Page 1 of 3 123 LastLast
Results 1 to 10 of 23

Thread: Unexpected error in fixing problems

  1. #1
    Junior Member
    Join Date
    Oct 2009
    Posts
    16

    Default Unexpected error in fixing problems

    These are the results of my HijackThis scan:
    I also got these messages:
    For some reason your system denied access to the Hosts file.
    If that happens you need to edit the file yourself.
    Click Start, Run, & type
    notepad C:\WINDOWS\system32\drivers\etc\hosts
    & press Enter.
    Find the line(s) HijackThis reports & delete them.
    Save file as 'host' (with quotes) & reboot.


    You have a particularly large amount of hijacked domains. It is probably better to delete the file itself than to fix each item (& create a backup).

    If you see the same IP address in all the reported 01 items, consider deleting your Hosts file, which is located at c:\WINDOWS\system32\drivers\etc\hosts.


    As I am not familiar with this I thought I would check with someone much more knowledgeable before deleting or changing anything.

    Thank you in advance.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:48:52 PM, on 10/11/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16876)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\SMINST\Scheduler.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
    C:\Program Files\Microsoft Security Essentials\msseces.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
    C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
    C:\Program Files\Spyware Terminator\sp_rsser.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    C:\Program Files\Registry Mechanic\RegMech.exe
    C:\WINDOWS\HPLiteSaver.exe
    C:\Program Files\eFax Messenger 4.4\J2GTray.exe
    C:\Program Files\palmOne\HOTSYNC.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O1 - Hosts: 74.125.45.100 4-open-davinci.com
    O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
    O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
    O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
    O1 - Hosts: 74.125.45.100 secure-plus-payments.com
    O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
    O1 - Hosts: 64.86.17.32 google.ae
    O1 - Hosts: 64.86.17.32 google.as
    O1 - Hosts: 64.86.17.32 google.at
    O1 - Hosts: 64.86.17.32 google.az
    O1 - Hosts: 64.86.17.32 google.ba
    O1 - Hosts: 64.86.17.32 google.be
    O1 - Hosts: 64.86.17.32 google.bg
    O1 - Hosts: 64.86.17.32 google.bs
    O1 - Hosts: 64.86.17.32 google.ca
    O1 - Hosts: 64.86.17.32 google.cd
    O1 - Hosts: 64.86.17.32 google.com.gh
    O1 - Hosts: 64.86.17.32 google.com.hk
    O1 - Hosts: 64.86.17.32 google.com.jm
    O1 - Hosts: 64.86.17.32 google.com.mx
    O1 - Hosts: 64.86.17.32 google.com.my
    O1 - Hosts: 64.86.17.32 google.com.na
    O1 - Hosts: 64.86.17.32 google.com.nf
    O1 - Hosts: 64.86.17.32 google.com.ng
    O1 - Hosts: 64.86.17.32 google.ch
    O1 - Hosts: 64.86.17.32 google.com.np
    O1 - Hosts: 64.86.17.32 google.com.pr
    O1 - Hosts: 64.86.17.32 google.com.qa
    O1 - Hosts: 64.86.17.32 google.com.sg
    O1 - Hosts: 64.86.17.32 google.com.tj
    O1 - Hosts: 64.86.17.32 google.com.tw
    O1 - Hosts: 64.86.17.32 google.dj
    O1 - Hosts: 64.86.17.32 google.de
    O1 - Hosts: 64.86.17.32 google.dk
    O1 - Hosts: 64.86.17.32 google.dm
    O1 - Hosts: 64.86.17.32 google.ee
    O1 - Hosts: 64.86.17.32 google.fi
    O1 - Hosts: 64.86.17.32 google.fm
    O1 - Hosts: 64.86.17.32 google.fr
    O1 - Hosts: 64.86.17.32 google.ge
    O1 - Hosts: 64.86.17.32 google.gg
    O1 - Hosts: 64.86.17.32 google.gm
    O1 - Hosts: 64.86.17.32 google.gr
    O1 - Hosts: 64.86.17.32 google.ht
    O1 - Hosts: 64.86.17.32 google.ie
    O1 - Hosts: 64.86.17.32 google.im
    O1 - Hosts: 64.86.17.32 google.in
    O1 - Hosts: 64.86.17.32 google.it
    O1 - Hosts: 64.86.17.32 google.ki
    O1 - Hosts: 64.86.17.32 google.la
    O1 - Hosts: 64.86.17.32 google.li
    O1 - Hosts: 64.86.17.32 google.lv
    O1 - Hosts: 64.86.17.32 google.ma
    O1 - Hosts: 64.86.17.32 google.ms
    O1 - Hosts: 64.86.17.32 google.mu
    O1 - Hosts: 64.86.17.32 google.mw
    O1 - Hosts: 64.86.17.32 google.nl
    O1 - Hosts: 64.86.17.32 google.no
    O1 - Hosts: 64.86.17.32 google.nr
    O1 - Hosts: 64.86.17.32 google.nu
    O1 - Hosts: 64.86.17.32 google.pl
    O1 - Hosts: 64.86.17.32 google.pn
    O1 - Hosts: 64.86.17.32 google.pt
    O1 - Hosts: 64.86.17.32 google.ro
    O1 - Hosts: 64.86.17.32 google.ru
    O1 - Hosts: 64.86.17.32 google.rw
    O1 - Hosts: 64.86.17.32 google.sc
    O1 - Hosts: 64.86.17.32 google.se
    O1 - Hosts: 64.86.17.32 google.sh
    O1 - Hosts: 64.86.17.32 google.si
    O1 - Hosts: 64.86.17.32 google.sm
    O1 - Hosts: 64.86.17.32 google.sn
    O1 - Hosts: 64.86.17.32 google.st
    O1 - Hosts: 64.86.17.32 google.tl
    O1 - Hosts: 64.86.17.32 google.tm
    O1 - Hosts: 64.86.17.32 google.tt
    O1 - Hosts: 64.86.17.32 google.us
    O1 - Hosts: 64.86.17.32 google.vu
    O1 - Hosts: 64.86.17.32 google.ws
    O1 - Hosts: 64.86.17.32 google.co.ck
    O1 - Hosts: 64.86.17.32 google.co.id
    O1 - Hosts: 64.86.17.32 google.co.il
    O1 - Hosts: 64.86.17.32 google.co.in
    O1 - Hosts: 64.86.17.32 google.co.jp
    O1 - Hosts: 64.86.17.32 google.co.kr
    O1 - Hosts: 64.86.17.32 google.co.ls
    O1 - Hosts: 64.86.17.32 google.co.ma
    O1 - Hosts: 64.86.17.32 google.co.nz
    O1 - Hosts: 64.86.17.32 google.co.tz
    O1 - Hosts: 64.86.17.32 google.co.ug
    O1 - Hosts: 64.86.17.32 google.co.uk
    O1 - Hosts: 64.86.17.32 google.co.za
    O1 - Hosts: 64.86.17.32 google.co.zm
    O1 - Hosts: 64.86.17.32 google.com
    O1 - Hosts: 64.86.17.32 google.com.af
    O1 - Hosts: 64.86.17.32 google.com.ag
    O1 - Hosts: 64.86.17.32 google.com.ar
    O1 - Hosts: 64.86.17.32 google.com.au
    O1 - Hosts: 64.86.17.32 google.com.bn
    O1 - Hosts: 64.86.17.32 google.com.br
    O1 - Hosts: 64.86.17.32 google.com.by
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
    O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    O4 - HKLM\..\Run: [MegaPanel] C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
    O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
    O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
    O4 - HKUS\S-1-5-21-776561741-2052111302-682003330-12441\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User '?')
    O4 - HKUS\S-1-5-21-776561741-2052111302-682003330-18319\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (User '?')
    O4 - HKUS\S-1-5-21-776561741-2052111302-682003330-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O4 - Global Startup: Clean Access Agent.lnk = ?
    O4 - Global Startup: HP Display LiteSaver Startup.lnk = C:\WINDOWS\HPLiteSaver.exe
    O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: Crawler Search - tbr:iemenu
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=smb&pf=desktop
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} -
    O16 - DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} -
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase6796.cab
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} -
    O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O20 - Winlogon Notify: ShoppersHotlineWired - C:\Program Files\ShoppersHotlineWired\shls.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

    --
    End of file - 17511 bytes

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi JDKasdan

    Download HostsXpert and unzip it to your desktop.

    Open HostsXpert that you earlier unzipped on your desktop

    • Click "Make Hosts Writable?" upper right corner (if available)
    • Click "Restore Microsoft's Original Hosts File" and then click OK
    • Close HostsXpert

    Note; IF you used any custom Hosts (eg. MVPS Hosts), you will have put them back manually

    Download at your desktop DDS from one of the links below:

    Link 1
    Link 2
    • Double click the tool to run it.
    • A black Screen will open, just read the contents and do nothing.
    • When the tool finish it will open 2 reports.
    • Copy/paste both reports back here and remove DDS from your desktop.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Oct 2009
    Posts
    16

    Default

    from DDS file:


    DDS (Ver_09-10-13.01) - NTFSx86
    Run by Administrator at 21:43:10.09 on Wed 10/14/2009
    Internet Explorer: 7.0.5730.13
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2021.737 [GMT -4:00]

    AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
    FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    C:\WINDOWS\system32\svchost -k rpcss
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k NetworkService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\SMINST\Scheduler.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
    C:\Program Files\Microsoft Security Essentials\msseces.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
    C:\Program Files\Spyware Terminator\sp_rsser.exe
    C:\Program Files\Registry Mechanic\RegMech.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    C:\WINDOWS\HPLiteSaver.exe
    C:\Program Files\eFax Messenger 4.4\J2GTray.exe
    C:\Program Files\palmOne\HOTSYNC.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\WinZip\WINZIP32.EXE
    c:\Program Files\Microsoft Security Essentials\MpCmdRun.exe
    C:\Documents and Settings\Administrator\Desktop\dds.scr
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://www.comcast.net/
    uInternet Settings,ProxyOverride = *.local
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\toolbar\ctbr.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
    BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
    BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
    TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
    TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - c:\progra~1\crawler\toolbar\ctbr.dll
    uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [TomTomHOME.exe] "c:\program files\tomtom home 2\TomTomHOMERunner.exe"
    uRun: [eFax 4.4] "c:\program files\efax messenger 4.4\J2GDllCmd.exe" /R
    uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
    uRun: [SpywareTerminatorUpdate] "c:\program files\spyware terminator\SpywareTerminatorUpdate.exe"
    uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [Persistence] c:\windows\system32\igfxpers.exe
    mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
    mRun: [SoundMAX] "c:\program files\analog devices\soundmax\Smax4.exe" /tray
    mRun: [SetRefresh] c:\program files\compaq\setrefresh\SetRefresh.exe
    mRun: [Recguard] c:\windows\sminst\Recguard.exe
    mRun: [Reminder] c:\windows\creator\Remind_XP.exe
    mRun: [Scheduler] c:\windows\sminst\Scheduler.exe
    mRun: [RoxioDragToDisc] "c:\program files\roxio\drag-to-disc\DrgToDsc.exe"
    mRun: [OrderReminder] c:\program files\hewlett-packard\orderreminder\OrderReminder.exe
    mRun: [MegaPanel] c:\program files\acnielsen\homescan internet transporter\HSTrans.exe
    mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
    mRun: [Samsung PanelMgr] c:\windows\samsung\panelmgr\SSMMgr.exe /autorun
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
    mRun: [NielsenOnline] c:\program files\netratingsnetsight\netsight\NielsenOnline.exe
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
    mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [SpywareTerminator] "c:\program files\spyware terminator\SpywareTerminatorShield.exe"
    mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
    mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
    dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
    StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\efax44~1.lnk - c:\program files\efax messenger 4.4\J2GTray.exe
    StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\HOTSYNC.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ciscos~1.lnk - c:\program files\cisco systems\vpn client\vpngui.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\cleana~1.lnk - c:\program files\cisco systems\clean access agent\CCAAgentLauncher.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdisp~1.lnk - c:\windows\HPLiteSaver.exe
    IE: &AOL Toolbar Search - c:\documents and settings\all users\application data\aol\ietoolbar\resources\en-us\local\search.html
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Crawler Search - tbr:iemenu
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
    IE: {7F9DB11C-E358-4ca6-A83D-ACC663939424} - {9999A076-A9E2-4C99-8A2B-632FC9429223} - c:\program files\bonjour\ExplorerPlugin.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/E/3/9/E39C664F-A8E3-4F69-A109-1AE9849204EE/OGAControl.cab
    DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533}
    DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} - hxxp://portal.partners.org/vpn/PHSVPNPortal.CAB
    DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6796.cab
    DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
    Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
    Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\crawler\toolbar\ctbr.dll
    Notify: igfxcui - igfxdev.dll
    Notify: ShoppersHotlineWired - c:\program files\shoppershotlinewired\shls.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    IFEO: image file execution options - svchost.exe
    IFEO: init32.exe - svchost.exe
    IFEO: pctsGui.exe - svchost.exe

