 17:11 . 2008-10-30 17:14 <DIR> d-------- c:\program files\Common Files\Apple
2008-10-30 17:03 . 2008-10-30 17:05 <DIR> d-------- c:\windows\System32\Adobe
2008-10-29 23:08 . 2008-10-29 23:08 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\Roxio
2008-10-29 17:27 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-10-29 16:41 . 2008-10-29 16:42 <DIR> d-------- c:\program files\VistaCodecPack
2008-10-29 16:39 . 2008-10-29 16:39 <DIR> d-------- c:\users\All Users\VistaCodecs
2008-10-29 16:39 . 2008-10-29 16:39 <DIR> d-------- c:\programdata\VistaCodecs
2008-10-29 15:18 . 2008-10-29 15:18 <DIR> d-------- c:\program files\Code de la Route pour les Nuls
2008-10-28 18:21 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-10-28 18:21 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-10-27 17:42 . 2008-10-27 17:42 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\HP
2008-10-27 17:42 . 2008-10-27 17:42 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\CyberLink
2008-10-26 23:59 . 2008-10-26 23:59 <DIR> d-------- c:\program files\Microsoft Silverlight
2008-10-26 23:53 . 2008-04-26 09:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
2008-10-26 19:07 . 2008-10-26 19:07 <DIR> d-------- C:\PerfLogs
2008-10-26 17:47 . 2008-01-19 08:33 2,623,488 --a------ c:\windows\System32\SLsvc.exe
2008-10-26 17:47 . 2008-01-19 08:36 1,541,120 --a------ c:\windows\System32\onex.dll
2008-10-26 17:45 . 2008-01-19 04:12 3,662,296 --a------ c:\windows\System32\locale.nls
2008-10-26 17:44 . 2008-01-19 08:33 8,139,264 --a------ c:\windows\System32\ssBranded.scr
2008-10-26 17:43 . 2008-01-19 08:35 3,072,000 --a------ c:\windows\System32\networkmap.dll
2008-10-26 17:42 . 2008-01-19 07:06 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2008-10-26 17:41 . 2008-01-19 08:36 704,512 --a------ c:\windows\System32\SmiEngine.dll
2008-10-26 17:41 . 2008-01-19 08:36 357,888 --a------ c:\windows\System32\wbemcomn.dll
2008-10-26 17:41 . 2008-01-19 08:34 305,152 --a------ c:\windows\System32\msdelta.dll
2008-10-26 17:41 . 2008-01-19 08:34 258,560 --a------ c:\windows\System32\dpx.dll
2008-10-26 17:41 . 2008-01-19 08:34 246,784 --a------ c:\windows\System32\drvstore.dll
2008-10-26 17:41 . 2008-01-19 08:36 218,624 --a------ c:\windows\System32\wdscore.dll
2008-10-26 17:41 . 2008-01-19 08:36 139,264 --a------ c:\windows\System32\SmiInstaller.dll
2008-10-26 17:41 . 2008-01-19 08:33 130,560 --a------ c:\windows\System32\PkgMgr.exe
2008-10-26 17:41 . 2008-01-19 08:36 129,536 --a------ c:\windows\System32\sqmapi.dll
2008-10-26 17:41 . 2008-01-19 08:35 35,328 --a------ c:\windows\System32\mspatcha.dll
2008-10-25 02:15 . 2008-10-25 02:52 <DIR> d-------- c:\users\Public\Games
2008-10-25 01:19 . 2008-10-25 01:19 <DIR> d-------- c:\users\All Users\Blizzard
2008-10-25 01:19 . 2008-10-25 01:19 <DIR> d-------- c:\programdata\Blizzard
2008-10-24 21:40 . 2008-10-24 21:40 <DIR> dr------- c:\windows\System32\config\systemprofile\Music
2008-10-24 20:37 . 2008-11-04 18:05 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\LimeWire
2008-10-24 20:19 . 2008-10-24 20:20 <DIR> d-------- c:\program files\Common Files\Adobe
2008-10-24 19:40 . 2008-10-24 20:14 <DIR> d-------- c:\users\All Users\NOS
2008-10-24 19:40 . 2008-10-24 20:14 <DIR> d-------- c:\programdata\NOS
2008-10-24 19:40 . 2008-10-24 19:40 <DIR> d-------- c:\program files\NOS
2008-10-24 19:34 . 2008-10-24 19:35 <DIR> d-------- c:\program files\LimeWire
2008-10-24 09:24 . 2008-10-24 09:24 269,312 --a------ c:\windows\System32\es.dll
2008-10-24 09:08 . 2008-10-24 09:34 <DIR> d-------- c:\program files\Common Files\Blizzard Entertainment
2008-10-23 19:59 . 2008-10-23 19:59 0 --a------ c:\users\Isabelle\AppData\Roaming\wklnhst.dat
2008-10-23 17:22 . 2008-11-04 18:06 1,660 --a------ c:\windows\bthservsdp.dat
2008-10-23 17:06 . 2008-10-24 08:51 <DIR> d-------- c:\users\Isabelle\WoW-2.3.0.7561-enGB
2008-10-23 16:54 . 2008-10-23 16:54 <DIR> d-------- c:\program files\Broadcom
2008-10-23 16:17 . 2008-10-26 19:36 <DIR> d-------- c:\users\All Users\NVIDIA
2008-10-23 16:17 . 2008-10-26 19:36 <DIR> d-------- c:\programdata\NVIDIA
2008-10-23 12:57 . 2008-10-23 12:57 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\GTek
2008-10-23 12:37 . 2007-02-14 08:55 356,352 --a------ c:\windows\System32\nvusmu.exe
2008-10-23 12:37 . 2006-12-01 06:37 3,903 --a------ c:\windows\System32\nvnrm.nvu
2008-10-23 12:37 . 2006-12-15 07:48 528 --a------ c:\windows\System32\nvsmu.nvu
2008-10-23 12:36 . 2008-10-23 12:36 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\InstallShield
2008-10-23 12:36 . 2006-11-08 23:48 356,352 --a------ c:\windows\System32\nvusmb.exe
2008-10-23 12:36 . 2006-10-20 00:36 1,864 --a------ c:\windows\System32\nvsmb.nvu
