View Full Version : Coupon Printer
My wife recently installed coupon printer and while I'm not 100% sure that this caused the problem, the computer has stopped functioning correctly. Here are the symptoms. After restart a box comes up that says "Multimedia Card Reader" with the message "Resource is not enough". Then a message comes up from Catalyst (the ati graphics card program) saying that you do not have rights to modify these settings (I am not modifying any settings.) This dialog box comes up twice. Once everything is all booted, there are a few other problems. First the toolbar is gone from the bottom of the desktop, Second internet explorer will not run (the screen flashes and that is it), third the network profiles aren't loaded and the network connections service doesn't run. Also right clicking doesn't allow me to paste. The following is my log file.
We are running Windows XP Home Edition Media Center. The computer was running fine until these problems. We don't normally use this computer for browsing although it is connected to the internet. Ok here is the log file.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:37 AM, on 1/24/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Mozy\mozybackup.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Mozy\mozystat.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
F:\Demos\officeFX\InstallOfficeFX.exe
C:\Program Files\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: AMUST 1-Login IE Helper - {FFF1A4CB-472E-404a-9898-0B73B6B2E421} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
O3 - Toolbar: AMUST 1-Login Toolbar - {F5BAA0B9-0DBF-4b42-BE9C-B2513ED71737} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AMUST 1-Login AutoUpdate] rundll32.exe "C:\Program Files\Common Files\AMUST\Updater\amupdater.dll",AMUSTUpdate AMUST 1-Login ONLYLOCAL
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKUS\S-1-5-21-3690015938-2637564805-925999644-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - HKUS\S-1-5-21-3690015938-2637564805-925999644-1008\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User '?')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Mozy Status.lnk = C:\Program Files\Mozy\mozystat.exe
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\Mozy\mozystat.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} (WebInstaller Control) - http://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} (WebInstaller Control) - http://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156216832609
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://targetphoto.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photofinale.com/ImageUploader/ImageUploader4.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O21 - SSODL: EPItZZQy - {2CEC6C2A-8646-C680-0D65-0E74600C38E7} - C:\WINDOWS\system32\vokz.dll (file missing)
O23 - Service: IPv6 Helper Service (6to4) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Application Management (AppMgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Windows Audio (AudioSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Computer Browser (Browser) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Bluetooth Support Service (BthServ) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Cryptographic Services (CryptSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: DCOM Server Process Launcher (DcomLaunch) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: DHCP Client (Dhcp) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Logical Disk Manager (dmserver) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Error Reporting Service (ERSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: COM+ Event System (EventSystem) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Fast User Switching Compatibility (FastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Help and Support (helpsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: HID Input Service (HidServ) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: Server (lanmanserver) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Workstation (lanmanworkstation) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: TCP/IP NetBIOS Helper (LmHosts) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: MHN - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: MozyHome Backup Service (MozyBackup) - Unknown owner - C:\Program Files\Mozy\mozybackup.exe
O23 - Service: Network Connections (Netman) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Network Location Awareness (NLA) (Nla) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Access Auto Connection Manager (RasAuto) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Remote Access Connection Manager (RasMan) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Remote Registry (RemoteRegistry) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Remote Procedure Call (RPC) (RpcSs) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Secondary Logon (seclogon) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: System Event Notification (SENS) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Shell Hardware Detection (ShellHWDetection) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)
O23 - Service: System Restore Service (srservice) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: SSDP Discovery Service (SSDPSRV) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Windows Image Acquisition (WIA) (stisvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Telephony (TapiSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Terminal Services (TermService) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Themes - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Distributed Link Tracking Client (TrkWks) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Universal Plug and Play Device Host (upnphost) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Windows Time (W32Time) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: WebClient - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Windows Management Instrumentation (winmgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Portable Media Serial Number Service (WmdmPmSN) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Windows Management Instrumentation Driver Extensions (Wmi) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Wireless Zero Configuration (WZCSVC) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Network Provisioning Service (xmlprov) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
--
End of file - 18393 bytes
Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.
If you think you have similar problems, please post a log in the HJT forum and wait for help.
Hello and welcome to the forums
My name is Katana and I will be helping you to remove any infection(s) that you may have.
Please observe these rules while we work:
Please Read All Instructions Carefully
If you don't understand something, stop and ask! Don't keep going on.
Please do not run any other tools or scans whilst I am helping you
Please continue to respond until I give you the "All Clear"
(Just because you can't see a problem doesn't mean it isn't there)
If you can do those few things, everything should go smoothly http://www.countingcows.de/laechel.gif
Please Note, your security programs may give warnings for some of the tools I will ask you to use.
Be assured, any links I give are safe
----------------------------------------------------------------------------------------
Download and Run ComboFix (by sUBs)
Please visit this webpage for instructions for downloading and running ComboFix:
Bleeping Computer ComboFix Tutorial (http://www.bleepingcomputer.com/combofix/how-to-use-combofix)
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log to post in your next reply
Re-enable all the programs that were disabled during the running of ComboFix..
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper
Thanks for replying. Here is the combofix log.
ComboFix 09-01-21.04 - chullz 2009-01-30 22:03:33.1 - NTFSx86
Running from: K:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-31 )))))))))))))))))))))))))))))))
.
2009-01-24 10:55 . 2009-01-24 10:55 <DIR> d-------- c:\documents and settings\chullz\Application Data\Sammsoft
2009-01-24 10:54 . 2009-01-24 10:54 <DIR> d-------- c:\program files\Advanced Registry Optimizer
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a--c--- c:\windows\system32\dllcache\explorer.exe
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a------ c:\windows\explorer.exe
2009-01-21 17:46 . 2009-01-24 08:22 <DIR> d-------- c:\program files\Coupons
2009-01-14 03:04 . 2008-08-28 04:04 333,056 --a------ c:\windows\system32\drivers\srv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-23 02:37 505,856 ----a-w c:\windows\system32\winlogon.exe
2009-01-23 02:37 14,336 ----a-w c:\windows\system32\lsass.exe
2009-01-23 02:37 110,080 ----a-w c:\windows\system32\services.exe
2009-01-22 20:39 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-22 00:07 --------- d-----w c:\program files\Google
2009-01-07 22:21 --------- d--h--w c:\documents and settings\chullz\Application Data\Move Networks
2009-01-06 00:49 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-06 00:49 60,808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-01-06 00:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-06 00:49 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-06 00:49 --------- d-----w c:\program files\Symantec
2008-10-23 13:01 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 20:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 20:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 20:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 20:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 20:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 20:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 20:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 20:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 20:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 20:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 20:34 625,032 ----a-w c:\windows\system32\SymNeti.dll
2008-10-03 20:34 242,056 ----a-w c:\windows\system32\SymRedir.dll
2008-10-03 10:15 247,326 ----a-w c:\windows\system32\strmdll.dll
2007-11-24 19:56 58,232 ----a-w c:\documents and settings\chullz\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
2005-03-02 12:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 09:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\$NtUninstallKB925902$\user32.dll
2008-04-13 18:12 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\dllcache\user32.dll
2008-04-13 18:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ws2_32.dll
2004-08-10 13:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll
2004-09-29 12:27 656896 2c07195588d69a067c2afdaa31759295 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll
2005-01-27 11:08 657920 a8eac5330876548e9966a7d13025d196 c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
2005-03-10 01:43 657920 c8663b488996e89a84c3d17c1d12b79e c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
2007-03-07 11:40 823296 b8f4db39ca7353752f245379d285c80e c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll
2007-04-25 03:08 823808 431defbb4a3d7b0dc062c1b064623a2f c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll
2007-06-27 08:40 824320 d6ed5e042c5207553e7f5e842918137f c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
2007-08-20 04:02 825344 357d54bf94fe9d6d8505a96b5c2a3bca c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
2007-10-10 17:47 825344 0e5d918f87efa7d2424d66b499c7eb04 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-06 20:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 07:03 827392 6316c2f0c61271c8abdff7429174879e c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-22 21:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 10:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2008-08-26 03:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
2008-10-16 14:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
2006-05-09 23:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB916281$\wininet.dll
2005-03-10 02:02 656896 6f018d6319be4f96426ea829b79e05d5 c:\windows\$NtUninstallKB916281_0$\wininet.dll
2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$NtUninstallKB918899$\wininet.dll
2006-06-23 05:25 664576 64ce26db72810b30f7855ea51e1df836 c:\windows\$NtUninstallKB922760$\wininet.dll
2006-09-14 02:31 664576 d207370287cf769aebebf03837784963 c:\windows\ie7\wininet.dll
2006-11-07 21:03 818688 92995334f993e6e49c25c6d02ec04401 c:\windows\ie7updates\KB928090-IE7\wininet.dll
2007-01-12 09:27 822784 be43d00d802c92f01c8cc952c6f483f8 c:\windows\ie7updates\KB931768-IE7\wininet.dll
2007-03-07 11:45 822784 5b35dae6e4886f64d1da58c4e3e01eb9 c:\windows\ie7updates\KB933566-IE7\wininet.dll
2007-04-25 02:41 822784 0586a7f0b2fdb94d624f399d4728e7c8 c:\windows\ie7updates\KB937143-IE7\wininet.dll
2007-06-27 08:34 823808 8068cbb58fe60cc95aeb2cff70178208 c:\windows\ie7updates\KB939653-IE7\wininet.dll
2007-08-20 04:04 824832 774435e499d8e9643ec961a6103c361f c:\windows\ie7updates\KB942615-IE7\wininet.dll
2007-10-10 17:56 824832 30c1e0f34ad2972c72a01db5c74ab065 c:\windows\ie7updates\KB944533-IE7\wininet.dll
2007-12-06 20:21 824832 806d274c9a6c3aaea5eae8e4af841e04 c:\windows\ie7updates\KB947864-IE7\wininet.dll
2008-03-01 07:06 826368 ad21461aef8244edec2ef18e55e1dcf3 c:\windows\ie7updates\KB950759-IE7\wininet.dll
2008-04-22 22:16 826368 f6589be784647cfdbc22ea51ccb1a57a c:\windows\ie7updates\KB953838-IE7\wininet.dll
2008-06-23 10:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll
2008-08-26 01:24 826368 ef8eba98145bfa44e80d17a3b3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll
2008-04-13 18:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wininet.dll
2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\wininet.dll
2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\dllcache\wininet.dll
2005-03-13 19:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-04-20 06:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 10:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 04:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 05:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 05:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2005-03-13 18:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 c:\windows\$NtUninstallKB917953$\tcpip.sys
2006-04-20 05:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
2007-10-30 11:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-13 13:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\tcpip.sys
2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\drivers\tcpip.sys
2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2009-01-22 20:37 505856 e853481fef64a5be3fc3732d9d3d926a c:\windows\system32\winlogon.exe
2008-04-13 13:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ndis.sys
2004-08-10 13:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2008-04-13 12:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys
2004-08-10 13:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 10:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 03:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
2008-08-14 14:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2005-03-01 18:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 06:55 2057600 1d659bfb788ed2ba45075624b748d249 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 02:38 2057600 515d30e2c90a3665a2739309334c9283 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 12:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\dllcache\ntkrnlpa.exe
2004-08-10 13:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 19:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 10:51 2182016 cef243f6defd20be4adde26c7ecacb54 c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 03:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
2008-08-14 15:11 2189184 31914172342bff330063f343ac6958fe c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2005-03-01 18:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 08:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 03:10 2180352 582a8dbaa58c3b1f176eb2817daee77c c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\Driver Cache\i386\ntoskrnl.exe
2008-04-13 13:27 2188928 0c89243c7c3ee199b96fcc16990e0679 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\dllcache\ntoskrnl.exe
2004-08-10 13:00 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntoskrnl.exe
2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
2007-06-13 05:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 13:00 1032192 a0732187050030ae399b241436565e64 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-13 18:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\system32\dllcache\explorer.exe
2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
2009-01-22 20:37 110080 5812a3513734517f8c2c5eab6b269864 c:\windows\system32\services.exe
2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
2009-01-22 20:37 14336 c3e6b717e7b284e1fa89ba9f7a1be1ed c:\windows\system32\lsass.exe
2008-04-13 18:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
2004-08-10 13:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe
2008-04-13 18:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
2004-08-10 13:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe
2004-08-10 13:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll
2008-04-13 18:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\termsrv.dll
2005-03-10 01:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll
2006-07-05 04:57 985088 0fdd84928a5dde2510761b7ec76ccec9 c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
2007-04-16 10:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
2004-08-10 13:00 983552 888190e31455fad793312f8d087146eb c:\windows\$NtUninstallKB917422$\kernel32.dll
2006-07-05 04:55 984064 d8db5397de07577c1cb50ba6d23b3ad4 c:\windows\$NtUninstallKB935839$\kernel32.dll
2008-04-13 18:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\kernel32.dll
2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\kernel32.dll
2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\dllcache\kernel32.dll
2008-04-13 18:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\powrprof.dll
2004-08-10 13:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
"AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"AMUST 1-Login AutoUpdate"="c:\program files\Common Files\AMUST\Updater\amupdater.dll" [2006-04-11 470328]
"YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2007-10-26 509224]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-05 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-22 180269]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-08 29744]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="c:\progra~1\Symantec\osCheck.exe" [2007-01-14 771704]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"CHotkey"="zHotkey.exe" [2005-05-03 c:\windows\zHotkey.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 c:\windows\system32\bthprops.cpl]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=G
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8891:TCP"= 8891:TCP:Pitbull
"50706:TCP"= 50706:TCP:PORT_50706
"41136:TCP"= 41136:TCP:PORT_41136
"58843:TCP"= 58843:TCP:PORT_58843
"45453:TCP"= 45453:TCP:PORT_45453
"46608:TCP"= 46608:TCP:PORT_46608
"24395:TCP"= 24395:TCP:PORT_24395
"58380:TCP"= 58380:TCP:PORT_58380
"12476:TCP"= 12476:TCP:PORT_12476
"44022:TCP"= 44022:TCP:PORT_44022
"23014:TCP"= 23014:TCP:PORT_23014
"61930:TCP"= 61930:TCP:PORT_61930
"46327:TCP"= 46327:TCP:PORT_46327
"34724:TCP"= 34724:TCP:PORT_34724
"19950:TCP"= 19950:TCP:PORT_19950
"49203:TCP"= 49203:TCP:PORT_49203
"23848:TCP"= 23848:TCP:PORT_23848
"48998:TCP"= 48998:TCP:PORT_48998
"53375:TCP"= 53375:TCP:PORT_53375
"40458:TCP"= 40458:TCP:PORT_40458
"6428:TCP"= 6428:TCP:PORT_6428
"37706:TCP"= 37706:TCP:PORT_37706
"47531:TCP"= 47531:TCP:PORT_47531
"46532:TCP"= 46532:TCP:PORT_46532
"32902:TCP"= 32902:TCP:PORT_32902
"17347:TCP"= 17347:TCP:PORT_17347
"17586:TCP"= 17586:TCP:PORT_17586
"26291:TCP"= 26291:TCP:PORT_26291
"55534:TCP"= 55534:TCP:PORT_55534
"41891:TCP"= 41891:TCP:PORT_41891
"48462:TCP"= 48462:TCP:PORT_48462
"18050:TCP"= 18050:TCP:PORT_18050
"31483:TCP"= 31483:TCP:PORT_31483
"33700:TCP"= 33700:TCP:PORT_33700
"31203:TCP"= 31203:TCP:PORT_31203
"43418:TCP"= 43418:TCP:PORT_43418
"24985:TCP"= 24985:TCP:PORT_24985
"19001:TCP"= 19001:TCP:PORT_19001
"42324:TCP"= 42324:TCP:PORT_42324
"10141:TCP"= 10141:TCP:PORT_10141
"15865:TCP"= 15865:TCP:PORT_15865
"36942:TCP"= 36942:TCP:PORT_36942
"30525:TCP"= 30525:TCP:PORT_30525
"41668:TCP"= 41668:TCP:PORT_41668
"46918:TCP"= 46918:TCP:PORT_46918
"34969:TCP"= 34969:TCP:PORT_34969
"31365:TCP"= 31365:TCP:PORT_31365
"46969:TCP"= 46969:TCP:PORT_46969
"24597:TCP"= 24597:TCP:PORT_24597
"20994:TCP"= 20994:TCP:PORT_20994
"41178:TCP"= 41178:TCP:PORT_41178
"28301:TCP"= 28301:TCP:PORT_28301
"59290:TCP"= 59290:TCP:PORT_59290
"24121:TCP"= 24121:TCP:PORT_24121
"57424:TCP"= 57424:TCP:PORT_57424
"44981:TCP"= 44981:TCP:PORT_44981
"58917:TCP"= 58917:TCP:PORT_58917
"19762:TCP"= 19762:TCP:PORT_19762
"13600:TCP"= 13600:TCP:PORT_13600
"50879:TCP"= 50879:TCP:PORT_50879
"25703:TCP"= 25703:TCP:PORT_25703
"25665:TCP"= 25665:TCP:PORT_25665
"61900:TCP"= 61900:TCP:PORT_61900
"39500:TCP"= 39500:TCP:PORT_39500
"20341:TCP"= 20341:TCP:PORT_20341
"19297:TCP"= 19297:TCP:PORT_19297
"38391:TCP"= 38391:TCP:PORT_38391
"49316:TCP"= 49316:TCP:PORT_49316
"59874:TCP"= 59874:TCP:PORT_59874
"37001:TCP"= 37001:TCP:PORT_37001
"53583:TCP"= 53583:TCP:PORT_53583
"16237:TCP"= 16237:TCP:PORT_16237
"64731:TCP"= 64731:TCP:PORT_64731
"20478:TCP"= 20478:TCP:PORT_20478
"9205:TCP"= 9205:TCP:PORT_9205
"21048:TCP"= 21048:TCP:PORT_21048
"13985:TCP"= 13985:TCP:PORT_13985
"17569:TCP"= 17569:TCP:PORT_17569
"39416:TCP"= 39416:TCP:PORT_39416
"64321:TCP"= 64321:TCP:PORT_64321
"5541:TCP"= 5541:TCP:PORT_5541
"11962:TCP"= 11962:TCP:PORT_11962
"17814:TCP"= 17814:TCP:PORT_17814
"23703:TCP"= 23703:TCP:PORT_23703
"30958:TCP"= 30958:TCP:PORT_30958
"56113:TCP"= 56113:TCP:PORT_56113
"57434:TCP"= 57434:TCP:PORT_57434
"6168:TCP"= 6168:TCP:PORT_6168
"46504:TCP"= 46504:TCP:PORT_46504
"33384:TCP"= 33384:TCP:PORT_33384
"56375:TCP"= 56375:TCP:PORT_56375
"51170:TCP"= 51170:TCP:PORT_51170
"19586:TCP"= 19586:TCP:PORT_19586
"25575:TCP"= 25575:TCP:PORT_25575
"42489:TCP"= 42489:TCP:PORT_42489
"48396:TCP"= 48396:TCP:PORT_48396
"31465:TCP"= 31465:TCP:PORT_31465
"10617:TCP"= 10617:TCP:PORT_10617
"65508:TCP"= 65508:TCP:PORT_65508
"33536:TCP"= 33536:TCP:PORT_33536
"38457:TCP"= 38457:TCP:PORT_38457
"10028:TCP"= 10028:TCP:PORT_10028
"36496:TCP"= 36496:TCP:PORT_36496
"7458:TCP"= 7458:TCP:PORT_7458
"37384:TCP"= 37384:TCP:PORT_37384
"10590:TCP"= 10590:TCP:PORT_10590
"45703:TCP"= 45703:TCP:PORT_45703
"36131:TCP"= 36131:TCP:PORT_36131
"22055:TCP"= 22055:TCP:PORT_22055
"22102:TCP"= 22102:TCP:PORT_22102
"21263:TCP"= 21263:TCP:PORT_21263
"57395:TCP"= 57395:TCP:PORT_57395
"48141:TCP"= 48141:TCP:PORT_48141
"54043:TCP"= 54043:TCP:PORT_54043
"47551:TCP"= 47551:TCP:PORT_47551
"20518:TCP"= 20518:TCP:PORT_20518
"28583:TCP"= 28583:TCP:PORT_28583
"25268:TCP"= 25268:TCP:PORT_25268
"40777:TCP"= 40777:TCP:PORT_40777
"26878:TCP"= 26878:TCP:PORT_26878
"40930:TCP"= 40930:TCP:PORT_40930
"22729:TCP"= 22729:TCP:PORT_22729
"23165:TCP"= 23165:TCP:PORT_23165
"14616:TCP"= 14616:TCP:PORT_14616
"12196:TCP"= 12196:TCP:PORT_12196
"29415:TCP"= 29415:TCP:PORT_29415
"28376:TCP"= 28376:TCP:PORT_28376
"23958:TCP"= 23958:TCP:PORT_23958
"8479:TCP"= 8479:TCP:PORT_8479
"7010:TCP"= 7010:TCP:PORT_7010
"28177:TCP"= 28177:TCP:PORT_28177
"17291:TCP"= 17291:TCP:PORT_17291
"55072:TCP"= 55072:TCP:PORT_55072
"17438:TCP"= 17438:TCP:PORT_17438
"12604:TCP"= 12604:TCP:PORT_12604
"25643:TCP"= 25643:TCP:PORT_25643
"56825:TCP"= 56825:TCP:PORT_56825
"49451:TCP"= 49451:TCP:PORT_49451
"42493:TCP"= 42493:TCP:PORT_42493
"11581:TCP"= 11581:TCP:PORT_11581
"62951:TCP"= 62951:TCP:PORT_62951
"53295:TCP"= 53295:TCP:PORT_53295
"9788:TCP"= 9788:TCP:PORT_9788
"59565:TCP"= 59565:TCP:PORT_59565
"40583:TCP"= 40583:TCP:PORT_40583
"14298:TCP"= 14298:TCP:PORT_14298
"47022:TCP"= 47022:TCP:PORT_47022
"61853:TCP"= 61853:TCP:PORT_61853
"56114:TCP"= 56114:TCP:PORT_56114
R2 713xTVCard;SAA7133 TV Card;c:\windows\system32\DRIVERS\SAA713x.sys [2005-03-15 277504]
R3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-08 29744]
S1 MozyFilter;MozyFilter;c:\windows\system32\DRIVERS\mozy.sys [2008-10-06 53752]
S3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-26 12800]
S3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-26 10112]
S3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-26 44544]
S3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-26 201472]
S3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-26 9728]
S3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\DRIVERS\atinewp2.sys [2005-06-01 485760]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - abp480n5
*Deregistered* - adpu160m
*Deregistered* - AegisP
*Deregistered* - AFD
*Deregistered* - agp440
*Deregistered* - agpCPQ
*Deregistered* - Aha154x
*Deregistered* - aic78u2
*Deregistered* - aic78xx
*Deregistered* - AliIde
*Deregistered* - alim1541
*Deregistered* - amdagp
*Deregistered* - amsint
*Deregistered* - Arp1394
*Deregistered* - asc
*Deregistered* - asc3350p
*Deregistered* - asc3550
*Deregistered* - Ati HotKey Poller
*Deregistered* - ATI Smart
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - cbidf
*Deregistered* - cd20xrnt
*Deregistered* - Cdfs
*Deregistered* - CLTNetCnService
*Deregistered* - CmdIde
*Deregistered* - comHost
*Deregistered* - Cpqarray
*Deregistered* - dac2w2k
*Deregistered* - dac960nt
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dpti2o
*Deregistered* - eeCtrl
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - GTNDIS5
*Deregistered* - hpn
*Deregistered* - HTTP
*Deregistered* - i2omgmt
*Deregistered* - i2omp
*Deregistered* - ini910u
*Deregistered* - IntelIde
*Deregistered* - Ip6Fw
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - LiveUpdate Notice Ex
*Deregistered* - LiveUpdate Notice Service
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MozyBackup
*Deregistered* - MozyFilter
*Deregistered* - mraid35x
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NwlnkIpx
*Deregistered* - NwlnkNb
*Deregistered* - NwlnkSpx
*Deregistered* - PartMgr
*Deregistered* - perc2
*Deregistered* - perc2hib
*Deregistered* - PptpMiniport
*Deregistered* - PrismXL
*Deregistered* - PSched
*Deregistered* - ql1080
*Deregistered* - Ql10wnt
*Deregistered* - ql12160
*Deregistered* - ql1240
*Deregistered* - ql1280
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - sisagp
*Deregistered* - Sparrow
*Deregistered* - sr
*Deregistered* - SRTSP
*Deregistered* - SRTSPX
*Deregistered* - swenum
*Deregistered* - sym_hi
*Deregistered* - sym_u3
*Deregistered* - symc810
*Deregistered* - symc8xx
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMIDSCO
*Deregistered* - SYMNDIS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TosIde
*Deregistered* - tunmp
*Deregistered* - ultra
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - viaagp
*Deregistered* - ViaIde
*Deregistered* - VolSnap
*Deregistered* - Wanarp
*Deregistered* - WMP54Gv4SVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1661f93b-57a3-11da-9baa-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79be7b9c-0e07-11da-b64f-00038a000015}]
\Shell\AutoRun\command - K:\smartAP.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6572fdc-3fec-11da-94d4-806d6172696f}]
\Shell\AutoRun\command - E:\run.bat
.