    ================= FIREFOX ===================

    FF - ProfilePath -
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

    ============= SERVICES / DRIVERS ===============

    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-10-4 206256]
    R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [2009-7-6 14336]
    R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2009-9-13 142592]
    R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2009-10-4 348824]
    R2 TomTomHOMEService;TomTomHOMEService;c:\program files\tomtom home 2\TomTomHOMEService.exe [2009-8-27 92008]
    R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [2008-8-6 6016]
    R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2007-1-23 36608]
    R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [2009-7-6 8832]
    S0 nielprt;Nielsen Patch Service;c:\windows\system32\drivers\nielprt.sys --> c:\windows\system32\drivers\nielprt.sys [?]
    S2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2007-2-10 29178224]
    S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys --> c:\windows\system32\drivers\SSPORT.sys [?]
    S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?]
    S3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [2009-2-11 15576]

    =============== Created Last 30 ================

    2009-10-11 18:40 <DIR> --d----- c:\program files\Trend Micro
    2009-10-09 11:40 4,778 a------- c:\windows\system32\tmp.reg
    2009-10-06 20:39 3,840 a------- c:\windows\system32\drivers\BANTExt.sys
    2009-10-06 20:39 <DIR> --d----- c:\program files\Belarc
    2009-10-04 12:52 159,600 a------- c:\windows\system32\drivers\pctgntdi.sys
    2009-10-04 12:52 206,256 a------- c:\windows\system32\drivers\PCTCore.sys
    2009-10-04 12:52 86,888 a------- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-10-04 12:52 <DIR> --d----- c:\program files\common files\PC Tools
    2009-10-04 12:52 64,392 a------- c:\windows\system32\drivers\pctplsg.sys
    2009-10-04 12:51 <DIR> --d----- c:\program files\Spyware Doctor
    2009-10-04 12:51 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC Tools
    2009-10-04 12:51 <DIR> --d----- c:\docume~1\admini~1\applic~1\PC Tools
    2009-10-01 20:00 195,440 -------- c:\windows\system32\MpSigStub.exe
    2009-10-01 19:58 <DIR> --d----- c:\program files\Microsoft Security Essentials
    2009-09-27 13:06 <DIR> --d----- c:\windows\SQL9_KB948109_ENU
    2009-09-27 13:00 <DIR> --d----- C:\f550d2eeee48e071993828ad3ceb
    2009-09-23 22:05 <DIR> --d----- c:\windows\SQL9_KB954606_ENU
    2009-09-22 23:09 <DIR> --d----- c:\windows\SQL9_KB960089_ENU
    2009-09-22 22:53 <DIR> --d----- c:\windows\system32\wbem\Repository
    2009-09-21 20:33 <DIR> --d----- c:\program files\Microsoft Easy Assist
    2009-09-21 20:32 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Applications

    ==================== Find3M ====================

    2009-09-13 23:29 142,592 a------- c:\windows\system32\drivers\sp_rsdrv2.sys
    2009-09-12 19:35 61,224 a------- c:\documents and settings\administrator\GoToAssistDownloadHelper.exe
    2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
    2009-08-13 11:16 512,000 a------- c:\windows\system32\dllcache\jscript.dll
    2009-08-06 19:24 327,896 a------- c:\windows\system32\dllcache\wucltui.dll
    2009-08-06 19:24 209,632 a------- c:\windows\system32\dllcache\wuweb.dll
    2009-08-06 19:24 35,552 a------- c:\windows\system32\dllcache\wups.dll
    2009-08-06 19:24 53,472 a------- c:\windows\system32\dllcache\wuauclt.exe
    2009-08-06 19:24 96,480 a------- c:\windows\system32\dllcache\cdm.dll
    2009-08-06 19:23 575,704 a------- c:\windows\system32\dllcache\wuapi.dll
    2009-08-06 19:23 1,929,952 a------- c:\windows\system32\dllcache\wuaueng.dll
    2009-08-06 19:23 274,288 a------- c:\windows\system32\mucltui.dll
    2009-08-06 19:23 215,920 a------- c:\windows\system32\muweb.dll
    2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
    2009-08-05 05:01 204,800 a------- c:\windows\system32\dllcache\mswebdvd.dll
    2009-08-03 15:07 403,816 a------- c:\windows\system32\OGACheckControl.dll
    2009-08-03 15:07 322,928 a------- c:\windows\system32\OGAAddin.dll
    2009-08-03 15:07 230,768 a------- c:\windows\system32\OGAEXEC.exe
    2009-07-19 09:33 3,597,824 a------- c:\windows\system32\dllcache\mshtml.dll
    2009-07-19 09:32 6,067,200 -------- c:\windows\system32\dllcache\ieframe.dll
    2009-07-17 15:01 58,880 a------- c:\windows\system32\dllcache\atl.dll
    2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
    2009-01-07 00:29 60,744 a------- c:\documents and settings\administrator\g2mdlhlpx.exe
    2009-01-01 23:34 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009010120090102\index.dat

    ============= FINISH: 21:44:18.95 ===============




    from Attach File:

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-10-13.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 7/31/2008 6:55:40 PM
    System Uptime: 10/14/2009 3:04:39 PM (6 hours ago)

    Motherboard: Hewlett-Packard | | 2820h
    Processor: Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz | XU1 PROCESSOR | 2393/800mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 65 GiB total, 37.544 GiB free.
    D: is FIXED (NTFS) - 10 GiB total, 6.576 GiB free.
    E: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318}
    Description: PS/2 Compatible Mouse
    Device ID: ACPI\PNP0F13\4&1E368A7A&0
    Manufacturer: Microsoft
    Name: PS/2 Compatible Mouse
    PNP Device ID: ACPI\PNP0F13\4&1E368A7A&0
    Service: i8042prt

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Cisco Systems VPN Adapter
    Device ID: ROOT\NET\0000
    Manufacturer: Cisco Systems
    Name: Cisco Systems VPN Adapter
    PNP Device ID: ROOT\NET\0000
    Service: CVirtA

    ==== System Restore Points ===================

    RP319: 9/7/2009 11:43:48 AM - Software Distribution Service 3.0
    RP320: 9/7/2009 1:46:26 PM - Software Distribution Service 3.0
    RP321: 9/7/2009 10:58:20 PM - Software Distribution Service 3.0
    RP322: 9/9/2009 12:15:19 AM - Software Distribution Service 3.0
    RP323: 9/9/2009 12:48:48 PM - Software Distribution Service 3.0
    RP324: 9/9/2009 10:30:26 PM - Spyware Doctor: Cleaning Threats
    RP325: 9/11/2009 10:38:05 AM - Software Distribution Service 3.0
    RP326: 9/11/2009 10:36:19 PM - Installed McAfee Virtual Technician
    RP327: 9/12/2009 1:00:08 AM - Software Distribution Service 3.0
    RP328: 9/12/2009 1:07:24 AM - Removed McAfee Virtual Technician
    RP329: 9/12/2009 3:00:32 AM - Software Distribution Service 3.0
    RP330: 9/12/2009 10:50:29 AM - Software Distribution Service 3.0
    RP331: 9/12/2009 6:53:32 PM - Cleaned registry with Windows Live OneCare safety scanner
    RP332: 9/12/2009 7:23:02 PM - Installed McAfee Virtual Technician
    RP333: 9/12/2009 8:25:26 PM - Removed McAfee Virtual Technician
    RP334: 9/12/2009 11:48:01 PM - Software Distribution Service 3.0
    RP335: 9/13/2009 12:43:14 PM - Software Distribution Service 3.0
    RP336: 9/13/2009 7:33:35 PM - Windows Defender Checkpoint
    RP337: 9/13/2009 11:38:34 PM - Spyware Terminator - restore point
    RP338: 9/14/2009 12:07:34 AM - Software Distribution Service 3.0
    RP339: 9/14/2009 3:55:12 PM - Software Distribution Service 3.0
    RP340: 9/14/2009 4:16:54 PM - Windows Defender Checkpoint
    RP341: 9/15/2009 9:23:07 PM - Software Distribution Service 3.0
    RP342: 9/16/2009 5:19:37 PM - Software Distribution Service 3.0
    RP343: 9/16/2009 6:21:34 PM - Software Distribution Service 3.0
    RP344: 9/17/2009 9:58:12 PM - Software Distribution Service 3.0
    RP345: 9/17/2009 10:07:05 PM - Software Distribution Service 3.0
    RP346: 9/18/2009 12:22:36 AM - Software Distribution Service 3.0
    RP347: 9/21/2009 6:25:02 PM - Software Distribution Service 3.0
    RP348: 9/21/2009 6:31:51 PM - Software Distribution Service 3.0
    RP349: 9/21/2009 8:33:03 PM - Installed Microsoft Easy Assist v2
    RP350: 9/21/2009 11:38:27 PM - Software Distribution Service 3.0
    RP351: 9/22/2009 8:15:19 PM - Software Distribution Service 3.0
    RP352: 9/22/2009 11:09:17 PM - Software Distribution Service 3.0
    RP353: 9/23/2009 11:44:26 AM - Software Distribution Service 3.0
    RP354: 9/23/2009 10:05:06 PM - Software Distribution Service 3.0
    RP355: 9/24/2009 7:47:54 PM - Software Distribution Service 3.0
    RP356: 9/25/2009 10:28:27 AM - Software Distribution Service 3.0
    RP357: 9/26/2009 12:12:49 AM - Software Distribution Service 3.0
    RP358: 9/27/2009 1:00:26 PM - Software Distribution Service 3.0
    RP359: 9/27/2009 1:06:13 PM - Software Distribution Service 3.0
    RP360: 9/28/2009 9:28:45 PM - Software Distribution Service 3.0
    RP361: 9/28/2009 9:33:31 PM - Software Distribution Service 3.0
    RP362: 9/28/2009 9:59:41 PM - Software Distribution Service 3.0
    RP363: 9/29/2009 10:22:22 PM - System Checkpoint
    RP364: 9/29/2009 11:44:11 PM - Software Distribution Service 3.0
    RP365: 10/1/2009 12:33:21 AM - Software Distribution Service 3.0
    RP366: 10/1/2009 8:00:32 PM - Software Distribution Service 3.0
    RP367: 10/1/2009 11:48:41 PM - Software Distribution Service 3.0
    RP368: 10/2/2009 10:54:04 AM - Software Distribution Service 3.0
    RP369: 10/2/2009 4:39:23 PM - Software Distribution Service 3.0
    RP370: 10/3/2009 2:01:47 PM - Software Distribution Service 3.0
    RP371: 10/3/2009 2:05:45 PM - Software Distribution Service 3.0
    RP372: 10/3/2009 11:31:58 PM - Removed Windows Defender
    RP373: 10/3/2009 11:34:08 PM - Removed Symantec Ghost Console Client.
    RP374: 10/4/2009 12:17:29 AM - Software Distribution Service 3.0
    RP375: 10/5/2009 8:39:52 PM - Software Distribution Service 3.0
    RP376: 10/7/2009 5:19:45 PM - Software Distribution Service 3.0
    RP377: 10/9/2009 10:36:38 AM - Software Distribution Service 3.0
    RP378: 10/11/2009 5:44:14 PM - Software Distribution Service 3.0
    RP379: 10/11/2009 6:18:12 PM - Spyware Terminator - restore point
    RP380: 10/12/2009 6:50:40 PM - System Checkpoint
    RP381: 10/13/2009 8:31:36 PM - Software Distribution Service 3.0
    RP382: 10/14/2009 9:10:05 PM - System Checkpoint