2008-10-23 11:59 . 2008-10-23 11:59 271,571,308 --a------ c:\windows\MEMORY.DMP
2008-10-23 11:36 . 2008-10-23 11:36 361,984 --a------ c:\windows\System32\IPSECSVC.DLL
2008-10-23 11:36 . 2008-10-23 11:36 272,896 --a------ c:\windows\System32\polstore.dll
2008-10-23 11:36 . 2008-10-23 11:36 61,440 --a------ c:\windows\System32\winipsec.dll
2008-10-23 11:36 . 2008-10-23 11:36 28,672 --a------ c:\windows\System32\FwRemoteSvr.dll
2008-10-23 11:35 . 2008-10-23 11:35 1,820 --a------ c:\windows\System32\rasctrnm.h
2008-10-23 11:34 . 2008-10-23 11:34 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-23 11:34 . 2008-10-23 11:34 1,695,744 --a------ c:\windows\System32\gameux.dll
2008-10-23 11:34 . 2008-10-23 11:34 28,160 --a------ c:\windows\System32\Apphlpdm.dll
2008-10-23 11:30 . 2008-10-23 11:30 428,544 --a------ c:\windows\System32\EncDec.dll
2008-10-23 11:30 . 2008-10-23 11:30 293,376 --a------ c:\windows\System32\psisdecd.dll
2008-10-23 11:30 . 2008-10-23 11:30 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-10-23 11:30 . 2008-10-23 11:30 177,664 --a------ c:\windows\System32\mpg2splt.ax
2008-10-23 11:30 . 2008-10-23 11:30 80,896 --a------ c:\windows\System32\MSNP.ax
2008-10-23 11:30 . 2008-10-23 11:30 69,632 --a------ c:\windows\System32\Mpeg2Data.ax
2008-10-23 11:30 . 2008-10-23 11:30 57,856 --a------ c:\windows\System32\MSDvbNP.ax
2008-10-23 11:23 . 2008-10-23 11:23 2,032,640 --a------ c:\windows\System32\win32k.sys
2008-10-23 11:17 . 2008-01-19 08:34 15,872 --a------ c:\windows\System32\hcrstco.dll
2008-10-23 11:17 . 2006-11-02 10:46 8,704 --a------ c:\windows\System32\hccoin.dll
2008-10-23 11:10 . 2008-10-23 11:10 6,656 --a------ c:\windows\System32\kbd106n.dll
2008-10-23 11:09 . 2008-10-23 11:09 988,216 --a------ c:\windows\System32\winload.exe
2008-10-23 11:09 . 2008-10-23 11:09 927,288 --a------ c:\windows\System32\winresume.exe
2008-10-23 11:09 . 2008-10-23 11:09 615,992 --a------ c:\windows\System32\ci.dll
2008-10-23 11:09 . 2008-10-23 11:09 378,368 --a------ c:\windows\System32\srcore.dll
2008-10-23 11:09 . 2008-10-23 11:09 318,464 --a------ c:\windows\System32\rstrui.exe
2008-10-23 11:09 . 2008-10-23 11:09 46,592 --a------ c:\windows\System32\setbcdlocale.dll
2008-10-23 11:09 . 2008-10-23 11:09 40,960 --a------ c:\windows\System32\srclient.dll
2008-10-23 11:09 . 2008-10-23 11:09 19,000 --a------ c:\windows\System32\kd1394.dll
2008-10-23 11:09 . 2008-10-23 11:09 14,848 --a------ c:\windows\System32\srdelayed.exe
2008-10-23 11:08 . 2008-10-23 11:07 873,152 --a------ c:\windows\System32\oem37.inf
2008-10-23 11:06 . 2008-10-23 11:06 295,936 --a------ c:\windows\System32\gdi32.dll
2008-10-23 11:06 . 2008-10-23 11:06 288,768 --a------ c:\windows\System32\drivers\srv.sys
2008-10-23 11:02 . 2008-10-23 11:02 113,664 --a------ c:\windows\System32\drivers\rmcast.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 14:19 --------- d-----w c:\programdata\Symantec
2008-11-01 14:19 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-01 12:59 --------- d-----w c:\program files\Norton Internet Security
2008-10-30 15:29 --------- d-----w c:\programdata\Roxio
2008-10-29 22:08 --------- d-----w c:\programdata\Sonic
2008-10-28 07:45 --------- d-----w c:\programdata\Hewlett-Packard
2008-10-27 16:42 --------- d-----w c:\programdata\HP
2008-10-26 22:58 --------- d-----w c:\program files\Microsoft Works
2008-10-26 18:26 174 --sha-w c:\program files\desktop.ini
2008-10-26 18:11 --------- d-----w c:\program files\Windows Sidebar
2008-10-26 18:11 --------- d-----w c:\program files\Windows Mail
2008-10-26 18:11 --------- d-----w c:\program files\Windows Journal
2008-10-26 18:11 --------- d-----w c:\program files\Windows Collaboration
2008-10-26 18:11 --------- d-----w c:\program files\Windows Calendar
2008-10-26 18:10 --------- d-----w c:\program files\Windows Photo Gallery
2008-10-26 18:10 --------- d-----w c:\program files\Windows Defender
2008-10-26 17:22 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-10-26 17:22 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-10-23 14:57 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-23 11:56 --------- d-----w c:\program files\HP
2008-10-23 11:55 --------- d-----w c:\program files\Hewlett-Packard
2008-10-23 10:34 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-10-23 10:34 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-10-23 10:34 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-10-23 10:34 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-10-23 10:34 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-23 10:25 --------- d-----w c:\program files\CONEXANT
2008-10-23 09:31 --------- d-----w c:\program files\Google