Contents of the 'Scheduled Tasks' folder
2009-01-19 c:\windows\Tasks\Norton Security Online - Run Full System Scan - chullz.job
- c:\progra~1\Symantec\Norton AntiVirus\Navw32.exe [2007-01-14 03:09]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8B9F574C-32E6-4004-AF4D-6993481C790F} - (no file)
SSODL-EPItZZQy-{2CEC6C2A-8646-C680-0D65-0E74600C38E7} - c:\windows\system32\vokz.dll
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} - hxxp://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} - hxxp://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 22:08:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,26,b8,5e,26,00,
e0,e8,d1,e2,63,26,f1,3f,c8,ff,68,90,3b,26,5c,ae,6e,84,c4,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,03,46,b9,b8,
a6,76,67,6a,9c,d6,61,af,45,84,18,94,5f,6f,37,d7,a1,a9,29,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,3d,3c,71,b7,9f,
dc,e9,1b,ff,7c,85,e0,43,d4,0e,fe,b5,a7,b9,1d,20,35,11,86,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,12,07,dd,0d,7f,
21,d3,4c,86,8c,21,01,be,91,eb,e7,e9,5f,c9,fe,bc,ad,42,2a,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,01,ad,dc,b1,
bd,5b,fd,f5,1d,4d,73,a8,13,5c,05,81,15,3b,6a,17,dc,fe,4e,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,0e,22,6d,67,b6,
56,19,8a,df,20,58,62,78,6b,cf,c8,fd,57,42,60,5d,81,ab,f8,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,71,e6,3b,c1,c4,
3e,24,3e,fb,a7,78,e6,12,2f,9a,ea,a3,8d,75,0a,b5,04,8f,49,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,fb,ef,0e,e5,32,
23,0d,a5,01,3a,48,fc,e8,04,4a,f1,90,cd,67,e4,36,b1,32,7a,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c3,e7,d0,db,cc,
15,36,e5,f6,0f,4e,58,98,5b,89,c9,8b,cd,ea,1c,db,2c,57,9e,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,f7,7c,3e,f9,01,
9a,61,88,3d,ce,ea,26,2d,45,aa,78,db,8a,97,10,b0,21,48,0e,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,98,19,c0,41,43,
f4,2b,a7,2a,b7,cc,b5,b9,7f,41,e7,2c,b4,f2,d2,fd,82,d7,82,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,fe,e6,69,6f,c3,
9c,ba,71,6c,43,2d,1e,aa,22,2f,9c,08,f7,13,a7,0a,48,8d,4d,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-01-30 22:11:49
ComboFix-quarantined-files.txt 2009-01-31 04:11:39
Pre-Run: 140,171,087,872 bytes free
Post-Run: 150,529,556,480 bytes free
632 --- E O F --- 2009-01-14 09:04:25
There looks to be a lot of problems on that machine, services not running and a lot of ports open to the internet ?
The quickest option would be to use System Restore to get to a point before Coupon Printer was installed.
If the machine functions properly when that is done, then you should update to SP3.
Please post a fresh Combofix log when you have done the above.
It will not let me run system restore. It keeps saying restart and try again. I tried to do this with a normal restart and also with a restart to safe mode. Neither one would work.
Hmmm....
Delete the copy of Combofix that you have, and download a fresh copy from HERE (http://www.techsupportforum.com/sectools/sUBs/ComboFix)
Run it as you did last time.
ComboFix 09-01-21.04 - chullz 2009-01-31 10:35:31.2 - NTFSx86
Running from: K:\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((( Files Created from 2008-12-28 to 2009-01-31 )))))))))))))))))))))))))))))))
.
2009-01-24 10:55 . 2009-01-24 10:55 <DIR> d-------- c:\documents and settings\chullz\Application Data\Sammsoft
2009-01-24 10:54 . 2009-01-24 10:54 <DIR> d-------- c:\program files\Advanced Registry Optimizer
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a--c--- c:\windows\system32\dllcache\explorer.exe
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a------ c:\windows\explorer.exe
2009-01-21 17:46 . 2009-01-24 08:22 <DIR> d-------- c:\program files\Coupons
2009-01-14 03:04 . 2008-08-28 04:04 333,056 --a------ c:\windows\system32\drivers\srv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-22 20:39 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-22 00:07 --------- d-----w c:\program files\Google
2009-01-07 22:21 --------- d--h--w c:\documents and settings\chullz\Application Data\Move Networks
2009-01-06 00:49 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-06 00:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-06 00:49 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-06 00:49 --------- d-----w c:\program files\Symantec
2007-11-24 19:56 58,232 ----a-w c:\documents and settings\chullz\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
2005-03-02 12:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 09:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\$NtUninstallKB925902$\user32.dll
2008-04-13 18:12 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\dllcache\user32.dll
2008-04-13 18:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ws2_32.dll
2004-08-10 13:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll
2004-09-29 12:27 656896 2c07195588d69a067c2afdaa31759295 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll
2005-01-27 11:08 657920 a8eac5330876548e9966a7d13025d196 c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
2005-03-10 01:43 657920 c8663b488996e89a84c3d17c1d12b79e c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
2007-03-07 11:40 823296 b8f4db39ca7353752f245379d285c80e c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll
2007-04-25 03:08 823808 431defbb4a3d7b0dc062c1b064623a2f c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll
2007-06-27 08:40 824320 d6ed5e042c5207553e7f5e842918137f c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
2007-08-20 04:02 825344 357d54bf94fe9d6d8505a96b5c2a3bca c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
2007-10-10 17:47 825344 0e5d918f87efa7d2424d66b499c7eb04 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-06 20:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 07:03 827392 6316c2f0c61271c8abdff7429174879e c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-22 21:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 10:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2008-08-26 03:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
2008-10-16 14:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
2006-05-09 23:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB916281$\wininet.dll
2005-03-10 02:02 656896 6f018d6319be4f96426ea829b79e05d5 c:\windows\$NtUninstallKB916281_0$\wininet.dll
2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$NtUninstallKB918899$\wininet.dll
2006-06-23 05:25 664576 64ce26db72810b30f7855ea51e1df836 c:\windows\$NtUninstallKB922760$\wininet.dll
2006-09-14 02:31 664576 d207370287cf769aebebf03837784963 c:\windows\ie7\wininet.dll
2006-11-07 21:03 818688 92995334f993e6e49c25c6d02ec04401 c:\windows\ie7updates\KB928090-IE7\wininet.dll
2007-01-12 09:27 822784 be43d00d802c92f01c8cc952c6f483f8 c:\windows\ie7updates\KB931768-IE7\wininet.dll
2007-03-07 11:45 822784 5b35dae6e4886f64d1da58c4e3e01eb9 c:\windows\ie7updates\KB933566-IE7\wininet.dll
2007-04-25 02:41 822784 0586a7f0b2fdb94d624f399d4728e7c8 c:\windows\ie7updates\KB937143-IE7\wininet.dll
2007-06-27 08:34 823808 8068cbb58fe60cc95aeb2cff70178208 c:\windows\ie7updates\KB939653-IE7\wininet.dll
2007-08-20 04:04 824832 774435e499d8e9643ec961a6103c361f c:\windows\ie7updates\KB942615-IE7\wininet.dll
2007-10-10 17:56 824832 30c1e0f34ad2972c72a01db5c74ab065 c:\windows\ie7updates\KB944533-IE7\wininet.dll
2007-12-06 20:21 824832 806d274c9a6c3aaea5eae8e4af841e04 c:\windows\ie7updates\KB947864-IE7\wininet.dll
2008-03-01 07:06 826368 ad21461aef8244edec2ef18e55e1dcf3 c:\windows\ie7updates\KB950759-IE7\wininet.dll
2008-04-22 22:16 826368 f6589be784647cfdbc22ea51ccb1a57a c:\windows\ie7updates\KB953838-IE7\wininet.dll
2008-06-23 10:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll
2008-08-26 01:24 826368 ef8eba98145bfa44e80d17a3b3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll
2008-04-13 18:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wininet.dll
2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\wininet.dll
2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\dllcache\wininet.dll
2005-03-13 19:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-04-20 06:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 10:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 04:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 05:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 05:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2005-03-13 18:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 c:\windows\$NtUninstallKB917953$\tcpip.sys
2006-04-20 05:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
2007-10-30 11:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-13 13:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\tcpip.sys
2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\drivers\tcpip.sys
2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2009-01-22 20:37 505856 e853481fef64a5be3fc3732d9d3d926a c:\windows\system32\winlogon.exe
2008-04-13 13:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ndis.sys
2004-08-10 13:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2008-04-13 12:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys
2004-08-10 13:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 10:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 03:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
2008-08-14 14:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2005-03-01 18:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 06:55 2057600 1d659bfb788ed2ba45075624b748d249 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 02:38 2057600 515d30e2c90a3665a2739309334c9283 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 12:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\dllcache\ntkrnlpa.exe
2004-08-10 13:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 19:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 10:51 2182016 cef243f6defd20be4adde26c7ecacb54 c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 03:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
2008-08-14 15:11 2189184 31914172342bff330063f343ac6958fe c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2005-03-01 18:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 08:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 03:10 2180352 582a8dbaa58c3b1f176eb2817daee77c c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\Driver Cache\i386\ntoskrnl.exe
2008-04-13 13:27 2188928 0c89243c7c3ee199b96fcc16990e0679 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\dllcache\ntoskrnl.exe
2004-08-10 13:00 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntoskrnl.exe
2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
2007-06-13 05:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 13:00 1032192 a0732187050030ae399b241436565e64 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-13 18:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\system32\dllcache\explorer.exe
2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
2009-01-22 20:37 110080 5812a3513734517f8c2c5eab6b269864 c:\windows\system32\services.exe
2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
2009-01-22 20:37 14336 c3e6b717e7b284e1fa89ba9f7a1be1ed c:\windows\system32\lsass.exe
2008-04-13 18:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
2004-08-10 13:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe
2008-04-13 18:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
2004-08-10 13:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe
2004-08-10 13:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll
2008-04-13 18:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\termsrv.dll
2005-03-10 01:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll
2006-07-05 04:57 985088 0fdd84928a5dde2510761b7ec76ccec9 c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
2007-04-16 10:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
2004-08-10 13:00 983552 888190e31455fad793312f8d087146eb c:\windows\$NtUninstallKB917422$\kernel32.dll
2006-07-05 04:55 984064 d8db5397de07577c1cb50ba6d23b3ad4 c:\windows\$NtUninstallKB935839$\kernel32.dll
2008-04-13 18:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\kernel32.dll
2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\kernel32.dll
2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\dllcache\kernel32.dll
2008-04-13 18:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\powrprof.dll
2004-08-10 13:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
"AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"AMUST 1-Login AutoUpdate"="c:\program files\Common Files\AMUST\Updater\amupdater.dll" [2006-04-11 470328]
"YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2007-10-26 509224]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-05 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-22 180269]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-08 29744]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="c:\progra~1\Symantec\osCheck.exe" [2007-01-14 771704]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"CHotkey"="zHotkey.exe" [2005-05-03 c:\windows\zHotkey.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 c:\windows\system32\bthprops.cpl]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=G
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8891:TCP"= 8891:TCP:Pitbull
"50706:TCP"= 50706:TCP:PORT_50706
"41136:TCP"= 41136:TCP:PORT_41136
"58843:TCP"= 58843:TCP:PORT_58843
"45453:TCP"= 45453:TCP:PORT_45453
"46608:TCP"= 46608:TCP:PORT_46608
"24395:TCP"= 24395:TCP:PORT_24395
"58380:TCP"= 58380:TCP:PORT_58380
"12476:TCP"= 12476:TCP:PORT_12476
"44022:TCP"= 44022:TCP:PORT_44022
"23014:TCP"= 23014:TCP:PORT_23014
"61930:TCP"= 61930:TCP:PORT_61930
"46327:TCP"= 46327:TCP:PORT_46327
"34724:TCP"= 34724:TCP:PORT_34724
"19950:TCP"= 19950:TCP:PORT_19950
"49203:TCP"= 49203:TCP:PORT_49203
"23848:TCP"= 23848:TCP:PORT_23848
"48998:TCP"= 48998:TCP:PORT_48998
"53375:TCP"= 53375:TCP:PORT_53375
"40458:TCP"= 40458:TCP:PORT_40458
"6428:TCP"= 6428:TCP:PORT_6428
"37706:TCP"= 37706:TCP:PORT_37706
"47531:TCP"= 47531:TCP:PORT_47531
"46532:TCP"= 46532:TCP:PORT_46532
"32902:TCP"= 32902:TCP:PORT_32902
"17347:TCP"= 17347:TCP:PORT_17347
"17586:TCP"= 17586:TCP:PORT_17586
"26291:TCP"= 26291:TCP:PORT_26291
"55534:TCP"= 55534:TCP:PORT_55534
"41891:TCP"= 41891:TCP:PORT_41891
"48462:TCP"= 48462:TCP:PORT_48462
"18050:TCP"= 18050:TCP:PORT_18050
"31483:TCP"= 31483:TCP:PORT_31483
"33700:TCP"= 33700:TCP:PORT_33700
"31203:TCP"= 31203:TCP:PORT_31203
"43418:TCP"= 43418:TCP:PORT_43418
"24985:TCP"= 24985:TCP:PORT_24985
"19001:TCP"= 19001:TCP:PORT_19001
"42324:TCP"= 42324:TCP:PORT_42324
"10141:TCP"= 10141:TCP:PORT_10141
"15865:TCP"= 15865:TCP:PORT_15865
"36942:TCP"= 36942:TCP:PORT_36942
"30525:TCP"= 30525:TCP:PORT_30525
"41668:TCP"= 41668:TCP:PORT_41668
"46918:TCP"= 46918:TCP:PORT_46918
"34969:TCP"= 34969:TCP:PORT_34969
"31365:TCP"= 31365:TCP:PORT_31365
"46969:TCP"= 46969:TCP:PORT_46969
"24597:TCP"= 24597:TCP:PORT_24597
"20994:TCP"= 20994:TCP:PORT_20994
"41178:TCP"= 41178:TCP:PORT_41178
"28301:TCP"= 28301:TCP:PORT_28301
"59290:TCP"= 59290:TCP:PORT_59290
"24121:TCP"= 24121:TCP:PORT_24121
"57424:TCP"= 57424:TCP:PORT_57424
"44981:TCP"= 44981:TCP:PORT_44981
"58917:TCP"= 58917:TCP:PORT_58917
"19762:TCP"= 19762:TCP:PORT_19762
"13600:TCP"= 13600:TCP:PORT_13600
"50879:TCP"= 50879:TCP:PORT_50879
"25703:TCP"= 25703:TCP:PORT_25703
"25665:TCP"= 25665:TCP:PORT_25665
"61900:TCP"= 61900:TCP:PORT_61900
"39500:TCP"= 39500:TCP:PORT_39500
"20341:TCP"= 20341:TCP:PORT_20341
"19297:TCP"= 19297:TCP:PORT_19297
"38391:TCP"= 38391:TCP:PORT_38391
"49316:TCP"= 49316:TCP:PORT_49316