    ==== Installed Programs ======================


    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 9.1.3
    Adobe Shockwave Player 11
    Adobe® Photoshop® Album Starter Edition 3.2
    Amazon MP3 Downloader 1.0.3
    Apple Mobile Device Support
    Apple Software Update
    Audacity 1.2.6
    Belarc Advisor 8.1
    Bonjour
    Cisco
    Cisco Clean Access Agent
    Citrix XenApp Web Plugin
    Compatibility Pack for the 2007 Office system
    Crawler Toolbar with Web Security Guard
    Critical Update for Windows Media Player 11 (KB959772)
    Detto IntelliMover
    eFax Messenger
    Epocrates Essentials
    ERUNT 1.1j
    FileMaker Pro 10
    FileMaker Pro 6
    FirstClass® Client
    FTDI USB Serial Converter Drivers
    Google Toolbar for Internet Explorer
    Google Updater
    GoToMeeting 4.0.0.320
    High Definition Audio Driver Package - KB888111
    HijackThis 2.0.2
    Homescan Internet Transporter
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    HP Backup and Recovery Manager
    HP Display LiteSaver
    HP Help and Support
    HP Product Detection
    Intel(R) Graphics Media Accelerator Driver
    Intel(R) PRO Network Connections 12.1.14.1
    Intel® Management Engine Interface
    InterVideo Register Manager
    InterVideo WinDVD
    iTunes
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    LaserJet 1020 series
    LightScribe System Software 1.12.29.2
    Malwarebytes' Anti-Malware
    McAfee SecurityCenter
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Antimalware
    Microsoft Application Error Reporting
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Easy Assist v2
    Microsoft Image Composer 1.5
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    Microsoft National Language Support Downlevel APIs
    Microsoft Office 2003 Resource Kit
    Microsoft Office 2003 Web Components
    Microsoft Office 2007 Primary Interop Assemblies
    Microsoft Office 2007 Service Pack 2 (SP2)
    Microsoft Office Access MUI (English) 2007
    Microsoft Office Access Setup Metadata MUI (English) 2007
    Microsoft Office Excel MUI (English) 2007
    Microsoft Office Outlook MUI (English) 2007
    Microsoft Office PowerPoint MUI (English) 2007
    Microsoft Office Professional 2007
    Microsoft Office Professional Edition 2003
    Microsoft Office Proof (English) 2007
    Microsoft Office Proof (French) 2007
    Microsoft Office Proof (Spanish) 2007
    Microsoft Office Proofing (English) 2007
    Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    Microsoft Office Publisher MUI (English) 2007
    Microsoft Office Shared MUI (English) 2007
    Microsoft Office Shared Setup Metadata MUI (English) 2007
    Microsoft Office Small Business Connectivity Components
    Microsoft Office Word MUI (English) 2007
    Microsoft Security Essentials
    Microsoft Software Update for Web Folders (English) 12
    Microsoft SQL Server 2005
    Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
    Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
    Microsoft SQL Server Native Client
    Microsoft SQL Server Setup Support Files (English)
    Microsoft SQL Server VSS Writer
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Mozilla Firefox (3.0.11)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 6.0 Parser (KB933579)
    Nielsen//NetRatings
    OGA Notifier 2.0.0048.0
    OrderReminder HP LaserJet 1020
    Palm Desktop
    PDFCreator
    Picasa 3
    QuickTime
    RealPlayer
    Registry Mechanic 8.0
    RootsMagic 3.2.6.0
    Roxio Creator Audio
    Roxio Creator Basic v9
    Roxio Creator Copy
    Roxio Creator Data
    Roxio Creator Tools
    Roxio Drag-to-Disc
    Samsung CLP-300 Series
    SAMSUNG Dr. Printer
    Security Update for 2007 Microsoft Office System (KB969559)
    Security Update for 2007 Microsoft Office System (KB969679)
    Security Update for Microsoft Office Excel 2007 (KB969682)
    Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    Security Update for Microsoft Office Publisher 2007 (KB969693)
    Security Update for Microsoft Office system 2007 (KB969613)
    Security Update for Microsoft Office Word 2007 (KB969604)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 7 (KB972260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows Media Player 9 (KB936782)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923789)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    Sonic Activation Module
    SoundMAX
    Spelling Dictionaries Support For Adobe Reader 9
    Spybot - Search & Destroy
    Spyware Doctor 6.1
    Spyware Terminator
    TomTom HOME 2.7.2.1825
    TomTom HOME Visual Studio Merge Modules
    UltraVNC v1.0.2
    Update for 2007 Microsoft Office System (KB967642)
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft Office Outlook 2007 (KB969907)
    Update for Outlook 2007 Junk Email Filter (kb973514)
    Update for Windows XP (KB942763)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB973815)
    VPN Client
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Live OneCare safety scanner
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinZip

    ==== Event Viewer Messages From Past Week ========

    10/9/2009 12:04:49 PM, error: Service Control Manager [7024] - The SQL Server (MSSMLBIZ) service terminated with service-specific error 3417 (0xD59).
    10/9/2009 12:04:49 PM, error: Service Control Manager [7000] - The SSPORT service failed to start due to the following error: The system cannot find the file specified.
    10/9/2009 12:02:31 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    10/9/2009 12:02:26 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
    10/9/2009 11:52:10 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNASvc with arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
    10/9/2009 11:51:22 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BANTExt Fips intelppm IPSec mfehidk MpFilter MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss sp_rsdrv2 Tcpip
    10/9/2009 11:51:18 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
    10/9/2009 11:51:18 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/9/2009 11:51:18 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/9/2009 11:51:18 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    10/9/2009 11:51:18 AM, error: Service Control Manager [7001] - The Cisco Systems, Inc. VPN Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/9/2009 11:51:18 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/9/2009 11:51:18 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/9/2009 10:39:34 AM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    10/7/2009 6:23:54 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PC Tools Security Service service to connect.
    10/7/2009 6:23:54 PM, error: Service Control Manager [7000] - The PC Tools Security Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

    ==== End Of File ===========================

  4. #4
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Nothing special there.

    Please go to Kaspersky website and perform an online antivirus scan.

    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
    5. Click on My Computer under Scan.
    6. Once the scan is complete, it will display the results. Click on View Scan Report.
    7. You will see a list of infected items there. Click on Save Report As....
    8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    9. Please post this log in your next reply along with a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #5
    Junior Member
    Join Date
    Oct 2009
    Posts
    16

    Default

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Thursday, October 15, 2009
    Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Friday, October 16, 2009 00:41:07
    Records in database: 3002958
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    C:\
    D:\
    E:\

    Scan statistics:
    Objects scanned: 84422
    Threats found: 1
    Infected objects found: 1
    Suspicious objects found: 0
    Scan duration: 01:46:57


    File name / Threat / Threats count
    C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\19TJ5SU1\index[2].htm Infected: Trojan.HTML.Fraud.d 1

    Selected area has been scanned.