2008-10-23 09:20 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-10-23 09:20 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2008-10-23 09:20 10,671 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-10-23 09:20 --------- d-----w c:\program files\Symantec
2008-10-23 08:54 --------- d-----w c:\program files\Java
2008-10-23 07:30 --------- d-sh--w c:\programdata\Templates
2008-10-23 07:30 --------- d-sh--w c:\programdata\Start Menu
2008-10-23 07:30 --------- d-sh--w c:\programdata\Favorites
2008-10-23 07:30 --------- d-sh--w c:\programdata\Documents
2008-10-23 07:30 --------- d-sh--w c:\programdata\Desktop
2008-10-23 07:30 --------- d-sh--w c:\programdata\Application Data
2008-10-22 15:21 21,248 ----a-w c:\windows\Help\OEM\scripts\HPScript.exe
2008-10-06 10:51 20,224 ----a-w c:\windows\Help\OEM\scripts\HC_checkMUI.dll
2008-10-03 12:14 39,984 ----a-w c:\windows\system32\drivers\symids.sys
2008-10-03 12:14 37,936 ----a-w c:\windows\system32\drivers\symndisv.sys
2008-10-03 12:14 27,696 ----a-w c:\windows\system32\drivers\symredrv.sys
2008-10-03 12:14 187,952 ----a-w c:\windows\system32\drivers\symtdi.sys
2008-10-03 12:14 146,096 ----a-w c:\windows\system32\drivers\symfw.sys
2008-10-03 12:14 12,848 ----a-w c:\windows\system32\drivers\symdns.sys
2008-10-03 12:14 10,804 ----a-w c:\windows\system32\drivers\SymRedir.cat
2008-10-03 12:14 1,358 ----a-w c:\windows\system32\drivers\SymRedir.inf
2008-10-02 15:42 482,176 ----a-w c:\windows\system32\drivers\ATSwpWDF.sys
2008-08-29 09:18 87,336 ----a-w c:\windows\System32\dns-sd.exe
2008-08-29 08:53 61,440 ----a-w c:\windows\System32\dnssd.dll
2008-08-21 15:16 11,520 ----a-w c:\windows\Help\OEM\scripts\HCNetworkTest.exe
2008-08-09 07:30 1,007,616 ----a-w c:\windows\System32\VSFilter.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-09-26 206184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-24 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-11 317128]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2008-10-31 2468200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
c:\users\Isabelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ppcb_32.lnk - c:\program files\ppcbooster\ppcb_32.exe [2008-10-28 24576]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-03-29 719664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4527DDE8-7EE8-4BE8-968B-8354CE5108FB}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{9440D337-E719-4E7A-9152-7BE0FAE1E8F0}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C873D722-3AF7-4309-86D6-BBCF22F83260}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{A5610F73-3B15-41BA-A0A3-E18C80128A7D}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{4034DCE0-7C0D-48FC-80AD-F28B154411D9}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A79E4013-A084-4C2A-BCDF-34F46693AEF9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{A6632A32-4C19-4D8E-83ED-165D1E509AF7}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20081031.001\IDSvix86.sys [2008-10-07 270384]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 51280]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2008-10-02 482176]
R3 btwaudio;Bluetooth Audio Device Service;c:\windows\system32\drivers\btwaudio.sys [2007-04-18 79664]
R3 btwavdt;Bluetooth AVDT;c:\windows\system32\drivers\btwavdt.sys [2007-04-18 81200]
R3 btwrchid;btwrchid;c:\windows\system32\DRIVERS\btwrchid.sys [2007-04-18 16432]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDRT32.sys [2008-03-03 188416]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\Drivers\SYMNDISV.SYS [2008-10-03 37936]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3332e1d2-a66f-11dd-a745-001e377a58b9}]
\shell\AutoRun\command - F:\InstallTomTomHOME.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-VnrBlock21 - c:\program files\VnrBlock\VnrBlock21.exe
HKCU-Run-mondrv411 - c:\windows\mondrv411.exe
HKLM-Run-mondrv411 - c:\windows\mondrv411.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://uk.yahoo.com/
R0 -: HKLM-Main,Start Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NO&c=73&bd=Pavilion&pf=laptop
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 -: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-04 18:43:09
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-04 18:46:22
ComboFix-quarantined-files.txt 2008-11-04 17:46:09
Pre-Run: 160*861*220*864 bytes free
Post-Run: 160,378,769,408 bytes free
301 --- E O F --- 2008-10-31 21:51:00
Hi
We're not done yet :)
IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.
LimeWire
I'd like you to read the this thread (http://forums.spybot.info/showthread.php?t=282).
Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).
Delete these folders afterwards:
c:\users\Isabelle\AppData\Roaming\LimeWire
c:\program files\LimeWire
Empty Recycle Bin.
After that:
Disable Ad Watch
* Right click on the Ad-Watch icon in the system tray.