"59874:TCP"= 59874:TCP:PORT_59874
"37001:TCP"= 37001:TCP:PORT_37001
"53583:TCP"= 53583:TCP:PORT_53583
"16237:TCP"= 16237:TCP:PORT_16237
"64731:TCP"= 64731:TCP:PORT_64731
"20478:TCP"= 20478:TCP:PORT_20478
"9205:TCP"= 9205:TCP:PORT_9205
"21048:TCP"= 21048:TCP:PORT_21048
"13985:TCP"= 13985:TCP:PORT_13985
"17569:TCP"= 17569:TCP:PORT_17569
"39416:TCP"= 39416:TCP:PORT_39416
"64321:TCP"= 64321:TCP:PORT_64321
"5541:TCP"= 5541:TCP:PORT_5541
"11962:TCP"= 11962:TCP:PORT_11962
"17814:TCP"= 17814:TCP:PORT_17814
"23703:TCP"= 23703:TCP:PORT_23703
"30958:TCP"= 30958:TCP:PORT_30958
"56113:TCP"= 56113:TCP:PORT_56113
"57434:TCP"= 57434:TCP:PORT_57434
"6168:TCP"= 6168:TCP:PORT_6168
"46504:TCP"= 46504:TCP:PORT_46504
"33384:TCP"= 33384:TCP:PORT_33384
"56375:TCP"= 56375:TCP:PORT_56375
"51170:TCP"= 51170:TCP:PORT_51170
"19586:TCP"= 19586:TCP:PORT_19586
"25575:TCP"= 25575:TCP:PORT_25575
"42489:TCP"= 42489:TCP:PORT_42489
"48396:TCP"= 48396:TCP:PORT_48396
"31465:TCP"= 31465:TCP:PORT_31465
"10617:TCP"= 10617:TCP:PORT_10617
"65508:TCP"= 65508:TCP:PORT_65508
"33536:TCP"= 33536:TCP:PORT_33536
"38457:TCP"= 38457:TCP:PORT_38457
"10028:TCP"= 10028:TCP:PORT_10028
"36496:TCP"= 36496:TCP:PORT_36496
"7458:TCP"= 7458:TCP:PORT_7458
"37384:TCP"= 37384:TCP:PORT_37384
"10590:TCP"= 10590:TCP:PORT_10590
"45703:TCP"= 45703:TCP:PORT_45703
"36131:TCP"= 36131:TCP:PORT_36131
"22055:TCP"= 22055:TCP:PORT_22055
"22102:TCP"= 22102:TCP:PORT_22102
"21263:TCP"= 21263:TCP:PORT_21263
"57395:TCP"= 57395:TCP:PORT_57395
"48141:TCP"= 48141:TCP:PORT_48141
"54043:TCP"= 54043:TCP:PORT_54043
"47551:TCP"= 47551:TCP:PORT_47551
"20518:TCP"= 20518:TCP:PORT_20518
"28583:TCP"= 28583:TCP:PORT_28583
"25268:TCP"= 25268:TCP:PORT_25268
"40777:TCP"= 40777:TCP:PORT_40777
"26878:TCP"= 26878:TCP:PORT_26878
"40930:TCP"= 40930:TCP:PORT_40930
"22729:TCP"= 22729:TCP:PORT_22729
"23165:TCP"= 23165:TCP:PORT_23165
"14616:TCP"= 14616:TCP:PORT_14616
"12196:TCP"= 12196:TCP:PORT_12196
"29415:TCP"= 29415:TCP:PORT_29415
"28376:TCP"= 28376:TCP:PORT_28376
"23958:TCP"= 23958:TCP:PORT_23958
"8479:TCP"= 8479:TCP:PORT_8479
"7010:TCP"= 7010:TCP:PORT_7010
"28177:TCP"= 28177:TCP:PORT_28177
"17291:TCP"= 17291:TCP:PORT_17291
"55072:TCP"= 55072:TCP:PORT_55072
"17438:TCP"= 17438:TCP:PORT_17438
"12604:TCP"= 12604:TCP:PORT_12604
"25643:TCP"= 25643:TCP:PORT_25643
"56825:TCP"= 56825:TCP:PORT_56825
"49451:TCP"= 49451:TCP:PORT_49451
"42493:TCP"= 42493:TCP:PORT_42493
"11581:TCP"= 11581:TCP:PORT_11581
"62951:TCP"= 62951:TCP:PORT_62951
"53295:TCP"= 53295:TCP:PORT_53295
"9788:TCP"= 9788:TCP:PORT_9788
"59565:TCP"= 59565:TCP:PORT_59565
"40583:TCP"= 40583:TCP:PORT_40583
"14298:TCP"= 14298:TCP:PORT_14298
"47022:TCP"= 47022:TCP:PORT_47022
"61853:TCP"= 61853:TCP:PORT_61853
"56114:TCP"= 56114:TCP:PORT_56114
R2 713xTVCard;SAA7133 TV Card;c:\windows\system32\DRIVERS\SAA713x.sys [2005-03-15 277504]
R3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-08 29744]
S1 MozyFilter;MozyFilter;c:\windows\system32\DRIVERS\mozy.sys [2008-10-06 53752]
S3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-26 12800]
S3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-26 10112]
S3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-26 44544]
S3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-26 201472]
S3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-26 9728]
S3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\DRIVERS\atinewp2.sys [2005-06-01 485760]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - abp480n5
*Deregistered* - adpu160m
*Deregistered* - AegisP
*Deregistered* - AFD
*Deregistered* - agp440
*Deregistered* - agpCPQ
*Deregistered* - Aha154x
*Deregistered* - aic78u2
*Deregistered* - aic78xx
*Deregistered* - AliIde
*Deregistered* - alim1541
*Deregistered* - amdagp
*Deregistered* - amsint
*Deregistered* - Arp1394
*Deregistered* - asc
*Deregistered* - asc3350p
*Deregistered* - asc3550
*Deregistered* - Ati HotKey Poller
*Deregistered* - ATI Smart
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - cbidf
*Deregistered* - cd20xrnt
*Deregistered* - Cdfs
*Deregistered* - CLTNetCnService
*Deregistered* - CmdIde
*Deregistered* - comHost
*Deregistered* - Cpqarray
*Deregistered* - dac2w2k
*Deregistered* - dac960nt
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dpti2o
*Deregistered* - eeCtrl
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - GTNDIS5
*Deregistered* - hpn
*Deregistered* - HTTP
*Deregistered* - i2omgmt
*Deregistered* - i2omp
*Deregistered* - ini910u
*Deregistered* - IntelIde
*Deregistered* - Ip6Fw
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - LiveUpdate Notice Ex
*Deregistered* - LiveUpdate Notice Service
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MozyBackup
*Deregistered* - MozyFilter
*Deregistered* - mraid35x
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NwlnkIpx
*Deregistered* - NwlnkNb
*Deregistered* - NwlnkSpx
*Deregistered* - PartMgr
*Deregistered* - perc2
*Deregistered* - perc2hib
*Deregistered* - PptpMiniport
*Deregistered* - PrismXL
*Deregistered* - PSched
*Deregistered* - ql1080
*Deregistered* - Ql10wnt
*Deregistered* - ql12160
*Deregistered* - ql1240
*Deregistered* - ql1280
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - sisagp
*Deregistered* - Sparrow
*Deregistered* - sr
*Deregistered* - SRTSP
*Deregistered* - SRTSPX
*Deregistered* - swenum
*Deregistered* - sym_hi
*Deregistered* - sym_u3
*Deregistered* - symc810
*Deregistered* - symc8xx
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMIDSCO
*Deregistered* - SYMNDIS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TosIde
*Deregistered* - tunmp
*Deregistered* - ultra
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - viaagp
*Deregistered* - ViaIde
*Deregistered* - VolSnap
*Deregistered* - Wanarp
*Deregistered* - WMP54Gv4SVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1661f93b-57a3-11da-9baa-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79be7b9c-0e07-11da-b64f-00038a000015}]
\Shell\AutoRun\command - K:\smartAP.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6572fdc-3fec-11da-94d4-806d6172696f}]
\Shell\AutoRun\command - E:\run.bat
.
Contents of the 'Scheduled Tasks' folder
2009-01-19 c:\windows\Tasks\Norton Security Online - Run Full System Scan - chullz.job
- c:\progra~1\Symantec\Norton AntiVirus\Navw32.exe [2007-01-14 03:09]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} - hxxp://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} - hxxp://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-31 10:37:43
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,26,b8,5e,26,00,
e0,e8,d1,e2,63,26,f1,3f,c8,ff,68,90,3b,26,5c,ae,6e,84,c4,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,03,46,b9,b8,
a6,76,67,6a,9c,d6,61,af,45,84,18,94,5f,6f,37,d7,a1,a9,29,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,3d,3c,71,b7,9f,
dc,e9,1b,ff,7c,85,e0,43,d4,0e,fe,b5,a7,b9,1d,20,35,11,86,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,12,07,dd,0d,7f,
21,d3,4c,86,8c,21,01,be,91,eb,e7,e9,5f,c9,fe,bc,ad,42,2a,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,01,ad,dc,b1,
bd,5b,fd,f5,1d,4d,73,a8,13,5c,05,81,15,3b,6a,17,dc,fe,4e,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,0e,22,6d,67,b6,
56,19,8a,df,20,58,62,78,6b,cf,c8,fd,57,42,60,5d,81,ab,f8,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,71,e6,3b,c1,c4,
3e,24,3e,fb,a7,78,e6,12,2f,9a,ea,a3,8d,75,0a,b5,04,8f,49,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,fb,ef,0e,e5,32,
23,0d,a5,01,3a,48,fc,e8,04,4a,f1,90,cd,67,e4,36,b1,32,7a,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c3,e7,d0,db,cc,
15,36,e5,f6,0f,4e,58,98,5b,89,c9,8b,cd,ea,1c,db,2c,57,9e,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,f7,7c,3e,f9,01,
9a,61,88,3d,ce,ea,26,2d,45,aa,78,db,8a,97,10,b0,21,48,0e,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,98,19,c0,41,43,
f4,2b,a7,2a,b7,cc,b5,b9,7f,41,e7,2c,b4,f2,d2,fd,82,d7,82,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,fe,e6,69,6f,c3,
9c,ba,71,6c,43,2d,1e,aa,22,2f,9c,08,f7,13,a7,0a,48,8d,4d,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(648)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-01-31 10:41:11
ComboFix-quarantined-files.txt 2009-01-31 16:41:02
ComboFix2.txt 2009-01-31 04:11:51
Pre-Run: 150,614,978,560 bytes free
Post-Run: 150,597,599,232 bytes free
605 --- E O F --- 2009-01-14 09:04:25
Something went wrong there, please do the following
Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the /U, it needs to be there.
http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png
Download and Run ComboFix
ComboFix.exe 1 (http://subs.geekstogo.com/ComboFix.exe)
ComboFix.exe 2 (http://www.forospyware.com/sUBs/ComboFix.exe)
ComboFix.exe 3 (http://download.bleepingcomputer.com/sUBs/ComboFix.exe)
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix SHOULD NOT be used unless requested by a forum helper
Ok. I was having a challenge getting cf to the desktop, but I finally was successful. Here are the results. (Thanks for your patience.)
ComboFix 09-02-01.01 - chullz 2009-02-01 14:56:32.3 - NTFSx86
Running from: c:\documents and settings\chullz\Desktop\ComboFix.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-01-01 to 2009-02-01 )))))))))))))))))))))))))))))))
.
2009-02-01 14:46 . 2009-02-01 13:43 3,307,596 --a------ C:\ComboFix.exe
2009-01-24 10:55 . 2009-01-24 10:55 <DIR> d-------- c:\documents and settings\chullz\Application Data\Sammsoft
2009-01-24 10:54 . 2009-01-24 10:54 <DIR> d-------- c:\program files\Advanced Registry Optimizer
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a--c--- c:\windows\system32\dllcache\explorer.exe
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a------ c:\windows\explorer.exe
2009-01-21 17:46 . 2009-01-24 08:22 <DIR> d-------- c:\program files\Coupons
2009-01-14 03:04 . 2008-08-28 04:04 333,056 --a------ c:\windows\system32\drivers\srv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-22 20:39 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-22 00:07 --------- d-----w c:\program files\Google
2009-01-07 22:21 --------- d--h--w c:\documents and settings\chullz\Application Data\Move Networks
2009-01-06 00:49 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-06 00:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-06 00:49 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-06 00:49 --------- d-----w c:\program files\Symantec
2007-11-24 19:56 58,232 ----a-w c:\documents and settings\chullz\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
2005-03-02 12:19 577024 1800f293bccc8ede8a70e12b88d80036 c:\windows\$hf_mig$\KB890859\SP2QFE\user32.dll
2007-03-08 09:48 578048 7aa4f6c00405dfc4b70ed4214e7d687b c:\windows\$hf_mig$\KB925902\SP2QFE\user32.dll
2005-03-02 12:09 577024 de2db164bbb35db061af0997e4499054 c:\windows\$NtUninstallKB925902$\user32.dll
2008-04-13 18:12 578560 b26b135ff1b9f60c9388b4a7d16f600b c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\user32.dll
2007-03-08 09:36 577536 b409909f6e2e8a7067076ed748abf1e7 c:\windows\system32\dllcache\user32.dll
2008-04-13 18:12 82432 2ccc474eb85ceaa3e1fa1726580a3e5a c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ws2_32.dll
2004-08-10 13:00 82944 2ed0b7f12a60f90092081c50fa0ec2b2 c:\windows\system32\ws2_32.dll
2004-09-29 12:27 656896 2c07195588d69a067c2afdaa31759295 c:\windows\$hf_mig$\KB834707\SP2QFE\wininet.dll
2005-01-27 11:08 657920 a8eac5330876548e9966a7d13025d196 c:\windows\$hf_mig$\KB867282\SP2QFE\wininet.dll
2005-03-10 01:43 657920 c8663b488996e89a84c3d17c1d12b79e c:\windows\$hf_mig$\KB890923\SP2QFE\wininet.dll
2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$hf_mig$\KB916281\SP2QFE\wininet.dll
2007-03-07 11:40 823296 b8f4db39ca7353752f245379d285c80e c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll
2007-04-25 03:08 823808 431defbb4a3d7b0dc062c1b064623a2f c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll
2007-06-27 08:40 824320 d6ed5e042c5207553e7f5e842918137f c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll
2007-08-20 04:02 825344 357d54bf94fe9d6d8505a96b5c2a3bca c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll
2007-10-10 17:47 825344 0e5d918f87efa7d2424d66b499c7eb04 c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-06 20:01 825344 b5b411bb229ae6ead7652a32ed47bfb9 c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 07:03 827392 6316c2f0c61271c8abdff7429174879e c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-22 21:35 827392 41546b396a526918da7995a02ea04e51 c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2008-06-23 10:01 827904 c66402a06b83b036c195242c0c8cf83c c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll
2008-08-26 03:08 827904 77c192fe56a70d7fa0247ba0a6201c32 c:\windows\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
2008-10-16 14:24 827904 0d5b75171ff51775b630a431b6c667e8 c:\windows\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
2006-05-09 23:23 658432 38ab7a56f566d9aaad31812494944824 c:\windows\$NtUninstallKB916281$\wininet.dll
2005-03-10 02:02 656896 6f018d6319be4f96426ea829b79e05d5 c:\windows\$NtUninstallKB916281_0$\wininet.dll
2006-05-09 23:25 663552 d94cffdb53e7ac867438e2dfd50e7cbc c:\windows\$NtUninstallKB918899$\wininet.dll
2006-06-23 05:25 664576 64ce26db72810b30f7855ea51e1df836 c:\windows\$NtUninstallKB922760$\wininet.dll
2006-09-14 02:31 664576 d207370287cf769aebebf03837784963 c:\windows\ie7\wininet.dll
2006-11-07 21:03 818688 92995334f993e6e49c25c6d02ec04401 c:\windows\ie7updates\KB928090-IE7\wininet.dll
2007-01-12 09:27 822784 be43d00d802c92f01c8cc952c6f483f8 c:\windows\ie7updates\KB931768-IE7\wininet.dll
2007-03-07 11:45 822784 5b35dae6e4886f64d1da58c4e3e01eb9 c:\windows\ie7updates\KB933566-IE7\wininet.dll
2007-04-25 02:41 822784 0586a7f0b2fdb94d624f399d4728e7c8 c:\windows\ie7updates\KB937143-IE7\wininet.dll
2007-06-27 08:34 823808 8068cbb58fe60cc95aeb2cff70178208 c:\windows\ie7updates\KB939653-IE7\wininet.dll
2007-08-20 04:04 824832 774435e499d8e9643ec961a6103c361f c:\windows\ie7updates\KB942615-IE7\wininet.dll
2007-10-10 17:56 824832 30c1e0f34ad2972c72a01db5c74ab065 c:\windows\ie7updates\KB944533-IE7\wininet.dll
2007-12-06 20:21 824832 806d274c9a6c3aaea5eae8e4af841e04 c:\windows\ie7updates\KB947864-IE7\wininet.dll
2008-03-01 07:06 826368 ad21461aef8244edec2ef18e55e1dcf3 c:\windows\ie7updates\KB950759-IE7\wininet.dll
2008-04-22 22:16 826368 f6589be784647cfdbc22ea51ccb1a57a c:\windows\ie7updates\KB953838-IE7\wininet.dll
2008-06-23 10:57 826368 8c13d4a7479fa0a026eda8abce82c0ed c:\windows\ie7updates\KB956390-IE7\wininet.dll
2008-08-26 01:24 826368 ef8eba98145bfa44e80d17a3b3453300 c:\windows\ie7updates\KB958215-IE7\wininet.dll
2008-04-13 18:12 666112 7a4f775abb2f1c97def3e73afa2faedd c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\wininet.dll
2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\wininet.dll
2008-10-16 14:38 826368 6741eaf7b7f110e803a6e38f6e5fa6b0 c:\windows\system32\dllcache\wininet.dll
2005-03-13 19:17 359936 6129e70f3d2f1e60860c930ebeaf92c2 c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2006-04-20 06:18 360576 b2220c618b42a2212a59d91ebd6fc4b4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
2007-10-30 10:53 360832 64798ecfa43d78c7178375fcdd16d8c8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2008-06-20 04:44 360960 744e57c99232201ae98c49168b918f48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
2008-06-20 05:51 361600 9aefa14bd6b182d61e3119fa5f436d3d c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
2008-06-20 05:59 361600 ad978a1b783b5719720cff204b666c8e c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
2005-03-13 18:55 359808 0e66b538096a6529d1ac66e78eb0d5c8 c:\windows\$NtUninstallKB917953$\tcpip.sys