    ========================================================


    HIJACK THIS LOG:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:17:01 PM, on 10/15/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16876)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\SMINST\Scheduler.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
    C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\Microsoft Security Essentials\msseces.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
    C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
    c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Registry Mechanic\RegMech.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\HPLiteSaver.exe
    C:\Program Files\eFax Messenger 4.4\J2GTray.exe
    C:\Program Files\palmOne\HOTSYNC.EXE
    C:\Program Files\Spyware Terminator\sp_rsser.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O1 - Hosts: 74.125.45.100 4-open-davinci.com
    O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
    O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
    O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
    O1 - Hosts: 74.125.45.100 secure-plus-payments.com
    O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
    O1 - Hosts: 64.86.17.32 google.ae
    O1 - Hosts: 64.86.17.32 google.as
    O1 - Hosts: 64.86.17.32 google.at
    O1 - Hosts: 64.86.17.32 google.az
    O1 - Hosts: 64.86.17.32 google.ba
    O1 - Hosts: 64.86.17.32 google.be
    O1 - Hosts: 64.86.17.32 google.bg
    O1 - Hosts: 64.86.17.32 google.bs
    O1 - Hosts: 64.86.17.32 google.ca
    O1 - Hosts: 64.86.17.32 google.cd
    O1 - Hosts: 64.86.17.32 google.com.gh
    O1 - Hosts: 64.86.17.32 google.com.hk
    O1 - Hosts: 64.86.17.32 google.com.jm
    O1 - Hosts: 64.86.17.32 google.com.mx
    O1 - Hosts: 64.86.17.32 google.com.my
    O1 - Hosts: 64.86.17.32 google.com.na
    O1 - Hosts: 64.86.17.32 google.com.nf
    O1 - Hosts: 64.86.17.32 google.com.ng
    O1 - Hosts: 64.86.17.32 google.ch
    O1 - Hosts: 64.86.17.32 google.com.np
    O1 - Hosts: 64.86.17.32 google.com.pr
    O1 - Hosts: 64.86.17.32 google.com.qa
    O1 - Hosts: 64.86.17.32 google.com.sg
    O1 - Hosts: 64.86.17.32 google.com.tj
    O1 - Hosts: 64.86.17.32 google.com.tw
    O1 - Hosts: 64.86.17.32 google.dj
    O1 - Hosts: 64.86.17.32 google.de
    O1 - Hosts: 64.86.17.32 google.dk
    O1 - Hosts: 64.86.17.32 google.dm
    O1 - Hosts: 64.86.17.32 google.ee
    O1 - Hosts: 64.86.17.32 google.fi
    O1 - Hosts: 64.86.17.32 google.fm
    O1 - Hosts: 64.86.17.32 google.fr
    O1 - Hosts: 64.86.17.32 google.ge
    O1 - Hosts: 64.86.17.32 google.gg
    O1 - Hosts: 64.86.17.32 google.gm
    O1 - Hosts: 64.86.17.32 google.gr
    O1 - Hosts: 64.86.17.32 google.ht
    O1 - Hosts: 64.86.17.32 google.ie
    O1 - Hosts: 64.86.17.32 google.im
    O1 - Hosts: 64.86.17.32 google.in
    O1 - Hosts: 64.86.17.32 google.it
    O1 - Hosts: 64.86.17.32 google.ki
    O1 - Hosts: 64.86.17.32 google.la
    O1 - Hosts: 64.86.17.32 google.li
    O1 - Hosts: 64.86.17.32 google.lv
    O1 - Hosts: 64.86.17.32 google.ma
    O1 - Hosts: 64.86.17.32 google.ms
    O1 - Hosts: 64.86.17.32 google.mu
    O1 - Hosts: 64.86.17.32 google.mw
    O1 - Hosts: 64.86.17.32 google.nl
    O1 - Hosts: 64.86.17.32 google.no
    O1 - Hosts: 64.86.17.32 google.nr
    O1 - Hosts: 64.86.17.32 google.nu
    O1 - Hosts: 64.86.17.32 google.pl
    O1 - Hosts: 64.86.17.32 google.pn
    O1 - Hosts: 64.86.17.32 google.pt
    O1 - Hosts: 64.86.17.32 google.ro
    O1 - Hosts: 64.86.17.32 google.ru
    O1 - Hosts: 64.86.17.32 google.rw
    O1 - Hosts: 64.86.17.32 google.sc
    O1 - Hosts: 64.86.17.32 google.se
    O1 - Hosts: 64.86.17.32 google.sh
    O1 - Hosts: 64.86.17.32 google.si
    O1 - Hosts: 64.86.17.32 google.sm
    O1 - Hosts: 64.86.17.32 google.sn
    O1 - Hosts: 64.86.17.32 google.st
    O1 - Hosts: 64.86.17.32 google.tl
    O1 - Hosts: 64.86.17.32 google.tm
    O1 - Hosts: 64.86.17.32 google.tt
    O1 - Hosts: 64.86.17.32 google.us
    O1 - Hosts: 64.86.17.32 google.vu
    O1 - Hosts: 64.86.17.32 google.ws
    O1 - Hosts: 64.86.17.32 google.co.ck
    O1 - Hosts: 64.86.17.32 google.co.id
    O1 - Hosts: 64.86.17.32 google.co.il
    O1 - Hosts: 64.86.17.32 google.co.in
    O1 - Hosts: 64.86.17.32 google.co.jp
    O1 - Hosts: 64.86.17.32 google.co.kr
    O1 - Hosts: 64.86.17.32 google.co.ls
    O1 - Hosts: 64.86.17.32 google.co.ma
    O1 - Hosts: 64.86.17.32 google.co.nz
    O1 - Hosts: 64.86.17.32 google.co.tz
    O1 - Hosts: 64.86.17.32 google.co.ug
    O1 - Hosts: 64.86.17.32 google.co.uk
    O1 - Hosts: 64.86.17.32 google.co.za
    O1 - Hosts: 64.86.17.32 google.co.zm
    O1 - Hosts: 64.86.17.32 google.com
    O1 - Hosts: 64.86.17.32 google.com.af
    O1 - Hosts: 64.86.17.32 google.com.ag
    O1 - Hosts: 64.86.17.32 google.com.ar
    O1 - Hosts: 64.86.17.32 google.com.au
    O1 - Hosts: 64.86.17.32 google.com.bn
    O1 - Hosts: 64.86.17.32 google.com.br
    O1 - Hosts: 64.86.17.32 google.com.by
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
    O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    O4 - HKLM\..\Run: [MegaPanel] C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
    O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
    O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
    O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O4 - Global Startup: Clean Access Agent.lnk = ?
    O4 - Global Startup: HP Display LiteSaver Startup.lnk = C:\WINDOWS\HPLiteSaver.exe
    O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: Crawler Search - tbr:iemenu
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=smb&pf=desktop
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} -
    O16 - DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} (PHSVPNPortal.VPNPortalCtl) - http://portal.partners.org/vpn/PHSVPNPortal.CAB
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase6796.cab
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} -
    O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O20 - Winlogon Notify: ShoppersHotlineWired - C:\Program Files\ShoppersHotlineWired\shls.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

    --
    End of file - 17232 bytes

  6. #6
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    So it looks like that those entries are still there.


    We will continue with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
    This tool is not a toy and not for everyday use.
    ComboFix SHOULD NOT be used unless requested by a forum helper


    http://www.bleepingcomputer.com/comb...o-use-combofix

    Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    If you need help to disable your protection programs see here.

    When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #7
    Junior Member
    Join Date
    Oct 2009
    Posts
    16

    Default

    COMBOFIX LOG:
    ComboFix 09-10-16.01 - Administrator 10/16/2009 14:19.1.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2021.1260 [GMT -4:00]
    Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
    AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
    FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\recycler\S-1-5-21-1161736384-3331605628-825593446-1003
    c:\recycler\S-1-5-21-3476338949-163548128-3470668939-500
    c:\recycler\S-1-5-21-4168050975-874015638-1818117690-500
    c:\windows\Downloaded Program Files\ODCTOOLS
    c:\windows\Installer\12a774.msp
    c:\windows\Installer\14fdb01.msp
    c:\windows\Installer\1f43f7.msp
    c:\windows\Installer\287cd86.msp
    c:\windows\Installer\290d6.msi
    c:\windows\Installer\2f631c7.msp
    c:\windows\Installer\30e630.msp
    c:\windows\Installer\310fc6b.msp
    c:\windows\Installer\3fc82.msp
    c:\windows\Installer\4b206.msp
    c:\windows\Installer\4f45f.msp
    c:\windows\Installer\7032a.msp
    c:\windows\Installer\d911f2.msp
    c:\windows\Installer\f4d5ac.msp
    c:\windows\system32\tmp.reg
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((( Files Created from 2009-09-16 to 2009-10-16 )))))))))))))))))))))))))))))))
    .

    2009-10-16 15:11 . 2009-10-16 15:11 -------- d-----w- c:\windows\SQL9_KB970892_ENU
    2009-10-16 15:02 . 2009-10-16 15:02 -------- d-----w- c:\windows\SQL9_KB970895_ENU
    2009-10-11 22:40 . 2009-10-11 22:40 -------- d-----w- c:\program files\Trend Micro
    2009-10-11 22:37 . 2009-10-11 22:38 -------- d-----w- c:\program files\ERUNT
    2009-10-07 00:39 . 2009-10-07 00:39 -------- d-----w- c:\program files\Belarc
    2009-10-07 00:39 . 2008-03-06 15:51 3840 ----a-w- c:\windows\system32\drivers\BANTExt.sys
    2009-10-04 16:52 . 2008-12-11 12:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2009-10-04 16:52 . 2009-08-24 18:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2009-10-04 16:52 . 2009-08-19 15:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-10-04 16:52 . 2009-10-04 16:55 -------- d-----w- c:\program files\Common Files\PC Tools
    2009-10-04 16:52 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2009-10-04 16:51 . 2009-10-16 15:00 -------- d-----w- c:\program files\Spyware Doctor
    2009-10-04 16:51 . 2009-10-04 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2009-10-04 16:51 . 2009-10-04 16:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools
    2009-10-02 00:00 . 2009-10-01 14:29 195440 ------w- c:\windows\system32\MpSigStub.exe
    2009-10-01 23:58 . 2009-10-01 23:58 -------- d-----w- c:\program files\Microsoft Security Essentials
    2009-09-27 17:06 . 2009-09-27 17:07 -------- d-----w- c:\windows\SQL9_KB948109_ENU
    2009-09-27 17:00 . 2009-09-27 17:01 -------- d-----w- C:\f550d2eeee48e071993828ad3ceb
    2009-09-24 02:05 . 2009-09-24 02:05 -------- d-----w- c:\windows\SQL9_KB954606_ENU
    2009-09-23 03:09 . 2009-09-23 03:09 -------- d-----w- c:\windows\SQL9_KB960089_ENU
    2009-09-23 02:53 . 2009-09-23 02:53 -------- d-----w- c:\windows\system32\wbem\Repository
    2009-09-22 00:33 . 2009-09-22 00:33 -------- d-----w- c:\program files\Microsoft Easy Assist
    2009-09-22 00:32 . 2009-09-22 00:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Applications

