Avast Log, Combofix, (2)Mbamlogs, HJT
AVAST
5/15/2003 12:00:51 AM SYSTEM 1196 Function setifaceUpdatePackages() has failed. Return code is 0x2000001D, dwRes is 2000001D.
5/15/2003 12:04:35 AM SYSTEM 1352 Function setifaceUpdatePackages() has failed. Return code is 0x2000001D, dwRes is 2000001D.
5/15/2003 12:43:26 AM SYSTEM 1388 Function setifaceUpdatePackages() has failed. Return code is 0x2000001D, dwRes is 2000001D.
5/15/2003 12:46:26 AM SYSTEM 1400 Function setifaceUpdatePackages() has failed. Return code is 0x2000001D, dwRes is 2000001D.
9/28/2008 12:36:38 PM SYSTEM 1172 Function setifaceUpdatePackages() has failed. Return code is 0x2000001A, dwRes is 2000001A.
11/2/2008 9:34:32 AM SYSTEM 1472 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
11/7/2008 7:55:17 PM SYSTEM 1724 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\shareddocs\TNTMeetingAttendees20081016.pdf (\\Hppavilion\shareddocs\TNTMeetingAttendees20081016.pdf) returning error, 00000005.
11/9/2008 7:33:16 PM SYSTEM 1564 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
11/9/2008 7:38:51 PM SYSTEM 1676 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
11/15/2008 9:11:20 AM SYSTEM 1636 Function setifaceUpdatePackages() has failed. Return code is 0x20000006, dwRes is 20000006.
11/15/2008 4:08:32 PM SYSTEM 1632 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
11/15/2008 4:08:33 PM SYSTEM 1632 An error has occured while attempting to update. Please check the logs.
11/15/2008 8:27:38 PM SYSTEM 1632 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
11/15/2008 8:27:39 PM SYSTEM 1632 An error has occured while attempting to update. Please check the logs.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\000_0001.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\000_0001.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\000_0006.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\000_0006.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\000_0009.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\000_0009.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0365.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0365.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0366.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0366.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0367.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0367.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0368.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0368.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0370.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0370.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0371.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0371.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0486.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\3905 Woodreed Leak\100_0486.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0636.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0636.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0637.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0637.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0638.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0638.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0639.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0639.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0640.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas 6th Grade Awards\100_0640.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0602.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0602.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0603.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0603.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0607.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0607.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0611.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0611.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0612.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0612.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0613.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0613.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0614.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0614.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0615.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Staishas Wall of Shame\100_0615.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0498.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0498.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0499.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0499.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0502.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0502.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0503.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0503.jpg) returning error, 00000005.
11/23/2008 5:36:18 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0504.jpg (C:\Documents and Settings\All Users\Documents\My Pictures\Kodak Pictures\Winniconne\100_0504.jpg) returning error, 00000005.
11/23/2008 5:41:56 PM SYSTEM 1436 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT (C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT) returning error, 00000005.
11/25/2008 11:30:38 PM SYSTEM 1592 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\HPPAVILION\Owner\Desktop\ksa fac loc.doc (\\HPPAVILION\Owner\Desktop\ksa fac loc.doc) returning error, 00000005.
11/25/2008 11:32:44 PM SYSTEM 1592 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\Desktop\ksa inv loc.doc (\\Hppavilion\owner\Desktop\ksa inv loc.doc) returning error, 00000005.
12/1/2008 12:30:44 PM SYSTEM 1592 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\My Documents\METRO\Checkstubs2008\20081125.pdf (\\Hppavilion\owner\My Documents\METRO\Checkstubs2008\20081125.pdf) returning error, 00000005.
12/1/2008 12:32:17 PM SYSTEM 1592 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\My Documents\METRO\Checkstubs2008\20081125.pdf (\\Hppavilion\owner\My Documents\METRO\Checkstubs2008\20081125.pdf) returning error, 00000005.
12/1/2008 12:52:41 PM SYSTEM 1592 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\My Documents\METRO\Checkstubs2008\Shortcut to 20081125.tiff.lnk (\\Hppavilion\owner\My Documents\METRO\Checkstubs2008\Shortcut to 20081125.tiff.lnk) returning error, 00000005.