* At the bottom of the screen there will be two checkable items called Active and Automatic.
o Active: This will turn Ad-Watch On\Off without closing it.
o Automatic: Suspicious activity will be blocked automatically.
* Uncheck both of those boxes.
* (When done, you can re-enable it using the same steps but this time check both boxes.)
Open notepad and copy/paste the text in the quotebox below into it:
File::
c:\windows\pptb1948.exe
c:\users\Isabelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ppcb_32.lnk
Folder::
c:\program files\ppcbooster
c:\users\Isabelle\AppData\Roaming\LimeWire
c:\program files\LimeWire
Save this as
CFScript
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.
Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.
Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.
Double-click ATF Cleaner.exe to open it
Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.
If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
Click Exit on the Main menu to close the program.
Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/virusscanner) as instructed in the screenshot here (http://i275.photobucket.com/albums/jj285/Bleeping/KAS/KAS9.gif).
Post back its report, a fresh hjt log and above mentioned ComboFix resultant log.
COMBOFIX LOG:
ComboFix 08-11-04.02 - Isabelle 2008-11-04 21:44:40.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1114 [GMT 1:00]
Running from: c:\users\Isabelle\Desktop\ComboFix.exe
Command switches used :: c:\users\Isabelle\Desktop\CFScript.txt.txt
FILE ::
c:\users\Isabelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ppcb_32.lnk
c:\windows\pptb1948.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\ppcbooster
c:\program files\ppcbooster\ppcb_32.exe
c:\program files\ppcbooster\ppcbu_32.exe
c:\users\Isabelle\AppData\Roaming\LimeWire
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\[PSP]Lego Batman [ESPALPSP.com].rar.torrent
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\Code de la Route 2004 (1000 Questions + Leçons).nrg.torrent
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\Code De La Route 2007 LuDivX.torrent
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\Lavasoft Ad-Aware 2008 Pro.torrent
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\Little.Britain.USA.S01E02.HDTV.XviD-SYS.avi.torrent
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\Little.Britain.USA.S01E04.HDTV.XviD-CRiMSON.avi.torrent
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\Little.Britain.USA.S01E05.HDTV.XviD-aAF.avi.torrent
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\Vista_Recovery_Disc.iso.torrent
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\Vista_Recovery_Disc.iso.torrent.bak
c:\users\Isabelle\AppData\Roaming\LimeWire\.AppSpecialShare\Windows Vista x64 Recovery Disc.iso.torrent
c:\users\Isabelle\AppData\Roaming\LimeWire\certificate\limewire.keystore
c:\users\Isabelle\AppData\Roaming\LimeWire\createtimes.cache
c:\users\Isabelle\AppData\Roaming\LimeWire\downloads.dat
c:\users\Isabelle\AppData\Roaming\LimeWire\fileurns.bak
c:\users\Isabelle\AppData\Roaming\LimeWire\fileurns.cache
c:\users\Isabelle\AppData\Roaming\LimeWire\filters.props
c:\users\Isabelle\AppData\Roaming\LimeWire\installation.props
c:\users\Isabelle\AppData\Roaming\LimeWire\library.dat
c:\users\Isabelle\AppData\Roaming\LimeWire\limewire.props
c:\users\Isabelle\AppData\Roaming\LimeWire\mojito.props
c:\users\Isabelle\AppData\Roaming\LimeWire\passive.mojito
c:\users\Isabelle\AppData\Roaming\LimeWire\promotion\promodb.backup
c:\users\Isabelle\AppData\Roaming\LimeWire\promotion\promodb.data
c:\users\Isabelle\AppData\Roaming\LimeWire\promotion\promodb.lck
c:\users\Isabelle\AppData\Roaming\LimeWire\promotion\promodb.log
c:\users\Isabelle\AppData\Roaming\LimeWire\promotion\promodb.properties
c:\users\Isabelle\AppData\Roaming\LimeWire\promotion\promodb.script
c:\users\Isabelle\AppData\Roaming\LimeWire\questions.props
c:\users\Isabelle\AppData\Roaming\LimeWire\simpp.xml
c:\users\Isabelle\AppData\Roaming\LimeWire\tables.props
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme.lwtp
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\[u]01_star.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\02_star.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\03_star.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\04_star.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\05_star.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\chat.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\forward_dn.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\forward_up.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\kill.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\kill_on.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\pause_dn.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\pause_up.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\play_dn.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\play_up.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\question.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\rewind_dn.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\rewind_up.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\stop_dn.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\stop_up.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\theme.txt
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\version.txt
c:\users\Isabelle\AppData\Roaming\LimeWire\themes\windows_theme\warning.gif
c:\users\Isabelle\AppData\Roaming\LimeWire\version.xml
c:\users\Isabelle\AppData\Roaming\LimeWire\versions.props
c:\users\Isabelle\AppData\Roaming\LimeWire\xml\data\audio.sxml2
c:\users\Isabelle\AppData\Roaming\LimeWire\xml\data\video.sxml2
c:\users\Isabelle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ppcb_32.lnk
c:\windows\pptb1948.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-04 to 2008-11-04 )))))))))))))))))))))))))))))))
.