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-10-16 18:02 . 2009-05-25 14:57 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-10-16 17:52 . 2008-08-06 14:53 -------- d-----w- c:\program files\Common Files\Adobe
    2009-10-16 15:17 . 2008-07-01 02:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-10-16 15:12 . 2008-07-01 02:13 -------- d-----w- c:\program files\Microsoft SQL Server
    2009-10-16 14:42 . 2009-09-14 03:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
    2009-10-16 14:42 . 2009-09-14 03:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\Spyware Terminator
    2009-10-12 20:56 . 2009-09-14 03:29 -------- d-----w- c:\program files\Spyware Terminator
    2009-10-09 16:20 . 2009-02-09 01:21 -------- d-----w- c:\program files\ShoppersHotlineWired
    2009-10-07 21:17 . 2009-01-02 22:45 -------- d-----w- c:\program files\palmOne
    2009-10-04 03:34 . 2008-08-07 18:10 -------- d-----w- c:\program files\Common Files\Symantec Shared
    2009-09-21 01:43 . 2009-01-11 05:03 -------- d-----w- c:\program files\Google
    2009-09-14 03:30 . 2009-09-14 03:29 -------- d-----w- c:\program files\Crawler
    2009-09-14 03:29 . 2009-09-14 03:29 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
    2009-09-14 03:22 . 2009-09-14 03:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\WinPatrol
    2009-09-14 03:22 . 2009-09-14 03:22 -------- d-----w- c:\program files\BillP Studios
    2009-09-13 22:34 . 2009-09-13 22:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
    2009-09-13 17:37 . 2009-09-13 17:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-09-13 17:33 . 2009-01-05 04:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-09-13 17:16 . 2009-01-05 04:54 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-09-13 16:47 . 2009-09-13 01:22 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2009-09-13 02:36 . 2009-09-13 01:26 -------- d-----w- c:\program files\McAfee
    2009-09-13 02:08 . 2008-08-06 18:03 -------- d-----w- c:\program files\Citrix
    2009-09-13 01:27 . 2009-09-13 01:27 -------- d-----w- c:\program files\Common Files\McAfee
    2009-09-13 01:27 . 2009-09-13 01:26 -------- d-----w- c:\program files\McAfee.com
    2009-09-12 23:35 . 2009-09-12 23:35 61224 ----a-w- c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe
    2009-09-12 21:04 . 2009-09-12 21:02 -------- d-----w- c:\program files\Windows Live Safety Center
    2009-09-12 05:15 . 2009-09-12 05:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\Office Genuine Advantage
    2009-09-12 05:09 . 2009-09-12 05:09 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
    2009-09-12 03:57 . 2009-09-12 03:57 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2009-09-12 03:57 . 2009-09-12 03:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-09-11 22:03 . 2009-09-11 21:58 -------- d-sh--w- c:\documents and settings\All Users\Application Data\f4e8cf5
    2009-09-11 14:18 . 2006-02-28 02:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-10 18:54 . 2009-09-13 17:37 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-09-10 18:53 . 2009-09-13 17:37 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-09-04 21:03 . 2006-02-28 02:00 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-08-26 08:00 . 2006-02-28 02:00 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-18 03:33 . 2009-08-18 03:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-06 23:24 . 2006-02-28 02:00 327896 ----a-w- c:\windows\system32\wucltui.dll
    2009-08-06 23:24 . 2006-02-28 02:00 209632 ----a-w- c:\windows\system32\wuweb.dll
    2009-08-06 23:24 . 2007-07-30 23:19 44768 ----a-w- c:\windows\system32\wups2.dll
    2009-08-06 23:24 . 2006-02-28 02:00 35552 ----a-w- c:\windows\system32\wups.dll
    2009-08-06 23:24 . 2006-02-28 02:00 53472 ----a-w- c:\windows\system32\wuauclt.exe
    2009-08-06 23:24 . 2006-02-28 02:00 96480 ----a-w- c:\windows\system32\cdm.dll
    2009-08-06 23:23 . 2006-02-28 02:00 575704 ----a-w- c:\windows\system32\wuapi.dll
    2009-08-06 23:23 . 2009-06-26 21:56 215920 ----a-w- c:\windows\system32\muweb.dll
    2009-08-06 23:23 . 2009-06-26 21:56 274288 ----a-w- c:\windows\system32\mucltui.dll
    2009-08-06 23:23 . 2006-02-28 02:00 1929952 ----a-w- c:\windows\system32\wuaueng.dll
    2009-08-05 09:01 . 2006-02-28 02:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-04 15:13 . 2006-02-28 02:00 2145280 ----a-w- c:\windows\system32\ntoskrnl.exe
    2009-08-04 14:20 . 2006-02-28 02:00 2023936 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2009-08-03 19:07 . 2009-08-03 19:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
    2009-08-03 19:07 . 2009-08-03 19:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
    2009-08-03 19:07 . 2009-08-03 19:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
    2009-06-03 20:31 . 2009-09-11 14:39 180224 ----a-w- c:\program files\mozilla firefox\components\nsgkff30_meter2.dll
    2008-08-16 21:42 . 2008-08-16 21:42 13112 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
    2008-08-16 21:42 . 2008-08-16 21:42 70456 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
    2008-08-16 21:42 . 2008-08-16 21:42 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
    2008-08-16 21:42 . 2008-08-16 21:42 20800 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
    2008-08-16 21:43 . 2008-08-16 21:43 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
    2008-08-16 21:42 . 2008-08-16 21:42 31032 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
    2008-08-16 21:42 . 2008-08-16 21:42 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
    2008-05-21 12:41 . 2008-05-21 12:41 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
    2008-05-21 12:41 . 2008-05-21 12:41 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
    2008-05-21 12:41 . 2008-05-21 12:41 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
    2008-06-05 17:58 . 2008-06-05 17:58 648504 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
    2008-08-16 21:42 . 2008-08-16 21:42 23864 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-01-24 2289664]
    "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-08-27 247144]
    "eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-10-07 95744]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-19 39408]
    "SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2009-09-14 3055616]
    "RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376]
    "AdobeUpdater6"="c:\program files\Common Files\Adobe\Updater6\Adobe_Updater.exe" [2009-01-08 2521464]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-07 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-07 166424]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-07 137752]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-07-10 1036288]
    "SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
    "Recguard"="c:\windows\Sminst\Recguard.exe" [2006-05-12 1138688]
    "Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-03-31 761856]
    "Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-07-10 872448]
    "RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-10-30 1116920]
    "OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
    "MegaPanel"="c:\program files\ACNielsen\Homescan Internet Transporter\HSTrans.exe" [2006-05-11 2064384]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
    "Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2007-05-30 520192]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-28 198160]
    "NielsenOnline"="c:\program files\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2009-02-25 45056]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-10 645328]
    "SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-09-14 2171904]
    "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

    c:\documents and settings\Administrator\Start Menu\Programs\Startup\
    eFax 4.4.lnk - c:\program files\eFax Messenger 4.4\J2GTray.exe [2008-10-7 656896]
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
    HotSync Manager.lnk - c:\program files\palmOne\HOTSYNC.EXE [2004-4-13 299008]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2009-1-2 1466384]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ShoppersHotlineWired]
    2009-03-26 22:16 376832 ----a-w- c:\program files\ShoppersHotlineWired\shls.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-776561741-2052111302-682003330-18319\Scripts\Logon\0\0]
    "Script"=ghsstaff.bat

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\WINDOWS\\SMINST\\Scheduler.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\palmOne\\HOTSYNC.EXE"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/4/2009 12:52 PM 206256]
    R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [7/6/2009 11:12 PM 14336]
    R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [9/13/2009 11:29 PM 142592]
    R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/27/2009 11:05 AM 92008]
    R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [8/6/2008 11:11 AM 6016]
    R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [1/23/2007 4:13 PM 36608]
    R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [7/6/2009 11:12 PM 8832]
    S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys --> c:\windows\system32\DRIVERS\nielprt.sys [?]
    S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
    S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/4/2009 12:51 PM 348824]
    S3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [2/11/2009 9:30 PM 15576]

    --- Other Services/Drivers In Memory ---

    *Deregistered* - mchInjDrv

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder

    2009-08-10 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

    2009-10-16 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-11 22:28]

    2009-09-12 c:\windows\Tasks\McAfee SecurityCenter.job
    - c:\progra~1\McAfee\MSC\mcshell.exe [2009-09-13 04:26]

    2009-09-13 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-13 01:26]

    2009-09-13 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-13 01:26]

    2009-10-16 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-07-02 21:36]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.comcast.net/
    uInternet Settings,ProxyOverride = *.local
    IE: &AOL Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Crawler Search - tbr:iemenu
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
    DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} - hxxp://portal.partners.org/vpn/PHSVPNPortal.CAB
    FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\rc5ov57n.default\
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Mozilla Firefox\plugins\npicaN.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-10-16 14:26
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(940)
    c:\program files\ShoppersHotlineWired\shls.dll
    .
    Completion time: 2009-10-16 14:29
    ComboFix-quarantined-files.txt 2009-10-16 18:28

    Pre-Run: 39,831,859,200 bytes free
    Post-Run: 40,114,012,160 bytes free

    WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

    283 --- E O F --- 2009-10-16 15:34

    ======================================================

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:39:58 PM, on 10/16/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16876)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\SMINST\Scheduler.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
    C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    C:\WINDOWS\system32\ctfmon.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
    C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\Registry Mechanic\RegMech.exe
    C:\WINDOWS\HPLiteSaver.exe
    C:\Program Files\eFax Messenger 4.4\J2GTray.exe
    C:\Program Files\palmOne\HOTSYNC.EXE
    C:\Program Files\Spyware Terminator\sp_rsser.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O1 - Hosts: 74.125.45.100 4-open-davinci.com
    O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
    O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
    O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
    O1 - Hosts: 74.125.45.100 secure-plus-payments.com
    O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
    O1 - Hosts: 64.86.17.32 google.ae
    O1 - Hosts: 64.86.17.32 google.as
    O1 - Hosts: 64.86.17.32 google.at
    O1 - Hosts: 64.86.17.32 google.az
    O1 - Hosts: 64.86.17.32 google.ba
    O1 - Hosts: 64.86.17.32 google.be
    O1 - Hosts: 64.86.17.32 google.bg
    O1 - Hosts: 64.86.17.32 google.bs
    O1 - Hosts: 64.86.17.32 google.ca
    O1 - Hosts: 64.86.17.32 google.cd
    O1 - Hosts: 64.86.17.32 google.com.gh
    O1 - Hosts: 64.86.17.32 google.com.hk
    O1 - Hosts: 64.86.17.32 google.com.jm
    O1 - Hosts: 64.86.17.32 google.com.mx
    O1 - Hosts: 64.86.17.32 google.com.my
    O1 - Hosts: 64.86.17.32 google.com.na
    O1 - Hosts: 64.86.17.32 google.com.nf
    O1 - Hosts: 64.86.17.32 google.com.ng
    O1 - Hosts: 64.86.17.32 google.ch
    O1 - Hosts: 64.86.17.32 google.com.np
    O1 - Hosts: 64.86.17.32 google.com.pr
    O1 - Hosts: 64.86.17.32 google.com.qa
    O1 - Hosts: 64.86.17.32 google.com.sg
    O1 - Hosts: 64.86.17.32 google.com.tj
    O1 - Hosts: 64.86.17.32 google.com.tw
    O1 - Hosts: 64.86.17.32 google.dj
    O1 - Hosts: 64.86.17.32 google.de
    O1 - Hosts: 64.86.17.32 google.dk
    O1 - Hosts: 64.86.17.32 google.dm
    O1 - Hosts: 64.86.17.32 google.ee
    O1 - Hosts: 64.86.17.32 google.fi
    O1 - Hosts: 64.86.17.32 google.fm
    O1 - Hosts: 64.86.17.32 google.fr
    O1 - Hosts: 64.86.17.32 google.ge
    O1 - Hosts: 64.86.17.32 google.gg
    O1 - Hosts: 64.86.17.32 google.gm
    O1 - Hosts: 64.86.17.32 google.gr
    O1 - Hosts: 64.86.17.32 google.ht
    O1 - Hosts: 64.86.17.32 google.ie
    O1 - Hosts: 64.86.17.32 google.im
    O1 - Hosts: 64.86.17.32 google.in
    O1 - Hosts: 64.86.17.32 google.it
    O1 - Hosts: 64.86.17.32 google.ki
    O1 - Hosts: 64.86.17.32 google.la
    O1 - Hosts: 64.86.17.32 google.li
    O1 - Hosts: 64.86.17.32 google.lv
    O1 - Hosts: 64.86.17.32 google.ma
    O1 - Hosts: 64.86.17.32 google.ms
    O1 - Hosts: 64.86.17.32 google.mu
    O1 - Hosts: 64.86.17.32 google.mw
    O1 - Hosts: 64.86.17.32 google.nl
    O1 - Hosts: 64.86.17.32 google.no
    O1 - Hosts: 64.86.17.32 google.nr
    O1 - Hosts: 64.86.17.32 google.nu
    O1 - Hosts: 64.86.17.32 google.pl
    O1 - Hosts: 64.86.17.32 google.pn
    O1 - Hosts: 64.86.17.32 google.pt
    O1 - Hosts: 64.86.17.32 google.ro
    O1 - Hosts: 64.86.17.32 google.ru
    O1 - Hosts: 64.86.17.32 google.rw
    O1 - Hosts: 64.86.17.32 google.sc
    O1 - Hosts: 64.86.17.32 google.se
    O1 - Hosts: 64.86.17.32 google.sh
    O1 - Hosts: 64.86.17.32 google.si
    O1 - Hosts: 64.86.17.32 google.sm
    O1 - Hosts: 64.86.17.32 google.sn
    O1 - Hosts: 64.86.17.32 google.st
    O1 - Hosts: 64.86.17.32 google.tl
    O1 - Hosts: 64.86.17.32 google.tm
    O1 - Hosts: 64.86.17.32 google.tt
    O1 - Hosts: 64.86.17.32 google.us
    O1 - Hosts: 64.86.17.32 google.vu
    O1 - Hosts: 64.86.17.32 google.ws
    O1 - Hosts: 64.86.17.32 google.co.ck
    O1 - Hosts: 64.86.17.32 google.co.id
    O1 - Hosts: 64.86.17.32 google.co.il
    O1 - Hosts: 64.86.17.32 google.co.in
    O1 - Hosts: 64.86.17.32 google.co.jp
    O1 - Hosts: 64.86.17.32 google.co.kr
    O1 - Hosts: 64.86.17.32 google.co.ls
    O1 - Hosts: 64.86.17.32 google.co.ma
    O1 - Hosts: 64.86.17.32 google.co.nz
    O1 - Hosts: 64.86.17.32 google.co.tz
    O1 - Hosts: 64.86.17.32 google.co.ug
    O1 - Hosts: 64.86.17.32 google.co.uk
    O1 - Hosts: 64.86.17.32 google.co.za
    O1 - Hosts: 64.86.17.32 google.co.zm
    O1 - Hosts: 64.86.17.32 google.com
    O1 - Hosts: 64.86.17.32 google.com.af
    O1 - Hosts: 64.86.17.32 google.com.ag
    O1 - Hosts: 64.86.17.32 google.com.ar
    O1 - Hosts: 64.86.17.32 google.com.au
    O1 - Hosts: 64.86.17.32 google.com.bn
    O1 - Hosts: 64.86.17.32 google.com.br
    O1 - Hosts: 64.86.17.32 google.com.by
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
    O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    O4 - HKLM\..\Run: [MegaPanel] C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
    O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
    O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
    O4 - HKCU\..\Run: [AdobeUpdater6] "C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe"
    O4 - HKUS\S-1-5-21-776561741-2052111302-682003330-12441\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User '?')
    O4 - HKUS\S-1-5-21-776561741-2052111302-682003330-18319\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (User '?')
    O4 - HKUS\S-1-5-21-776561741-2052111302-682003330-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O4 - Global Startup: Clean Access Agent.lnk = ?
    O4 - Global Startup: HP Display LiteSaver Startup.lnk = C:\WINDOWS\HPLiteSaver.exe
    O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: Crawler Search - tbr:iemenu
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=smb&pf=desktop
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} -
    O16 - DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} (PHSVPNPortal.VPNPortalCtl) - http://portal.partners.org/vpn/PHSVPNPortal.CAB
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase6796.cab
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} -
    O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O20 - Winlogon Notify: ShoppersHotlineWired - C:\Program Files\ShoppersHotlineWired\shls.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