12/1/2008 12:58:14 PM SYSTEM 1592 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\My Documents\METRO\Checkstubs2008\20081125.pdf (\\Hppavilion\owner\My Documents\METRO\Checkstubs2008\20081125.pdf) returning error, 00000005.
12/1/2008 1:05:22 PM SYSTEM 1592 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\My Documents\METRO\Checkstubs2008\20081125.pdf (\\Hppavilion\owner\My Documents\METRO\Checkstubs2008\20081125.pdf) returning error, 00000005.
12/5/2008 11:38:14 AM SYSTEM 1536 Sign of "VBS:Malware-gen" has been found in "http://www.awesomevideoz.com/m6/movie1.php?id=1632\http:\\www.awesomevideoz.com\m6\movie1" file.
12/5/2008 11:38:31 AM SYSTEM 1536 Sign of "VBS:Malware-gen" has been found in "http://www.awesomevideoz.com/m6/movie1.php?id=1632\http:\\www.awesomevideoz.com\m6\movie1" file.
12/18/2008 4:42:22 AM SYSTEM 1584 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
12/18/2008 4:44:28 AM SYSTEM 1400 Function setifaceUpdateFiles() has failed. Return code is 0xC0000142, dwRes is C0000142.
12/23/2008 12:37:55 PM SYSTEM 1384 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT (C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT) returning error, 00000005.
1/8/2009 10:11:32 PM SYSTEM 1404 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: D:\Adobe Acrobat 6.0 Professional\setup.exe (D:\Adobe Acrobat 6.0 Professional\setup.exe) returning error, 0000001E.
1/23/2009 2:11:03 PM SYSTEM 1576 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
1/23/2009 2:11:03 PM SYSTEM 1576 An error has occured while attempting to update. Please check the logs.
2/4/2009 11:29:20 AM mc 1432 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\My Documents\METRO\BusRouteDescriptions\~WRD1104.tmp (\\Hppavilion\owner\My Documents\METRO\BusRouteDescriptions\~WRD1104.tmp) returning error, 0000A420.
2/28/2009 8:13:02 PM SYSTEM 1396 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT (C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT) returning error, 00000005.
2/28/2009 11:47:40 PM SYSTEM 1396 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT (C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT) returning error, 00000005.
3/22/2009 8:44:26 PM SYSTEM 1496 Function setifaceUpdateFiles() has failed. Return code is 0xC0000142, dwRes is C0000142.
3/22/2009 8:44:27 PM SYSTEM 1496 An error has occured while attempting to update. Please check the logs.
4/9/2009 11:57:35 AM SYSTEM 1592 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT (C:\DOCUMENTS AND SETTINGS\MC\APPLICATION DATA\MICROSOFT\TEMPLATES\NORMAL.DOT) returning error, 00000005.
4/25/2009 10:57:57 PM SYSTEM 1428 Sign of "JS

acked-AA [Trj]" has been found in "http://www.nearear.org/" file.
5/17/2009 10:41:56 AM ¸ 1456 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
5/21/2009 12:59:06 AM SYSTEM 1508 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
5/21/2009 4:59:11 AM SYSTEM 1508 Function setifaceUpdatePackages() has failed. Return code is 0xC0000142, dwRes is C0000142.
5/24/2009 9:58:20 PM SYSTEM 1576 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
6/2/2009 8:00:33 PM SYSTEM 1456 Function setifaceUpdatePackages() has failed. Return code is 0x00000008, dwRes is 00000008.
6/2/2009 8:00:34 PM SYSTEM 1456 An error has occured while attempting to update. Please check the logs.
6/28/2009 5:28:12 PM SYSTEM 1608 Function setifaceUpdatePackages() has failed. Return code is 0x00000008, dwRes is 00000008.
6/28/2009 5:28:13 PM SYSTEM 1608 An error has occured while attempting to update. Please check the logs.
7/11/2009 7:41:19 PM SYSTEM 1652 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\My Documents\RealEstate\DrGlenn\Kentbury\Disclosures.pdf (\\Hppavilion\owner\My Documents\RealEstate\DrGlenn\Kentbury\Disclosures.pdf) returning error, 00000035.
7/12/2009 2:20:10 AM SYSTEM 1652 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\MC\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\XLCUNM54\LIBCORE[1].JS (C:\DOCUMENTS AND SETTINGS\MC\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\XLCUNM54\LIBCORE[1].JS) returning error, 00000005.