2006-04-20 05:51 359808 1dbf125862891817f374f407626967f4 c:\windows\$NtUninstallKB941644$\tcpip.sys
2007-10-30 11:20 360064 90caff4b094573449a0872a0f919b178 c:\windows\$NtUninstallKB951748$\tcpip.sys
2008-04-13 13:20 361344 93ea8d04ec73a85db02eb8805988f733 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\tcpip.sys
2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\dllcache\tcpip.sys
2008-06-20 04:45 360320 2a5554fc5b1e04e131230e3ce035c3f9 c:\windows\system32\drivers\tcpip.sys
2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2009-01-22 20:37 505856 e853481fef64a5be3fc3732d9d3d926a c:\windows\system32\winlogon.exe
2008-04-13 13:20 182656 1df7f42665c94b825322fae71721130d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ndis.sys
2004-08-10 13:00 182912 558635d3af1c7546d26067d5d9b6959e c:\windows\system32\drivers\ndis.sys
2008-04-13 12:53 36608 3bb22519a194418d5fec05d800a19ad0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys
2004-08-10 13:00 29056 4448006b6bc60e6c027932cfc38d6855 c:\windows\system32\drivers\ip6fw.sys
2005-03-01 17:36 2056832 d8aba3eab509627e707a3b14f00fbb6b c:\windows\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe
2006-12-19 10:12 2059392 ba4b97c00a437c1cc3da365d93ee1e9d c:\windows\$hf_mig$\KB929338\SP2QFE\ntkrnlpa.exe
2007-02-28 03:15 2059392 4d3dbdccbf97f5ba1e74f322b155c3ba c:\windows\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe
2008-08-14 03:18 2062976 63ec865dff6ccfc7bef94b5c50297cad c:\windows\$hf_mig$\KB956841\SP2QFE\ntkrnlpa.exe
2008-08-14 03:33 2066048 4ac58f03eb94a72809949d757fc39d80 c:\windows\$hf_mig$\KB956841\SP3GDR\ntkrnlpa.exe
2008-08-14 14:39 2066048 a25e9b86effb2af33bf51e676b68bfb0 c:\windows\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe
2005-03-01 18:34 2056832 81013f36b21c7f72cf784cc6731e0002 c:\windows\$NtUninstallKB929338$\ntkrnlpa.exe
2006-12-19 06:55 2057600 1d659bfb788ed2ba45075624b748d249 c:\windows\$NtUninstallKB931784$\ntkrnlpa.exe
2007-02-28 02:38 2057600 515d30e2c90a3665a2739309334c9283 c:\windows\$NtUninstallKB956841$\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\Driver Cache\i386\ntkrnlpa.exe
2008-04-13 12:31 2065792 109f8e3e3c82e337bb71b6bc9b895d61 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\ntkrnlpa.exe
2008-08-14 03:22 2057728 ba002228743b6824d87f0551dbc86d45 c:\windows\system32\dllcache\ntkrnlpa.exe
2004-08-10 13:00 2056832 947fb1d86d14afcffdb54bf837ec25d0 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntkrnlpa.exe
2005-03-01 19:04 2179456 28187802b7c368c0d3aef7d4c382aabb c:\windows\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe
2006-12-19 10:51 2182016 cef243f6defd20be4adde26c7ecacb54 c:\windows\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe
2007-02-28 03:55 2182144 5a5c8db4aa962c714c8371fbdf189fc9 c:\windows\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe
2008-08-14 03:57 2185984 ce69dbd54221f2d40e49ff6db77c6507 c:\windows\$hf_mig$\KB956841\SP2QFE\ntoskrnl.exe
2008-08-14 04:11 2189184 eeaf32f8e15a24f62becb1bd403bb5c5 c:\windows\$hf_mig$\KB956841\SP3GDR\ntoskrnl.exe
2008-08-14 15:11 2189184 31914172342bff330063f343ac6958fe c:\windows\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe
2005-03-01 18:59 2179328 4d4cf2c14550a4b7718e94a6e581856e c:\windows\$NtUninstallKB929338$\ntoskrnl.exe
2006-12-19 08:17 2180352 8f0deab1f81fb83f9c5995853ce48b9f c:\windows\$NtUninstallKB931784$\ntoskrnl.exe
2007-02-28 03:10 2180352 582a8dbaa58c3b1f176eb2817daee77c c:\windows\$NtUninstallKB956841$\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\Driver Cache\i386\ntoskrnl.exe
2008-04-13 13:27 2188928 0c89243c7c3ee199b96fcc16990e0679 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\ntoskrnl.exe
2008-08-14 04:00 2180352 21c91da9cb53aa8a37041ba9684a8458 c:\windows\system32\dllcache\ntoskrnl.exe
2004-08-10 13:00 2180992 ce218bc7088681faa06633e218596ca7 c:\windows\system32\ReinstallBackups\0001\DriverFiles\i386\ntoskrnl.exe
2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\explorer.exe
2007-06-13 05:26 1033216 7712df0cdde3a5ac89843e61cd5b3658 c:\windows\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-10 13:00 1032192 a0732187050030ae399b241436565e64 c:\windows\$NtUninstallKB938828$\explorer.exe
2008-04-13 18:12 1033728 12896823fb95bfb3dc9b46bcaedc9923 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\explorer.exe
2009-01-22 14:52 1032192 a0732187050030ae399b241436565e64 c:\windows\system32\dllcache\explorer.exe
2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
2009-01-22 20:37 110080 5812a3513734517f8c2c5eab6b269864 c:\windows\system32\services.exe
2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
2009-01-22 20:37 14336 c3e6b717e7b284e1fa89ba9f7a1be1ed c:\windows\system32\lsass.exe
2008-04-13 18:12 15360 5f1d5f88303d4a4dbc8e5f97ba967cc3 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ctfmon.exe
2004-08-10 13:00 15360 24232996a38c0b0cf151c2140ae29fc8 c:\windows\system32\ctfmon.exe
2008-04-13 18:12 26112 a93aee1928a9d7ce3e16d24ec7380f89 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
2004-08-10 13:00 24576 39b1ffb03c2296323832acbae50d2aff c:\windows\system32\userinit.exe
2004-08-10 13:00 295424 b60c877d16d9c880b952fda04adf16e6 c:\windows\$NtUninstallKB895961$\termsrv.dll
2008-04-13 18:12 295424 ff3477c03be7201c294c35f684b3479f c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\termsrv.dll
2005-03-10 01:49 295424 c29a5286e64d97385178452d5f307b98 c:\windows\system32\termsrv.dll
2006-07-05 04:57 985088 0fdd84928a5dde2510761b7ec76ccec9 c:\windows\$hf_mig$\KB917422\SP2QFE\kernel32.dll
2007-04-16 10:07 986112 09f7cb3687f86edaa4ca081f7ab66c03 c:\windows\$hf_mig$\KB935839\SP2QFE\kernel32.dll
2004-08-10 13:00 983552 888190e31455fad793312f8d087146eb c:\windows\$NtUninstallKB917422$\kernel32.dll
2006-07-05 04:55 984064 d8db5397de07577c1cb50ba6d23b3ad4 c:\windows\$NtUninstallKB935839$\kernel32.dll
2008-04-13 18:11 989696 c24b983d211c34da8fcc1ac38477971d c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\kernel32.dll
2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\kernel32.dll
2007-04-16 09:52 984576 a01f9ca902a88f7ced06884174d6419d c:\windows\system32\dllcache\kernel32.dll
2008-04-13 18:12 17408 50a166237a0fa771261275a405646cc0 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\powrprof.dll
2004-08-10 13:00 17408 1b5f6923abb450692e9fe0672c897aed c:\windows\system32\powrprof.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
"AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"AMUST 1-Login AutoUpdate"="c:\program files\Common Files\AMUST\Updater\amupdater.dll" [2006-04-11 470328]
"YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2007-10-26 509224]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-05 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-22 180269]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-08 29744]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="c:\progra~1\Symantec\osCheck.exe" [2007-01-14 771704]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"CHotkey"="zHotkey.exe" [2005-05-03 c:\windows\zHotkey.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 c:\windows\system32\bthprops.cpl]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8891:TCP"= 8891:TCP:Pitbull
"50706:TCP"= 50706:TCP:PORT_50706
"41136:TCP"= 41136:TCP:PORT_41136
"58843:TCP"= 58843:TCP:PORT_58843
"45453:TCP"= 45453:TCP:PORT_45453
"46608:TCP"= 46608:TCP:PORT_46608
"24395:TCP"= 24395:TCP:PORT_24395
"58380:TCP"= 58380:TCP:PORT_58380
"12476:TCP"= 12476:TCP:PORT_12476
"44022:TCP"= 44022:TCP:PORT_44022
"23014:TCP"= 23014:TCP:PORT_23014
"61930:TCP"= 61930:TCP:PORT_61930
"46327:TCP"= 46327:TCP:PORT_46327
"34724:TCP"= 34724:TCP:PORT_34724
"19950:TCP"= 19950:TCP:PORT_19950
"49203:TCP"= 49203:TCP:PORT_49203
"23848:TCP"= 23848:TCP:PORT_23848
"48998:TCP"= 48998:TCP:PORT_48998
"53375:TCP"= 53375:TCP:PORT_53375
"40458:TCP"= 40458:TCP:PORT_40458
"6428:TCP"= 6428:TCP:PORT_6428
"37706:TCP"= 37706:TCP:PORT_37706
"47531:TCP"= 47531:TCP:PORT_47531
"46532:TCP"= 46532:TCP:PORT_46532
"32902:TCP"= 32902:TCP:PORT_32902
"17347:TCP"= 17347:TCP:PORT_17347
"17586:TCP"= 17586:TCP:PORT_17586
"26291:TCP"= 26291:TCP:PORT_26291
"55534:TCP"= 55534:TCP:PORT_55534
"41891:TCP"= 41891:TCP:PORT_41891
"48462:TCP"= 48462:TCP:PORT_48462
"18050:TCP"= 18050:TCP:PORT_18050
"31483:TCP"= 31483:TCP:PORT_31483
"33700:TCP"= 33700:TCP:PORT_33700
"31203:TCP"= 31203:TCP:PORT_31203
"43418:TCP"= 43418:TCP:PORT_43418
"24985:TCP"= 24985:TCP:PORT_24985
"19001:TCP"= 19001:TCP:PORT_19001
"42324:TCP"= 42324:TCP:PORT_42324
"10141:TCP"= 10141:TCP:PORT_10141
"15865:TCP"= 15865:TCP:PORT_15865
"36942:TCP"= 36942:TCP:PORT_36942
"30525:TCP"= 30525:TCP:PORT_30525
"41668:TCP"= 41668:TCP:PORT_41668
"46918:TCP"= 46918:TCP:PORT_46918
"34969:TCP"= 34969:TCP:PORT_34969
"31365:TCP"= 31365:TCP:PORT_31365
"46969:TCP"= 46969:TCP:PORT_46969
"24597:TCP"= 24597:TCP:PORT_24597
"20994:TCP"= 20994:TCP:PORT_20994
"41178:TCP"= 41178:TCP:PORT_41178
"28301:TCP"= 28301:TCP:PORT_28301
"59290:TCP"= 59290:TCP:PORT_59290
"24121:TCP"= 24121:TCP:PORT_24121
"57424:TCP"= 57424:TCP:PORT_57424
"44981:TCP"= 44981:TCP:PORT_44981
"58917:TCP"= 58917:TCP:PORT_58917
"19762:TCP"= 19762:TCP:PORT_19762
"13600:TCP"= 13600:TCP:PORT_13600
"50879:TCP"= 50879:TCP:PORT_50879
"25703:TCP"= 25703:TCP:PORT_25703
"25665:TCP"= 25665:TCP:PORT_25665
"61900:TCP"= 61900:TCP:PORT_61900
"39500:TCP"= 39500:TCP:PORT_39500
"20341:TCP"= 20341:TCP:PORT_20341
"19297:TCP"= 19297:TCP:PORT_19297
"38391:TCP"= 38391:TCP:PORT_38391
"49316:TCP"= 49316:TCP:PORT_49316
"59874:TCP"= 59874:TCP:PORT_59874
"37001:TCP"= 37001:TCP:PORT_37001
"53583:TCP"= 53583:TCP:PORT_53583
"16237:TCP"= 16237:TCP:PORT_16237
"64731:TCP"= 64731:TCP:PORT_64731
"20478:TCP"= 20478:TCP:PORT_20478
"9205:TCP"= 9205:TCP:PORT_9205
"21048:TCP"= 21048:TCP:PORT_21048
"13985:TCP"= 13985:TCP:PORT_13985
"17569:TCP"= 17569:TCP:PORT_17569
"39416:TCP"= 39416:TCP:PORT_39416
"64321:TCP"= 64321:TCP:PORT_64321
"5541:TCP"= 5541:TCP:PORT_5541
"11962:TCP"= 11962:TCP:PORT_11962
"17814:TCP"= 17814:TCP:PORT_17814
"23703:TCP"= 23703:TCP:PORT_23703
"30958:TCP"= 30958:TCP:PORT_30958
"56113:TCP"= 56113:TCP:PORT_56113
"57434:TCP"= 57434:TCP:PORT_57434
"6168:TCP"= 6168:TCP:PORT_6168
"46504:TCP"= 46504:TCP:PORT_46504
"33384:TCP"= 33384:TCP:PORT_33384
"56375:TCP"= 56375:TCP:PORT_56375
"51170:TCP"= 51170:TCP:PORT_51170
"19586:TCP"= 19586:TCP:PORT_19586
"25575:TCP"= 25575:TCP:PORT_25575
"42489:TCP"= 42489:TCP:PORT_42489
"48396:TCP"= 48396:TCP:PORT_48396
"31465:TCP"= 31465:TCP:PORT_31465
"10617:TCP"= 10617:TCP:PORT_10617
"65508:TCP"= 65508:TCP:PORT_65508
"33536:TCP"= 33536:TCP:PORT_33536
"38457:TCP"= 38457:TCP:PORT_38457
"10028:TCP"= 10028:TCP:PORT_10028
"36496:TCP"= 36496:TCP:PORT_36496
"7458:TCP"= 7458:TCP:PORT_7458
"37384:TCP"= 37384:TCP:PORT_37384
"10590:TCP"= 10590:TCP:PORT_10590
"45703:TCP"= 45703:TCP:PORT_45703
"36131:TCP"= 36131:TCP:PORT_36131
"22055:TCP"= 22055:TCP:PORT_22055
"22102:TCP"= 22102:TCP:PORT_22102
"21263:TCP"= 21263:TCP:PORT_21263
"57395:TCP"= 57395:TCP:PORT_57395
"48141:TCP"= 48141:TCP:PORT_48141
"54043:TCP"= 54043:TCP:PORT_54043
"47551:TCP"= 47551:TCP:PORT_47551
"20518:TCP"= 20518:TCP:PORT_20518
"28583:TCP"= 28583:TCP:PORT_28583
"25268:TCP"= 25268:TCP:PORT_25268
"40777:TCP"= 40777:TCP:PORT_40777
"26878:TCP"= 26878:TCP:PORT_26878
"40930:TCP"= 40930:TCP:PORT_40930
"22729:TCP"= 22729:TCP:PORT_22729
"23165:TCP"= 23165:TCP:PORT_23165
"14616:TCP"= 14616:TCP:PORT_14616
"12196:TCP"= 12196:TCP:PORT_12196
"29415:TCP"= 29415:TCP:PORT_29415
"28376:TCP"= 28376:TCP:PORT_28376
"23958:TCP"= 23958:TCP:PORT_23958
"8479:TCP"= 8479:TCP:PORT_8479
"7010:TCP"= 7010:TCP:PORT_7010
"28177:TCP"= 28177:TCP:PORT_28177
"17291:TCP"= 17291:TCP:PORT_17291
"55072:TCP"= 55072:TCP:PORT_55072
"17438:TCP"= 17438:TCP:PORT_17438
"12604:TCP"= 12604:TCP:PORT_12604
"25643:TCP"= 25643:TCP:PORT_25643
"56825:TCP"= 56825:TCP:PORT_56825
"49451:TCP"= 49451:TCP:PORT_49451
"42493:TCP"= 42493:TCP:PORT_42493
"11581:TCP"= 11581:TCP:PORT_11581
"62951:TCP"= 62951:TCP:PORT_62951
"53295:TCP"= 53295:TCP:PORT_53295
"9788:TCP"= 9788:TCP:PORT_9788
"59565:TCP"= 59565:TCP:PORT_59565
"40583:TCP"= 40583:TCP:PORT_40583
"14298:TCP"= 14298:TCP:PORT_14298
"47022:TCP"= 47022:TCP:PORT_47022
"61853:TCP"= 61853:TCP:PORT_61853
"56114:TCP"= 56114:TCP:PORT_56114
R2 713xTVCard;SAA7133 TV Card;c:\windows\system32\DRIVERS\SAA713x.sys [2005-03-15 277504]
R3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-08 29744]
S1 MozyFilter;MozyFilter;c:\windows\system32\DRIVERS\mozy.sys [2008-10-06 53752]
S3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-26 12800]
S3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-26 10112]
S3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-26 44544]
S3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-26 201472]
S3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-26 9728]
S3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\DRIVERS\atinewp2.sys [2005-06-01 485760]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*Deregistered* - abp480n5
*Deregistered* - adpu160m
*Deregistered* - AegisP
*Deregistered* - AFD
*Deregistered* - agp440
*Deregistered* - agpCPQ
*Deregistered* - Aha154x
*Deregistered* - aic78u2
*Deregistered* - aic78xx
*Deregistered* - AliIde
*Deregistered* - alim1541
*Deregistered* - amdagp
*Deregistered* - amsint
*Deregistered* - Arp1394
*Deregistered* - asc
*Deregistered* - asc3350p
*Deregistered* - asc3550
*Deregistered* - Ati HotKey Poller
*Deregistered* - ATI Smart
*Deregistered* - audstub
*Deregistered* - Beep
*Deregistered* - cbidf
*Deregistered* - cd20xrnt
*Deregistered* - Cdfs
*Deregistered* - CLTNetCnService
*Deregistered* - CmdIde
*Deregistered* - comHost
*Deregistered* - Cpqarray
*Deregistered* - dac2w2k
*Deregistered* - dac960nt
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dpti2o
*Deregistered* - eeCtrl
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - Fastfat
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - GTNDIS5
*Deregistered* - hpn
*Deregistered* - HTTP
*Deregistered* - i2omgmt
*Deregistered* - i2omp
*Deregistered* - ini910u
*Deregistered* - IntelIde
*Deregistered* - Ip6Fw
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - LiveUpdate Notice Ex
*Deregistered* - LiveUpdate Notice Service
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MozyBackup
*Deregistered* - MozyFilter
*Deregistered* - mraid35x
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NwlnkIpx
*Deregistered* - NwlnkNb
*Deregistered* - NwlnkSpx
*Deregistered* - PartMgr
*Deregistered* - perc2
*Deregistered* - perc2hib
*Deregistered* - PptpMiniport
*Deregistered* - PrismXL
*Deregistered* - PSched
*Deregistered* - ql1080
*Deregistered* - Ql10wnt
*Deregistered* - ql12160
*Deregistered* - ql1240
*Deregistered* - ql1280
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - sisagp
*Deregistered* - Sparrow
*Deregistered* - sr
*Deregistered* - SRTSP
*Deregistered* - SRTSPX
*Deregistered* - swenum
*Deregistered* - sym_hi
*Deregistered* - sym_u3
*Deregistered* - symc810
*Deregistered* - symc8xx
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMIDSCO
*Deregistered* - SYMNDIS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TosIde
*Deregistered* - tunmp
*Deregistered* - ultra
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - viaagp
*Deregistered* - ViaIde
*Deregistered* - VolSnap
*Deregistered* - Wanarp
*Deregistered* - WMP54Gv4SVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1661f93b-57a3-11da-9baa-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79be7b9c-0e07-11da-b64f-00038a000015}]
\Shell\AutoRun\command - K:\smartAP.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6572fdc-3fec-11da-94d4-806d6172696f}]
\Shell\AutoRun\command - E:\run.bat
.