    --
    End of file - 17202 bytes


    When I started the HJT scan, I got this message:
    "For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file, HJT may not be able to fix this."

    Is there anything I need to do here?

    I also got this message:
    You have a particularly amount of hijacked domains. It is probably better to delete the file itelft than to fix each item (& create a backup)>
    If you see the same IP address in the reported O1 items consider deleting your Hosts file located at: c:\WINDOWS\system32\drivers\etc\hosts.


    Is there anything I need to do here? I noticed that the IP address 74.125.45.100 comes up a number of times as does 64.86.17.32.

    Thanks!

  8. #8
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Yes hosts file has some bad entries.

    Let's try this:

    Open notepad and copy/paste the text in the codebox below into it:

    Code:
    File::
    c:\WINDOWS\system32\drivers\etc\hosts
    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.



    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.

    After that, please use hostsxpert again like instructed before and post back fresh HijackThis log and a fresh combofix log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #9
    Junior Member
    Join Date
    Oct 2009
    Posts
    16

    Default

    COMBOFIX LOG:

    ComboFix 09-10-16.09 - Administrator 10/17/2009 12:31.2.2 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2021.1279 [GMT -4:00]
    Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe
    Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
    AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
    AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
    FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

    FILE ::
    "c:\windows\system32\drivers\etc\hosts"
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\Installer\117f59d.msp
    c:\windows\Installer\4b75cf.msp
    c:\windows\system32\drivers\etc\hosts

    .
    ((((((((((((((((((((((((( Files Created from 2009-09-17 to 2009-10-17 )))))))))))))))))))))))))))))))
    .

    2009-10-16 15:11 . 2009-10-16 15:11 -------- d-----w- c:\windows\SQL9_KB970892_ENU
    2009-10-16 15:02 . 2009-10-16 15:02 -------- d-----w- c:\windows\SQL9_KB970895_ENU
    2009-10-11 22:40 . 2009-10-11 22:40 -------- d-----w- c:\program files\Trend Micro
    2009-10-11 22:37 . 2009-10-11 22:38 -------- d-----w- c:\program files\ERUNT
    2009-10-07 00:39 . 2009-10-07 00:39 -------- d-----w- c:\program files\Belarc
    2009-10-07 00:39 . 2008-03-06 15:51 3840 ----a-w- c:\windows\system32\drivers\BANTExt.sys
    2009-10-04 16:52 . 2008-12-11 12:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2009-10-04 16:52 . 2009-08-24 18:05 206256 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2009-10-04 16:52 . 2009-08-19 15:01 86888 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2009-10-04 16:52 . 2009-10-04 16:55 -------- d-----w- c:\program files\Common Files\PC Tools
    2009-10-04 16:52 . 2008-12-10 15:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2009-10-04 16:51 . 2009-10-16 15:00 -------- d-----w- c:\program files\Spyware Doctor
    2009-10-04 16:51 . 2009-10-04 16:51 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
    2009-10-04 16:51 . 2009-10-04 16:51 -------- d-----w- c:\documents and settings\Administrator\Application Data\PC Tools
    2009-10-02 00:00 . 2009-10-01 14:29 195440 ------w- c:\windows\system32\MpSigStub.exe
    2009-10-01 23:58 . 2009-10-01 23:58 -------- d-----w- c:\program files\Microsoft Security Essentials
    2009-09-27 17:06 . 2009-09-27 17:07 -------- d-----w- c:\windows\SQL9_KB948109_ENU
    2009-09-27 17:00 . 2009-09-27 17:01 -------- d-----w- C:\f550d2eeee48e071993828ad3ceb
    2009-09-24 02:05 . 2009-09-24 02:05 -------- d-----w- c:\windows\SQL9_KB954606_ENU
    2009-09-23 03:09 . 2009-09-23 03:09 -------- d-----w- c:\windows\SQL9_KB960089_ENU
    2009-09-23 02:53 . 2009-09-23 02:53 -------- d-----w- c:\windows\system32\wbem\Repository
    2009-09-22 00:33 . 2009-09-22 00:33 -------- d-----w- c:\program files\Microsoft Easy Assist
    2009-09-22 00:32 . 2009-09-22 00:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Applications

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-10-17 16:31 . 2009-05-25 14:57 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2009-10-17 15:55 . 2009-09-14 03:29 -------- d-----w- c:\documents and settings\Administrator\Application Data\Spyware Terminator
    2009-10-17 02:52 . 2008-07-01 02:13 -------- d-----w- c:\program files\Microsoft SQL Server
    2009-10-16 17:52 . 2008-08-06 14:53 -------- d-----w- c:\program files\Common Files\Adobe
    2009-10-16 15:17 . 2008-07-01 02:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
    2009-10-16 14:42 . 2009-09-14 03:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Spyware Terminator
    2009-10-12 20:56 . 2009-09-14 03:29 -------- d-----w- c:\program files\Spyware Terminator
    2009-10-09 16:20 . 2009-02-09 01:21 -------- d-----w- c:\program files\ShoppersHotlineWired
    2009-10-07 21:17 . 2009-01-02 22:45 -------- d-----w- c:\program files\palmOne
    2009-10-04 03:34 . 2008-08-07 18:10 -------- d-----w- c:\program files\Common Files\Symantec Shared
    2009-09-21 01:43 . 2009-01-11 05:03 -------- d-----w- c:\program files\Google
    2009-09-14 03:30 . 2009-09-14 03:29 -------- d-----w- c:\program files\Crawler
    2009-09-14 03:29 . 2009-09-14 03:29 142592 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys
    2009-09-14 03:22 . 2009-09-14 03:22 -------- d-----w- c:\documents and settings\Administrator\Application Data\WinPatrol
    2009-09-14 03:22 . 2009-09-14 03:22 -------- d-----w- c:\program files\BillP Studios
    2009-09-13 22:34 . 2009-09-13 22:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
    2009-09-13 17:37 . 2009-09-13 17:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2009-09-13 17:33 . 2009-01-05 04:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2009-09-13 17:16 . 2009-01-05 04:54 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2009-09-13 16:47 . 2009-09-13 01:22 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
    2009-09-13 02:36 . 2009-09-13 01:26 -------- d-----w- c:\program files\McAfee
    2009-09-13 02:08 . 2008-08-06 18:03 -------- d-----w- c:\program files\Citrix
    2009-09-13 01:27 . 2009-09-13 01:27 -------- d-----w- c:\program files\Common Files\McAfee
    2009-09-13 01:27 . 2009-09-13 01:26 -------- d-----w- c:\program files\McAfee.com
    2009-09-12 23:35 . 2009-09-12 23:35 61224 ----a-w- c:\documents and settings\Administrator\GoToAssistDownloadHelper.exe
    2009-09-12 21:04 . 2009-09-12 21:02 -------- d-----w- c:\program files\Windows Live Safety Center
    2009-09-12 05:15 . 2009-09-12 05:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\Office Genuine Advantage
    2009-09-12 05:09 . 2009-09-12 05:09 136 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\fusioncache.dat
    2009-09-12 03:57 . 2009-09-12 03:57 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
    2009-09-12 03:57 . 2009-09-12 03:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-09-11 22:03 . 2009-09-11 21:58 -------- d-sh--w- c:\documents and settings\All Users\Application Data\f4e8cf5
    2009-09-11 14:18 . 2006-02-28 02:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
    2009-09-10 18:54 . 2009-09-13 17:37 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-09-10 18:53 . 2009-09-13 17:37 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-09-04 21:03 . 2006-02-28 02:00 58880 ----a-w- c:\windows\system32\msasn1.dll
    2009-08-29 07:36 . 2006-02-28 02:00 832512 ----a-w- c:\windows\system32\wininet.dll
    2009-08-29 07:36 . 2006-02-28 02:00 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-08-29 07:36 . 2006-02-28 02:00 17408 ------w- c:\windows\system32\corpol.dll
    2009-08-26 08:00 . 2006-02-28 02:00 247326 ----a-w- c:\windows\system32\strmdll.dll
    2009-08-18 03:33 . 2009-08-18 03:33 1193832 ----a-w- c:\windows\system32\FM20.DLL
    2009-08-06 23:24 . 2006-02-28 02:00 327896 ----a-w- c:\windows\system32\wucltui.dll
    2009-08-06 23:24 . 2006-02-28 02:00 209632 ----a-w- c:\windows\system32\wuweb.dll
    2009-08-06 23:24 . 2007-07-30 23:19 44768 ----a-w- c:\windows\system32\wups2.dll
    2009-08-06 23:24 . 2006-02-28 02:00 35552 ----a-w- c:\windows\system32\wups.dll
    2009-08-06 23:24 . 2006-02-28 02:00 53472 ------w- c:\windows\system32\wuauclt.exe
    2009-08-06 23:24 . 2006-02-28 02:00 96480 ----a-w- c:\windows\system32\cdm.dll
    2009-08-06 23:23 . 2006-02-28 02:00 575704 ----a-w- c:\windows\system32\wuapi.dll
    2009-08-06 23:23 . 2009-06-26 21:56 215920 ----a-w- c:\windows\system32\muweb.dll
    2009-08-06 23:23 . 2009-06-26 21:56 274288 ----a-w- c:\windows\system32\mucltui.dll
    2009-08-06 23:23 . 2006-02-28 02:00 1929952 ----a-w- c:\windows\system32\wuaueng.dll
    2009-08-05 09:01 . 2006-02-28 02:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
    2009-08-04 15:13 . 2006-02-28 02:00 2145280 ------w- c:\windows\system32\ntoskrnl.exe
    2009-08-04 14:20 . 2006-02-28 02:00 2023936 ------w- c:\windows\system32\ntkrnlpa.exe
    2009-08-03 19:07 . 2009-08-03 19:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll
    2009-08-03 19:07 . 2009-08-03 19:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll
    2009-08-03 19:07 . 2009-08-03 19:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe
    2009-06-03 20:31 . 2009-09-11 14:39 180224 ----a-w- c:\program files\mozilla firefox\components\nsgkff30_meter2.dll
    2008-08-16 21:42 . 2008-08-16 21:42 13112 ----a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
    2008-08-16 21:42 . 2008-08-16 21:42 70456 ----a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
    2008-08-16 21:42 . 2008-08-16 21:42 91448 ----a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
    2008-08-16 21:42 . 2008-08-16 21:42 20800 ----a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
    2008-08-16 21:43 . 2008-08-16 21:43 206136 ----a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
    2008-08-16 21:42 . 2008-08-16 21:42 31032 ----a-w- c:\program files\mozilla firefox\plugins\icafile.dll
    2008-08-16 21:42 . 2008-08-16 21:42 40248 ----a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
    2008-05-21 12:41 . 2008-05-21 12:41 479232 ----a-w- c:\program files\mozilla firefox\plugins\msvcm80.dll
    2008-05-21 12:41 . 2008-05-21 12:41 548864 ----a-w- c:\program files\mozilla firefox\plugins\msvcp80.dll
    2008-05-21 12:41 . 2008-05-21 12:41 626688 ----a-w- c:\program files\mozilla firefox\plugins\msvcr80.dll
    2008-06-05 17:58 . 2008-06-05 17:58 648504 ----a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
    2008-08-16 21:42 . 2008-08-16 21:42 23864 ----a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
    .