7/12/2009 11:01:16 AM SYSTEM 1652 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\DOCUMENTS AND SETTINGS\MC\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\7VP9QNSO\EXPANSION_EMBED[1].JS (C:\DOCUMENTS AND SETTINGS\MC\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\7VP9QNSO\EXPANSION_EMBED[1].JS) returning error, 00000005.
7/12/2009 6:03:07 PM SYSTEM 1652 Function setifaceUpdatePackages() has failed. Return code is 0x00000008, dwRes is 00000008.
7/12/2009 6:03:09 PM SYSTEM 1652 An error has occured while attempting to update. Please check the logs.
7/19/2009 5:06:41 PM SYSTEM 1616 Sign of "JS

dfka-JS [Expl]" has been found in "http://ef2tr.cn/traff2/pdf.php?spl=pdf_ie2\{gzip}" file.
8/15/2009 7:32:52 AM SYSTEM 1636 Function setifaceUpdatePackages() has failed. Return code is 0x20000004, dwRes is 20000004.
8/18/2009 12:15:27 AM SYSTEM 1616 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\My Documents\RealEstate\Trinkaus\BuyersAgree.pdf (\\Hppavilion\owner\My Documents\RealEstate\Trinkaus\BuyersAgree.pdf) returning error, 00000035.
8/22/2009 9:46:21 AM SYSTEM 1632 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: C:\System Volume Information\_restore{978D1590-02AB-4DC1-9A42-F70E49674C3D}\RP315\A0037285.msi (C:\System Volume Information\_restore{978D1590-02AB-4DC1-9A42-F70E49674C3D}\RP315\A0037285.msi) returning error, 0000A413.
8/27/2009 5:59:19 PM SYSTEM 1632 Function setifaceUpdatePackages() has failed. Return code is 0x00000008, dwRes is 00000008.
8/27/2009 5:59:20 PM SYSTEM 1632 An error has occured while attempting to update. Please check the logs.
8/28/2009 9:07:02 PM SYSTEM 1644 Sign of "Win32:LdPinch-CYW [Trj]" has been found in "C:\WINDOWS\srpira1251508020.eXE" file.
8/28/2009 9:07:49 PM SYSTEM 1644 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\XLCUNM54\prx90[1].exe" file.
8/28/2009 9:08:02 PM SYSTEM 1644 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\DOCUME~1\mc\LOCALS~1\Temp\zazodin_1251514400.exe" file.
8/28/2009 9:24:36 PM SYSTEM 1644 AAVM - scanning warning: x_AavmCheckFileDirectEx [UNI]: \\Hppavilion\owner\My Documents\SOFCC\Ushers MOH\UsherInfoDoc.xls (\\Hppavilion\owner\My Documents\SOFCC\Ushers MOH\UsherInfoDoc.xls) returning error, 00000035.
8/28/2009 9:43:15 PM SYSTEM 1632 Sign of "JS:FakeAV-W [Trj]" has been found in "http://plamet.info/?uid=13300" file.
8/28/2009 11:45:35 PM SYSTEM 1276 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/29/2009 9:27:33 AM SYSTEM 1624 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/29/2009 9:57:38 AM SYSTEM 1624 Sign of "JS:FakeAV-W [Trj]" has been found in "http://scarre.info/?uid=13300" file.
8/29/2009 1:59:51 PM SYSTEM 1628 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/29/2009 2:00:09 PM SYSTEM 1628 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\87PF0U1M\index[1].htm" file.
8/29/2009 5:33:18 PM SYSTEM 1284 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/29/2009 6:18:21 PM SYSTEM 1284 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/29/2009 6:18:30 PM SYSTEM 1284 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/29/2009 6:18:30 PM SYSTEM 1284 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\BU0JWT3U\index[1].htm" file.
8/29/2009 6:33:20 PM SYSTEM 1284 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/29/2009 7:18:24 PM SYSTEM 1284 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/29/2009 7:18:50 PM SYSTEM 1284 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\1DAYC5BI\index[1].htm" file.
8/29/2009 7:18:50 PM SYSTEM 1284 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/29/2009 7:33:27 PM SYSTEM 1284 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/29/2009 8:18:27 PM SYSTEM 1284 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/29/2009 8:35:11 PM SYSTEM 1284 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\IZ94IKT3\index[1].htm" file.
8/29/2009 8:58:13 PM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/29/2009 9:43:17 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/29/2009 9:43:19 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\IZ94IKT3\index[1].htm" file.
8/29/2009 9:58:15 PM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/29/2009 10:43:45 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/29/2009 10:44:04 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\BU0JWT3U\index[1].htm" file.
8/29/2009 11:04:59 PM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/30/2009 1:35:15 PM SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "http://sighal.info/?uid=13300" file.
8/30/2009 7:50:34 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/30/2009 7:50:36 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\XLCUNM54\index[1].htm" file.
8/30/2009 8:05:33 PM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/30/2009 8:35:35 PM SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "http://outliv.info/?uid=13300" file.
8/30/2009 8:50:36 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/30/2009 8:50:37 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\XE3CY1AE\index[1].htm" file.
8/30/2009 9:05:35 PM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/30/2009 9:35:38 PM SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "http://outliv.info/?uid=13300" file.
8/30/2009 9:50:39 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://visualsecuritysupply.com/index.php?affid=12400" file.
8/30/2009 9:50:40 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "C:\Documents and Settings\mc\Local Settings\Temporary Internet Files\Content.IE5\7VP9QNSO\index[2].htm" file.
8/30/2009 10:05:38 PM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/31/2009 4:36:05 PM SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "http://gelded.info/?uid=13300" file.
8/31/2009 4:50:56 PM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/31/2009 5:05:54 PM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
8/31/2009 11:36:19 PM SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "http://orodes.info/?uid=13300" file.
9/1/2009 6:11:57 AM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
9/1/2009 6:26:57 AM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
9/1/2009 6:57:02 AM SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "http://fosset.info/?uid=13300" file.
9/1/2009 4:42:16 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://securitytoolworld.com/index.php?affid=12400" file.
9/1/2009 4:57:13 PM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
9/1/2009 9:07:28 PM SYSTEM 1636 Sign of "JS:FakeAV-W [Trj]" has been found in "http://polear.info/?uid=13300" file.
9/1/2009 9:22:34 PM SYSTEM 1636 Sign of "JS:FakeAV-AH [Trj]" has been found in "http://securitytoolworld.com/index.php?affid=12400" file.
9/2/2009 6:37:29 AM SYSTEM 1636 Sign of "JS:ScriptIP-inf [Trj]" has been found in "http://61.235.117.83/redirectsoft/popup/" file.
9/2/2009 8:18:33 PM SYSTEM 1284 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\webserver\webserver.exe" file.
9/3/2009 2:26:21 AM SYSTEM 1628 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\webserver\webserver.exe" file.
9/3/2009 6:23:48 PM SYSTEM 1628 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\webserver\webserver.exe" file.
COMBOFIX
ComboFix 09-09-02.02 - mc 09/03/2009 1:51.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.639.239 [GMT -4:00]
Running from: c:\documents and settings\mc\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\mc\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1351 [VPS 090902-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
file zipped: c:\windows\ectbbyn.dat
file zipped: c:\windows\ex1234.dat
file zipped: c:\windows\ex23567.dat
file zipped: c:\windows\mmsmark2.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\ectbbyn.dat
c:\windows\ex1234.dat
c:\windows\ex23567.dat
c:\windows\mmsmark2.dat
.
((((((((((((((((((((((((( Files Created from 2009-08-03 to 2009-09-03 )))))))))))))))))))))))))))))))
.