2008-11-04 13:35 . 2008-11-04 13:35 <DIR> d-------- c:\program files\Trend Micro
2008-11-01 21:06 . 2008-11-02 10:33 <DIR> d-------- c:\users\All Users\Spybot - Search & Destroy
2008-11-01 21:06 . 2008-11-02 10:33 <DIR> d-------- c:\programdata\Spybot - Search & Destroy
2008-11-01 21:06 . 2008-11-01 21:10 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-11-01 14:00 . 2008-07-30 17:42 23,888 --a------ c:\windows\System32\drivers\COH_Mon.sys
2008-11-01 14:00 . 2008-07-30 17:28 10,537 --a------ c:\windows\System32\drivers\COH_Mon.cat
2008-11-01 14:00 . 2008-07-30 17:28 706 --a------ c:\windows\System32\drivers\COH_Mon.inf
2008-10-31 23:39 . 2008-10-31 23:39 <DIR> d-------- c:\program files\Lavasoft
2008-10-31 23:38 . 2008-10-31 23:38 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2008-10-31 20:24 . 2008-10-31 20:26 <DIR> d-------- c:\users\All Users\Lavasoft
2008-10-31 20:24 . 2008-10-31 20:26 <DIR> d-------- c:\programdata\Lavasoft
2008-10-31 09:23 . 2008-10-31 09:23 <DIR> d-------- c:\program files\Alwil Software
2008-10-31 09:23 . 2008-07-19 16:36 51,280 --a------ c:\windows\System32\drivers\aswMonFlt.sys
2008-10-30 17:40 . 2008-10-30 17:40 <DIR> d-------- c:\users\All Users\TomTom
2008-10-30 17:40 . 2008-10-30 17:40 <DIR> d-------- c:\programdata\TomTom
2008-10-30 17:39 . 2008-10-30 17:39 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\TomTom
2008-10-30 17:37 . 2008-10-30 17:37 <DIR> d-------- c:\program files\TomTom HOME 2
2008-10-30 17:34 . 2008-10-30 17:34 <DIR> d-------- c:\program files\TomTom DesktopSuite
2008-10-30 17:34 . 2008-10-30 17:34 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-10-30 17:18 . 2008-10-30 17:18 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\Apple Computer
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d----c--- c:\windows\System32\DRVSTORE
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d-------- c:\users\All Users\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d-------- c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d-------- c:\program files\iTunes
2008-10-30 17:17 . 2008-10-30 17:17 <DIR> d-------- c:\program files\iPod
2008-10-30 17:17 . 2008-04-17 13:12 107,368 --a------ c:\windows\System32\GEARAspi.dll
2008-10-30 17:17 . 2008-04-17 13:12 15,464 --a------ c:\windows\System32\drivers\GEARAspiWDM.sys
2008-10-30 17:15 . 2008-10-30 17:15 <DIR> d-------- c:\program files\Bonjour
2008-10-30 17:14 . 2008-10-30 17:17 <DIR> d-------- c:\users\All Users\Apple Computer
2008-10-30 17:14 . 2008-10-30 17:17 <DIR> d-------- c:\programdata\Apple Computer
2008-10-30 17:14 . 2008-10-30 17:15 <DIR> d-------- c:\program files\QuickTime
2008-10-30 17:12 . 2008-10-30 17:12 <DIR> d-------- c:\program files\Apple Software Update
2008-10-30 17:11 . 2008-10-30 17:11 <DIR> d-------- c:\users\All Users\Apple
2008-10-30 17:11 . 2008-10-30 17:11 <DIR> d-------- c:\programdata\Apple
2008-10-30 17:11 . 2008-10-30 17:14 <DIR> d-------- c:\program files\Common Files\Apple
2008-10-30 17:03 . 2008-10-30 17:05 <DIR> d-------- c:\windows\System32\Adobe
2008-10-29 23:08 . 2008-10-29 23:08 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\Roxio
2008-10-29 17:27 . 2008-08-12 04:39 443,392 --a------ c:\windows\System32\win32spl.dll
2008-10-29 16:41 . 2008-10-29 16:42 <DIR> d-------- c:\program files\VistaCodecPack
2008-10-29 16:39 . 2008-10-29 16:39 <DIR> d-------- c:\users\All Users\VistaCodecs
2008-10-29 16:39 . 2008-10-29 16:39 <DIR> d-------- c:\programdata\VistaCodecs
2008-10-29 15:18 . 2008-10-29 15:18 <DIR> d-------- c:\program files\Code de la Route pour les Nuls
2008-10-28 18:21 . 2008-09-18 05:56 147,456 --a------ c:\windows\System32\Faultrep.dll
2008-10-28 18:21 . 2008-09-18 05:56 125,952 --a------ c:\windows\System32\wersvc.dll
2008-10-27 17:42 . 2008-10-27 17:42 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\HP
2008-10-27 17:42 . 2008-10-27 17:42 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\CyberLink
2008-10-26 23:59 . 2008-10-26 23:59 <DIR> d-------- c:\program files\Microsoft Silverlight
2008-10-26 23:53 . 2008-04-26 09:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
2008-10-26 19:07 . 2008-10-26 19:07 <DIR> d-------- C:\PerfLogs
2008-10-26 17:47 . 2008-01-19 08:33 2,623,488 --a------ c:\windows\System32\SLsvc.exe
2008-10-26 17:47 . 2008-01-19 08:36 1,541,120 --a------ c:\windows\System32\onex.dll
2008-10-26 17:45 . 2008-01-19 04:12 3,662,296 --a------ c:\windows\System32\locale.nls
2008-10-26 17:44 . 2008-01-19 08:33 8,139,264 --a------ c:\windows\System32\ssBranded.scr
2008-10-26 17:43 . 2008-01-19 08:35 3,072,000 --a------ c:\windows\System32\networkmap.dll
2008-10-26 17:42 . 2008-01-19 07:06 8,147,456 --a------ c:\windows\System32\wmploc.DLL
2008-10-26 17:41 . 2008-01-19 08:36 704,512 --a------ c:\windows\System32\SmiEngine.dll
2008-10-26 17:41 . 2008-01-19 08:36 357,888 --a------ c:\windows\System32\wbemcomn.dll
2008-10-26 17:41 . 2008-01-19 08:34 305,152 --a------ c:\windows\System32\msdelta.dll
2008-10-26 17:41 . 2008-01-19 08:34 258,560 --a------ c:\windows\System32\dpx.dll
2008-10-26 17:41 . 2008-01-19 08:34 246,784 --a------ c:\windows\System32\drvstore.dll
2008-10-26 17:41 . 2008-01-19 08:36 218,624 --a------ c:\windows\System32\wdscore.dll
2008-10-26 17:41 . 2008-01-19 08:36 139,264 --a------ c:\windows\System32\SmiInstaller.dll
2008-10-26 17:41 . 2008-01-19 08:33 130,560 --a------ c:\windows\System32\PkgMgr.exe
2008-10-26 17:41 . 2008-01-19 08:36 129,536 --a------ c:\windows\System32\sqmapi.dll
2008-10-26 17:41 . 2008-01-19 08:35 35,328 --a------ c:\windows\System32\mspatcha.dll
2008-10-25 02:15 . 2008-10-25 02:52 <DIR> d-------- c:\users\Public\Games
2008-10-25 01:19 . 2008-10-25 01:19 <DIR> d-------- c:\users\All Users\Blizzard
2008-10-25 01:19 . 2008-10-25 01:19 <DIR> d-------- c:\programdata\Blizzard
2008-10-24 21:40 . 2008-10-24 21:40 <DIR> dr------- c:\windows\System32\config\systemprofile\Music
2008-10-24 20:19 . 2008-10-24 20:20 <DIR> d-------- c:\program files\Common Files\Adobe
2008-10-24 19:40 . 2008-10-24 20:14 <DIR> d-------- c:\users\All Users\NOS
2008-10-24 19:40 . 2008-10-24 20:14 <DIR> d-------- c:\programdata\NOS
2008-10-24 19:40 . 2008-10-24 19:40 <DIR> d-------- c:\program files\NOS
2008-10-24 09:24 . 2008-10-24 09:24 269,312 --a------ c:\windows\System32\es.dll
2008-10-24 09:08 . 2008-10-24 09:34 <DIR> d-------- c:\program files\Common Files\Blizzard Entertainment
2008-10-23 19:59 . 2008-10-23 19:59 0 --a------ c:\users\Isabelle\AppData\Roaming\wklnhst.dat
2008-10-23 17:22 . 2008-11-04 18:06 1,660 --a------ c:\windows\bthservsdp.dat
2008-10-23 17:06 . 2008-10-24 08:51 <DIR> d-------- c:\users\Isabelle\WoW-2.3.0.7561-enGB
2008-10-23 16:54 . 2008-10-23 16:54 <DIR> d-------- c:\program files\Broadcom
2008-10-23 16:17 . 2008-10-26 19:36 <DIR> d-------- c:\users\All Users\NVIDIA
2008-10-23 16:17 . 2008-10-26 19:36 <DIR> d-------- c:\programdata\NVIDIA
2008-10-23 12:57 . 2008-10-23 12:57 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\GTek
2008-10-23 12:37 . 2007-02-14 08:55 356,352 --a------ c:\windows\System32\nvusmu.exe
2008-10-23 12:37 . 2006-12-01 06:37 3,903 --a------ c:\windows\System32\nvnrm.nvu
2008-10-23 12:37 . 2006-12-15 07:48 528 --a------ c:\windows\System32\nvsmu.nvu
2008-10-23 12:36 . 2008-10-23 12:36 <DIR> d-------- c:\users\Isabelle\AppData\Roaming\InstallShield
2008-10-23 12:36 . 2006-11-08 23:48 356,352 --a------ c:\windows\System32\nvusmb.exe
2008-10-23 12:36 . 2006-10-20 00:36 1,864 --a------ c:\windows\System32\nvsmb.nvu
2008-10-23 11:59 . 2008-10-23 11:59 271,571,308 --a------ c:\windows\MEMORY.DMP
2008-10-23 11:36 . 2008-10-23 11:36 361,984 --a------ c:\windows\System32\IPSECSVC.DLL
2008-10-23 11:36 . 2008-10-23 11:36 272,896 --a------ c:\windows\System32\polstore.dll
2008-10-23 11:36 . 2008-10-23 11:36 61,440 --a------ c:\windows\System32\winipsec.dll
2008-10-23 11:36 . 2008-10-23 11:36 28,672 --a------ c:\windows\System32\FwRemoteSvr.dll
2008-10-23 11:35 . 2008-10-23 11:35 1,820 --a------ c:\windows\System32\rasctrnm.h
2008-10-23 11:34 . 2008-10-23 11:34 4,240,384 --a------ c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-23 11:34 . 2008-10-23 11:34 1,695,744 --a------ c:\windows\System32\gameux.dll
2008-10-23 11:34 . 2008-10-23 11:34 28,160 --a------ c:\windows\System32\Apphlpdm.dll
2008-10-23 11:30 . 2008-10-23 11:30 428,544 --a------ c:\windows\System32\EncDec.dll
2008-10-23 11:30 . 2008-10-23 11:30 293,376 --a------ c:\windows\System32\psisdecd.dll
2008-10-23 11:30 . 2008-10-23 11:30 217,088 --a------ c:\windows\System32\psisrndr.ax
2008-10-23 11:30 . 2008-10-23 11:30 177,664 --a------ c:\windows\System32\mpg2splt.ax
2008-10-23 11:30 . 2008-10-23 11:30 80,896 --a------ c:\windows\System32\MSNP.ax
2008-10-23 11:30 . 2008-10-23 11:30 69,632 --a------ c:\windows\System32\Mpeg2Data.ax
2008-10-23 11:30 . 2008-10-23 11:30 57,856 --a------ c:\windows\System32\MSDvbNP.ax
2008-10-23 11:23 . 2008-10-23 11:23 2,032,640 --a------ c:\windows\System32\win32k.sys
2008-10-23 11:17 . 2008-01-19 08:34 15,872 --a------ c:\windows\System32\hcrstco.dll
2008-10-23 11:17 . 2006-11-02 10:46 8,704 --a------ c:\windows\System32\hccoin.dll
2008-10-23 11:10 . 2008-10-23 11:10 6,656 --a------ c:\windows\System32\kbd106n.dll
2008-10-23 11:09 . 2008-10-23 11:09 988,216 --a------ c:\windows\System32\winload.exe
2008-10-23 11:09 . 2008-10-23 11:09 927,288 --a------ c:\windows\System32\winresume.exe
2008-10-23 11:09 . 2008-10-23 11:09 615,992 --a------ c:\windows\System32\ci.dll
2008-10-23 11:09 . 2008-10-23 11:09 378,368 --a------ c:\windows\System32\srcore.dll
2008-10-23 11:09 . 2008-10-23 11:09 318,464 --a------ c:\windows\System32\rstrui.exe
2008-10-23 11:09 . 2008-10-23 11:09 46,592 --a------ c:\windows\System32\setbcdlocale.dll
2008-10-23 11:09 . 2008-10-23 11:09 40,960 --a------ c:\windows\System32\srclient.dll
2008-10-23 11:09 . 2008-10-23 11:09 19,000 --a------ c:\windows\System32\kd1394.dll
2008-10-23 11:09 . 2008-10-23 11:09 14,848 --a------ c:\windows\System32\srdelayed.exe
2008-10-23 11:08 . 2008-10-23 11:07 873,152 --a------ c:\windows\System32\oem37.inf
2008-10-23 11:06 . 2008-10-23 11:06 295,936 --a------ c:\windows\System32\gdi32.dll
2008-10-23 11:06 . 2008-10-23 11:06 288,768 --a------ c:\windows\System32\drivers\srv.sys
2008-10-23 11:02 . 2008-10-23 11:02 113,664 --a------ c:\windows\System32\drivers\rmcast.sys
2008-10-23 11:02 . 2008-10-23 11:02 14,848 --a------ c:\windows\System32\wshrm.dll
2008-10-23 11:00 . 2008-10-23 11:00 0 --ah----- c:\windows\System32\drivers\Msft_Kernel_ATSwpWDF_01005.Wdf
2008-10-23 10:11 . 2008-10-23 10:11 2,048 --a------ c:\windows\System32\tzres.dll
2008-10-23 10:10 . 2008-10-23 10:10 303,616 --a------ c:\windows\System32\wmpeffects.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-01 14:19 --------- d-----w c:\programdata\Symantec
2008-11-01 14:19 --------- d-----w c:\program files\Common Files\Symantec Shared
2008-11-01 12:59 --------- d-----w c:\program files\Norton Internet Security
2008-10-30 15:29 --------- d-----w c:\programdata\Roxio
2008-10-29 22:08 --------- d-----w c:\programdata\Sonic
2008-10-28 07:45 --------- d-----w c:\programdata\Hewlett-Packard
2008-10-27 16:42 --------- d-----w c:\programdata\HP
2008-10-26 22:58 --------- d-----w c:\program files\Microsoft Works
2008-10-26 18:26 174 --sha-w c:\program files\desktop.ini
2008-10-26 18:11 --------- d-----w c:\program files\Windows Sidebar
2008-10-26 18:11 --------- d-----w c:\program files\Windows Mail
2008-10-26 18:11 --------- d-----w c:\program files\Windows Journal
2008-10-26 18:11 --------- d-----w c:\program files\Windows Collaboration
2008-10-26 18:11 --------- d-----w c:\program files\Windows Calendar
2008-10-26 18:10 --------- d-----w c:\program files\Windows Photo Gallery
2008-10-26 18:10 --------- d-----w c:\program files\Windows Defender
2008-10-26 17:22 82,432 ----a-w c:\windows\System32\axaltocm.dll
2008-10-26 17:22 101,888 ----a-w c:\windows\System32\ifxcardm.dll
2008-10-23 14:57 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-23 11:56 --------- d-----w c:\program files\HP
2008-10-23 11:55 --------- d-----w c:\program files\Hewlett-Packard
2008-10-23 10:34 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
2008-10-23 10:34 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
2008-10-23 10:34 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
2008-10-23 10:34 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
2008-10-23 10:34 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
2008-10-23 10:25 --------- d-----w c:\program files\CONEXANT
2008-10-23 09:31 --------- d-----w c:\program files\Google
2008-10-23 09:20 805 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2008-10-23 09:20 123,952 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2008-10-23 09:20 10,671 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-10-23 09:20 --------- d-----w c:\program files\Symantec
2008-10-23 08:54 --------- d-----w c:\program files\Java
2008-10-23 07:30 --------- d-sh--w c:\programdata\Templates
2008-10-23 07:30 --------- d-sh--w c:\programdata\Start Menu
2008-10-23 07:30 --------- d-sh--w c:\programdata\Favorites
2008-10-23 07:30 --------- d-sh--w c:\programdata\Documents
2008-10-23 07:30 --------- d-sh--w c:\programdata\Desktop
2008-10-23 07:30 --------- d-sh--w c:\programdata\Application Data
2008-10-22 15:21 21,248 ----a-w c:\windows\Help\OEM\scripts\HPScript.exe
2008-10-06 10:51 20,224 ----a-w c:\windows\Help\OEM\scripts\HC_checkMUI.dll
2008-10-03 12:14 39,984 ----a-w c:\windows\system32\drivers\symids.sys
2008-10-03 12:14 37,936 ----a-w c:\windows\system32\drivers\symndisv.sys
2008-10-03 12:14 27,696 ----a-w c:\windows\system32\drivers\symredrv.sys
2008-10-03 12:14 187,952 ----a-w c:\windows\system32\drivers\symtdi.sys
2008-10-03 12:14 146,096 ----a-w c:\windows\system32\drivers\symfw.sys
2008-10-03 12:14 12,848 ----a-w c:\windows\system32\drivers\symdns.sys
2008-10-03 12:14 10,804 ----a-w c:\windows\system32\drivers\SymRedir.cat
2008-10-03 12:14 1,358 ----a-w c:\windows\system32\drivers\SymRedir.inf
2008-10-02 15:42 482,176 ----a-w c:\windows\system32\drivers\ATSwpWDF.sys
2008-08-29 09:18 87,336 ----a-w c:\windows\System32\dns-sd.exe
2008-08-29 08:53 61,440 ----a-w c:\windows\System32\dnssd.dll
2008-08-21 15:16 11,520 ----a-w c:\windows\Help\OEM\scripts\HCNetworkTest.exe
2008-08-09 07:30 1,007,616 ----a-w c:\windows\System32\VSFilter.dll
.
((((((((((((((((((((((((((((( snapshot@2008-11-04_18.44.35,03 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-11-04 17:10:50 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-11-04 18:02:23 262,144 --sha-w c:\windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-11-04 17:08:11 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-11-04 20:40:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-11-04 17:08:11 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-11-04 20:40:59 32,768 --sha-w c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-11-04 17:08:11 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-11-04 20:40:59 16,384 --sha-w c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-11-04 17:31:37 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
+ 2008-11-04 20:43:43 262,144 ----a-w c:\windows\System32\config\systemprofile\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 484904]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2008-09-26 206184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-04-24 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-11 317128]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-19 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-19 8497696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-19 81920]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\Ad-Watch.exe" [2008-10-31 2468200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-03-29 719664]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{4527DDE8-7EE8-4BE8-968B-8354CE5108FB}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{9440D337-E719-4E7A-9152-7BE0FAE1E8F0}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{C873D722-3AF7-4309-86D6-BBCF22F83260}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{A5610F73-3B15-41BA-A0A3-E18C80128A7D}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{4034DCE0-7C0D-48FC-80AD-F28B154411D9}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{A79E4013-A084-4C2A-BCDF-34F46693AEF9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{A6632A32-4C19-4D8E-83ED-165D1E509AF7}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20081031.001\IDSvix86.sys [2008-10-07 270384]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2008-07-19 51280]
R3 ATSwpWDF;AuthenTec TruePrint USB WDF Driver;c:\windows\system32\Drivers\ATSwpWDF.sys [2008-10-02 482176]
R3 btwaudio;Bluetooth Audio Device Service;c:\windows\system32\drivers\btwaudio.sys [2007-04-18 79664]
R3 btwavdt;Bluetooth AVDT;c:\windows\system32\drivers\btwavdt.sys [2007-04-18 81200]
R3 btwrchid;btwrchid;c:\windows\system32\DRIVERS\btwrchid.sys [2007-04-18 16432]
R3 CnxtHdAudService;Conexant UAA Function Driver for High Definition Audio Service;c:\windows\system32\drivers\CHDRT32.sys [2008-03-03 188416]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\Drivers\SYMNDISV.SYS [2008-10-03 37936]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3332e1d2-a66f-11dd-a745-001e377a58b9}]
\shell\AutoRun\command - F:\InstallTomTomHOME.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-04 21:56:39
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-11-04 21:59:36
ComboFix-quarantined-files.txt 2008-11-04 20:59:26
ComboFix2.txt 2008-11-04 17:46:23
Pre-Run: 161*466*454*016 bytes free
Post-Run: 160,984,576,000 bytes free
368 --- E O F --- 2008-10-31 21:51:00
:D::D::D::D:
FRESH HJT LOG:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:11:44, on 04.11.2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\Explorer.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NO&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_NO&c=73&bd=Pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\Ad-Watch.exe
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
--
End of file - 11040 bytes
:D::D::D:
I can't get a KASPERSKY log, I click "save report as" and save as .txt but never get the file on my PC. Maybe because it's empty? The online scan report doesn't show any infected or suspicious object.
My spyware stopped acting up by the way :present::bigthumb::D:
Hi
You seem to have both Avast and Norton Internet Security running there. It's recommended to have only one antivirus program in same system. Decide which one you want to keep and uninstall the other one.
I can't get a KASPERSKY log, I click "save report as" and save as .txt but never get the file on my PC. Maybe because it's empty? The online scan report doesn't show any infected or suspicious object.
It's ok then :)
How's your system running now?
My system is running great!! :laugh:
Thank you SO MUCH!! :p::p::p:
I'm so happy you worked your little magic :laugh:
Kiitos! :red:
I know P2P isn't good at all but how about torrents? Are they as bad? Can we trust a file that has been downloaded and commented positively by other people?
You're welcome :)
I'd be very cautious with all p2p related things including torrents. If some person says something is safe then how can you be sure (s)he isn't bluffing? No way to be sure of that.
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)
Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.
If it has been less than five days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.