    ((((((((((((((((((((((((((((( SnapShot@2009-10-16_18.27.13 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2006-02-28 02:00 . 2009-08-29 07:36 44544 c:\windows\system32\pngfilt.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 44544 c:\windows\system32\pngfilt.dll
    + 2007-08-13 22:54 . 2009-08-29 07:36 52224 c:\windows\system32\msfeedsbs.dll
    - 2007-08-13 22:54 . 2009-06-29 16:12 52224 c:\windows\system32\msfeedsbs.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 27648 c:\windows\system32\jsproxy.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 27648 c:\windows\system32\jsproxy.dll
    + 2007-08-13 22:39 . 2009-08-28 10:28 13824 c:\windows\system32\ieudinit.exe
    - 2007-08-13 22:39 . 2009-06-29 11:07 13824 c:\windows\system32\ieudinit.exe
    - 2006-02-28 02:00 . 2009-06-29 16:12 44544 c:\windows\system32\iernonce.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 44544 c:\windows\system32\iernonce.dll
    - 2006-02-28 02:00 . 2009-06-29 11:07 70656 c:\windows\system32\ie4uinit.exe
    + 2006-02-28 02:00 . 2009-08-28 10:28 70656 c:\windows\system32\ie4uinit.exe
    + 2007-08-13 22:36 . 2009-08-29 07:36 63488 c:\windows\system32\icardie.dll
    - 2007-08-13 22:36 . 2009-06-29 16:12 63488 c:\windows\system32\icardie.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 44544 c:\windows\system32\dllcache\pngfilt.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 44544 c:\windows\system32\dllcache\pngfilt.dll
    + 2008-08-06 14:38 . 2009-08-29 07:36 52224 c:\windows\system32\dllcache\msfeedsbs.dll
    - 2008-08-06 14:38 . 2009-06-29 16:12 52224 c:\windows\system32\dllcache\msfeedsbs.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 27648 c:\windows\system32\dllcache\jsproxy.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 27648 c:\windows\system32\dllcache\jsproxy.dll
    - 2008-08-06 14:38 . 2009-06-29 11:07 13824 c:\windows\system32\dllcache\ieudinit.exe
    + 2008-08-06 14:38 . 2009-08-28 10:28 13824 c:\windows\system32\dllcache\ieudinit.exe
    + 2006-02-28 02:00 . 2009-08-29 07:36 44544 c:\windows\system32\dllcache\iernonce.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 44544 c:\windows\system32\dllcache\iernonce.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 78336 c:\windows\system32\dllcache\ieencode.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 78336 c:\windows\system32\dllcache\ieencode.dll
    + 2006-02-28 02:00 . 2009-08-28 10:28 70656 c:\windows\system32\dllcache\ie4uinit.exe
    - 2006-02-28 02:00 . 2009-06-29 11:07 70656 c:\windows\system32\dllcache\ie4uinit.exe
    + 2008-08-06 14:38 . 2009-08-29 07:36 63488 c:\windows\system32\dllcache\icardie.dll
    - 2008-08-06 14:38 . 2009-06-29 16:12 63488 c:\windows\system32\dllcache\icardie.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 17408 c:\windows\system32\dllcache\corpol.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 17408 c:\windows\system32\dllcache\corpol.dll
    + 2008-07-31 22:45 . 2009-10-17 16:00 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    - 2008-07-31 22:45 . 2009-10-16 14:47 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
    + 2008-07-31 22:45 . 2009-10-17 16:00 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    - 2008-07-31 22:45 . 2009-10-16 14:47 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
    - 2008-07-31 22:45 . 2009-10-16 14:47 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2009-10-16 21:52 . 2009-10-17 16:00 32768 c:\windows\system32\config\systemprofile\Cookies\index.dat
    + 2009-10-17 02:55 . 2009-06-29 16:12 44544 c:\windows\ie7updates\KB974455-IE7\pngfilt.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 52224 c:\windows\ie7updates\KB974455-IE7\msfeedsbs.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 27648 c:\windows\ie7updates\KB974455-IE7\jsproxy.dll
    + 2009-10-17 02:55 . 2009-06-29 11:07 13824 c:\windows\ie7updates\KB974455-IE7\ieudinit.exe
    + 2009-10-17 02:55 . 2009-06-29 16:12 44544 c:\windows\ie7updates\KB974455-IE7\iernonce.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 78336 c:\windows\ie7updates\KB974455-IE7\ieencode.dll
    + 2009-10-17 02:55 . 2009-06-29 11:07 70656 c:\windows\ie7updates\KB974455-IE7\ie4uinit.exe
    + 2009-10-17 02:55 . 2009-06-29 16:12 63488 c:\windows\ie7updates\KB974455-IE7\icardie.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 17408 c:\windows\ie7updates\KB974455-IE7\corpol.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 233472 c:\windows\system32\webcheck.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 233472 c:\windows\system32\webcheck.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 105984 c:\windows\system32\url.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 105984 c:\windows\system32\url.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 102912 c:\windows\system32\occache.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 102912 c:\windows\system32\occache.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 671232 c:\windows\system32\mstime.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 671232 c:\windows\system32\mstime.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 193024 c:\windows\system32\msrating.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 193024 c:\windows\system32\msrating.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 477696 c:\windows\system32\mshtmled.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 477696 c:\windows\system32\mshtmled.dll
    - 2007-08-13 22:54 . 2009-06-29 16:12 459264 c:\windows\system32\msfeeds.dll
    + 2007-08-13 22:54 . 2009-08-29 07:36 459264 c:\windows\system32\msfeeds.dll
    + 2007-08-13 22:34 . 2009-08-29 07:36 268288 c:\windows\system32\iertutil.dll
    - 2007-08-13 22:34 . 2009-06-29 16:12 268288 c:\windows\system32\iertutil.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 385024 c:\windows\system32\iedkcs32.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 385024 c:\windows\system32\iedkcs32.dll
    + 2007-07-11 16:27 . 2009-08-29 07:36 380928 c:\windows\system32\ieapfltr.dll
    - 2007-07-11 16:27 . 2009-06-29 16:12 380928 c:\windows\system32\ieapfltr.dll
    - 2006-02-28 02:00 . 2009-06-29 08:33 161792 c:\windows\system32\ieakui.dll
    + 2006-02-28 02:00 . 2009-08-27 05:18 161792 c:\windows\system32\ieakui.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 230400 c:\windows\system32\ieaksie.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 230400 c:\windows\system32\ieaksie.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 153088 c:\windows\system32\ieakeng.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 153088 c:\windows\system32\ieakeng.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 133120 c:\windows\system32\extmgr.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 133120 c:\windows\system32\extmgr.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 214528 c:\windows\system32\dxtrans.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 214528 c:\windows\system32\dxtrans.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 347136 c:\windows\system32\dxtmsft.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 347136 c:\windows\system32\dxtmsft.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 832512 c:\windows\system32\dllcache\wininet.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 233472 c:\windows\system32\dllcache\webcheck.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 233472 c:\windows\system32\dllcache\webcheck.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 105984 c:\windows\system32\dllcache\url.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 105984 c:\windows\system32\dllcache\url.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 102912 c:\windows\system32\dllcache\occache.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 102912 c:\windows\system32\dllcache\occache.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 671232 c:\windows\system32\dllcache\mstime.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 671232 c:\windows\system32\dllcache\mstime.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 193024 c:\windows\system32\dllcache\msrating.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 193024 c:\windows\system32\dllcache\msrating.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 477696 c:\windows\system32\dllcache\mshtmled.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 477696 c:\windows\system32\dllcache\mshtmled.dll
    + 2008-08-06 14:38 . 2009-08-29 07:36 459264 c:\windows\system32\dllcache\msfeeds.dll
    - 2008-08-06 14:38 . 2009-06-29 16:12 459264 c:\windows\system32\dllcache\msfeeds.dll
    + 2006-02-28 02:00 . 2009-08-27 05:18 634648 c:\windows\system32\dllcache\iexplore.exe
    - 2008-08-06 14:38 . 2009-06-29 16:12 268288 c:\windows\system32\dllcache\iertutil.dll
    + 2008-08-06 14:38 . 2009-08-29 07:36 268288 c:\windows\system32\dllcache\iertutil.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 385024 c:\windows\system32\dllcache\iedkcs32.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 385024 c:\windows\system32\dllcache\iedkcs32.dll
    - 2008-08-06 14:38 . 2009-06-29 16:12 380928 c:\windows\system32\dllcache\ieapfltr.dll
    + 2008-08-06 14:38 . 2009-08-29 07:36 380928 c:\windows\system32\dllcache\ieapfltr.dll
    - 2006-02-28 02:00 . 2009-06-29 08:33 161792 c:\windows\system32\dllcache\ieakui.dll
    + 2006-02-28 02:00 . 2009-08-27 05:18 161792 c:\windows\system32\dllcache\ieakui.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 230400 c:\windows\system32\dllcache\ieaksie.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 230400 c:\windows\system32\dllcache\ieaksie.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 153088 c:\windows\system32\dllcache\ieakeng.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 153088 c:\windows\system32\dllcache\ieakeng.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 133120 c:\windows\system32\dllcache\extmgr.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 133120 c:\windows\system32\dllcache\extmgr.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 214528 c:\windows\system32\dllcache\dxtrans.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 214528 c:\windows\system32\dllcache\dxtrans.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 347136 c:\windows\system32\dllcache\dxtmsft.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 347136 c:\windows\system32\dllcache\dxtmsft.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 124928 c:\windows\system32\dllcache\advpack.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 124928 c:\windows\system32\dllcache\advpack.dll
    - 2006-02-28 02:00 . 2009-06-29 16:12 124928 c:\windows\system32\advpack.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 124928 c:\windows\system32\advpack.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 827392 c:\windows\ie7updates\KB974455-IE7\wininet.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 233472 c:\windows\ie7updates\KB974455-IE7\webcheck.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 105984 c:\windows\ie7updates\KB974455-IE7\url.dll
    + 2009-10-17 02:56 . 2009-05-26 11:40 382840 c:\windows\ie7updates\KB974455-IE7\spuninst\updspapi.dll
    + 2009-10-17 02:56 . 2009-05-26 11:40 231288 c:\windows\ie7updates\KB974455-IE7\spuninst\spuninst.exe
    + 2009-10-17 02:55 . 2009-06-29 16:12 102912 c:\windows\ie7updates\KB974455-IE7\occache.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 671232 c:\windows\ie7updates\KB974455-IE7\mstime.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 193024 c:\windows\ie7updates\KB974455-IE7\msrating.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 477696 c:\windows\ie7updates\KB974455-IE7\mshtmled.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 459264 c:\windows\ie7updates\KB974455-IE7\msfeeds.dll
    + 2009-10-17 02:55 . 2009-06-29 08:35 634632 c:\windows\ie7updates\KB974455-IE7\iexplore.exe
    + 2009-10-17 02:55 . 2009-06-29 16:12 268288 c:\windows\ie7updates\KB974455-IE7\iertutil.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 385024 c:\windows\ie7updates\KB974455-IE7\iedkcs32.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 380928 c:\windows\ie7updates\KB974455-IE7\ieapfltr.dll
    + 2009-10-17 02:55 . 2009-06-29 08:33 161792 c:\windows\ie7updates\KB974455-IE7\ieakui.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 230400 c:\windows\ie7updates\KB974455-IE7\ieaksie.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 153088 c:\windows\ie7updates\KB974455-IE7\ieakeng.dll
    + 2009-10-17 02:56 . 2009-06-29 16:12 133120 c:\windows\ie7updates\KB974455-IE7\extmgr.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 214528 c:\windows\ie7updates\KB974455-IE7\dxtrans.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 347136 c:\windows\ie7updates\KB974455-IE7\dxtmsft.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 124928 c:\windows\ie7updates\KB974455-IE7\advpack.dll
    + 2009-10-17 15:54 . 2009-10-17 15:54 376832 c:\windows\ERDNT\AutoBackup\10-17-2009\Users\00000002\UsrClass.dat
    + 2009-10-17 15:54 . 2005-10-20 16:02 163328 c:\windows\ERDNT\AutoBackup\10-17-2009\ERDNT.EXE
    + 2006-02-28 02:00 . 2009-08-29 07:36 1168384 c:\windows\system32\urlmon.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 3598336 c:\windows\system32\mshtml.dll
    + 2007-08-13 22:54 . 2009-08-29 07:36 6067200 c:\windows\system32\ieframe.dll
    - 2007-08-13 22:54 . 2009-07-19 13:32 6067200 c:\windows\system32\ieframe.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 1168384 c:\windows\system32\dllcache\urlmon.dll
    + 2006-02-28 02:00 . 2009-08-29 07:36 3598336 c:\windows\system32\dllcache\mshtml.dll
    - 2008-08-06 14:38 . 2009-07-19 13:32 6067200 c:\windows\system32\dllcache\ieframe.dll
    + 2008-08-06 14:38 . 2009-08-29 07:36 6067200 c:\windows\system32\dllcache\ieframe.dll
    + 2009-10-17 02:55 . 2009-06-29 16:12 1159680 c:\windows\ie7updates\KB974455-IE7\urlmon.dll
    + 2009-10-17 02:55 . 2009-07-19 13:33 3597824 c:\windows\ie7updates\KB974455-IE7\mshtml.dll
    + 2009-10-17 02:55 . 2009-07-19 13:32 6067200 c:\windows\ie7updates\KB974455-IE7\ieframe.dll
    + 2009-10-17 15:54 . 2009-10-17 15:54 9728000 c:\windows\ERDNT\AutoBackup\10-17-2009\Users\00000001\NTUSER.DAT
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-01-24 2289664]
    "TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2009-08-27 247144]
    "eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" [2008-10-07 95744]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-19 39408]
    "SpywareTerminatorUpdate"="c:\program files\Spyware Terminator\SpywareTerminatorUpdate.exe" [2009-09-14 3055616]
    "RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2009-06-30 2836376]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-07 141848]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-07 166424]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-07 137752]
    "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-07-10 1036288]
    "SetRefresh"="c:\program files\Compaq\SetRefresh\SetRefresh.exe" [2003-11-20 525824]
    "Recguard"="c:\windows\Sminst\Recguard.exe" [2006-05-12 1138688]
    "Reminder"="c:\windows\Creator\Remind_XP.exe" [2006-03-31 761856]
    "Scheduler"="c:\windows\SMINST\Scheduler.exe" [2006-07-10 872448]
    "RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-10-30 1116920]
    "OrderReminder"="c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 98304]
    "MegaPanel"="c:\program files\ACNielsen\Homescan Internet Transporter\HSTrans.exe" [2006-05-11 2064384]
    "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
    "Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2007-05-30 520192]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
    "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-06-28 198160]
    "NielsenOnline"="c:\program files\NetRatingsNetSight\NetSight\NielsenOnline.exe" [2009-02-25 45056]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
    "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-07-10 645328]
    "SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2009-09-14 2171904]
    "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2009-09-13 1048392]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]