2009-08-29 23:56 . 2009-08-29 23:56 -------- d-----w- c:\program files\WOT
2009-08-29 13:51 . 2009-08-29 15:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-29 13:51 . 2009-08-29 13:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-29 13:45 . 2009-08-29 13:45 -------- d-----w- c:\program files\Trend Micro
2009-08-29 03:38 . 2007-10-09 17:13 38144 ----a-w- c:\windows\system32\drivers\EAPPkt.sys
2009-08-29 01:07 . 2009-08-29 01:07 -------- d-----w- c:\program files\webserver
2009-08-13 02:12 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-12 02:22 . 2009-08-26 19:27 -------- d-----w- c:\documents and settings\mc\Local Settings\Application Data\Temp
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 03:54 . 2008-11-12 01:45 -------- d-----w- c:\program files\REALTEK
2009-08-29 03:49 . 2008-06-07 19:44 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-24 03:09 . 2008-11-02 19:09 -------- d-----w- c:\documents and settings\mc\Application Data\U3
2009-08-17 16:10 . 2003-05-20 17:13 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2003-05-20 17:14 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2003-05-20 17:14 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2003-05-20 17:14 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2003-05-20 17:14 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2003-05-20 17:14 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2003-05-20 17:14 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2003-05-20 17:14 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2003-05-20 17:14 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-05 09:01 . 2004-08-04 12:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2004-08-04 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-12 03:01 . 2008-11-06 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-07-10 09:30 . 2009-01-24 22:04 -------- d-----w- c:\documents and settings\mc\Application Data\AdobeUM
2009-06-29 16:12 . 2004-08-04 12:00 827392 ------w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2004-08-04 12:00 17408 ------w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2004-08-04 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 12:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 12:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 12:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 12:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2004-08-04 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-12 12:31 . 2004-08-04 12:00 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2004-08-04 12:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2004-08-04 12:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2003-06-09 06:55 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2004-08-04 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-09-03_00.11.15 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-03 00:18 . 2009-09-03 00:18 16384 c:\windows\Temp\Perflib_Perfdata_504.dat
+ 2004-08-04 12:00 . 2009-09-03 00:27 72248 c:\windows\system32\perfc009.dat
- 2004-08-04 12:00 . 2009-09-02 23:51 72248 c:\windows\system32\perfc009.dat
+ 2004-08-04 12:00 . 2009-09-03 00:27 444156 c:\windows\system32\perfh009.dat
- 2004-08-04 12:00 . 2009-09-02 23:51 444156 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-03-04 39408]
"Google Update"="c:\documents and settings\mc\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-30 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-08-13 335872]
"Acronis*True*Image Monitor"="c:\program files\Acronis\TrueImage\TrueImageMonitor.exe" [2008-06-07 471637]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-06-07 65536]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Acrobat Assistant 8.0"="e:\program files\Adobe\Acrobat 8 Standard\Acrobat\Acrotray.exe" [2008-10-15 623992]
"AdobeVersionCue"="e:\program files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe" [2003-10-13 1732608]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"ATIModeChange"="Ati2mdxx.exe" - c:\windows\system32\Ati2mdxx.exe [2001-09-04 28672]
"PCTVOICE"="pctspk.exe" - c:\windows\system32\pctspk.exe [2002-07-18 163840]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-24 110592]
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-7-7 282624]
Microtek Scanner Finder.lnk - c:\program files\Microtek\ScanWizard 5\ScannerFinder.exe [2009-1-5 344064]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"53:TCP"= 53:TCP:webserver
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [5/20/2003 1:14 PM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [5/20/2003 1:14 PM 20560]
R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [8/28/2009 11:38 PM 38144]
S3 SCM488C;SCM Microsystems SCR120 PCMCIA Smart Card Reader;c:\windows\system32\drivers\pscr.sys [5/15/2003 3:13 PM 16128]
S3 wldel48b;Dell TrueMobile 1150 Series PCCard Driver;c:\windows\system32\drivers\wldel48b.sys [11/24/2008 11:46 AM 171520]
.
Contents of the 'Scheduled Tasks' folder
2009-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-20 00:24]
2009-09-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-20 00:24]
2009-09-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1060284298-1957994488-1003Core.job
- c:\documents and settings\mc\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-12 23:32]
2009-09-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1060284298-1957994488-1003UA.job
- c:\documents and settings\mc\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-12 23:32]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to existing PDF - e:\program files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - e:\program files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - e:\program files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - e:\program files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - e:\program files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - e:\program files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - e:\program files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - e:\program files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Web-Based Email Tools - hxxp://email04.secureserver.net/Download.CAB
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
FF - ProfilePath - c:\documents and settings\mc\Application Data\Mozilla\Firefox\Profiles\j5gsmim8.default\
FF - plugin: c:\documents and settings\mc\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPJPI142.dll
FF - plugin: c:\program files\Java\j2re1.4.2\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-03 02:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-515967899-1060284298-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5F862D6E-AF30-1B61-CFCD-1A2EC8579B38}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"oadilggdmaaedbgfhpfchablidkihp"=hex:6a,61,70,69,69,70,6c,6a,6b,66,63,64,66,70,
69,6d,63,67,63,63,00,f5
"nabjbglpgjahpoejijcomoolbcin"=hex:6a,61,70,69,69,70,6c,6a,6b,66,63,64,66,70,
69,6d,63,67,63,63,00,f5
[HKEY_USERS\S-1-5-21-515967899-1060284298-1957994488-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-515967899-1060284298-1957994488-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000004
"State"=dword:00000003
[HKEY_USERS\S-1-5-21-515967899-1060284298-1957994488-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000003
"State"=dword:00000003
[HKEY_USERS\S-1-5-21-515967899-1060284298-1957994488-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000002
"State"=dword:00000007
[HKEY_USERS\S-1-5-21-515967899-1060284298-1957994488-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\Outlook]
"Name"="Outlook"
"DisplayName"="Microsoft Outlook"
"Param1"="Outlook"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(588)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2009-09-03 2:22
ComboFix-quarantined-files.txt 2009-09-03 06:21
ComboFix2.txt 2009-09-03 00:13
Pre-Run: 3,815,690,240 bytes free
Post-Run: 3,755,454,464 bytes free
219 --- E O F --- 2009-08-30 02:46
Upload was successful
MALWAREBYTES #1 (aborted when noticed it ran past some directories that I knew were infected - AVAST was still running at this time)
Malwarebytes' Anti-Malware 1.40
Database version: 2743
Windows 5.1.2600 Service Pack 3
9/5/2009 7:27:14 AM
mbam-log-2009-09-05 (07-27-14).txt
Scan type: Full Scan (C:\|E:\|)
Objects scanned: 70532
Time elapsed: 8 hour(s), 20 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Qoobox\Quarantine\C\WINDOWS\pp11.exe.vir (Worm.Koobface) -> Quarantined and deleted successfully.
MALWAREBYTES LOG #2 (after turning off AVAST and disabling internet connection)
Malwarebytes' Anti-Malware 1.40
Database version: 2744
Windows 5.1.2600 Service Pack 3
9/5/2009 9:24:44 AM
mbam-log-2009-09-05 (09-24-44).txt
Scan type: Full Scan (C:\|E:\|)
Objects scanned: 185121
Time elapsed: 43 minute(s), 4 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\System Volume Information\_restore{978D1590-02AB-4DC1-9A42-F70E49674C3D}\RP325\A0037813.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{978D1590-02AB-4DC1-9A42-F70E49674C3D}\RP325\A0037814.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{978D1590-02AB-4DC1-9A42-F70E49674C3D}\RP325\A0037815.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{978D1590-02AB-4DC1-9A42-F70E49674C3D}\RP330\A0038084.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\WINDOWS\0535251103110107106.yux (KoobFace.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\vkl_1251508045 (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\vkl_1251509640 (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\vkl_1251518040 (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\vkl_1251518452 (Trojan.DNSChanger) -> Quarantined and deleted successfully.
FRESH HJT LOG
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:36:32 AM, on 9/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\pctspk.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\Acrotray.exe
E:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\mc\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\WINDOWS\system32\wuauclt.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Acronis*True*Image Monitor] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [AdobeVersionCue] E:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\mc\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to existing PDF - res://E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 8 Standard\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Web-Based Email Tools -
http://email04.secureserver.net/Download.CAB
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
https://activatemydsl.verizon.net/sdcCommon/download/DSL/Verizon High Speed Internet Installer.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) -
http://picasaweb.google.com/s/v/50.13/uploader2.cab
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) -
http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.1.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) -
http://www.evite.com/html/imageUpload/ImageUploader5.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1055142896196
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228828719226
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2) -
http://javadl-esd.sun.com/update/1.4.2/jinstall-1_4_2-windows-i586.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - E:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9c14e60a312e0) (gupdate1c9c14e60a312e0) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: webserver - Unknown owner - C:\Program Files\webserver\webserver.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 13111 bytes
PERFORMANCE
My PC appears to be performing better now. No warnings and no delayed performance.