Contents of the 'Scheduled Tasks' folder
2009-01-19 c:\windows\Tasks\Norton Security Online - Run Full System Scan - chullz.job
- c:\progra~1\Symantec\Norton AntiVirus\Navw32.exe [2007-01-14 03:09]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} - hxxp://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} - hxxp://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-01 15:03:48
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,26,b8,5e,26,00,
e0,e8,d1,e2,63,26,f1,3f,c8,ff,68,90,3b,26,5c,ae,6e,84,c4,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,03,46,b9,b8,
a6,76,67,6a,9c,d6,61,af,45,84,18,94,5f,6f,37,d7,a1,a9,29,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,3d,3c,71,b7,9f,
dc,e9,1b,ff,7c,85,e0,43,d4,0e,fe,b5,a7,b9,1d,20,35,11,86,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,12,07,dd,0d,7f,
21,d3,4c,86,8c,21,01,be,91,eb,e7,e9,5f,c9,fe,bc,ad,42,2a,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,01,ad,dc,b1,
bd,5b,fd,f5,1d,4d,73,a8,13,5c,05,81,15,3b,6a,17,dc,fe,4e,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,0e,22,6d,67,b6,
56,19,8a,df,20,58,62,78,6b,cf,c8,fd,57,42,60,5d,81,ab,f8,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,71,e6,3b,c1,c4,
3e,24,3e,fb,a7,78,e6,12,2f,9a,ea,a3,8d,75,0a,b5,04,8f,49,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,fb,ef,0e,e5,32,
23,0d,a5,01,3a,48,fc,e8,04,4a,f1,90,cd,67,e4,36,b1,32,7a,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c3,e7,d0,db,cc,
15,36,e5,f6,0f,4e,58,98,5b,89,c9,8b,cd,ea,1c,db,2c,57,9e,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,f7,7c,3e,f9,01,
9a,61,88,3d,ce,ea,26,2d,45,aa,78,db,8a,97,10,b0,21,48,0e,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,98,19,c0,41,43,
f4,2b,a7,2a,b7,cc,b5,b9,7f,41,e7,2c,b4,f2,d2,fd,82,d7,82,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,fe,e6,69,6f,c3,
9c,ba,71,6c,43,2d,1e,aa,22,2f,9c,08,f7,13,a7,0a,48,8d,4d,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Mozy\mozybackup.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
c:\program files\Logitech\SetPoint\SetPoint.exe
c:\program files\Mozy\mozystat.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
.
**************************************************************************
.
Completion time: 2009-02-01 15:12:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-01 21:12:52
ComboFix2.txt 2009-01-31 16:41:12
Pre-Run: 150,602,010,624 bytes free
Post-Run: 150,504,599,552 bytes free
620 --- E O F --- 2009-01-14 09:04:25
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:30:40 PM, on 2/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Mozy\mozybackup.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Mozy\mozystat.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\WINDOWS\explorer.exe
K:\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: AMUST 1-Login IE Helper - {FFF1A4CB-472E-404a-9898-0B73B6B2E421} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
O3 - Toolbar: AMUST 1-Login Toolbar - {F5BAA0B9-0DBF-4b42-BE9C-B2513ED71737} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AMUST 1-Login AutoUpdate] rundll32.exe "C:\Program Files\Common Files\AMUST\Updater\amupdater.dll",AMUSTUpdate AMUST 1-Login ONLYLOCAL
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKUS\S-1-5-21-3690015938-2637564805-925999644-1008\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User '?')
O4 - HKUS\S-1-5-21-3690015938-2637564805-925999644-1008\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem (User '?')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User '?')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Mozy Status.lnk = C:\Program Files\Mozy\mozystat.exe
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\Mozy\mozystat.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} (WebInstaller Control) - http://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} (WebInstaller Control) - http://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156216832609
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://targetphoto.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photofinale.com/ImageUploader/ImageUploader4.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
O23 - Service: IPv6 Helper Service (6to4) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Application Management (AppMgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Windows Audio (AudioSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Computer Browser (Browser) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Bluetooth Support Service (BthServ) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Cryptographic Services (CryptSvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: DCOM Server Process Launcher (DcomLaunch) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: DHCP Client (Dhcp) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Logical Disk Manager (dmserver) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Error Reporting Service (ERSvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: COM+ Event System (EventSystem) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Fast User Switching Compatibility (FastUserSwitchingCompatibility) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Help and Support (helpsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: HID Input Service (HidServ) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: Server (lanmanserver) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Workstation (lanmanworkstation) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: TCP/IP NetBIOS Helper (LmHosts) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: MHN - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: MozyHome Backup Service (MozyBackup) - Unknown owner - C:\Program Files\Mozy\mozybackup.exe
O23 - Service: Network Connections (Netman) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Network Location Awareness (NLA) (Nla) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Remote Access Auto Connection Manager (RasAuto) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Remote Access Connection Manager (RasMan) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Remote Registry (RemoteRegistry) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Remote Procedure Call (RPC) (RpcSs) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Task Scheduler (Schedule) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Secondary Logon (seclogon) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: System Event Notification (SENS) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Shell Hardware Detection (ShellHWDetection) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)
O23 - Service: System Restore Service (srservice) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: SSDP Discovery Service (SSDPSRV) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Windows Image Acquisition (WIA) (stisvc) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Telephony (TapiSrv) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Terminal Services (TermService) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Themes - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Distributed Link Tracking Client (TrkWks) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Universal Plug and Play Device Host (upnphost) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Windows Time (W32Time) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: WebClient - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Windows Management Instrumentation (winmgmt) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Portable Media Serial Number Service (WmdmPmSN) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Windows Management Instrumentation Driver Extensions (Wmi) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O23 - Service: Security Center (wscsvc) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\system32\svchost.exe (file missing)
O23 - Service: Wireless Zero Configuration (WZCSVC) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: Network Provisioning Service (xmlprov) - Unknown owner - C:\WINDOWS\System32\svchost.exe (file missing)
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
--
End of file - 18318 bytes
Create A Batch File
Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the quote to Notepad.
Save it as "All Files" and name it look.bat Please save it on your desktop.
@echo off
if exist C:\kresults.txt del /q C:\kresults.txt
Echo Searching ..... Please Wait
FOR %%G IN (
svchost.exe
) DO (
echo %%G >> C:\kresults.txt
dir C:\*.* /L /A /B /S|Find "%%G" >> C:\kresults.txt
echo. >> C:\kresults.txt
echo. >> C:\kresults.txt
)
Echo Finished
start notepad C:\kresults.txt
del /q %0
exit
Double click on look.bat
Please be patient, as this will search the entire disc
Notepad will open, please copy/paste the results here.
svchost.exe
c:\windows\prefetch\svchost.exe-3530f672.pf
c:\windows\softwaredistribution\download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe
Custom CFScript
Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
KillAll::
FCopy::
c:\windows\softwaredistribution\download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe|C:\WINDOWS\System32\svchost.exe
File::
Save this as CFScript.txt and place it on your desktop.
http://i51.photobucket.com/albums/f387/Katana_1970/CFScriptb.gif
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper
Please see if you can connect to the internet now.
I do have a connection to the internet now. Here are the results of the log.
ComboFix 09-02-01.01 - chullz 2009-02-03 5:53:17.4 - NTFSx86
Running from: c:\documents and settings\chullz\Desktop\ComboFix.exe
Command switches used :: K:\CFScript.txt
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\windows\softwaredistribution\download\dd9ab5193501484cf5e6884fa1d22f9e\svchost.exe --> c:\windows\System32\svchost.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.
2009-02-03 05:53 . 2004-08-10 13:00 14,336 --a------ c:\windows\system32\svchost.exe
2009-02-03 05:53 . 2004-08-10 13:00 14,336 --a--c--- c:\windows\system32\dllcache\svchost.exe
2009-02-01 14:46 . 2009-02-01 13:43 3,307,596 --a------ C:\ComboFix.exe
2009-01-24 10:55 . 2009-01-24 10:55 <DIR> d-------- c:\documents and settings\chullz\Application Data\Sammsoft
2009-01-24 10:54 . 2009-01-24 10:54 <DIR> d-------- c:\program files\Advanced Registry Optimizer
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a--c--- c:\windows\system32\dllcache\explorer.exe
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a------ c:\windows\explorer.exe
2009-01-21 17:46 . 2009-01-24 08:22 <DIR> d-------- c:\program files\Coupons
2009-01-14 03:04 . 2008-08-28 04:04 333,056 --a------ c:\windows\system32\drivers\srv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 12:03 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-22 00:07 --------- d-----w c:\program files\Google
2009-01-07 22:21 --------- d--h--w c:\documents and settings\chullz\Application Data\Move Networks
2009-01-06 00:49 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-06 00:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-06 00:49 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-06 00:49 --------- d-----w c:\program files\Symantec
2007-11-24 19:56 58,232 ----a-w c:\documents and settings\chullz\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2009-01-22 20:37 505856 e853481fef64a5be3fc3732d9d3d926a c:\windows\system32\winlogon.exe
2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
2009-01-22 20:37 110080 5812a3513734517f8c2c5eab6b269864 c:\windows\system32\services.exe
2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
2009-01-22 20:37 14336 c3e6b717e7b284e1fa89ba9f7a1be1ed c:\windows\system32\lsass.exe
.
((((((((((((((((((((((((((((( snapshot@2009-02-01_15.11.44.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-03 11:58:37 16,384 ----atw c:\windows\temp\Perflib_Perfdata_4f0.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
"AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"AMUST 1-Login AutoUpdate"="c:\program files\Common Files\AMUST\Updater\amupdater.dll" [2006-04-11 470328]
"YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2007-10-26 509224]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-05 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-22 180269]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-08 29744]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="c:\progra~1\Symantec\osCheck.exe" [2007-01-14 771704]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"CHotkey"="zHotkey.exe" [2005-05-03 c:\windows\zHotkey.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 c:\windows\system32\bthprops.cpl]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Mozy Status.lnk - c:\program files\Mozy\mozystat.exe [2008-10-06 2954544]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-01-31 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Mozy Status.lnk - c:\program files\Mozy\mozystat.exe [2008-10-06 2954544]
MozyHome Status.lnk - c:\program files\Mozy\mozystat.exe [2008-10-06 2954544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8891:TCP"= 8891:TCP:Pitbull
"50706:TCP"= 50706:TCP:PORT_50706
"41136:TCP"= 41136:TCP:PORT_41136
"58843:TCP"= 58843:TCP:PORT_58843
"45453:TCP"= 45453:TCP:PORT_45453
"46608:TCP"= 46608:TCP:PORT_46608
"24395:TCP"= 24395:TCP:PORT_24395
"58380:TCP"= 58380:TCP:PORT_58380
"12476:TCP"= 12476:TCP:PORT_12476
"44022:TCP"= 44022:TCP:PORT_44022
"23014:TCP"= 23014:TCP:PORT_23014
"61930:TCP"= 61930:TCP:PORT_61930
"46327:TCP"= 46327:TCP:PORT_46327
"34724:TCP"= 34724:TCP:PORT_34724
"19950:TCP"= 19950:TCP:PORT_19950
"49203:TCP"= 49203:TCP:PORT_49203
"23848:TCP"= 23848:TCP:PORT_23848
"48998:TCP"= 48998:TCP:PORT_48998
"53375:TCP"= 53375:TCP:PORT_53375
"40458:TCP"= 40458:TCP:PORT_40458
"6428:TCP"= 6428:TCP:PORT_6428
"37706:TCP"= 37706:TCP:PORT_37706
"47531:TCP"= 47531:TCP:PORT_47531
"46532:TCP"= 46532:TCP:PORT_46532
"32902:TCP"= 32902:TCP:PORT_32902
"17347:TCP"= 17347:TCP:PORT_17347
"17586:TCP"= 17586:TCP:PORT_17586
"26291:TCP"= 26291:TCP:PORT_26291
"55534:TCP"= 55534:TCP:PORT_55534
"41891:TCP"= 41891:TCP:PORT_41891
"48462:TCP"= 48462:TCP:PORT_48462
"18050:TCP"= 18050:TCP:PORT_18050
"31483:TCP"= 31483:TCP:PORT_31483
"33700:TCP"= 33700:TCP:PORT_33700
"31203:TCP"= 31203:TCP:PORT_31203
"43418:TCP"= 43418:TCP:PORT_43418
"24985:TCP"= 24985:TCP:PORT_24985
"19001:TCP"= 19001:TCP:PORT_19001
"42324:TCP"= 42324:TCP:PORT_42324
"10141:TCP"= 10141:TCP:PORT_10141
"15865:TCP"= 15865:TCP:PORT_15865
"36942:TCP"= 36942:TCP:PORT_36942
"30525:TCP"= 30525:TCP:PORT_30525
"41668:TCP"= 41668:TCP:PORT_41668
"46918:TCP"= 46918:TCP:PORT_46918
"34969:TCP"= 34969:TCP:PORT_34969
"31365:TCP"= 31365:TCP:PORT_31365
"46969:TCP"= 46969:TCP:PORT_46969
"24597:TCP"= 24597:TCP:PORT_24597
"20994:TCP"= 20994:TCP:PORT_20994
"41178:TCP"= 41178:TCP:PORT_41178
"28301:TCP"= 28301:TCP:PORT_28301
"59290:TCP"= 59290:TCP:PORT_59290
"24121:TCP"= 24121:TCP:PORT_24121
"57424:TCP"= 57424:TCP:PORT_57424
"44981:TCP"= 44981:TCP:PORT_44981
"58917:TCP"= 58917:TCP:PORT_58917
"19762:TCP"= 19762:TCP:PORT_19762
"13600:TCP"= 13600:TCP:PORT_13600
"50879:TCP"= 50879:TCP:PORT_50879
"25703:TCP"= 25703:TCP:PORT_25703
"25665:TCP"= 25665:TCP:PORT_25665
"61900:TCP"= 61900:TCP:PORT_61900
"39500:TCP"= 39500:TCP:PORT_39500
"20341:TCP"= 20341:TCP:PORT_20341
"19297:TCP"= 19297:TCP:PORT_19297
"38391:TCP"= 38391:TCP:PORT_38391
"49316:TCP"= 49316:TCP:PORT_49316
"59874:TCP"= 59874:TCP:PORT_59874
"37001:TCP"= 37001:TCP:PORT_37001
"53583:TCP"= 53583:TCP:PORT_53583
"16237:TCP"= 16237:TCP:PORT_16237
"64731:TCP"= 64731:TCP:PORT_64731
"20478:TCP"= 20478:TCP:PORT_20478
"9205:TCP"= 9205:TCP:PORT_9205
"21048:TCP"= 21048:TCP:PORT_21048
"13985:TCP"= 13985:TCP:PORT_13985
"17569:TCP"= 17569:TCP:PORT_17569
"39416:TCP"= 39416:TCP:PORT_39416
"64321:TCP"= 64321:TCP:PORT_64321
"5541:TCP"= 5541:TCP:PORT_5541
"11962:TCP"= 11962:TCP:PORT_11962
"17814:TCP"= 17814:TCP:PORT_17814
"23703:TCP"= 23703:TCP:PORT_23703
"30958:TCP"= 30958:TCP:PORT_30958
"56113:TCP"= 56113:TCP:PORT_56113
"57434:TCP"= 57434:TCP:PORT_57434
"6168:TCP"= 6168:TCP:PORT_6168
"46504:TCP"= 46504:TCP:PORT_46504
"33384:TCP"= 33384:TCP:PORT_33384
"56375:TCP"= 56375:TCP:PORT_56375
"51170:TCP"= 51170:TCP:PORT_51170
"19586:TCP"= 19586:TCP:PORT_19586
"25575:TCP"= 25575:TCP:PORT_25575
"42489:TCP"= 42489:TCP:PORT_42489
"48396:TCP"= 48396:TCP:PORT_48396
"31465:TCP"= 31465:TCP:PORT_31465
"10617:TCP"= 10617:TCP:PORT_10617
"65508:TCP"= 65508:TCP:PORT_65508
"33536:TCP"= 33536:TCP:PORT_33536
"38457:TCP"= 38457:TCP:PORT_38457
"10028:TCP"= 10028:TCP:PORT_10028
"36496:TCP"= 36496:TCP:PORT_36496
"7458:TCP"= 7458:TCP:PORT_7458
"37384:TCP"= 37384:TCP:PORT_37384
"10590:TCP"= 10590:TCP:PORT_10590
"45703:TCP"= 45703:TCP:PORT_45703
"36131:TCP"= 36131:TCP:PORT_36131
"22055:TCP"= 22055:TCP:PORT_22055
"22102:TCP"= 22102:TCP:PORT_22102
"21263:TCP"= 21263:TCP:PORT_21263
"57395:TCP"= 57395:TCP:PORT_57395
"48141:TCP"= 48141:TCP:PORT_48141
"54043:TCP"= 54043:TCP:PORT_54043
"47551:TCP"= 47551:TCP:PORT_47551
"20518:TCP"= 20518:TCP:PORT_20518
"28583:TCP"= 28583:TCP:PORT_28583
"25268:TCP"= 25268:TCP:PORT_25268
"40777:TCP"= 40777:TCP:PORT_40777
"26878:TCP"= 26878:TCP:PORT_26878
"40930:TCP"= 40930:TCP:PORT_40930
"22729:TCP"= 22729:TCP:PORT_22729
"23165:TCP"= 23165:TCP:PORT_23165
"14616:TCP"= 14616:TCP:PORT_14616
"12196:TCP"= 12196:TCP:PORT_12196
"29415:TCP"= 29415:TCP:PORT_29415
"28376:TCP"= 28376:TCP:PORT_28376
"23958:TCP"= 23958:TCP:PORT_23958
"8479:TCP"= 8479:TCP:PORT_8479
"7010:TCP"= 7010:TCP:PORT_7010
"28177:TCP"= 28177:TCP:PORT_28177
"17291:TCP"= 17291:TCP:PORT_17291
"55072:TCP"= 55072:TCP:PORT_55072
"17438:TCP"= 17438:TCP:PORT_17438
"12604:TCP"= 12604:TCP:PORT_12604
"25643:TCP"= 25643:TCP:PORT_25643
"56825:TCP"= 56825:TCP:PORT_56825
"49451:TCP"= 49451:TCP:PORT_49451
"42493:TCP"= 42493:TCP:PORT_42493
"11581:TCP"= 11581:TCP:PORT_11581
"62951:TCP"= 62951:TCP:PORT_62951
"53295:TCP"= 53295:TCP:PORT_53295
"9788:TCP"= 9788:TCP:PORT_9788
"59565:TCP"= 59565:TCP:PORT_59565
"40583:TCP"= 40583:TCP:PORT_40583
"14298:TCP"= 14298:TCP:PORT_14298
"47022:TCP"= 47022:TCP:PORT_47022
"61853:TCP"= 61853:TCP:PORT_61853
"56114:TCP"= 56114:TCP:PORT_56114
R2 713xTVCard;SAA7133 TV Card;c:\windows\system32\DRIVERS\SAA713x.sys [2005-03-15 277504]
R3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-08 29744]
S1 MozyFilter;MozyFilter;c:\windows\system32\DRIVERS\mozy.sys [2008-10-06 53752]
S3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-26 12800]
S3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-26 10112]
S3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-26 44544]
S3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-26 201472]
S3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-26 9728]
S3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\DRIVERS\atinewp2.sys [2005-06-01 485760]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-02 99376]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*NewlyCreated* - GTNDIS5
*Deregistered* - 6to4
*Deregistered* - ALG
*Deregistered* - Ati HotKey Poller
*Deregistered* - ATI Smart
*Deregistered* - AudioSrv
*Deregistered* - Automatic LiveUpdate Scheduler
*Deregistered* - BITS
*Deregistered* - Browser
*Deregistered* - BthServ
*Deregistered* - cbidf
*Deregistered* - ccEvtMgr
*Deregistered* - ccSetMgr
*Deregistered* - cd20xrnt
*Deregistered* - Cdfs
*Deregistered* - CLTNetCnService
*Deregistered* - CmdIde
*Deregistered* - comHost
*Deregistered* - COMSysApp
*Deregistered* - Cpqarray
*Deregistered* - CryptSvc
*Deregistered* - dac2w2k
*Deregistered* - dac960nt
*Deregistered* - DcomLaunch
*Deregistered* - Dhcp
*Deregistered* - dmio
*Deregistered* - dmload
*Deregistered* - dmserver
*Deregistered* - dpti2o
*Deregistered* - eeCtrl
*Deregistered* - ehRecvr
*Deregistered* - ehSched
*Deregistered* - EraserUtilRebootDrv
*Deregistered* - ERSvc
*Deregistered* - EventSystem
*Deregistered* - Fastfat
*Deregistered* - FastUserSwitchingCompatibility
*Deregistered* - Fips
*Deregistered* - FltMgr
*Deregistered* - Ftdisk
*Deregistered* - Gpc
*Deregistered* - GTNDIS5
*Deregistered* - gusvc
*Deregistered* - helpsvc
*Deregistered* - HidServ
*Deregistered* - hpn
*Deregistered* - HTTP
*Deregistered* - HTTPFilter
*Deregistered* - i2omgmt
*Deregistered* - i2omp
*Deregistered* - ImapiService
*Deregistered* - ini910u
*Deregistered* - IntelIde
*Deregistered* - Ip6Fw
*Deregistered* - IpNat
*Deregistered* - IPSec
*Deregistered* - KSecDD
*Deregistered* - lanmanserver
*Deregistered* - lanmanworkstation
*Deregistered* - LiveUpdate
*Deregistered* - LiveUpdate Notice Ex
*Deregistered* - LiveUpdate Notice Service
*Deregistered* - LmHosts
*Deregistered* - McrdSvc
*Deregistered* - MDM
*Deregistered* - mnmdd
*Deregistered* - MountMgr
*Deregistered* - MozyBackup
*Deregistered* - MozyFilter
*Deregistered* - mraid35x
*Deregistered* - MRxDAV
*Deregistered* - MRxSmb
*Deregistered* - Msfs
*Deregistered* - mssmbios
*Deregistered* - Mup
*Deregistered* - NAVENG
*Deregistered* - NAVEX15
*Deregistered* - NDIS
*Deregistered* - Ndisuio
*Deregistered* - NdisWan
*Deregistered* - NDProxy
*Deregistered* - NetBIOS
*Deregistered* - NetBT
*Deregistered* - Netman
*Deregistered* - Nla
*Deregistered* - Npfs
*Deregistered* - Ntfs
*Deregistered* - Null
*Deregistered* - NwlnkIpx
*Deregistered* - NwlnkNb
*Deregistered* - NwlnkSpx
*Deregistered* - PartMgr
*Deregistered* - perc2
*Deregistered* - perc2hib
*Deregistered* - PolicyAgent
*Deregistered* - PptpMiniport
*Deregistered* - PrismXL
*Deregistered* - ProtectedStorage
*Deregistered* - PSched
*Deregistered* - ql1080
*Deregistered* - Ql10wnt
*Deregistered* - ql12160
*Deregistered* - ql1240
*Deregistered* - ql1280
*Deregistered* - RasAcd
*Deregistered* - Rasl2tp
*Deregistered* - RasMan
*Deregistered* - RasPppoe
*Deregistered* - Raspti
*Deregistered* - Rdbss
*Deregistered* - RDPCDD
*Deregistered* - rdpdr
*Deregistered* - RemoteRegistry
*Deregistered* - RpcSs
*Deregistered* - SamSs
*Deregistered* - Schedule
*Deregistered* - seclogon
*Deregistered* - SENS
*Deregistered* - SharedAccess
*Deregistered* - ShellHWDetection
*Deregistered* - sisagp
*Deregistered* - Sparrow
*Deregistered* - SPBBCDrv
*Deregistered* - sr
*Deregistered* - srservice
*Deregistered* - SRTSP
*Deregistered* - SRTSPX
*Deregistered* - Srv
*Deregistered* - SSDPSRV
*Deregistered* - stisvc
*Deregistered* - swenum
*Deregistered* - sym_hi
*Deregistered* - sym_u3
*Deregistered* - Symantec Core LC
*Deregistered* - SymAppCore
*Deregistered* - symc810
*Deregistered* - symc8xx
*Deregistered* - SYMDNS
*Deregistered* - SymEvent
*Deregistered* - SYMFW
*Deregistered* - SYMIDS
*Deregistered* - SYMIDSCO
*Deregistered* - SYMNDIS
*Deregistered* - SYMREDRV
*Deregistered* - SYMTDI
*Deregistered* - TapiSrv
*Deregistered* - Tcpip
*Deregistered* - Tcpip6
*Deregistered* - TermDD
*Deregistered* - TermService
*Deregistered* - Themes
*Deregistered* - TosIde
*Deregistered* - TrkWks
*Deregistered* - tunmp
*Deregistered* - ultra
*Deregistered* - Update
*Deregistered* - VgaSave
*Deregistered* - viaagp
*Deregistered* - ViaIde
*Deregistered* - VolSnap
*Deregistered* - W32Time
*Deregistered* - Wanarp
*Deregistered* - WebClient
*Deregistered* - winmgmt
*Deregistered* - WMP54Gv4SVC
*Deregistered* - wscsvc
*Deregistered* - wuauserv
*Deregistered* - WZCSVC
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1661f93b-57a3-11da-9baa-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79be7b9c-0e07-11da-b64f-00038a000015}]
\Shell\AutoRun\command - K:\smartAP.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6572fdc-3fec-11da-94d4-806d6172696f}]
\Shell\AutoRun\command - E:\run.bat
.
Contents of the 'Scheduled Tasks' folder
2009-01-19 c:\windows\Tasks\Norton Security Online - Run Full System Scan - chullz.job
- c:\progra~1\Symantec\Norton AntiVirus\Navw32.exe [2007-01-14 03:09]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} - hxxp://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} - hxxp://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-03 06:02:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,26,b8,5e,26,00,
e0,e8,d1,e2,63,26,f1,3f,c8,ff,68,90,3b,26,5c,ae,6e,84,c4,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,03,46,b9,b8,
a6,76,67,6a,9c,d6,61,af,45,84,18,94,5f,6f,37,d7,a1,a9,29,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,3d,3c,71,b7,9f,
dc,e9,1b,ff,7c,85,e0,43,d4,0e,fe,b5,a7,b9,1d,20,35,11,86,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,12,07,dd,0d,7f,
21,d3,4c,86,8c,21,01,be,91,eb,e7,e9,5f,c9,fe,bc,ad,42,2a,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,01,ad,dc,b1,
bd,5b,fd,f5,1d,4d,73,a8,13,5c,05,81,15,3b,6a,17,dc,fe,4e,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,0e,22,6d,67,b6,
56,19,8a,df,20,58,62,78,6b,cf,c8,fd,57,42,60,5d,81,ab,f8,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,71,e6,3b,c1,c4,
3e,24,3e,fb,a7,78,e6,12,2f,9a,ea,a3,8d,75,0a,b5,04,8f,49,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,fb,ef,0e,e5,32,
23,0d,a5,01,3a,48,fc,e8,04,4a,f1,90,cd,67,e4,36,b1,32,7a,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c3,e7,d0,db,cc,
15,36,e5,f6,0f,4e,58,98,5b,89,c9,8b,cd,ea,1c,db,2c,57,9e,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,f7,7c,3e,f9,01,
9a,61,88,3d,ce,ea,26,2d,45,aa,78,db,8a,97,10,b0,21,48,0e,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,98,19,c0,41,43,
f4,2b,a7,2a,b7,cc,b5,b9,7f,41,e7,2c,b4,f2,d2,fd,82,d7,82,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,fe,e6,69,6f,c3,
9c,ba,71,6c,43,2d,1e,aa,22,2f,9c,08,f7,13,a7,0a,48,8d,4d,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\program files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Common Files\Symantec Shared\ccSvcHst.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Mozy\mozybackup.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
c:\program files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\rundll32.exe
c:\progra~1\Yahoo!\browser\ycommon.exe
c:\progra~1\Yahoo!\YOP\SSDK02.exe
c:\progra~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
c:\program files\Symantec\LiveUpdate\AUPDATE.EXE
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
c:\program files\Symantec\LiveUpdate\LuCallbackProxy.exe
.
**************************************************************************
.
Completion time: 2009-02-03 6:21:47 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-03 12:21:30
ComboFix2.txt 2009-02-01 21:12:58
ComboFix3.txt 2009-01-31 16:41:12
Pre-Run: 150,512,279,552 bytes free
Post-Run: 150,563,639,296 bytes free
589 --- E O F --- 2009-01-14 09:04:25
Jackpot :) :)
Recovery Console
!!!!!! Warning !!!!!!.... Your log shows that Recovery Console is not installed.
Due to the threat that current and future malware poses it is vital that you have some form of recovery console.
Go to Microsoft's website => http://support.microsoft.com/kb/310994
Select the download that's appropriate for your Operating System - (SP3 Users should download the SP2 pack)
http://i51.photobucket.com/albums/f387/Katana_1970/KB310994.gif
Download the file & save it as its originally named, next to ComboFix.exe.
http://i51.photobucket.com/albums/f387/Katana_1970/rc1.gif
Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please post the contents of that log.
Kaspersky Online Scanner .
Your Antivirus and/or Antispyware may give a warning during the scan. This is perfectly normal
NOTE:- This scan is best done from IE (Internet Explorer)
NOTE:- Vista users should start IE by Start(Vista Orb) >> Internet Explorer >> Right-Click Run As Admin
Go Here http://www.kaspersky.com/kos/eng/partner/default/kavwebscan.html
Read the Requirements and limitations before you click Accept.
Once the database has downloaded, click My Computer in the left pane
Now go and put the kettle on !
When the scan has completed, click Save Report As...
Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
**Note**
To optimize scanning time and produce a more sensible report for review: Close any open programs.
Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.
Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
ComboFix 09-02-02.04 - chullz 2009-02-03 17:47:23.5 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.438 [GMT -6:00]
Running from: c:\documents and settings\chullz\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\chullz\Desktop\WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
AV: Norton Security Online *On-access scanning disabled* (Updated)
FW: Norton Security Online *enabled*
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2009-01-03 to 2009-02-03 )))))))))))))))))))))))))))))))
.
2009-02-03 05:53 . 2004-08-10 13:00 14,336 --a------ c:\windows\system32\svchost.exe
2009-02-03 05:53 . 2004-08-10 13:00 14,336 --a--c--- c:\windows\system32\dllcache\svchost.exe
2009-02-01 14:46 . 2009-02-01 13:43 3,307,596 --a------ C:\ComboFix.exe
2009-01-24 10:55 . 2009-01-24 10:55 <DIR> d-------- c:\documents and settings\chullz\Application Data\Sammsoft
2009-01-24 10:54 . 2009-01-24 10:54 <DIR> d-------- c:\program files\Advanced Registry Optimizer
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a--c--- c:\windows\system32\dllcache\explorer.exe
2009-01-22 14:52 . 2009-01-22 14:52 1,032,192 --a------ c:\windows\explorer.exe
2009-01-21 17:46 . 2009-01-24 08:22 <DIR> d-------- c:\program files\Coupons
2009-01-14 03:04 . 2008-08-28 04:04 333,056 --a------ c:\windows\system32\drivers\srv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 23:39 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-23 02:37 505,856 ----a-w c:\windows\system32\winlogon.exe
2009-01-23 02:37 14,336 ----a-w c:\windows\system32\lsass.exe
2009-01-23 02:37 110,080 ----a-w c:\windows\system32\services.exe
2009-01-22 00:07 --------- d-----w c:\program files\Google
2009-01-07 22:21 --------- d--h--w c:\documents and settings\chullz\Application Data\Move Networks
2009-01-06 00:49 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-06 00:49 60,808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-01-06 00:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-06 00:49 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-06 00:49 --------- d-----w c:\program files\Symantec
2007-11-24 19:56 58,232 ----a-w c:\documents and settings\chullz\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2009-01-22 20:37 505856 e853481fef64a5be3fc3732d9d3d926a c:\windows\system32\winlogon.exe
2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
2009-01-22 20:37 110080 5812a3513734517f8c2c5eab6b269864 c:\windows\system32\services.exe
2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
2009-01-22 20:37 14336 c3e6b717e7b284e1fa89ba9f7a1be1ed c:\windows\system32\lsass.exe
.
((((((((((((((((((((((((((((( snapshot@2009-02-01_15.11.44.46 )))))))))))))))))))))))))))))))))))))))))
.
- 2005-10-20 12:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 02:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2000-08-31 14:00:00 286,720 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 14:00:00 161,792 ----a-w c:\windows\SWREG.exe
+ 2009-02-03 23:28:22 16,384 ----atw c:\windows\temp\Perflib_Perfdata_244.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
"AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"AMUST 1-Login AutoUpdate"="c:\program files\Common Files\AMUST\Updater\amupdater.dll" [2006-04-11 470328]
"YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2007-10-26 509224]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-05 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-22 180269]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-08 29744]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="c:\progra~1\Symantec\osCheck.exe" [2007-01-14 771704]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"CHotkey"="zHotkey.exe" [2005-05-03 c:\windows\zHotkey.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 c:\windows\system32\bthprops.cpl]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Mozy Status.lnk - c:\program files\Mozy\mozystat.exe [2008-10-06 2954544]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-01-31 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Mozy Status.lnk - c:\program files\Mozy\mozystat.exe [2008-10-06 2954544]
MozyHome Status.lnk - c:\program files\Mozy\mozystat.exe [2008-10-06 2954544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8891:TCP"= 8891:TCP:Pitbull
"50706:TCP"= 50706:TCP:PORT_50706
"41136:TCP"= 41136:TCP:PORT_41136
"58843:TCP"= 58843:TCP:PORT_58843
"45453:TCP"= 45453:TCP:PORT_45453
"46608:TCP"= 46608:TCP:PORT_46608
"24395:TCP"= 24395:TCP:PORT_24395
"58380:TCP"= 58380:TCP:PORT_58380
"12476:TCP"= 12476:TCP:PORT_12476
"44022:TCP"= 44022:TCP:PORT_44022
"23014:TCP"= 23014:TCP:PORT_23014
"61930:TCP"= 61930:TCP:PORT_61930
"46327:TCP"= 46327:TCP:PORT_46327
"34724:TCP"= 34724:TCP:PORT_34724
"19950:TCP"= 19950:TCP:PORT_19950
"49203:TCP"= 49203:TCP:PORT_49203
"23848:TCP"= 23848:TCP:PORT_23848
"48998:TCP"= 48998:TCP:PORT_48998
"53375:TCP"= 53375:TCP:PORT_53375
"40458:TCP"= 40458:TCP:PORT_40458
"6428:TCP"= 6428:TCP:PORT_6428
"37706:TCP"= 37706:TCP:PORT_37706
"47531:TCP"= 47531:TCP:PORT_47531
"46532:TCP"= 46532:TCP:PORT_46532
"32902:TCP"= 32902:TCP:PORT_32902
"17347:TCP"= 17347:TCP:PORT_17347
"17586:TCP"= 17586:TCP:PORT_17586
"26291:TCP"= 26291:TCP:PORT_26291
"55534:TCP"= 55534:TCP:PORT_55534
"41891:TCP"= 41891:TCP:PORT_41891
"48462:TCP"= 48462:TCP:PORT_48462
"18050:TCP"= 18050:TCP:PORT_18050
"31483:TCP"= 31483:TCP:PORT_31483
"33700:TCP"= 33700:TCP:PORT_33700
"31203:TCP"= 31203:TCP:PORT_31203
"43418:TCP"= 43418:TCP:PORT_43418
"24985:TCP"= 24985:TCP:PORT_24985
"19001:TCP"= 19001:TCP:PORT_19001
"42324:TCP"= 42324:TCP:PORT_42324
"10141:TCP"= 10141:TCP:PORT_10141
"15865:TCP"= 15865:TCP:PORT_15865
"36942:TCP"= 36942:TCP:PORT_36942
"30525:TCP"= 30525:TCP:PORT_30525
"41668:TCP"= 41668:TCP:PORT_41668
"46918:TCP"= 46918:TCP:PORT_46918
"34969:TCP"= 34969:TCP:PORT_34969
"31365:TCP"= 31365:TCP:PORT_31365
"46969:TCP"= 46969:TCP:PORT_46969
"24597:TCP"= 24597:TCP:PORT_24597
"20994:TCP"= 20994:TCP:PORT_20994
"41178:TCP"= 41178:TCP:PORT_41178
"28301:TCP"= 28301:TCP:PORT_28301
"59290:TCP"= 59290:TCP:PORT_59290
"24121:TCP"= 24121:TCP:PORT_24121
"57424:TCP"= 57424:TCP:PORT_57424
"44981:TCP"= 44981:TCP:PORT_44981
"58917:TCP"= 58917:TCP:PORT_58917
"19762:TCP"= 19762:TCP:PORT_19762
"13600:TCP"= 13600:TCP:PORT_13600
"50879:TCP"= 50879:TCP:PORT_50879
"25703:TCP"= 25703:TCP:PORT_25703
"25665:TCP"= 25665:TCP:PORT_25665
"61900:TCP"= 61900:TCP:PORT_61900
"39500:TCP"= 39500:TCP:PORT_39500
"20341:TCP"= 20341:TCP:PORT_20341
"19297:TCP"= 19297:TCP:PORT_19297
"38391:TCP"= 38391:TCP:PORT_38391
"49316:TCP"= 49316:TCP:PORT_49316
"59874:TCP"= 59874:TCP:PORT_59874
"37001:TCP"= 37001:TCP:PORT_37001
"53583:TCP"= 53583:TCP:PORT_53583
"16237:TCP"= 16237:TCP:PORT_16237
"64731:TCP"= 64731:TCP:PORT_64731
"20478:TCP"= 20478:TCP:PORT_20478
"9205:TCP"= 9205:TCP:PORT_9205
"21048:TCP"= 21048:TCP:PORT_21048
"13985:TCP"= 13985:TCP:PORT_13985
"17569:TCP"= 17569:TCP:PORT_17569
"39416:TCP"= 39416:TCP:PORT_39416
"64321:TCP"= 64321:TCP:PORT_64321
"5541:TCP"= 5541:TCP:PORT_5541
"11962:TCP"= 11962:TCP:PORT_11962
"17814:TCP"= 17814:TCP:PORT_17814
"23703:TCP"= 23703:TCP:PORT_23703
"30958:TCP"= 30958:TCP:PORT_30958
"56113:TCP"= 56113:TCP:PORT_56113
"57434:TCP"= 57434:TCP:PORT_57434
"6168:TCP"= 6168:TCP:PORT_6168
"46504:TCP"= 46504:TCP:PORT_46504
"33384:TCP"= 33384:TCP:PORT_33384
"56375:TCP"= 56375:TCP:PORT_56375
"51170:TCP"= 51170:TCP:PORT_51170
"19586:TCP"= 19586:TCP:PORT_19586
"25575:TCP"= 25575:TCP:PORT_25575
"42489:TCP"= 42489:TCP:PORT_42489
"48396:TCP"= 48396:TCP:PORT_48396
"31465:TCP"= 31465:TCP:PORT_31465
"10617:TCP"= 10617:TCP:PORT_10617
"65508:TCP"= 65508:TCP:PORT_65508
"33536:TCP"= 33536:TCP:PORT_33536
"38457:TCP"= 38457:TCP:PORT_38457
"10028:TCP"= 10028:TCP:PORT_10028
"36496:TCP"= 36496:TCP:PORT_36496
"7458:TCP"= 7458:TCP:PORT_7458
"37384:TCP"= 37384:TCP:PORT_37384
"10590:TCP"= 10590:TCP:PORT_10590
"45703:TCP"= 45703:TCP:PORT_45703
"36131:TCP"= 36131:TCP:PORT_36131
"22055:TCP"= 22055:TCP:PORT_22055
"22102:TCP"= 22102:TCP:PORT_22102
"21263:TCP"= 21263:TCP:PORT_21263
"57395:TCP"= 57395:TCP:PORT_57395
"48141:TCP"= 48141:TCP:PORT_48141
"54043:TCP"= 54043:TCP:PORT_54043
"47551:TCP"= 47551:TCP:PORT_47551
"20518:TCP"= 20518:TCP:PORT_20518
"28583:TCP"= 28583:TCP:PORT_28583
"25268:TCP"= 25268:TCP:PORT_25268
"40777:TCP"= 40777:TCP:PORT_40777
"26878:TCP"= 26878:TCP:PORT_26878
"40930:TCP"= 40930:TCP:PORT_40930
"22729:TCP"= 22729:TCP:PORT_22729
"23165:TCP"= 23165:TCP:PORT_23165
"14616:TCP"= 14616:TCP:PORT_14616
"12196:TCP"= 12196:TCP:PORT_12196
"29415:TCP"= 29415:TCP:PORT_29415
"28376:TCP"= 28376:TCP:PORT_28376
"23958:TCP"= 23958:TCP:PORT_23958
"8479:TCP"= 8479:TCP:PORT_8479
"7010:TCP"= 7010:TCP:PORT_7010
"28177:TCP"= 28177:TCP:PORT_28177
"17291:TCP"= 17291:TCP:PORT_17291
"55072:TCP"= 55072:TCP:PORT_55072
"17438:TCP"= 17438:TCP:PORT_17438
"12604:TCP"= 12604:TCP:PORT_12604
"25643:TCP"= 25643:TCP:PORT_25643
"56825:TCP"= 56825:TCP:PORT_56825
"49451:TCP"= 49451:TCP:PORT_49451
"42493:TCP"= 42493:TCP:PORT_42493
"11581:TCP"= 11581:TCP:PORT_11581
"62951:TCP"= 62951:TCP:PORT_62951
"53295:TCP"= 53295:TCP:PORT_53295
"9788:TCP"= 9788:TCP:PORT_9788
"59565:TCP"= 59565:TCP:PORT_59565
"40583:TCP"= 40583:TCP:PORT_40583
"14298:TCP"= 14298:TCP:PORT_14298
"47022:TCP"= 47022:TCP:PORT_47022
"61853:TCP"= 61853:TCP:PORT_61853
"56114:TCP"= 56114:TCP:PORT_56114
R1 MozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2007-02-19 53752]
R3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-26 12800]
R3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-26 10112]
R3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-26 44544]
R3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-26 201472]
R3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-26 9728]
R3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\drivers\atinewp2.sys [2006-07-14 485760]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-05 99376]
S2 713xTVCard;SAA7133 TV Card;c:\windows\system32\drivers\SAA713x.sys [2005-03-15 277504]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2007-02-25 29744]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*NewlyCreated* - GTNDIS5
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1661f93b-57a3-11da-9baa-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79be7b9c-0e07-11da-b64f-00038a000015}]
\Shell\AutoRun\command - K:\smartAP.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6572fdc-3fec-11da-94d4-806d6172696f}]
\Shell\AutoRun\command - E:\run.bat
.
Contents of the 'Scheduled Tasks' folder
2009-01-19 c:\windows\Tasks\Norton Security Online - Run Full System Scan - chullz.job
- c:\progra~1\Symantec\Norton AntiVirus\Navw32.exe [2007-01-14 03:09]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} - hxxp://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} - hxxp://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-03 17:50:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,26,b8,5e,26,00,
e0,e8,d1,e2,63,26,f1,3f,c8,ff,68,90,3b,26,5c,ae,6e,84,c4,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,82,03,46,b9,b8,
a6,76,67,6a,9c,d6,61,af,45,84,18,94,5f,6f,37,d7,a1,a9,29,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:25,da,ec,7e,55,20,c9,26,3d,3c,71,b7,9f,
dc,e9,1b,ff,7c,85,e0,43,d4,0e,fe,b5,a7,b9,1d,20,35,11,86,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,12,07,dd,0d,7f,
21,d3,4c,86,8c,21,01,be,91,eb,e7,e9,5f,c9,fe,bc,ad,42,2a,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,41,01,ad,dc,b1,
bd,5b,fd,f5,1d,4d,73,a8,13,5c,05,81,15,3b,6a,17,dc,fe,4e,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,0e,22,6d,67,b6,
56,19,8a,df,20,58,62,78,6b,cf,c8,fd,57,42,60,5d,81,ab,f8,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,71,e6,3b,c1,c4,
3e,24,3e,fb,a7,78,e6,12,2f,9a,ea,a3,8d,75,0a,b5,04,8f,49,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,fb,ef,0e,e5,32,
23,0d,a5,01,3a,48,fc,e8,04,4a,f1,90,cd,67,e4,36,b1,32,7a,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,c3,e7,d0,db,cc,
15,36,e5,f6,0f,4e,58,98,5b,89,c9,8b,cd,ea,1c,db,2c,57,9e,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,f7,7c,3e,f9,01,
9a,61,88,3d,ce,ea,26,2d,45,aa,78,db,8a,97,10,b0,21,48,0e,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,98,19,c0,41,43,
f4,2b,a7,2a,b7,cc,b5,b9,7f,41,e7,2c,b4,f2,d2,fd,82,d7,82,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\system32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,fe,e6,69,6f,c3,
9c,ba,71,6c,43,2d,1e,aa,22,2f,9c,08,f7,13,a7,0a,48,8d,4d,6c,43,2d,1e,aa,22,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(672)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-02-03 17:53:19
ComboFix-quarantined-files.txt 2009-02-03 23:52:41
ComboFix2.txt 2009-02-03 12:21:49
ComboFix3.txt 2009-02-01 21:12:58
ComboFix4.txt 2009-01-31 16:41:12
Pre-Run: 150,511,083,520 bytes free
Post-Run: 150,493,171,712 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect /usepmtimer
403 --- E O F --- 2009-01-14 09:04:25
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, February 3, 2009
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, February 04, 2009 01:13:24
Records in database: 1741956
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\
Scan statistics:
Files scanned: 72475
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 01:37:19
File name / Threat name / Threats count
D:\i386\Apps\App03130\comps\toolbar\toolbr.exe Infected: not-a-virus:AdWare.Win32.SearchIt.t 1
The selected area was scanned.
Step 1
Custom CFScript
Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
File::
D:\i386\Apps\App03130\comps\toolbar\toolbr.exe
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{79be7b9c-0e07-11da-b64f-00038a000015}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6572fdc-3fec-11da-94d4-806d6172696f}]
RegNull::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
Save this as CFScript.txt and place it on your desktop.
http://i51.photobucket.com/albums/f387/Katana_1970/CFScriptb.gif
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own. This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper
----------------------------------------------------------- -----------------------------------------------------------
Step 2
Backup the Registry
Download ERUNT (http://www.softpedia.com/get/Tweak/Registry-Tweak/Erunt-g.shtml) to your desktop
Double-click on the file to install the program
Untick the NTREGOPT desktop shortcut option
Click No when you get the option to run Erunt at Windows startup.
During the installation, tick Launch Erunt
Accept the defaults for running a backup
Erunt will then backup your registry
----------------------------------------------------------- -----------------------------------------------------------
Step 3
This step will close all the open ports that are showing in your log.
If you have any problems using your machine after this then please use the registry backup that was made in the previous step
Create A Registry File
Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the quote to Notepad.
Save it as "All Files" and name it Regfix.reg Please save it on your desktop.
REGEDIT4
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8891:TCP"=-
"50706:TCP"=-
"41136:TCP"=-
"58843:TCP"=-
"45453:TCP"=-
"46608:TCP"=-
"24395:TCP"=-
"58380:TCP"=-
"12476:TCP"=-
"44022:TCP"=-
"23014:TCP"=-
"61930:TCP"=-
"46327:TCP"=-
"34724:TCP"=-
"19950:TCP"=-
"49203:TCP"=-
"23848:TCP"=-
"48998:TCP"=-
"53375:TCP"=-
"40458:TCP"=-
"6428:TCP"=-
"37706:TCP"=-
"47531:TCP"=-
"46532:TCP"=-
"32902:TCP"=-
"17347:TCP"=-
"17586:TCP"=-
"26291:TCP"=-
"55534:TCP"=-
"41891:TCP"=-
"48462:TCP"=-
"18050:TCP"=-
"31483:TCP"=-
"33700:TCP"=-
"31203:TCP"=-
"43418:TCP"=-
"24985:TCP"=-
"19001:TCP"=-
"42324:TCP"=-
"10141:TCP"=-
"15865:TCP"=-
"36942:TCP"=-
"30525:TCP"=-
"41668:TCP"=-
"46918:TCP"=-
"34969:TCP"=-
"31365:TCP"=-
"46969:TCP"=-
"24597:TCP"=-
"20994:TCP"=-
"41178:TCP"=-
"28301:TCP"=-
"59290:TCP"=-
"24121:TCP"=-
"57424:TCP"=-
"44981:TCP"=-
"58917:TCP"=-
"19762:TCP"=-
"13600:TCP"=-
"50879:TCP"=-
"25703:TCP"=-
"25665:TCP"=-
"61900:TCP"=-
"39500:TCP"=-
"20341:TCP"=-
"19297:TCP"=-
"38391:TCP"=-
"49316:TCP"=-
"59874:TCP"=-
"37001:TCP"=-
"53583:TCP"=-
"16237:TCP"=-
"64731:TCP"=-
"20478:TCP"=-
"9205:TCP"=-
"21048:TCP"=-
"13985:TCP"=-
"17569:TCP"=-
"39416:TCP"=-
"64321:TCP"=-
"5541:TCP"=-
"11962:TCP"=-
"17814:TCP"=-
"23703:TCP"=-
"30958:TCP"=-
"56113:TCP"=-
"57434:TCP"=-
"6168:TCP"=-
"46504:TCP"=-
"33384:TCP"=-
"56375:TCP"=-
"51170:TCP"=-
"19586:TCP"=-
"25575:TCP"=-
"42489:TCP"=-
"48396:TCP"=-
"31465:TCP"=-
"10617:TCP"=-
"65508:TCP"=-
"33536:TCP"=-
"38457:TCP"=-
"10028:TCP"=-
"36496:TCP"=-
"7458:TCP"=-
"37384:TCP"=-
"10590:TCP"=-
"45703:TCP"=-
"36131:TCP"=-
"22055:TCP"=-
"22102:TCP"=-
"21263:TCP"=-
"57395:TCP"=-
"48141:TCP"=-
"54043:TCP"=-
"47551:TCP"=-
"20518:TCP"=-
"28583:TCP"=-
"25268:TCP"=-
"40777:TCP"=-
"26878:TCP"=-
"40930:TCP"=-
"22729:TCP"=-
"23165:TCP"=-
"14616:TCP"=-
"12196:TCP"=-
"29415:TCP"=-
"28376:TCP"=-
"23958:TCP"=-
"8479:TCP"=-
"7010:TCP"=-
"28177:TCP"=-
"17291:TCP"=-
"55072:TCP"=-
"17438:TCP"=-
"12604:TCP"=-
"25643:TCP"=-
"56825:TCP"=-
"49451:TCP"=-
"42493:TCP"=-
"11581:TCP"=-
"62951:TCP"=-
"53295:TCP"=-
"9788:TCP"=-
"59565:TCP"=-
"40583:TCP"=-
"14298:TCP"=-
"47022:TCP"=-
"61853:TCP"=-
"56114:TCP"=-
Make sure there are NO blank lines before REGEDIT4 and ONE blank line at the end/bottom
Double click on Regfix.reg and click Yes at the prompt
----------------------------------------------------------- -----------------------------------------------------------
Step 4
Logs/Information to Post in Reply
Please post the following logs/Information in your reply
Combofix Log
How are things running now ?
----------------------------------------------------------- -----------------------------------------------------------
Additional Notes
I recommend that you update to SP3 as soon as you can now
I performed all of the steps that you listed except installing service pack 3. The computer is working much better thank you. I thought that there was a problem, but I am pretty sure that my batteries were just low in my keyboard. I ran a HiJackthis log at that time (before I figured out about the batteries). I have included the log as well as the combofix log.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:56:29 AM, on 2/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Mozy\mozybackup.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Mozy\mozystat.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\chullz\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: TwcToolbarBhoApp Class - {AA1F9DDB-E605-4ba6-81D4-E427DEE012AD} - C:\WINDOWS\system32\TwcToolbarBho.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: AMUST 1-Login IE Helper - {FFF1A4CB-472E-404a-9898-0B73B6B2E421} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
O3 - Toolbar: AMUST 1-Login Toolbar - {F5BAA0B9-0DBF-4b42-BE9C-B2513ED71737} - C:\Program Files\AMUST\1-Login\PMIEObjects.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: The Weather Channel Toolbar - {2E5E800E-6AC0-411E-940A-369530A35E43} - C:\WINDOWS\system32\TwcToolbarIe7.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AMUST 1-Login AutoUpdate] rundll32.exe "C:\Program Files\Common Files\AMUST\Updater\amupdater.dll",AMUSTUpdate AMUST 1-Login ONLYLOCAL
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\PROGRA~1\Symantec\osCheck.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AROReminder] C:\Program Files\Advanced Registry Optimizer\aro.exe -rem
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Mozy Status.lnk = C:\Program Files\Mozy\mozystat.exe
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\Mozy\mozystat.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} (WebInstaller Control) - http://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} (WebInstaller Control) - http://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156216832609
O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://targetphoto.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photofinale.com/ImageUploader/ImageUploader4.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: MozyHome Backup Service (MozyBackup) - Unknown owner - C:\Program Files\Mozy\mozybackup.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Print Spooler (Spooler) - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: WMP54Gv4SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
--
End of file - 14029 bytes
ComboFix 09-02-04.01 - chullz 2009-02-04 21:34:46.6 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.416 [GMT -6:00]
Running from: c:\documents and settings\chullz\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\chullz\Desktop\CFScript.txt.txt
AV: Norton Security Online *On-access scanning disabled* (Updated)
FW: Norton Security Online *enabled*
* Created a new restore point
FILE ::
d:\i386\Apps\App03130\comps\toolbar\toolbr.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\i386\Apps\App03130\comps\toolbar\toolbr.exe
.
((((((((((((((((((((((((( Files Created from 2009-01-05 to 2009-02-05 )))))))))))))))))))))))))))))))
.
2009-02-03 19:20 . 2009-02-03 19:18 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-03 19:20 . 2009-02-03 19:18 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-03 05:53 . 2004-08-10 13:00 14,336 --a------ c:\windows\system32\svchost.exe
2009-02-03 05:53 . 2004-08-10 13:00 14,336 --a--c--- c:\windows\system32\dllcache\svchost.exe
2009-02-01 14:46 . 2009-02-01 13:43 3,307,596 --a------ C:\ComboFix.exe
2009-01-24 10:55 . 2009-01-24 10:55 <DIR> d-------- c:\documents and settings\chullz\Application Data\Sammsoft
2009-01-24 10:54 . 2009-01-24 10:54 <DIR> d-------- c:\program files\Advanced Registry Optimizer
2009-01-22 14:52 . 2007-06-13 04:23 1,033,216 --a--c--- c:\windows\system32\dllcache\explorer.exe
2009-01-22 14:52 . 2007-06-13 04:23 1,033,216 --a------ c:\windows\explorer.exe
2009-01-21 17:46 . 2009-01-24 08:22 <DIR> d-------- c:\program files\Coupons
2009-01-14 03:04 . 2008-12-11 05:57 333,184 --a------ c:\windows\system32\drivers\srv.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-05 03:38 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-02-04 01:18 --------- d-----w c:\program files\Java
2009-01-23 02:37 505,856 ----a-w c:\windows\system32\winlogon.exe
2009-01-23 02:37 14,336 ----a-w c:\windows\system32\lsass.exe
2009-01-23 02:37 110,080 ----a-w c:\windows\system32\services.exe
2009-01-22 00:07 --------- d-----w c:\program files\Google
2009-01-07 22:21 --------- d--h--w c:\documents and settings\chullz\Application Data\Move Networks
2009-01-06 00:49 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-06 00:49 60,808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-01-06 00:49 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-06 00:49 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-06 00:49 --------- d-----w c:\program files\Symantec
2007-11-24 19:56 58,232 ----a-w c:\documents and settings\chullz\Application Data\GDIPFONTCACHEV1.DAT
.
------- Sigcheck -------
2008-04-13 18:12 507904 ed0ef0a136dec83df69f04118870003e c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
2009-01-22 20:37 505856 e853481fef64a5be3fc3732d9d3d926a c:\windows\system32\winlogon.exe
2008-04-13 18:12 108544 0e776ed5f7cc9f94299e70461b7b8185 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\services.exe
2009-01-22 20:37 110080 5812a3513734517f8c2c5eab6b269864 c:\windows\system32\services.exe
2008-04-13 18:12 13312 bf2466b3e18e970d8a976fb95fc1ca85 c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\lsass.exe
2009-01-22 20:37 14336 c3e6b717e7b284e1fa89ba9f7a1be1ed c:\windows\system32\lsass.exe
.
((((((((((((((((((((((((((((( snapshot@2009-02-01_15.11.44.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-30 12:39:22 26,488 -c----w c:\windows\$NtUninstallKB958687$\spcustom.dll
+ 2007-11-30 12:39:22 17,272 -c----w c:\windows\$NtUninstallKB958687$\spmsg.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\$NtUninstallKB958687$\spuninst.exe
+ 2007-11-30 11:18:51 755,576 -c----w c:\windows\$NtUninstallKB958687$\update.exe
+ 2007-11-30 11:18:51 382,840 -c----w c:\windows\$NtUninstallKB958687$\updspapi.dll
- 2005-10-20 12:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
+ 2005-10-21 02:02:28 163,328 ----a-w c:\windows\ERDNT\Hiv-backup\ERDNT.EXE
- 2000-08-31 14:00:00 286,720 ----a-w c:\windows\SWREG.exe
+ 2000-08-31 14:00:00 161,792 ----a-w c:\windows\SWREG.exe
- 2008-08-28 10:04:17 333,056 ----a-w c:\windows\system32\dllcache\srv.sys
+ 2008-12-11 11:57:21 333,184 -c--a-w c:\windows\system32\dllcache\srv.sys
- 2005-03-04 16:06:58 49,248 ----a-w c:\windows\system32\java.exe
+ 2009-02-04 01:18:46 144,792 ----a-w c:\windows\system32\java.exe
- 2005-03-04 16:07:06 49,250 ----a-w c:\windows\system32\javaw.exe
+ 2009-02-04 01:18:46 144,792 ----a-w c:\windows\system32\javaw.exe
- 2005-03-04 17:36:48 127,078 ----a-w c:\windows\system32\javaws.exe
+ 2009-02-04 01:18:47 148,888 ----a-w c:\windows\system32\javaws.exe
+ 2009-02-05 02:58:22 16,384 ----atw c:\windows\temp\Perflib_Perfdata_400.dat
+ 2009-02-05 02:58:28 16,384 ----atw c:\windows\temp\Perflib_Perfdata_44c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy2]
@="{747E722C-CB46-4a9d-BDFE-192AAD5099B1}"
[HKEY_CLASSES_ROOT\CLSID\{747E722C-CB46-4a9d-BDFE-192AAD5099B1}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Mozy3]
@="{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}"
[HKEY_CLASSES_ROOT\CLSID\{EE6F5A00-7898-40f7-AB77-51FF9D6DEB20}]
2008-10-06 12:45 3044656 --a------ c:\program files\Mozy\mozyshell.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-18 68856]
"AROReminder"="c:\program files\Advanced Registry Optimizer\aro.exe" [2008-08-22 2084480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunKistEM"="c:\program files\Digital Media Reader\shwiconem.exe" [2004-11-15 135168]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\point32.exe" [2004-06-03 204800]
"AMUST 1-Login AutoUpdate"="c:\program files\Common Files\AMUST\Updater\amupdater.dll" [2006-04-11 470328]
"YOP"="c:\progra~1\Yahoo!\YOP\yop.exe" [2007-10-26 509224]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-05 98304]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-22 180269]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-08 29744]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="c:\progra~1\Symantec\osCheck.exe" [2007-01-14 771704]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-03 136600]
"CHotkey"="zHotkey.exe" [2005-05-03 c:\windows\zHotkey.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 c:\windows\system32\bthprops.cpl]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2004-08-10 c:\windows\system32\narrator.exe]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
Mozy Status.lnk - c:\program files\Mozy\mozystat.exe [2008-10-06 2954544]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-01-31 805392]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Mozy Status.lnk - c:\program files\Mozy\mozystat.exe [2008-10-06 2954544]
MozyHome Status.lnk - c:\program files\Mozy\mozystat.exe [2008-10-06 2954544]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8891:TCP"= 8891:TCP:Pitbull
"50706:TCP"= 50706:TCP:PORT_50706
"41136:TCP"= 41136:TCP:PORT_41136
"58843:TCP"= 58843:TCP:PORT_58843
"45453:TCP"= 45453:TCP:PORT_45453
"46608:TCP"= 46608:TCP:PORT_46608
"24395:TCP"= 24395:TCP:PORT_24395
"58380:TCP"= 58380:TCP:PORT_58380
"12476:TCP"= 12476:TCP:PORT_12476
"44022:TCP"= 44022:TCP:PORT_44022
"23014:TCP"= 23014:TCP:PORT_23014
"61930:TCP"= 61930:TCP:PORT_61930
"46327:TCP"= 46327:TCP:PORT_46327
"34724:TCP"= 34724:TCP:PORT_34724
"19950:TCP"= 19950:TCP:PORT_19950
"49203:TCP"= 49203:TCP:PORT_49203
"23848:TCP"= 23848:TCP:PORT_23848
"48998:TCP"= 48998:TCP:PORT_48998
"53375:TCP"= 53375:TCP:PORT_53375
"40458:TCP"= 40458:TCP:PORT_40458
"6428:TCP"= 6428:TCP:PORT_6428
"37706:TCP"= 37706:TCP:PORT_37706
"47531:TCP"= 47531:TCP:PORT_47531
"46532:TCP"= 46532:TCP:PORT_46532
"32902:TCP"= 32902:TCP:PORT_32902
"17347:TCP"= 17347:TCP:PORT_17347
"17586:TCP"= 17586:TCP:PORT_17586
"26291:TCP"= 26291:TCP:PORT_26291
"55534:TCP"= 55534:TCP:PORT_55534
"41891:TCP"= 41891:TCP:PORT_41891
"48462:TCP"= 48462:TCP:PORT_48462
"18050:TCP"= 18050:TCP:PORT_18050
"31483:TCP"= 31483:TCP:PORT_31483
"33700:TCP"= 33700:TCP:PORT_33700
"31203:TCP"= 31203:TCP:PORT_31203
"43418:TCP"= 43418:TCP:PORT_43418
"24985:TCP"= 24985:TCP:PORT_24985
"19001:TCP"= 19001:TCP:PORT_19001
"42324:TCP"= 42324:TCP:PORT_42324
"10141:TCP"= 10141:TCP:PORT_10141
"15865:TCP"= 15865:TCP:PORT_15865
"36942:TCP"= 36942:TCP:PORT_36942
"30525:TCP"= 30525:TCP:PORT_30525
"41668:TCP"= 41668:TCP:PORT_41668
"46918:TCP"= 46918:TCP:PORT_46918
"34969:TCP"= 34969:TCP:PORT_34969
"31365:TCP"= 31365:TCP:PORT_31365
"46969:TCP"= 46969:TCP:PORT_46969
"24597:TCP"= 24597:TCP:PORT_24597
"20994:TCP"= 20994:TCP:PORT_20994
"41178:TCP"= 41178:TCP:PORT_41178
"28301:TCP"= 28301:TCP:PORT_28301
"59290:TCP"= 59290:TCP:PORT_59290
"24121:TCP"= 24121:TCP:PORT_24121
"57424:TCP"= 57424:TCP:PORT_57424
"44981:TCP"= 44981:TCP:PORT_44981
"58917:TCP"= 58917:TCP:PORT_58917
"19762:TCP"= 19762:TCP:PORT_19762
"13600:TCP"= 13600:TCP:PORT_13600
"50879:TCP"= 50879:TCP:PORT_50879
"25703:TCP"= 25703:TCP:PORT_25703
"25665:TCP"= 25665:TCP:PORT_25665
"61900:TCP"= 61900:TCP:PORT_61900
"39500:TCP"= 39500:TCP:PORT_39500
"20341:TCP"= 20341:TCP:PORT_20341
"19297:TCP"= 19297:TCP:PORT_19297
"38391:TCP"= 38391:TCP:PORT_38391
"49316:TCP"= 49316:TCP:PORT_49316
"59874:TCP"= 59874:TCP:PORT_59874
"37001:TCP"= 37001:TCP:PORT_37001
"53583:TCP"= 53583:TCP:PORT_53583
"16237:TCP"= 16237:TCP:PORT_16237
"64731:TCP"= 64731:TCP:PORT_64731
"20478:TCP"= 20478:TCP:PORT_20478
"9205:TCP"= 9205:TCP:PORT_9205
"21048:TCP"= 21048:TCP:PORT_21048
"13985:TCP"= 13985:TCP:PORT_13985
"17569:TCP"= 17569:TCP:PORT_17569
"39416:TCP"= 39416:TCP:PORT_39416
"64321:TCP"= 64321:TCP:PORT_64321
"5541:TCP"= 5541:TCP:PORT_5541
"11962:TCP"= 11962:TCP:PORT_11962
"17814:TCP"= 17814:TCP:PORT_17814
"23703:TCP"= 23703:TCP:PORT_23703
"30958:TCP"= 30958:TCP:PORT_30958
"56113:TCP"= 56113:TCP:PORT_56113
"57434:TCP"= 57434:TCP:PORT_57434
"6168:TCP"= 6168:TCP:PORT_6168
"46504:TCP"= 46504:TCP:PORT_46504
"33384:TCP"= 33384:TCP:PORT_33384
"56375:TCP"= 56375:TCP:PORT_56375
"51170:TCP"= 51170:TCP:PORT_51170
"19586:TCP"= 19586:TCP:PORT_19586
"25575:TCP"= 25575:TCP:PORT_25575
"42489:TCP"= 42489:TCP:PORT_42489
"48396:TCP"= 48396:TCP:PORT_48396
"31465:TCP"= 31465:TCP:PORT_31465
"10617:TCP"= 10617:TCP:PORT_10617
"65508:TCP"= 65508:TCP:PORT_65508
"33536:TCP"= 33536:TCP:PORT_33536
"38457:TCP"= 38457:TCP:PORT_38457
"10028:TCP"= 10028:TCP:PORT_10028
"36496:TCP"= 36496:TCP:PORT_36496
"7458:TCP"= 7458:TCP:PORT_7458
"37384:TCP"= 37384:TCP:PORT_37384
"10590:TCP"= 10590:TCP:PORT_10590
"45703:TCP"= 45703:TCP:PORT_45703
"36131:TCP"= 36131:TCP:PORT_36131
"22055:TCP"= 22055:TCP:PORT_22055
"22102:TCP"= 22102:TCP:PORT_22102
"21263:TCP"= 21263:TCP:PORT_21263
"57395:TCP"= 57395:TCP:PORT_57395
"48141:TCP"= 48141:TCP:PORT_48141
"54043:TCP"= 54043:TCP:PORT_54043
"47551:TCP"= 47551:TCP:PORT_47551
"20518:TCP"= 20518:TCP:PORT_20518
"28583:TCP"= 28583:TCP:PORT_28583
"25268:TCP"= 25268:TCP:PORT_25268
"40777:TCP"= 40777:TCP:PORT_40777
"26878:TCP"= 26878:TCP:PORT_26878
"40930:TCP"= 40930:TCP:PORT_40930
"22729:TCP"= 22729:TCP:PORT_22729
"23165:TCP"= 23165:TCP:PORT_23165
"14616:TCP"= 14616:TCP:PORT_14616
"12196:TCP"= 12196:TCP:PORT_12196
"29415:TCP"= 29415:TCP:PORT_29415
"28376:TCP"= 28376:TCP:PORT_28376
"23958:TCP"= 23958:TCP:PORT_23958
"8479:TCP"= 8479:TCP:PORT_8479
"7010:TCP"= 7010:TCP:PORT_7010
"28177:TCP"= 28177:TCP:PORT_28177
"17291:TCP"= 17291:TCP:PORT_17291
"55072:TCP"= 55072:TCP:PORT_55072
"17438:TCP"= 17438:TCP:PORT_17438
"12604:TCP"= 12604:TCP:PORT_12604
"25643:TCP"= 25643:TCP:PORT_25643
"56825:TCP"= 56825:TCP:PORT_56825
"49451:TCP"= 49451:TCP:PORT_49451
"42493:TCP"= 42493:TCP:PORT_42493
"11581:TCP"= 11581:TCP:PORT_11581
"62951:TCP"= 62951:TCP:PORT_62951
"53295:TCP"= 53295:TCP:PORT_53295
"9788:TCP"= 9788:TCP:PORT_9788
"59565:TCP"= 59565:TCP:PORT_59565
"40583:TCP"= 40583:TCP:PORT_40583
"14298:TCP"= 14298:TCP:PORT_14298
"47022:TCP"= 47022:TCP:PORT_47022
"61853:TCP"= 61853:TCP:PORT_61853
"56114:TCP"= 56114:TCP:PORT_56114
R1 MozyFilter;mozyFilter;c:\windows\system32\drivers\mozy.sys [2007-02-19 53752]
R3 ATIDACXX;ATI DTV Wonder Analog Audio Capture Device;c:\windows\system32\drivers\atidacxx.sys [2005-09-26 12800]
R3 ATIDDCXX;ATI DTV Wonder Digital BDA Capture Device;c:\windows\system32\drivers\atiddcxx.sys [2005-09-26 10112]
R3 ATIDTUXX;ATI DTV Wonder Digital And Analog Tuner Device;c:\windows\system32\drivers\atidtuxx.sys [2005-09-26 44544]
R3 ATIDVCXX;ATI DTV Wonder Analog AV Capture Device;c:\windows\system32\drivers\atidvcxx.sys [2005-09-26 201472]
R3 ATIDXBXX;ATI DTV Wonder Analog AV Crossbar Device;c:\windows\system32\drivers\atidxbxx.sys [2005-09-26 9728]
R3 atinewp2;ATI eHomeWonder, WDM Video CODEC;c:\windows\system32\drivers\atinewp2.sys [2006-07-14 485760]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-05 99376]
S2 713xTVCard;SAA7133 TV Card;c:\windows\system32\drivers\SAA713x.sys [2005-03-15 277504]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2007-02-25 29744]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
*NewlyCreated* - GTNDIS5
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1661f93b-57a3-11da-9baa-806d6172696f}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
.
Contents of the 'Scheduled Tasks' folder
2009-01-19 c:\windows\Tasks\Norton Security Online - Run Full System Scan - chullz.job
- c:\progra~1\Symantec\Norton AntiVirus\Navw32.exe [2007-01-14 03:09]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.emachines.com/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &AOL Toolbar search - c:\program files\AOL Toolbar\toolbar.dll/SEARCH.HTML
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: {1FCB3C09-892F-4D11-A4F8-0ED215A5D8B3} - hxxp://concept.gamberjohnson.com/core/ext/blah/WebInstaller.ocx
DPF: {43E2397B-0735-45E3-B1AC-CE1D2A9F07A8} - hxxp://gamber.conceptconfigurator.com/core/ext/blah/WebInstaller.ocx
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-04 21:38:18
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(668)
c:\windows\system32\Ati2evxx.dll
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-02-04 21:40:43
ComboFix-quarantined-files.txt 2009-02-05 03:40:10
ComboFix2.txt 2009-02-03 23:53:22
ComboFix3.txt 2009-02-03 12:21:49
ComboFix4.txt 2009-02-01 21:12:58
ComboFix5.txt 2009-02-05 03:33:24
Pre-Run: 150,089,363,456 bytes free
Post-Run: 150,135,242,752 bytes free
355 --- E O F --- 2009-02-05 02:55:15
I performed all of the steps that you listed except installing service pack 3.
You need to update to SP3.
Fix With HJT
Close all other windows and then start HiJack This
Click Do A System Scan Only
When it has finished scanning put a check next to the following lines IF still present
O9 - Extra button: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
O9 - Extra 'Tools' menuitem: The Weather Channel - {2E5E800E-6AC0-411E-940A-369530A35E43} - (no file)
- Close ALL open windows (especially Internet Explorer!)-
Now click Fix checked
Click yes to any prompts
Close HijackThis
Are there any problems now?
Katana-
Thank you very much for all your help. I did decide to install sp3. I was hesitant due to an issue with AMD processors. I am happy so far. My computer is running great. I haven't seen any issues. I am wondering what I need to do to clean things up. I am guessing that I should run combofix with the /u switch. Also save a current system settings. On my other computers I have been running comodo firewall and spywareblaster. I plan to install these on this computer now. Any other suggestions? Again I appreciate your work.
Thanks,
grhull
Congratulations your logs look clean :)
Let's see if I can help you keep it that way
First lets tidy up
Please delete RSIT.exe and C:\RSIT (entire folder)
You can also delete any logs we have produced, and empty your Recycle bin.
Uninstall Combofix
This will clear your System Volume Information restore points and remove all the infected files that were quarantined
Click START then RUN
Now type Combofix /u in the runbox and click OK. Note the space between the X and the /U, it needs to be there.
http://i189.photobucket.com/albums/z176/EPL47/CF_Cleanup.png
----------------------------------------------------------- -----------------------------------------------------------
The following is some info to help you stay safe and clean.
You may already have some of the following programs, but I include the full list for the benefit of all the other people who will be reading this thread in the future.
( Vista users must ensure that any programs are Vista compatible BEFORE installing )
Online Scanners
I would recommend a scan at one or more of the following sites at least once a month.
http://www.pandasecurity.com/activescan
http://www.kaspersky.com/kos/eng/partner/71706/kavwebscan.html
!!! Make sure that all your programs are updated !!!
Secunia Software Inspector does all the work for you, .... see HERE (http://secunia.com/software_inspector/) for details
AntiSpyware
AntiSpyware is not the same thing as Antivirus.
Different AntiSpyware programs detect different things, so in this case it is recommended that you have more than one.
You should only have one running all the time, the other/s should be used "on demand" on a regular basis.
Most of the programs in this list have a free (for Home Users ) and paid versions,
it is worth paying for one and having "realtime" protection, unless you intend to do a manual scan often.
Spybot - Search & Destroy (http://www.safer-networking.org/) <<< A must have program It includes host protection and registry protection A hosts file is a bit like a phone book, it points to the actual numeric address (i.e. the IP address) from the human friendly name of a website. This feature can be used to block malicious websites
MalwareBytes Anti-malware (http://www.malwarebytes.org/mbam.php) <<< A New and effective program
a-squared Free (http://www.emsisoft.com/en/software/free/) <<< A good "realtime" or "on demand" scanner
superantispyware (http://www.superantispyware.com/) <<< A good "realtime" or "on demand" scanner
Prevention
These programs don't detect malware, they help stop it getting on your machine in the first place.
Each does a different job, so you can have more than one
Winpatrol (http://www.winpatrol.com) An excellent startup manager and then some !! Notifies you if programs are added to startup Allows delayed startup A must have addition
SpywareBlaster 4.0 (http://www.javacoolsoftware.com/spywareblaster.html) SpywareBlaster sets killbits in the registry to prevent known malicious activex controls from installing themselves on your computer.
SpywareGuard 2.2 (http://www.javacoolsoftware.com/spywareguard.html) SpywareGuard provides real-time protection against spyware. Not required if you have other "realtime" antispyware or Winpatrol
ZonedOut (http://www.funkytoad.com/index.php?option=com_content&view=article&id=15&Itemid=33) Formerly known as IE-SPYAD, adds a long list of sites and domains associated with known advertisers and marketers to the Restricted sites zone of Internet Explorer.
MVPS HOSTS (http://www.mvps.org/winhelp2002/hosts.zip) This little program packs a powerful punch as it blocks ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial (http://www.mvps.org/winhelp2002/hosts.htm) by WinHelp2002. Not required if you are using other host file protections
Internet Browsers
Microsoft has worked hard to make IE.7 a more secure browser, unfortunately whilst it is still the leading browser of choice it will always be under attack from the bad guys.
Using a different web browser can help stop malware getting on your machine.
Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
If you are still using IE6 then either update, or get one of the following.
FireFox (http://www.mozilla.com/en-US/firefox/) With many addons available that make customization easy this is a very popular choice NoScript and AdBlockPlus addons are essential
Opera (http://www.opera.com/) Another popular alternative
Netscape (http://browser.netscape.com/addons) Another popular alternative Also has Addons available
Cleaning Temporary Internet Files and Tracking Cookies
Temporary Internet Files are mainly the files that are downloaded when you open a web page.
Unfortunately, if the site you visit is of a dubious nature or has been hacked, they can also be an entry point for malware.
It is a good idea to empty the Temporary Internet Files folder on a regular basis.
Tracking Cookies are files that websites use to monitor which sites you visit and how often.
A lot of Antispyware scanners pick up these tracking cookies and flag them as unwanted.
CAUTION :- If you delete all your cookies you will lose any autologin information for sites that you visit, and will need your passwords
Both of these can be cleaned manually, but a quicker option is to use a program
ATF Cleaner (http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25) Free and very simple to use
CCleaner (http://www.ccleaner.com/) Free and very flexible, you can chose which cookies to keep
Also PLEASE read this article.....So How Did I Get Infected In The First Place (http://forum.malwareremoval.com/viewtopic.php?t=4959)
The last and most important thing I can tell you is UPDATE.
If you don't update your security programs (Antivirus, Antispyware even Windows) then you are at risk.
Malware changes on a day to day basis. You should update every week at the very least.
If you follow this advice then (with a bit of luck) you will never have to hear from me again :D
If you could post back one more time to let me know everything is OK, then I can have this thread archived.
Happy surfing K'
Everything is back to normal. I had an issue with a graphics driver and media center for some reason, but I got the latest driver and all is well.
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.
Note:If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.
If it has been less than four days since your last response and you need the thread re-opened, please send me or MOD a private message (pm). A valid, working link to the closed topic is required.