    c:\documents and settings\Administrator\Start Menu\Programs\Startup\
    eFax 4.4.lnk - c:\program files\eFax Messenger 4.4\J2GTray.exe [2008-10-7 656896]
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
    HotSync Manager.lnk - c:\program files\palmOne\HOTSYNC.EXE [2004-4-13 299008]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Cisco Systems VPN Client.lnk - c:\program files\Cisco Systems\VPN Client\vpngui.exe [2009-1-2 1466384]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ShoppersHotlineWired]
    2009-03-26 22:16 376832 ----a-w- c:\program files\ShoppersHotlineWired\shls.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-776561741-2052111302-682003330-18319\Scripts\Logon\0\0]
    "Script"=ghsstaff.bat

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
    @=""

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\WINDOWS\\SMINST\\Scheduler.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\palmOne\\HOTSYNC.EXE"=
    "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
    "c:\\Program Files\\Spyware Terminator\\SpywareTerminatorUpdate.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

    R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [10/4/2009 12:52 PM 206256]
    R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [7/6/2009 11:12 PM 14336]
    R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [9/13/2009 11:29 PM 142592]
    R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [8/27/2009 11:05 AM 92008]
    R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [8/6/2008 11:11 AM 6016]
    R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [1/23/2007 4:13 PM 36608]
    R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [7/6/2009 11:12 PM 8832]
    S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys --> c:\windows\system32\DRIVERS\nielprt.sys [?]
    S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys --> c:\windows\system32\Drivers\SSPORT.sys [?]
    S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?]
    S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [10/4/2009 12:51 PM 348824]
    S3 Wdm1;USB Bridge Cable Driver;c:\windows\system32\drivers\usbbc.sys [2/11/2009 9:30 PM 15576]

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe"
    .
    Contents of the 'Scheduled Tasks' folder

    2009-08-10 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

    2009-10-17 c:\windows\Tasks\Google Software Updater.job
    - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-11 22:28]

    2009-09-12 c:\windows\Tasks\McAfee SecurityCenter.job
    - c:\progra~1\McAfee\MSC\mcshell.exe [2009-09-13 04:26]

    2009-09-13 c:\windows\Tasks\McDefragTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-13 01:26]

    2009-09-13 c:\windows\Tasks\McQcTask.job
    - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-09-13 01:26]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.comcast.net/
    uInternet Settings,ProxyOverride = *.local
    IE: &AOL Toolbar Search - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Crawler Search - tbr:iemenu
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    Trusted Zone: internet
    Trusted Zone: mcafee.com
    Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
    DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} - hxxp://portal.partners.org/vpn/PHSVPNPortal.CAB
    FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\rc5ov57n.default\
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-10-17 12:35
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------

    [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,79,00,73,00,\
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(940)
    c:\program files\ShoppersHotlineWired\shls.dll
    .
    Completion time: 2009-10-17 12:37
    ComboFix-quarantined-files.txt 2009-10-17 16:37
    ComboFix2.txt 2009-10-16 18:29

    Pre-Run: 39,847,305,216 bytes free
    Post-Run: 39,868,792,832 bytes free

    416 --- E O F --- 2009-10-16 19:01

    ======================================================

    HIJACK THIS LOG:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:40:58 PM, on 10/17/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16915)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    C:\Program Files\McAfee\MPF\MPFSrv.exe
    C:\Program Files\Spyware Terminator\sp_rsser.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\SMINST\Scheduler.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
    C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
    C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
    C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\HPLiteSaver.exe
    C:\Program Files\eFax Messenger 4.4\J2GTray.exe
    C:\Program Files\palmOne\HOTSYNC.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SetRefresh] C:\Program Files\Compaq\SetRefresh\SetRefresh.exe
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\Sminst\Recguard.exe
    O4 - HKLM\..\Run: [Reminder] C:\WINDOWS\Creator\Remind_XP.exe
    O4 - HKLM\..\Run: [Scheduler] C:\WINDOWS\SMINST\Scheduler.exe
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [OrderReminder] C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe
    O4 - HKLM\..\Run: [MegaPanel] C:\Program Files\ACNielsen\Homescan Internet Transporter\HSTrans.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe /autorun
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [NielsenOnline] C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
    O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [SpywareTerminatorUpdate] "C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe"
    O4 - HKCU\..\Run: [RegistryMechanic] C:\Program Files\Registry Mechanic\RegMech.exe /H
    O4 - HKUS\S-1-5-21-776561741-2052111302-682003330-12441\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden (User '?')
    O4 - HKUS\S-1-5-21-776561741-2052111302-682003330-18319\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (User '?')
    O4 - HKUS\S-1-5-21-776561741-2052111302-682003330-500\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Startup: HotSync Manager.lnk = C:\Program Files\palmOne\HOTSYNC.EXE
    O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
    O4 - Global Startup: Clean Access Agent.lnk = ?
    O4 - Global Startup: HP Display LiteSaver Startup.lnk = C:\WINDOWS\HPLiteSaver.exe
    O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
    O8 - Extra context menu item: Crawler Search - tbr:iemenu
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=smb&pf=desktop
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} -
    O16 - DPF: {225781F3-B27C-4182-83F1-CBF79247D36B} (PHSVPNPortal.VPNPortalCtl) - http://portal.partners.org/vpn/PHSVPNPortal.CAB
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase6796.cab
    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} -
    O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O20 - Winlogon Notify: ShoppersHotlineWired - C:\Program Files\ShoppersHotlineWired\shls.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
    O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: PC Angel (PCA) - SoftThinks - C:\WINDOWS\SMINST\PCAngel.exe
    O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
    O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe

    --
    End of file - 12976 bytes

  10. #10
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Looks better

    I'd like you to check a file for malware.

    C:\Program Files\ShoppersHotlineWired\shls.dll
    • Copy/Paste the first file on the list into the white Upload a file box.
    • Click Send/Submit, and the file will upload to VirusTotal/Jotti, where it will be scanned by several anti-virus programmes.
    • After a while, a window will open, with details of what the scans found.
    • Save the complete results in a Notepad/Word document on your desktop.
    • Post back results here, please.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •