Cant Remove TrojanDownloader.NX [RESOLVED], Computer running slow, windows security center says i have TrojanDownl |
![]() ![]() |
Cant Remove TrojanDownloader.NX [RESOLVED], Computer running slow, windows security center says i have TrojanDownl |
Jan 17 2008, 12:29 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Hello,
Im new here and have a problem. Windows security center says i have a TrojanDownloader.NX on my computer and must remove it. There is a link to go to and its just a bogus website. There is also a yellow triangle in the taskbar and when ever i click on it it goes to the same website. Aslo, their is a different Windows Security Center message (its red) and says their is a specific spyware on my computer. I dont know what to do. I run spybot as well as webroot spy sweeper and it picks up nothing. I downloaded HijackThis v2.0.2 and heres a recent log. Also, my task manager does not work and says it has been disabled my the Administrator. Please Help!!!!! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:29:01 PM, on 1/17/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\WINDOWS\system32\qiawpbjj.exe F:\WINDOWS\system32\devldr32.exe F:\WINDOWS\Explorer.EXE F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe F:\PROGRA~1\mcafee.com\agent\mcagent.exe f:\progra~1\mcafee.com\vso\mcvsescn.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe F:\Program Files\iTunes\iTunesHelper.exe F:\WINDOWS\System32\CTsvcCDA.EXE F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe F:\WINDOWS\Dit.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe F:\Program Files\Messenger\msmsgs.exe f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe F:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe F:\WINDOWS\system32\ctfmon.exe F:\WINDOWS\System32\svchost.exe F:\Program Files\Viewpoint\Common\ViewpointService.exe F:\WINDOWS\wanmpsvc.exe F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe f:\progra~1\mcafee.com\vso\mcvsftsn.exe F:\Program Files\Microsoft Office\Office10\msoffice.exe F:\WINDOWS\System32\MsPMSPSv.exe f:\PROGRA~1\mcafee.com\vso\mcshield.exe F:\Program Files\iPod\bin\iPodService.exe F:\Program Files\Webroot\Spy Sweeper\SSU.EXE F:\Program Files\Trend Micro\HijackThis\HijackThis.exe f:\program files\common files\aol\1124472623\ee\aolsoftware.exe F:\WINDOWS\system32\winlogon.exe F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe F:\WINDOWS\system32\wuauclt.exe f:\program files\common files\aol\1124472623\ee\aolsoftware.exe F2 - REG:system.ini: UserInit=F:\WINDOWS\system32\qiawpbjj.exe,F:\WINDOWS\system32\userinit.exe O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file) O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file) O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file) O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file) O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file) O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file) O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file) O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file) O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file) O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file) O2 - BHO: (no name) - {66E72884-4FD2-464F-A6B8-468F31C40E36} - (no file) O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file) O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file) O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file) O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file) O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file) O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file) O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file) O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file) O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file) O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file) O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file) O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" O4 - HKLM\..\Run: [DIAGENT] "F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE" startup O4 - HKLM\..\Run: [AHQInit] "F:\Program Files\Creative\SBLive\Program\AHQInit.exe" O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [AOLDialer] "F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" O4 - HKLM\..\Run: [AOL Spyware Protection] "F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [HostManager] "F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe" O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ViewMgr] "F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" O4 - HKLM\..\Run: [CICache] CICache.exe O4 - HKLM\..\Run: [Dit] Dit.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" O4 - HKLM\..\Run: [KernelFaultCheck] F:\WINDOWS\system32\dumprep 0 -k O4 - HKLM\..\Run: [SpySweeper] F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray O4 - HKCU\..\Run: [AIM] "F:\Program Files\AIM\aim.exe" -cnetwait.odl O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Aim6] "F:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [swg] "F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background (User 'Sarah McGorry') O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [System Support] system32.exe (User 'Sarah McGorry') O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [Aim6] "F:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (User 'Sarah McGorry') O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe (User 'Sarah McGorry') O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe O4 - Global Startup: Kodak EasyShare software.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Kodak software updater.lnk = F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Save Image to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimagetofolder.html O8 - Extra context menu item: &Save Image to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimages.html O8 - Extra context menu item: &Save Link to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveltof.html O8 - Extra context menu item: &Save Link to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savelink.html O8 - Extra context menu item: &Save Page to Folder... - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savepagetofolder.html O8 - Extra context menu item: &Save this Page to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savewebpage.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - F:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .asx: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O12 - Plugin for .wmv: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1119890110780 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab O21 - SSODL: E404Helper - {cd1a382a-ef49-4ac6-8ca1-b17d9c1c35f6} - e404d.dll (file missing) O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\System32\CTsvcCDA.EXE O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - f:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - F:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - F:\WINDOWS\wanmpsvc.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe -- End of file - 13187 bytes |
|
|
Jan 17 2008, 02:41 PM
Post
#2
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
Hello
Download ComboFix from one of the locations below, and save it to your Desktop. Link 1Double click combofix.exe and follow the prompts. When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply Note: Do not mouseclick combofix's window while its running. That may cause it to stall |
|
|
Jan 17 2008, 04:38 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Thanks for your reply.
Heres a log from ComboFix ComboFix 08-01-18.1 - Franny 2008-01-18 17:14:25.2 - NTFSx86 Running from: F:\Documents and Settings\Franny\Desktop\ComboFix.exe WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin.zip F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin1.zip F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin2.zip F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin3.zip F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin4.zip F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CnsMin5.zip F:\Program Files\3721 F:\Program Files\3721\assist\asbar.dll F:\Program Files\3721\helper.dll F:\Program Files\Accoona F:\Program Files\Accoona\ASearchAssist.dll F:\Program Files\akl F:\Program Files\akl\akl.dll F:\Program Files\akl\akl.exe F:\Program Files\akl\curlog.htm F:\Program Files\akl\keylog.txt F:\Program Files\akl\readme.txt F:\Program Files\akl\uninstall.exe F:\Program Files\akl\unsetup.dat F:\Program Files\akl\unsetup.exe F:\Program Files\amsys F:\Program Files\amsys\awmsg.dat F:\Program Files\amsys\guid.dat F:\Program Files\amsys\ijl15.dll F:\Program Files\amsys\mfc42.dll F:\Program Files\amsys\msvcrt.dll F:\Program Files\amsys\unins000.dat F:\Program Files\amsys\unis000.exe F:\Program Files\amsys\winam.dat F:\Program Files\e-zshopper F:\Program Files\e-zshopper\BarLcher.dll F:\Program Files\p2pnetworks F:\Program Files\p2pnetworks\amp2pl.exe F:\WINDOWS\764.exe F:\WINDOWS\7search.dll F:\WINDOWS\absolute key logger.lnk F:\WINDOWS\aconti.exe F:\WINDOWS\aconti.ini F:\WINDOWS\aconti.log F:\WINDOWS\aconti.sdb F:\WINDOWS\acontidialer.txt F:\WINDOWS\adbar.dll F:\WINDOWS\cbinst$.exe F:\WINDOWS\daxtime.dll F:\WINDOWS\default.htm F:\WINDOWS\dp0.dll F:\WINDOWS\eventlowg.dll F:\WINDOWS\fhfmm-Uninstaller.exe F:\WINDOWS\fhfmm.exe F:\WINDOWS\flt.dll F:\WINDOWS\hcwprn.exe F:\WINDOWS\hotporn.exe F:\WINDOWS\ie_32.exe F:\WINDOWS\iexplorr23.dll F:\WINDOWS\jd2002.dll F:\WINDOWS\kkcomp$.exe F:\WINDOWS\kkcomp.dll F:\WINDOWS\kkcomp.exe F:\WINDOWS\kvnab$.exe F:\WINDOWS\kvnab.dll F:\WINDOWS\kvnab.exe F:\WINDOWS\liqad$.exe F:\WINDOWS\liqad.dll F:\WINDOWS\liqad.exe F:\WINDOWS\liqui-Uninstaller.exe F:\WINDOWS\liqui.dll F:\WINDOWS\liqui.exe F:\WINDOWS\ngd.dll F:\WINDOWS\pbar.dll F:\WINDOWS\pbsysie.dll F:\WINDOWS\settn.dll F:\WINDOWS\spredirect.dll F:\WINDOWS\system32\ace16win.dll F:\WINDOWS\system32\acespy F:\WINDOWS\system32\acespy\__acelog.ndx F:\WINDOWS\system32\acespy\systune.exe F:\WINDOWS\system32\din.ip F:\WINDOWS\system32\drivers\4_stars.gif F:\WINDOWS\system32\drivers\5_stars.gif F:\WINDOWS\system32\drivers\alert_icon.gif F:\WINDOWS\system32\drivers\arrow.gif F:\WINDOWS\system32\drivers\buy_btn.gif F:\WINDOWS\system32\drivers\close_icon.gif F:\WINDOWS\system32\drivers\detect.htm F:\WINDOWS\system32\drivers\download_btn.gif F:\WINDOWS\system32\drivers\features.gif F:\WINDOWS\system32\drivers\header_bg.gif F:\WINDOWS\system32\drivers\icon_warning.gif F:\WINDOWS\system32\drivers\logo_bg.gif F:\WINDOWS\system32\drivers\perfect_cleaner_box.jpg F:\WINDOWS\system32\drivers\perfect_cleaner_box_small.jpg F:\WINDOWS\system32\drivers\perfect_cleaner_header.gif F:\WINDOWS\system32\drivers\perfect_cleaner_header_small.gif F:\WINDOWS\system32\drivers\protect.gif F:\WINDOWS\system32\drivers\s_detect.htm F:\WINDOWS\system32\drivers\secuity_center_logo.gif F:\WINDOWS\system32\drivers\spy_away_box.jpg F:\WINDOWS\system32\drivers\spy_away_box_small.jpg F:\WINDOWS\system32\drivers\spy_away_header.gif F:\WINDOWS\system32\drivers\spy_away_header_small.gif F:\WINDOWS\system32\drivers\users_rating.gif F:\WINDOWS\system32\drivers\v.gif F:\WINDOWS\system32\drivers\x.gif F:\WINDOWS\system32\ESHOPEE.exe F:\WINDOWS\system32\gtv_sd.bin F:\WINDOWS\system32\jofstvyt.sbin F:\WINDOWS\system32\msole32.exe F:\WINDOWS\system32\prrbpgbr.sys F:\WINDOWS\system32\stfv.bin F:\WINDOWS\system32\sznf.ascii F:\WINDOWS\system32\vxddsk.exe F:\WINDOWS\system32\wml.exe F:\WINDOWS\vxddsk.exe F:\WINDOWS\wbeCheck.exe F:\WINDOWS\wbeInst$.exe F:\WINDOWS\winh32.exe F:\WINDOWS\wml.exe F:\WINDOWS\xadbrk.dll F:\WINDOWS\xadbrk.exe F:\WINDOWS\xadbrk_.exe F:\WINDOWS\xxxvideo.exe . ((((((((((((((((((((((((( Files Created from 2007-12-18 to 2008-01-18 ))))))))))))))))))))))))))))))) . 2008-01-18 17:24 . 2008-01-18 17:24 <DIR> d-------- F:\Program Files\e-zshopper 2008-01-18 17:24 . 2008-01-18 17:24 <DIR> d-------- F:\Program Files\amsys 2008-01-18 17:23 . 2008-01-18 17:24 <DIR> d-------- F:\WINDOWS\system32\acespy 2008-01-18 17:23 . 2008-01-18 17:25 <DIR> d-------- F:\Program Files\p2pnetworks 2008-01-18 17:23 . 2008-01-18 17:25 <DIR> d-------- F:\Program Files\akl 2008-01-18 17:23 . 2008-01-18 17:25 <DIR> d-------- F:\Program Files\Accoona 2008-01-18 17:23 . 2008-01-18 17:25 <DIR> d-------- F:\Program Files\3721 2008-01-17 16:58 . 2000-08-31 08:00 51,200 --a------ F:\WINDOWS\NirCmd.exe 2008-01-16 16:47 . 2008-01-16 16:47 <DIR> d-------- F:\Program Files\Trend Micro 2008-01-16 13:43 . 2008-01-16 13:43 <DIR> d-------- F:\Documents and Settings\NetworkService\Application Data\Webroot 2008-01-16 13:30 . 2008-01-16 13:30 <DIR> d-------- F:\Program Files\Common Files\Symantec Shared 2008-01-16 13:30 . 2008-01-16 13:30 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Symantec 2008-01-14 19:44 . 2008-01-14 19:44 54,156 --ah----- F:\WINDOWS\QTFont.qfn 2008-01-14 19:44 . 2008-01-14 19:44 1,409 --a------ F:\WINDOWS\QTFont.for 2008-01-12 20:34 . 2008-01-12 20:34 <DIR> d-------- F:\Documents and Settings\Steve\Application Data\acccore 2008-01-12 15:47 . 2008-01-12 15:47 <DIR> d-------- F:\Documents and Settings\Steve\Application Data\Webroot 2008-01-05 13:56 . 2008-01-05 13:56 <DIR> d-------- F:\Documents and Settings\Franny\Application Data\Webroot 2008-01-05 11:52 . 2008-01-05 11:52 <DIR> d-------- F:\Documents and Settings\All Users\Application Data\Webroot 2008-01-05 11:52 . 2007-10-01 16:40 1,526,072 --a------ F:\WINDOWS\WRSetup.dll 2008-01-05 11:52 . 2007-10-01 16:24 20,280 --a------ F:\WINDOWS\system32\drivers\SSFS0BB9.sys 2008-01-04 22:42 . 2008-01-05 11:51 164 --a------ F:\install.dat 2008-01-01 17:18 . 2008-01-01 17:18 <DIR> d-------- F:\Documents and Settings\Steve\Application Data\Apple Computer 2007-12-26 11:09 . 2007-12-26 11:09 <DIR> d-------- F:\Documents and Settings\Franny\Application Data\ArcSoft 2007-12-26 10:59 . 2007-12-26 11:00 <DIR> d-------- F:\My Videos 2007-12-25 10:46 . 2006-10-04 09:06 1,197,294 -----c--- F:\WINDOWS\system32\dllcache\sysmain.sdb 2007-12-25 10:46 . 2006-10-04 09:06 764,868 -----c--- F:\WINDOWS\system32\dllcache\apph_sp.sdb 2007-12-25 10:46 . 2006-10-04 09:06 217,118 -----c--- F:\WINDOWS\system32\dllcache\apphelp.sdb 2007-12-25 10:45 . 2008-01-10 19:26 870,128 --a------ F:\WINDOWS\system32\mcs.rma 2007-12-25 10:45 . 2008-01-10 19:26 4 --a------ F:\WINDOWS\system32\BEB8A3 2007-12-25 10:41 . 2007-12-25 11:41 <DIR> d-------- F:\WINDOWS\system32\drivers\UMDF 2007-12-25 10:35 . 2007-12-25 10:35 8,413 --a------ F:\WINDOWS\system32\drivers\mcstrm.sys 2007-12-25 10:21 . 2007-12-25 12:15 <DIR> d-------- F:\Program Files\Best Buy Rhapsody 2007-12-25 10:16 . 2007-12-25 10:16 <DIR> d-------- F:\Program Files\Common Files\ArcSoft 2007-12-25 10:16 . 2007-12-25 10:16 <DIR> d-------- F:\Program Files\ArcSoft 2007-12-25 10:16 . 2006-01-24 10:20 1,645,320 --a------ F:\WINDOWS\system32\GdiPlus.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-01-18 22:24 9,984 ----a-w F:\WINDOWS\kvnab$.exe 2008-01-18 22:24 9,728 ----a-w F:\WINDOWS\kvnab.dll 2008-01-18 22:24 9,472 ----a-w F:\WINDOWS\liqad.exe 2008-01-18 22:24 32,256 ----a-w F:\WINDOWS\wbeInst$.exe 2008-01-18 22:24 32,256 ----a-w F:\WINDOWS\hcwprn.exe 2008-01-18 22:24 32,000 ----a-w F:\WINDOWS\settn.dll 2008-01-18 22:24 31,744 ----a-w F:\WINDOWS\kvnab.exe 2008-01-18 22:24 30,464 ----a-w F:\WINDOWS\xadbrk.exe 2008-01-18 22:24 30,464 ----a-w F:\WINDOWS\system32\ESHOPEE.exe 2008-01-18 22:24 29,440 ----a-w F:\WINDOWS\xadbrk_.exe 2008-01-18 22:24 29,184 ----a-w F:\WINDOWS\liqad.dll 2008-01-18 22:24 28,672 ----a-w F:\WINDOWS\liqad$.exe 2008-01-18 22:24 28,672 ----a-w F:\WINDOWS\jd2002.dll 2008-01-18 22:24 28,672 ----a-w F:\WINDOWS\eventlowg.dll 2008-01-18 22:24 27,904 ----a-w F:\WINDOWS\iexplorr23.dll 2008-01-18 22:24 26,624 ----a-w F:\WINDOWS\xadbrk.dll 2008-01-18 22:24 26,624 ----a-w F:\WINDOWS\wbeCheck.exe 2008-01-18 22:24 26,112 ----a-w F:\WINDOWS\liqui-Uninstaller.exe 2008-01-18 22:24 25,088 ----a-w F:\WINDOWS\adbar.dll 2008-01-18 22:24 24,832 ----a-w F:\WINDOWS\kkcomp.exe 2008-01-18 22:24 24,832 ----a-w F:\WINDOWS\cbinst$.exe 2008-01-18 22:24 24,320 ----a-w F:\WINDOWS\spredirect.dll 2008-01-18 22:24 23,552 ----a-w F:\WINDOWS\fhfmm.exe 2008-01-18 22:24 23,040 ----a-w F:\WINDOWS\pbsysie.dll 2008-01-18 22:24 21,248 ----a-w F:\WINDOWS\daxtime.dll 2008-01-18 22:24 18,432 ----a-w F:\WINDOWS\kkcomp$.exe 2008-01-18 22:24 15,360 ----a-w F:\WINDOWS\liqui.exe 2008-01-18 22:24 15,360 ----a-w F:\WINDOWS\liqui.dll 2008-01-18 22:24 14,592 ----a-w F:\WINDOWS\system32\msole32.exe 2008-01-18 22:24 14,592 ----a-w F:\WINDOWS\kkcomp.dll 2008-01-18 22:24 13,568 ----a-w F:\WINDOWS\fhfmm-Uninstaller.exe 2008-01-18 22:23 26,624 ----a-w F:\WINDOWS\hotporn.exe 2008-01-18 22:23 26,368 ----a-w F:\WINDOWS\wml.exe 2008-01-18 22:23 25,856 ----a-w F:\WINDOWS\flt.dll 2008-01-18 22:23 24,320 ----a-w F:\WINDOWS\xxxvideo.exe 2008-01-18 22:23 23,808 ----a-w F:\WINDOWS\ie_32.exe 2008-01-18 22:23 23,552 ----a-w F:\WINDOWS\dp0.dll 2008-01-18 22:23 22,528 ----a-w F:\WINDOWS\7search.dll 2008-01-18 22:23 20,992 ----a-w F:\WINDOWS\ngd.dll 2008-01-18 22:23 18,944 ----a-w F:\WINDOWS\system32\wml.exe 2008-01-18 22:23 18,432 ----a-w F:\WINDOWS\system32\ace16win.dll 2008-01-18 22:23 15,104 ----a-w F:\WINDOWS\system32\vxddsk.exe 2008-01-18 22:23 12,800 ----a-w F:\WINDOWS\vxddsk.exe 2008-01-18 22:23 12,800 ----a-w F:\WINDOWS\pbar.dll 2008-01-18 22:22 13,056 ----a-w F:\WINDOWS\764.exe 2008-01-17 03:12 13,568 ----a-w F:\WINDOWS\system32\drivers\USBCRFT.SYS 2008-01-11 01:45 --------- d-----w F:\Program Files\Google 2008-01-10 21:27 --------- d-----w F:\Documents and Settings\Franny\Application Data\LimeWire 2008-01-09 20:39 --------- d--h--w F:\Program Files\InstallShield Installation Information 2007-12-29 16:08 --------- d-----w F:\Documents and Settings\Franny\Application Data\U3 2007-12-25 15:24 --------- d-----w F:\Program Files\Real 2007-12-25 13:33 --------- d-----w F:\Documents and Settings\All Users\Application Data\Viewpoint 2007-12-24 19:19 --------- d-----w F:\Program Files\Pure Networks 2007-12-24 06:35 --------- d-----w F:\Documents and Settings\Faith McGorry\Application Data\Lavasoft 2007-12-24 06:32 --------- d-----w F:\Program Files\QuickTime 2007-12-24 06:03 --------- d-----w F:\Program Files\Microsoft AntiSpyware 2007-12-24 05:39 --------- d-----w F:\Program Files\Creative 2007-12-24 05:39 --------- d-----w F:\Program Files\Common Files\aolshare 2007-12-24 05:39 --------- d-----w F:\Program Files\Common Files\AOL 2007-12-24 05:38 --------- d-----w F:\Program Files\America Online 9.0 2007-12-24 05:36 --------- d-----w F:\Program Files\Common Files\Adobe 2007-12-15 17:06 --------- d-----w F:\Documents and Settings\Faith McGorry\Application Data\U3 2007-11-30 22:15 131,592 ----a-w F:\WINDOWS\system32\qiawpbjj.exe 2007-11-07 09:26 721,920 ----a-w F:\WINDOWS\system32\lsasrv.dll 2007-10-29 22:43 1,287,680 ----a-w F:\WINDOWS\system32\quartz.dll 2007-10-27 22:40 222,720 ----a-w F:\WINDOWS\system32\wmasf.dll 2007-03-19 22:58 20,992 ----a-w F:\Documents and Settings\Franny\Application Data\GDIPFONTCACHEV1.DAT 2006-12-13 21:56 21,296 ----a-w F:\Documents and Settings\sean\Application Data\GDIPFONTCACHEV1.DAT 2005-04-10 17:03 20,520 ----a-w F:\Documents and Settings\Faith McGorry\Application Data\GDIPFONTCACHEV1.DAT 2001-08-18 12:00 94,784 --sh--w F:\WINDOWS\twain.dll 2004-08-04 04:56 50,688 --sh--w F:\WINDOWS\twain_32.dll 2004-08-04 04:56 54,784 --sha-w F:\WINDOWS\system32\msvcirt.dll 2004-08-04 04:56 343,040 --sha-w F:\WINDOWS\system32\msvcrt.dll 2007-05-17 11:28 549,376 --sh--w F:\WINDOWS\system32\oleaut32.dll 2004-08-04 04:56 83,456 --sh--w F:\WINDOWS\system32\olepro32.dll 2004-08-04 04:56 11,776 --sh--w F:\WINDOWS\system32\regsvr32.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000000-d9e3-4bc6-a0bd-3d0ca4be5271}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{00000012-890e-4aac-afd9-eff6954a34dd}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{029e02f0-a0e5-4b19-b958-7bf2db29fb13}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06dfedaa-6196-11d5-bfc8-00508b4a487d}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1adbcce8-cf84-441e-9b38-afc7a19c06a4}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{51641ef3-8a7a-4d84-8659-b0911e947cc8}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53C330D6-A4AB-419B-B45D-FD4411C1FEF4}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54645654-2225-4455-44A1-9F4543D34546}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{669695bc-a811-4a9d-8cdf-ba8c795f261e}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{66E72884-4FD2-464F-A6B8-468F31C40E36}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6abc861a-31e7-4d91-b43b-d3c98f22a5c0}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{944864a5-3916-46e2-96a9-a2e84f3f1208}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a4a435cf-3583-11d4-91bd-0048546a1450}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{b8875bfe-b021-11d4-bfa8-00508b8e9bd3}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{bb936323-19fa-4521-ba29-eca6a121bc78}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c2680e10-1655-4a0e-87f8-4259325a84b7}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c4ca6559-2cf1-48b6-96b2-8340a06fd129}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{c5af2622-8c75-4dfb-9693-23ab7686a456}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ca1d1b05-9c66-11d5-a009-000103c1e50b}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d8efadf1-9009-11d6-8c73-608c5dc19089}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9147a0a-a866-4214-b47c-da821891240f}] [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e9306072-417e-43e3-81d5-369490beef7c}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AIM"="F:\Program Files\AIM\aim.exe" [2006-08-01 14:35 67112] "MSMSGS"="F:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208] "Aim6"="F:\Program Files\AIM6\aim6.exe" [2007-09-29 15:22 50528] "swg"="F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-08 19:43 68856] "ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [2004-08-03 23:56 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Share-to-Web Namespace Daemon"="F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 12:11 57344] "DIAGENT"="F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.exe" [2001-08-30 04:00 172122] "AHQInit"="F:\Program Files\Creative\SBLive\Program\AHQInit.exe" [2001-03-27 20:00 102400] "VSOCheckTask"="f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [2003-08-08 21:02 122880] "VirusScan Online"="f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [2003-08-18 00:50 163840] "MCAgentExe"="f:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2003-08-27 14:00 245760] "MCUpdateExe"="F:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [2003-08-21 21:10 180224] "MPFExe"="F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [2004-04-19 10:29 1187899] "AOLDialer"="F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216] "AOL Spyware Protection"="F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [2004-03-19 13:17 78960] "HostManager"="F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe" [2006-09-25 19:52 50736] "TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-07-04 21:52 180269] "QuickTime Task"="F:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58 282624] "iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576] "ViewMgr"="F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [2004-11-10 23:15 111816] "CICache"="CICache.exe" [2002-09-05 14:21 24576 F:\WINDOWS\CICache.exe] "Dit"="Dit.exe" [2004-04-27 14:34 86016 F:\WINDOWS\Dit.exe] "Adobe Photo Downloader"="F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 07:55 61440] "KernelFaultCheck"="F:\WINDOWS\system32\dumprep 0 -k" [ ] "SpySweeper"="F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 16:40 5367608] F:\Documents and Settings\All Users\Start Menu\Programs\Startup\ HPAiODevice(hp officejet 7100 series) - 1.lnk - F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe [2002-11-23 19:55:48] Kodak EasyShare software.lnk - F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-09-03 06:45:28] Kodak software updater.lnk - F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 14:12:08] Microsoft Office.lnk - F:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 04:01:04] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"= 1 (0x1) "<NO NAME>"= 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "E404Helper"= {cd1a382a-ef49-4ac6-8ca1-b17d9c1c35f6} - e404d.dll [ ] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] --a------ 2004-10-13 11:24 1694208 F:\Program Files\Messenger\msmsgs.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup] R2 Viewpoint Manager Service;Viewpoint Manager Service;"F:\Program Files\Viewpoint\Common\ViewpointService.exe" [2007-01-04 16:38] S3 bfastfao;bfastfao;F:\DOCUME~1\sean\LOCALS~1\Temp\bfastfao.sys [2001-09-19 23:07] S3 CardReaderFilter;Card Reader Filter;F:\WINDOWS\system32\Drivers\USBCRFT.SYS [2008-01-16 22:12] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] \Shell\AutoRun\command - H:\LaunchU3.exe -a *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder "2008-01-15 17:26:00 F:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - F:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-01-18 22:29:00 F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Faith McGorry).job" - F:\PROGRA~1\mcafee.com\agent\mcupdate.ex - F:\PROGRA~1\mcafee.com\agent "2008-01-18 22:25:00 F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Fran McGorry).job" - F:\PROGRA~1\mcafee.com\agent\mcupdate.ex - F:\PROGRA~1\mcafee.com\agent "2008-01-18 22:26:00 F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Fran).job" - F:\PROGRA~1\mcafee.com\agent\mcupdate.ex - F:\PROGRA~1\mcafee.com\agent "2008-01-18 22:28:00 F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Franny McGorry).job" - F:\PROGRA~1\mcafee.com\agent\mcupdate.ex - F:\PROGRA~1\mcafee.com\agent "2008-01-18 22:25:00 F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Franny).job" - F:\PROGRA~1\mcafee.com\agent\mcupdate.ex - F:\PROGRA~1\mcafee.com\agent.FrannyYMcAfee SecurityCenter periodically checks for updates for your McAfee Security Services. "2008-01-18 22:25:00 F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Sarah McGorry).job" - F:\PROGRA~1\mcafee.com\agent\mcupdate.ex - F:\PROGRA~1\mcafee.com\agent "2008-01-18 22:25:00 F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-sean).job" - F:\PROGRA~1\mcafee.com\agent\mcupdate.ex - F:\PROGRA~1\mcafee.com\agent "2008-01-18 22:25:00 F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Stephen McGorry).job" - F:\PROGRA~1\mcafee.com\agent\mcupdate.ex - F:\PROGRA~1\mcafee.com\agent "2008-01-18 22:29:00 F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Steve).job" - F:\PROGRA~1\mcafee.com\agent\mcupdate.ex - F:\PROGRA~1\mcafee.com\agent "2008-01-15 04:00:00 F:\WINDOWS\Tasks\wrSpySweeper_L8E29693CA260428AA2A8269F7784436E.job" - F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe>/ScheduleSweep=wrSpySweeper_L8E29693CA260428AA2A8269F7784436E - F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.ex - A:\ . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-18 17:25:19 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... F:\WINDOWS\system32\vxddsk.exe 20736 bytes F:\WINDOWS\system32\wml.exe 21248 bytes F:\WINDOWS\system32\msole32.exe 23808 bytes scan completed successfully hidden files: 3 ************************************************************************** . Completion time: 2008-01-18 17:29:36 ComboFix-quarantined-files.txt 2008-01-18 22:29:23 . 2008-01-10 08:03:22 --- E O F --- AND here is HijackThis Log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:38:09 PM, on 1/18/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\WINDOWS\system32\qiawpbjj.exe F:\WINDOWS\system32\devldr32.exe F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe F:\PROGRA~1\mcafee.com\agent\mcagent.exe f:\progra~1\mcafee.com\vso\mcvsescn.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe F:\Program Files\iTunes\iTunesHelper.exe F:\WINDOWS\System32\CTsvcCDA.EXE F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe F:\WINDOWS\Dit.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe F:\Program Files\Messenger\msmsgs.exe f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe F:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe F:\WINDOWS\system32\ctfmon.exe F:\WINDOWS\System32\svchost.exe F:\Program Files\Viewpoint\Common\ViewpointService.exe F:\WINDOWS\wanmpsvc.exe F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe f:\progra~1\mcafee.com\vso\mcvsftsn.exe F:\Program Files\Microsoft Office\Office10\msoffice.exe F:\WINDOWS\System32\MsPMSPSv.exe F:\Program Files\iPod\bin\iPodService.exe F:\Program Files\Webroot\Spy Sweeper\SSU.EXE F:\Program Files\Trend Micro\HijackThis\HijackThis.exe f:\program files\common files\aol\1124472623\ee\aolsoftware.exe F:\WINDOWS\system32\winlogon.exe F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe F:\WINDOWS\system32\wuauclt.exe F:\Program Files\AIM6\aolsoftware.exe F:\WINDOWS\system32\wscntfy.exe F:\WINDOWS\Explorer.exe f:\program files\common files\aol\1124472623\ee\aolsoftware.exe O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file) O2 - BHO: (no name) - {00000012-890e-4aac-afd9-eff6954a34dd} - (no file) O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file) O2 - BHO: (no name) - {06dfedaa-6196-11d5-bfc8-00508b4a487d} - (no file) O2 - BHO: (no name) - {12F02779-6D88-4958-8AD3-83C12D86ADC7} - (no file) O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file) O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file) O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file) O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: (no name) - {53C330D6-A4AB-419B-B45D-FD4411C1FEF4} - (no file) O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file) O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file) O2 - BHO: (no name) - {66E72884-4FD2-464F-A6B8-468F31C40E36} - (no file) O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file) O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file) O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file) O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file) O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file) O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file) O2 - BHO: (no name) - {c4ca6559-2cf1-48b6-96b2-8340a06fd129} - (no file) O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file) O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file) O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file) O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file) O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file) O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" O4 - HKLM\..\Run: [DIAGENT] "F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE" startup O4 - HKLM\..\Run: [AHQInit] "F:\Program Files\Creative\SBLive\Program\AHQInit.exe" O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [AOLDialer] "F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" O4 - HKLM\..\Run: [AOL Spyware Protection] "F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [HostManager] "F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe" O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ViewMgr] "F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" O4 - HKLM\..\Run: [CICache] CICache.exe O4 - HKLM\..\Run: [Dit] Dit.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" O4 - HKLM\..\Run: [SpySweeper] F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray O4 - HKCU\..\Run: [AIM] "F:\Program Files\AIM\aim.exe" -cnetwait.odl O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Aim6] "F:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [swg] "F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background (User 'Sarah McGorry') O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [System Support] system32.exe (User 'Sarah McGorry') O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [Aim6] "F:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp (User 'Sarah McGorry') O4 - HKUS\S-1-5-21-436374069-1035525444-725345543-1007\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe (User 'Sarah McGorry') O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe O4 - Global Startup: Kodak EasyShare software.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Kodak software updater.lnk = F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Save Image to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimagetofolder.html O8 - Extra context menu item: &Save Image to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimages.html O8 - Extra context menu item: &Save Link to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveltof.html O8 - Extra context menu item: &Save Link to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savelink.html O8 - Extra context menu item: &Save Page to Folder... - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savepagetofolder.html O8 - Extra context menu item: &Save this Page to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savewebpage.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - F:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .asx: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O12 - Plugin for .wmv: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1119890110780 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab O21 - SSODL: E404Helper - {cd1a382a-ef49-4ac6-8ca1-b17d9c1c35f6} - e404d.dll (file missing) O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\System32\CTsvcCDA.EXE O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - f:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - F:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - F:\WINDOWS\wanmpsvc.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe -- End of file - 13050 bytes |
|
|
Jan 17 2008, 05:01 PM
Post
#4
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
Hello
1. Close any open browsers. 2. Open notepad and copy/paste the text in the quotebox below into it: QUOTE File:: F:\WINDOWS\kvnab$.exe F:\WINDOWS\kvnab.dll F:\WINDOWS\liqad.exe F:\WINDOWS\wbeInst$.exe F:\WINDOWS\hcwprn.exe F:\WINDOWS\settn.dll F:\WINDOWS\kvnab.exe F:\WINDOWS\xadbrk.exe F:\WINDOWS\system32\ESHOPEE.exe F:\WINDOWS\xadbrk_.exe F:\WINDOWS\liqad.dll F:\WINDOWS\liqad$.exe F:\WINDOWS\jd2002.dll F:\WINDOWS\eventlowg.dll F:\WINDOWS\iexplorr23.dll F:\WINDOWS\xadbrk.dll F:\WINDOWS\wbeCheck.exe F:\WINDOWS\liqui-Uninstaller.exe F:\WINDOWS\adbar.dll F:\WINDOWS\kkcomp.exe F:\WINDOWS\cbinst$.exe F:\WINDOWS\spredirect.dll F:\WINDOWS\fhfmm.exe F:\WINDOWS\pbsysie.dll F:\WINDOWS\daxtime.dll F:\WINDOWS\kkcomp$.exe F:\WINDOWS\liqui.exe F:\WINDOWS\liqui.dll F:\WINDOWS\system32\msole32.exe F:\WINDOWS\kkcomp.dll F:\WINDOWS\fhfmm-Uninstaller.exe F:\WINDOWS\hotporn.exe F:\WINDOWS\wml.exe F:\WINDOWS\flt.dll F:\WINDOWS\xxxvideo.exe F:\WINDOWS\ie_32.exe F:\WINDOWS\dp0.dll F:\WINDOWS\7search.dll F:\WINDOWS\ngd.dll F:\WINDOWS\system32\wml.exe F:\WINDOWS\system32\ace16win.dll F:\WINDOWS\system32\vxddsk.exe F:\WINDOWS\vxddsk.exe F:\WINDOWS\pbar.dll F:\WINDOWS\764.exe F:\WINDOWS\system32\qiawpbjj.exe F:\WINDOWS\system32\vxddsk.exe 20736 bytes F:\WINDOWS\system32\wml.exe F:\WINDOWS\system32\msole32.exe F:\DOCUME~1\sean\LOCALS~1\Temp\bfastfao.sys Folder:: F:\Program Files\e-zshopper F:\Program Files\amsys F:\WINDOWS\system32\acespy F:\Program Files\p2pnetworks F:\Program Files\akl F:\Program Files\Accoona F:\Program Files\3721 Registry:: [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H] Driver:: bfastfao Save this as CFScript.txt, in the same location as ComboFix.exe ![]() Refering to the picture above, drag CFScript into ComboFix.exe When finished, it shall produce a log for you at "C:\ComboFix.txt" Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall Reboot and post a new HijackThis log |
|
|
Jan 17 2008, 06:11 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Thanks again,
Heres the latest HijackThis Log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:08:54 PM, on 1/18/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\WINDOWS\system32\devldr32.exe F:\WINDOWS\Explorer.EXE F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe F:\WINDOWS\System32\CTsvcCDA.EXE f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe F:\PROGRA~1\mcafee.com\agent\mcagent.exe f:\progra~1\mcafee.com\vso\mcvsescn.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe F:\Program Files\Common Files\AOL\ACS\AOLDial.exe F:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe F:\Program Files\iTunes\iTunesHelper.exe F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe F:\WINDOWS\Dit.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe F:\Program Files\Messenger\msmsgs.exe F:\Program Files\AIM6\aim6.exe F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe F:\WINDOWS\system32\ctfmon.exe F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe F:\WINDOWS\System32\svchost.exe F:\Program Files\Viewpoint\Common\ViewpointService.exe F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe F:\WINDOWS\wanmpsvc.exe F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe F:\Program Files\Microsoft Office\Office10\msoffice.exe f:\progra~1\mcafee.com\vso\mcvsftsn.exe F:\WINDOWS\System32\MsPMSPSv.exe F:\Program Files\AIM6\aolsoftware.exe f:\PROGRA~1\mcafee.com\vso\mcshield.exe F:\Program Files\iPod\bin\iPodService.exe F:\WINDOWS\system32\wuauclt.exe F:\WINDOWS\system32\wuauclt.exe F:\Program Files\Trend Micro\HijackThis\HijackThis.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" O4 - HKLM\..\Run: [DIAGENT] "F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE" startup O4 - HKLM\..\Run: [AHQInit] "F:\Program Files\Creative\SBLive\Program\AHQInit.exe" O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [AOLDialer] "F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" O4 - HKLM\..\Run: [AOL Spyware Protection] "F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [HostManager] "F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe" O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ViewMgr] "F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" O4 - HKLM\..\Run: [CICache] CICache.exe O4 - HKLM\..\Run: [Dit] Dit.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" O4 - HKLM\..\Run: [SpySweeper] F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray O4 - HKCU\..\Run: [AIM] F:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Aim6] "F:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [swg] F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe O4 - Global Startup: Kodak EasyShare software.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Kodak software updater.lnk = F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Save Image to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimagetofolder.html O8 - Extra context menu item: &Save Image to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimages.html O8 - Extra context menu item: &Save Link to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveltof.html O8 - Extra context menu item: &Save Link to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savelink.html O8 - Extra context menu item: &Save Page to Folder... - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savepagetofolder.html O8 - Extra context menu item: &Save this Page to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savewebpage.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - F:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .asx: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O12 - Plugin for .wmv: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1119890110780 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab O21 - SSODL: E404Helper - {cd1a382a-ef49-4ac6-8ca1-b17d9c1c35f6} - e404d.dll (file missing) O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\System32\CTsvcCDA.EXE O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - f:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - F:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - F:\WINDOWS\wanmpsvc.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe -- End of file - 10596 bytes |
|
|
Jan 17 2008, 06:19 PM
Post
#6
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
Hello
1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present): O9 - Extra button: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) O21 - SSODL: E404Helper - {cd1a382a-ef49-4ac6-8ca1-b17d9c1c35f6} - e404d.dll (file missing) 2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis. Reboot and do this Please download Deckard's System Scanner (DSS) and save it to your Desktop.
|
|
|
Jan 17 2008, 06:50 PM
Post
#7
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Here it is,
Thanks Deckard's System Scanner v20071014.68 Run by Franny on 2008-01-18 19:40:07 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 5: 2008-01-19 00:40:34 UTC - RP5 - Deckard's System Scanner Restore Point 4: 2008-01-18 23:11:08 UTC - RP4 - ComboFix created restore point 3: 2008-01-17 21:59:51 UTC - RP3 - ComboFix created restore point 2: 2008-01-17 20:58:36 UTC - RP2 - System Checkpoint 1: 2008-01-16 20:54:42 UTC - RP1 - System Checkpoint Backed up registry hives. Performed disk cleanup. -- HijackThis (run as Franny.exe) ---------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:44:07 PM, on 1/18/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\WINDOWS\system32\devldr32.exe F:\WINDOWS\Explorer.EXE F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe F:\WINDOWS\System32\CTsvcCDA.EXE f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe f:\progra~1\mcafee.com\vso\mcvsescn.exe F:\PROGRA~1\mcafee.com\agent\mcagent.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe F:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe F:\Program Files\iTunes\iTunesHelper.exe F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe F:\WINDOWS\Dit.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe F:\Program Files\Messenger\msmsgs.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe F:\Program Files\AIM6\aim6.exe F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe F:\WINDOWS\system32\ctfmon.exe F:\WINDOWS\System32\svchost.exe F:\Program Files\Viewpoint\Common\ViewpointService.exe F:\WINDOWS\wanmpsvc.exe F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe f:\progra~1\mcafee.com\vso\mcvsftsn.exe F:\Program Files\Microsoft Office\Office10\msoffice.exe F:\Program Files\AIM6\aolsoftware.exe F:\WINDOWS\System32\MsPMSPSv.exe f:\PROGRA~1\mcafee.com\vso\mcshield.exe F:\Program Files\iPod\bin\iPodService.exe F:\WINDOWS\system32\wuauclt.exe F:\Documents and Settings\Franny\Desktop\dss.exe F:\Program Files\AIM6\anotify.exe F:\PROGRA~1\TRENDM~1\HIJACK~1\Franny.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" O4 - HKLM\..\Run: [DIAGENT] "F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE" startup O4 - HKLM\..\Run: [AHQInit] "F:\Program Files\Creative\SBLive\Program\AHQInit.exe" O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [AOLDialer] "F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" O4 - HKLM\..\Run: [AOL Spyware Protection] "F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [HostManager] "F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe" O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ViewMgr] "F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" O4 - HKLM\..\Run: [CICache] CICache.exe O4 - HKLM\..\Run: [Dit] Dit.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" O4 - HKLM\..\Run: [SpySweeper] "F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray O4 - HKCU\..\Run: [AIM] F:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Aim6] "F:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [swg] F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe O4 - Global Startup: Kodak EasyShare software.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Kodak software updater.lnk = F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Save Image to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimagetofolder.html O8 - Extra context menu item: &Save Image to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimages.html O8 - Extra context menu item: &Save Link to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveltof.html O8 - Extra context menu item: &Save Link to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savelink.html O8 - Extra context menu item: &Save Page to Folder... - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savepagetofolder.html O8 - Extra context menu item: &Save this Page to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savewebpage.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - F:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .asx: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O12 - Plugin for .wmv: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1119890110780 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\System32\CTsvcCDA.EXE O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - f:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - F:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - F:\WINDOWS\wanmpsvc.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe -- End of file - 10143 bytes -- HijackThis Fixed Entries (F:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) ----------- backup-20080118-192945-244 O9 - Extra button: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) backup-20080118-192946-223 O21 - SSODL: E404Helper - {cd1a382a-ef49-4ac6-8ca1-b17d9c1c35f6} - e404d.dll (file missing) backup-20080118-192946-508 O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {99868720-F4B1-4636-88C3-1BC09F510657} - F:\WINDOWS\System32\wldr.dll (file missing) -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R1 MPFIREWL - f:\windows\system32\drivers\mpfirewall.sys <Not Verified; McAfee Security; McAfee Personal Firewall Plus> R2 MCSTRM - f:\windows\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path Manager® (32-bit)> S3 CardReaderFilter (Card Reader Filter) - f:\windows\system32\drivers\usbcrft.sys <Not Verified; ICSI Technology Ltd.; USB Card Reader and FlashDisk> -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 AdobeActiveFileMonitor5.0 (Adobe Active File Monitor V5) - f:\program files\adobe\photoshop elements 5.0\photoshopelementsfileagent.exe R2 Viewpoint Manager Service - "f:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager> S2 AOLService (AOL Spyware Protection Service) - f:\progra~1\common~1\aol\aolspy~1\\aolserv.exe -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2008-01-18 19:44:00 494 --a------ F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Steve).job 2008-01-18 19:44:00 496 --a------ F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Franny).job 2008-01-18 19:44:00 510 --a------ F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Faith McGorry).job 2008-01-18 19:43:00 512 --a------ F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Franny McGorry).job 2008-01-18 19:42:40 492 --a------ F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Fran).job 2008-01-18 19:40:07 514 --a------ F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Stephen McGorry).job 2008-01-18 19:40:07 492 --a------ F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-sean).job 2008-01-18 19:40:06 510 --a------ F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Sarah McGorry).job 2008-01-18 19:40:06 508 --a------ F:\WINDOWS\Tasks\McAfee.com Update Check (PHILADEL-K4X8AA-Fran McGorry).job 2008-01-15 12:26:00 284 --a------ F:\WINDOWS\Tasks\AppleSoftwareUpdate.job 2008-01-14 23:00:00 1650 --a------ F:\WINDOWS\Tasks\wrSpySweeper_L8E29693CA260428AA2A8269F7784436E.job -- Files created between 2007-12-18 and 2008-01-18 ----------------------------- 2008-01-16 16:47:20 0 d-------- F:\Program Files\Trend Micro 2008-01-16 13:43:32 0 d-------- F:\Documents and Settings\NetworkService\Application Data\Webroot 2008-01-16 13:30:04 0 d-------- F:\Program Files\Common Files\Symantec Shared 2008-01-16 13:30:04 0 d-------- F:\Documents and Settings\All Users\Application Data\Symantec 2008-01-12 20:34:05 0 d-------- F:\Documents and Settings\Steve\Application Data\acccore 2008-01-12 15:47:25 0 d-------- F:\Documents and Settings\Steve\Application Data\Webroot 2008-01-05 13:56:51 0 d-------- F:\Documents and Settings\Franny\Application Data\Webroot 2008-01-05 11:52:35 0 d-------- F:\Documents and Settings\All Users\Application Data\Webroot 2008-01-04 22:42:20 164 --a------ F:\install.dat 2008-01-01 17:18:43 0 d-------- F:\Documents and Settings\Steve\Application Data\Apple Computer 2007-12-26 11:09:06 0 d-------- F:\Documents and Settings\Franny\Application Data\ArcSoft 2007-12-26 10:59:21 0 d-------- F:\My Videos 2007-12-25 10:45:58 4 --a------ F:\WINDOWS\system32\BEB8A3 2007-12-25 10:41:14 0 d-------- F:\WINDOWS\system32\drivers\UMDF 2007-12-25 10:35:36 8413 --a------ F:\WINDOWS\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path Manager® (32-bit)> 2007-12-25 10:21:41 0 d-------- F:\Program Files\Best Buy Rhapsody 2007-12-25 10:16:55 0 d-------- F:\Program Files\Common Files\ArcSoft 2007-12-25 10:16:53 0 d-------- F:\Program Files\ArcSoft 2007-12-24 15:43:18 0 d-------- F:\Program Files\Common Files\ODBC -- Find3M Report --------------------------------------------------------------- 2008-01-16 13:30:04 0 d-------- F:\Program Files\Common Files 2008-01-10 20:45:31 0 d-------- F:\Program Files\Google 2008-01-10 16:27:45 0 d-------- F:\Documents and Settings\Franny\Application Data\LimeWire 2008-01-09 15:39:28 0 d--h----- F:\Program Files\InstallShield Installation Information 2007-12-29 11:08:59 0 d-------- F:\Documents and Settings\Franny\Application Data\U3 2007-12-25 11:26:49 0 d-------- F:\Documents and Settings\Franny\Application Data\Real 2007-12-25 10:24:45 0 d-------- F:\Program Files\Real 2007-12-24 14:19:41 0 d-------- F:\Program Files\Pure Networks 2007-12-24 01:32:51 0 d-------- F:\Program Files\QuickTime 2007-12-24 01:03:14 0 d-------- F:\Program Files\Microsoft AntiSpyware 2007-12-24 00:39:06 0 d-------- F:\Program Files\Creative 2007-12-24 00:39:03 0 d-------- F:\Program Files\Common Files\aolshare 2007-12-24 00:39:02 0 d-------- F:\Program Files\Common Files\AOL 2007-12-24 00:38:54 0 d-------- F:\Program Files\America Online 9.0 2007-12-24 00:36:43 0 d-------- F:\Program Files\Common Files\Adobe 2007-11-30 17:14:00 2 --a------ F:\WINDOWS\system32\faxwin32.bin 2007-11-04 17:30:02 714 --a------ F:\WINDOWS\eReg.dat -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Share-to-Web Namespace Daemon"="F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [07/03/2001 12:11 PM] "DIAGENT"="F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.exe" [08/30/2001 04:00 AM] "AHQInit"="F:\Program Files\Creative\SBLive\Program\AHQInit.exe" [03/27/2001 08:00 PM] "VSOCheckTask"="f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [08/08/2003 09:02 PM] "VirusScan Online"="f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [08/18/2003 12:50 AM] "MCAgentExe"="f:\PROGRA~1\mcafee.com\agent\mcagent.exe" [08/27/2003 02:00 PM] "MCUpdateExe"="F:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [08/21/2003 09:10 PM] "MPFExe"="F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [04/19/2004 10:29 AM] "AOLDialer"="F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [10/23/2006 07:50 AM] "AOL Spyware Protection"="F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [03/19/2004 01:17 PM] "HostManager"="F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe" [09/25/2006 07:52 PM] "TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [07/04/2005 09:52 PM] "QuickTime Task"="F:\Program Files\QuickTime\qttask.exe" [10/25/2006 06:58 PM] "iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [10/30/2006 09:36 AM] "ViewMgr"="F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [11/10/2004 11:15 PM] "CICache"="CICache.exe" [09/05/2002 02:21 PM F:\WINDOWS\CICache.exe] "Dit"="Dit.exe" [04/27/2004 02:34 PM F:\WINDOWS\Dit.exe] "Adobe Photo Downloader"="F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [09/14/2006 07:55 AM] "SpySweeper"="F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [10/01/2007 04:40 PM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AIM"="F:\Program Files\AIM\aim.exe" [08/01/2006 02:35 PM] "MSMSGS"="F:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM] "Aim6"="F:\Program Files\AIM6\aim6.exe" [09/29/2007 03:22 PM] "swg"="F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/08/2007 07:43 PM] "ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [08/03/2004 11:56 PM] F:\Documents and Settings\All Users\Start Menu\Programs\Startup\ HPAiODevice(hp officejet 7100 series) - 1.lnk - F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe [11/23/2002 7:55:48 PM] Kodak EasyShare software.lnk - F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [9/3/2005 6:45:28 AM] Kodak software updater.lnk - F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2/13/2004 2:12:08 PM] Microsoft Office.lnk - F:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 4:01:04 AM] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] @=0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume shadow copy" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup] -- End of Deckard's System Scanner: finished at 2008-01-18 19:46:16 ------------ Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Home Edition (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: Intel® Pentium® 4 CPU 1.90GHz Percentage of Memory in Use: 69% Physical Memory (total/avail): 511.01 MiB / 155.56 MiB Pagefile Memory (total/avail): 1247.34 MiB / 926.39 MiB Virtual Memory (total/avail): 2047.88 MiB / 1939.08 MiB A: is Removable (No Media) D: is CDROM (No Media) E: is CDROM (No Media) F: is Fixed (NTFS) - 111.79 GiB total, 28.54 GiB free. \\.\PHYSICALDRIVE0 - WDC WD1200BB-00GUC0 - 111.79 GiB - 1 partition \PARTITION0 (bootable) - Installable File System - 111.79 GiB - F: -- Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. Windows Internal Firewall is enabled. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "F:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="F:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare" "F:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"="F:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=F:\Documents and Settings\All Users APPDATA=F:\Documents and Settings\Franny\Application Data CLASSPATH=.;F:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip CLIENTNAME=Console CommonProgramFiles=F:\Program Files\Common Files COMPUTERNAME=PHILADEL-K4X8AA ComSpec=F:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=F: HOMEPATH=\Documents and Settings\Franny LOGONSERVER=\\PHILADEL-K4X8AA NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=F:\WINDOWS\system32;F:\WINDOWS;F:\WINDOWS\system32\wbem;F:\Program Files\QuickTime\QTSystem\;F:\Program Files\Common Files\Adobe\AGL PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 1 Stepping 2, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0102 ProgramFiles=F:\Program Files PROMPT=$P$G QTJAVA=F:\Program Files\Java\jre1.5.0_02\lib\ext\QTJava.zip SESSIONNAME=Console SystemDrive=F: SystemRoot=F:\WINDOWS TEMP=F:\DOCUME~1\Franny\LOCALS~1\Temp TMP=F:\DOCUME~1\Franny\LOCALS~1\Temp USERDOMAIN=PHILADEL-K4X8AA USERNAME=Franny USERPROFILE=F:\Documents and Settings\Franny windir=F:\WINDOWS -- User Profiles --------------------------------------------------------------- Fran McGorry (admin) Faith McGorry (admin) Sarah McGorry (admin) Steve (admin) Franny (admin) sean (admin) Administrator (admin) -- Add/Remove Programs --------------------------------------------------------- --> F:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> F:\Program Files\Creative\SBLive\Program\Upddrv2k.EXE --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\News\CTNews.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\AudioHQ.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\CTMixer.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\Diagnose2.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\HTML.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\Midi.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\PlayCenter2\Player2.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\Recorder\Recorder.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\Restore.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\SoundFont.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\SBLive\WaveStudio\Wstudio.isu" --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Creative\Uninstall\Installer.isu" --> MsiExec.exe /I{C4CBAD7E-DF4A-4FEC-AC17-8BC709AFB844} --> MsiExec.exe /X{EE43210C-266E-4101-8FBC-04378D5E9D42} --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 F:\WINDOWS\INF\PCHealth.inf 3D Groove Playback Engine --> RunDll32 F:\WINDOWS\DOWNLO~1\GrooveAX.dll,_RemoveGroove@16 Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5102} Adobe Help Center 2.1 --> MsiExec.exe /I{25569723-DC5A-4467-A639-79535BF01B71} Adobe Photoshop Elements 5.0 --> msiexec /I {A7B609FB-83D8-4FC3-8477-1BC65ECFE85B} Adobe Premiere Elements 3.0 --> msiexec /I {530AFAFF-6F0A-48BB-88D0-04F9658322D3} Adobe Premiere Elements 3.0 --> MsiExec.exe /I{530AFAFF-6F0A-48BB-88D0-04F9658322D3} Adobe Premiere Elements 3.0 Templates --> MsiExec.exe /I{6EACDDF4-4220-49A3-9204-984C86852C3D} AIM 6 --> F:\Program Files\AIM6\uninst.exe AIM Toolbar --> F:\Program Files\AIM Toolbar\uninstall.exe AIM Toolbar 5.0 --> "F:\Program Files\AOL\AIM Toolbar 5.0\uninstall.exe" AOL Coach Version 1.0(Build:20040229.1 en) --> F:\Program Files\Common Files\aolshare\Coach\AolCInUn.exe AOL Coach Version 2.0(Build:20041026.5 en) --> F:\Program Files\Common Files\AolCoach\en_en\AolCInUn.exe -lang=en_en -ext=UDP AOL Deskbar --> "F:\Program Files\AOL Deskbar\UNWISE.EXE" /u "F:\Program Files\AOL Deskbar\INSTALL.LOG" AOL Explorer --> F:\Program Files\Common Files\AOL\1124472623\ee\services\browser\ver1_1_1042\uninst.exe AOL Instant Messenger --> F:\Program Files\AIM\uninstll.exe -LOG= F:\Program Files\AIM\install.log -OEM= AOL Spyware Protection --> F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\UNWISE.EXE F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\INSTALL.LOG AOL Uninstaller (Choose which Products to Remove) --> F:\Program Files\Common Files\AOL\uninstaller.exe Apple Software Update --> MsiExec.exe /I{A50C25D7-62E9-4511-AD70-8E2DA5E79B7D} ArcSoft MediaConverter 2 --> RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{1B15D991-5619-4BC1-B71E-3DE793B792FC}\setup.exe" -l0x9 BearShare --> F:\PROGRA~1\BEARSH~1\BEARSH~1\UNWISE.EXE F:\PROGRA~1\BEARSH~1\BEARSH~1\INSTALL.LOG Best Buy Digital Music Store --> F:\PROGRA~1\BESTBU~1\Unwise32.exe /A F:\PROGRA~1\BESTBU~1\install.log Canon Camera Window for ZoomBrowser EX --> F:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{A29EA741-24F7-4C07-9B2C-06CB6491BE4A} Canon EOS 10D WIA Driver --> F:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{095659A2-739F-4D9A-A916-66C7CAD16F9E} Canon EOS Kiss REBEL 300D WIA Driver --> F:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{31A57C3E-30DD-421F-B5C7-974DACB0D05F} Canon PhotoRecord --> MsiExec.exe /X{BEF56F2D-56ED-4176-BF72-7B68D4A3B98D} Canon RAW Image Task for ZoomBrowser EX --> F:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{FAF0DAD8-1EA7-4FEF-80E5-8D8D6EBD5A23} Canon RemoteCapture Task for ZoomBrowser EX --> F:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{2236B741-6631-49AE-B76E-3E14CA01CC87} Canon Utilities File Viewer Utility 1.3 --> F:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{2D1C2321-8FDB-49B8-A66B-4008DC0B6B5D} Canon Utilities PhotoStitch 3.1 --> F:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{F11A403B-0DE9-4953-B790-7A2F014FBB2B} Canon Utilities RemoteCapture 2.7 --> F:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{14220DB1-DD96-4BCD-B3D5-03A4EA6631C4} Canon Utilities ZoomBrowser EX --> MsiExec.exe /X{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2} CardRd81 --> MsiExec.exe /I{54C8FE84-89C4-40E8-976C-439EB0729BD6} CCScore --> MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992} CopySafe Plugin --> F:\PROGRA~1\Copysafe\UNWISE.EXE F:\PROGRA~1\Copysafe\INSTALL.LOG CR2 --> MsiExec.exe /I{432C3720-37BF-4BD7-8E49-F38E090246D0} DivX Web Player --> F:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN EA.com Matchup --> RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{2F173C40-563E-11D4-89C5-0010ADDAAC33}\setup.exe" -l0x0 Uninstall EA.com Update --> RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{9AB97F52-512B-43EF-AAEC-4825C17B32ED}\setup.exe" -l0x0 Uninstall ESSBrwr --> MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6} ESSCDBK --> MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD} ESScore --> MsiExec.exe /I{9D8FEE90-0377-49A9-AEFB-525BDE549BA4} ESSCT --> MsiExec.exe /I{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8} ESSEMAIL --> MsiExec.exe /I{FEDE2483-87B7-44C1-A5BB-D75AEB8B6340} ESSgui --> MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A} ESShelp --> MsiExec.exe /I{87843A41-7808-4F2E-B13F-25C1E67CF2FD} ESSini --> MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765} ESSPCD --> MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5} ESSPDock --> MsiExec.exe /I{FCDB1C92-03C6-4C76-8625-371224256091} ESSSONIC --> MsiExec.exe /I{4F677FC7-7AA8-412B-A957-F13CBE1C7331} ESSTOOLS --> MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589} ESSTUTOR --> MsiExec.exe /I{CA60320D-6A16-49C8-A34F-84EEF4799567} essvcpt --> MsiExec.exe /I{D1973749-F5E7-40EB-B528-F2B78685B9FF} ESSvpaht --> MsiExec.exe /I{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69} ESSvpot --> MsiExec.exe /I{48C82F7A-F100-4DAB-A310-8E18BF2159E1} HighMAT Extension to Microsoft Windows XP CD Writing Wizard --> MsiExec.exe /X{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F} HijackThis 2.0.2 --> "F:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall HLPIndex --> MsiExec.exe /I{38441BE7-79B0-42B8-8297-833704F949FE} HLPPDOCK --> MsiExec.exe /I{154508C0-07C5-4659-A7A0-E49968750D21} HLPSFO --> MsiExec.exe /I{8DD94CA3-BCD2-49C0-B537-F3B5D95FF0C8} Hotfix for Windows Media Format 11 SDK (KB929399) --> "F:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" Hotfix for Windows Media Format SDK (KB902344) --> "F:\WINDOWS\$NtUninstallKB902344$\spuninst\spuninst.exe" hp officejet 7100 series --> F:\WINDOWS\system32\hpocon09.exe /u 1128863938 /d "hp officejet 7100 series" HP Photo Printing Software --> F:\WINDOWS\IsUninst.exe -f"F:\Program Files\Hewlett-Packard\Photo Printing\Uninstall.isu" -c"F:\Program Files\Hewlett-Packard\Photo Printing\hpiunPC.dll HP Share-to-Web --> RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{748F4870-8350-11D3-B0BF-080009FB4A19}\setup.exe" --MAIN -l9 iPod for Windows 2005-01-11 --> F:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{3476E8FA-00F1-48AF-8771-236C84FC7CB8} /l1033 iPod for Windows 2006-06-28 --> F:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BD57EA4D-026E-4F08-9B93-080E282B81FE} /l1033 iTunes --> MsiExec.exe /I{446DBFFA-4088-48E3-8932-74316BA4CAE4} J2SE Runtime Environment 5.0 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150020} JMPINTRO 5.0.1 --> RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{BBCC38A7-3871-43B9-A518-BD9F6F992722}\setup.exe" -l0x9 Kodak EasyShare software --> F:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_190007_39bd037\Setup.exe /APR-REMOVE KSU --> MsiExec.exe /I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267} LimeWire 4.14.8 --> "F:\Program Files\LimeWire\uninstall.exe" Macromedia Flash Player 8 --> RunDll32 advpack.dll,LaunchINFSection F:\WINDOWS\INF\swflash.inf,DefaultUninstall,5 Macromedia Shockwave Player --> F:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE F:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log McAfee Personal Firewall Express --> F:\PROGRA~1\McAfee.com\PERSON~1\UNWISE.EXE /U F:\PROGRA~1\McAfee.com\PERSON~1\INSTALL.LOG McAfee SecurityCenter --> f:\PROGRA~1\mcafee.com\shared\mcappins.exe /v=3 /uninstall=1 /interact=1 /script_proactive=0 /start=f:\PROGRA~1\mcafee.com\agent\uninst\screm.ui::uninstall.htm McAfee VirusScan --> f:\PROGRA~1\mcafee.com\shared\mcappins.exe /v=3 /uninstall=1 /interact=1 /script_proactive=1 /start=f:\PROGRA~1\mcafee.com\agent\uninst\vsoremui.dll::uninstall.htm Microsoft Base Smart Card Cryptographic Service Provider Package --> "F:\WINDOWS\$NtUninstallbasecsp$\spuninst\spuninst.exe" Microsoft Office XP Professional --> MsiExec.exe /I{91110409-6000-11D3-8CFE-0050048383C9} Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "F:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe" MSN Music Assistant --> rundll32 advpack.dll,LaunchINFSection F:\WINDOWS\INF\msninst.inf,Uninstall Multi-Card Reader & Flash Disk --> RunDll32 F:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "F:\Program Files\InstallShield Installation Information\{83F3EED2-DDE2-4434-8FBE-9D2A1E7C2BC8}\SETUP.EXE" -l0x9 -wUninst Notifier --> MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2} OfotoXMI --> MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45} OTtBP --> MsiExec.exe /I{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C} OTtBPSDK --> MsiExec.exe /I{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353} QuickTime --> MsiExec.exe /I{50D8FFDD-90CD-4859-841F-AA1961C7767A} RealPlayer --> F:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} SFR --> MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B} SHASTA --> MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237} SKIN0001 --> MsiExec.exe /I{FDF9943A-3D5C-46B3-9679-586BD237DDEE} SKINXSDK --> MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F} Sound Blaster Live! Value --> F:\Program Files\Creative\Uninstall\CTUNINST.EXE /U:UNINST1.INI Spy Sweeper --> "F:\Program Files\Webroot\Spy Sweeper\unins000.exe" Symantec Technical Support Web Controls --> MsiExec.exe /X{9743AF47-B746-4324-B4C4-512E67D04370} Viewpoint Manager (Remove Only) --> F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe /u /k Viewpoint Media Player --> F:\Program Files\Viewpoint\Viewpoint Experience Technology\mtsAxInstaller.exe /u VPRINTOL --> MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370} Windows Media Connect --> "F:\WINDOWS\$NtUninstallWMCSetup$\spuninst\spuninst.exe" Windows Media Format 11 runtime --> "F:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" WinZip --> "F:\Program Files\WinZip\WINZIP32.EXE" /uninstall WIRELESS --> MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F} -- Application Event Log ------------------------------------------------------- Event Record #/Type1993 / Success Event Submitted/Written: 01/18/2008 07:32:18 PM Event ID/Source: 2570 / Adobe Active File Monitor 5.0 Event Description: Adobe Active File Monitor Service has Started. Event Record #/Type1985 / Success Event Submitted/Written: 01/18/2008 07:04:51 PM Event ID/Source: 2570 / Adobe Active File Monitor 5.0 Event Description: Adobe Active File Monitor Service has Started. Event Record #/Type1983 / Error Event Submitted/Written: 01/18/2008 06:56:15 PM Event ID/Source: 1000 / Application Error Event Description: Faulting application McShield.exe, version 6.0.0.100, faulting module kernel32.dll, version 5.1.2600.3119, fault address 0x00012a5b. Processing media-specific event for [McShield.exe!ws!] Event Record #/Type1982 / Error Event Submitted/Written: 01/18/2008 06:55:50 PM Event ID/Source: 5051 / McLogEvent Event Description: A thread in process f:\PROGRA~1\mcafee.com\vso\mcshield.exe took longer than 241608 ms to complete a request. The process will be terminated. Thread id : 1224 (0x4c8) Thread address : 0x7c90eb94 Thread message : Build Sep 8 2001 15:13:39 / 5100.194 Object being scanned = \Device\HarddiskVolume1\Documents and Settings\All Users\Application Data\AOL\AOLDiag\AOL\ServiceHostUSGM\Win32\1.5.6.1\fcs19.tmp ( @ 7025 (7024,7019,7011,93)) Event Record #/Type1975 / Success Event Submitted/Written: 01/18/2008 06:49:19 PM Event ID/Source: 2570 / Adobe Active File Monitor 5.0 Event Description: Adobe Active File Monitor Service has Started. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type73259 / Warning Event Submitted/Written: 01/18/2008 07:36:28 PM Event ID/Source: 4226 / Tcpip Event Description: TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts. Event Record #/Type73254 / Error Event Submitted/Written: 01/18/2008 07:33:56 PM Event ID/Source: 7000 / Service Control Manager Event Description: The Application Layer Gateway Service service failed to start due to the following error: %%1053 Event Record #/Type73253 / Error Event Submitted/Written: 01/18/2008 07:33:54 PM Event ID/Source: 7009 / Service Control Manager Event Description: Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect. Event Record #/Type73196 / Error Event Submitted/Written: 01/18/2008 07:05:08 PM Event ID/Source: 54 / Print Event Description: Document Microsoft Word - mso78C77.doc was corrupted and has been deleted. The associated driver is: hp officejet 7100 series. Event Record #/Type73191 / Error Event Submitted/Written: 01/18/2008 06:56:28 PM Event ID/Source: 7034 / Service Control Manager Event Description: The McAfee.com McShield service terminated unexpectedly. It has done this 1 time(s). -- End of Deckard's System Scanner: finished at 2008-01-18 19:46:16 ------------ |
|
|
Jan 17 2008, 07:13 PM
Post
#8
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
Hello
Backup Your Registry with ERUNT
Note: to restore your registry, go to the folder and start ERDNT.exe Now we need to fix your problems by making a .reg file. Copy the code below into a Notepad file. Name the file as fix.reg, change the "Save as Type" to "All files" and save it on the desktop. CODE Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\New.net Startup] Then double click on the fix.reg file, when it prompts to merge click "Yes". Please do an online scan with Kaspersky WebScanner Click on Kaspersky Online Scanner and click Accept You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
Scan Mail Bases
Reboot and post a new DSS log |
|
|
Jan 18 2008, 11:42 AM
Post
#9
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
I got a problem.....
Whenever i try to copy the Kaspersky log my internet frezzes and i go task manager and the cpu usage is 100% but i can though copy the DSS Log here it is Deckard's System Scanner v20071014.68 Run by Franny on 2008-01-19 11:54:22 Computer is in Normal Mode. -------------------------------------------------------------------------------- Percentage of Memory in Use: 77% (more than 75%). -- HijackThis (run as Franny.exe) ---------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:54:59 AM, on 1/19/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe F:\WINDOWS\System32\CTsvcCDA.EXE f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe F:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe F:\WINDOWS\System32\svchost.exe F:\Program Files\Viewpoint\Common\ViewpointService.exe F:\WINDOWS\wanmpsvc.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe F:\WINDOWS\System32\MsPMSPSv.exe f:\PROGRA~1\mcafee.com\vso\mcshield.exe F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe F:\WINDOWS\system32\devldr32.exe F:\WINDOWS\Explorer.EXE F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE F:\PROGRA~1\mcafee.com\vso\mcvsshld.exe F:\Program Files\Common Files\AOL\ACS\AOLDial.exe F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe F:\Program Files\iTunes\iTunesHelper.exe F:\WINDOWS\Dit.exe F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe F:\Program Files\Messenger\msmsgs.exe F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe F:\WINDOWS\system32\ctfmon.exe F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe f:\progra~1\mcafee.com\vso\mcvsescn.exe F:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe F:\Program Files\iPod\bin\iPodService.exe F:\Program Files\Microsoft Office\Office10\msoffice.exe f:\program files\mcafee.com\agent\mcagent.exe F:\WINDOWS\system32\wuauclt.exe f:\progra~1\mcafee.com\vso\mcvsftsn.exe f:\program files\common files\aol\1124472623\ee\aolsoftware.exe F:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe F:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe F:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe f:\program files\common files\aol\1124472623\ee\aolsoftware.exe f:\program files\common files\aol\1124472623\ee\anotify.exe F:\WINDOWS\system32\NOTEPAD.EXE F:\Documents and Settings\Franny\Desktop\dss.exe F:\PROGRA~1\TRENDM~1\HIJACK~1\Franny.exe O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] "F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" O4 - HKLM\..\Run: [DIAGENT] "F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE" startup O4 - HKLM\..\Run: [AHQInit] "F:\Program Files\Creative\SBLive\Program\AHQInit.exe" O4 - HKLM\..\Run: [VSOCheckTask] "f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] "f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] f:\PROGRA~1\mcafee.com\agent\McUpdate.exe O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe O4 - HKLM\..\Run: [AOLDialer] "F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" O4 - HKLM\..\Run: [AOL Spyware Protection] "F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" O4 - HKLM\..\Run: [HostManager] "F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe" O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ViewMgr] "F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" O4 - HKLM\..\Run: [CICache] CICache.exe O4 - HKLM\..\Run: [Dit] Dit.exe O4 - HKLM\..\Run: [Adobe Photo Downloader] "F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" O4 - HKLM\..\Run: [SpySweeper] F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray O4 - HKCU\..\Run: [AIM] F:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Aim6] "F:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [swg] F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: HPAiODevice(hp officejet 7100 series) - 1.lnk = F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe O4 - Global Startup: Kodak EasyShare software.lnk = F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Kodak software updater.lnk = F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Save Image to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimagetofolder.html O8 - Extra context menu item: &Save Image to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveimages.html O8 - Extra context menu item: &Save Link to Folder - res://F:\Program Files\AskBar\bar\bin\askBar.dll/saveltof.html O8 - Extra context menu item: &Save Link to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savelink.html O8 - Extra context menu item: &Save Page to Folder... - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savepagetofolder.html O8 - Extra context menu item: &Save this Page to MyStuff - res://F:\Program Files\AskBar\bar\bin\askBar.dll/savewebpage.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - F:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .asx: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O12 - Plugin for .wmv: F:\Program Files\Netscape\Communicator\Program\PLUGINS\npdsplay.dll O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/hamsterball/raptisoftgameloader.cab O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo...otoUploader.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1119890110780 O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX27.cab O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - F:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - F:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\System32\CTsvcCDA.EXE O23 - Service: Google Updater Service (gusvc) - Google - F:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - F:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee.com McShield (McShield) - Unknown owner - f:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - f:\PROGRA~1\mcafee.com\vso\mcvsrte.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - F:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - F:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - F:\WINDOWS\wanmpsvc.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe -- End of file - 10738 bytes -- Files created between 2007-12-19 and 2008-01-19 ----------------------------- 2008-01-18 22:04:04 0 d-------- F:\Documents and Settings\All Users\Application Data\Kaspersky Lab 2008-01-18 22:04:01 0 d-------- F:\WINDOWS\system32\Kaspersky Lab 2008-01-16 16:47:20 0 d-------- F:\Program Files\Trend Micro 2008-01-16 13:43:32 0 d-------- F:\Documents and Settings\NetworkService\Application Data\Webroot 2008-01-16 13:30:04 0 d-------- F:\Program Files\Common Files\Symantec Shared 2008-01-16 13:30:04 0 d-------- F:\Documents and Settings\All Users\Application Data\Symantec 2008-01-12 20:34:05 0 d-------- F:\Documents and Settings\Steve\Application Data\acccore 2008-01-12 15:47:25 0 d-------- F:\Documents and Settings\Steve\Application Data\Webroot 2008-01-05 13:56:51 0 d-------- F:\Documents and Settings\Franny\Application Data\Webroot 2008-01-05 11:52:35 0 d-------- F:\Documents and Settings\All Users\Application Data\Webroot 2008-01-04 22:42:20 164 --a------ F:\install.dat 2008-01-01 17:18:43 0 d-------- F:\Documents and Settings\Steve\Application Data\Apple Computer 2007-12-26 11:09:06 0 d-------- F:\Documents and Settings\Franny\Application Data\ArcSoft 2007-12-26 10:59:21 0 d-------- F:\My Videos 2007-12-25 10:45:58 4 --a------ F:\WINDOWS\system32\BEB8A3 2007-12-25 10:41:14 0 d-------- F:\WINDOWS\system32\drivers\UMDF 2007-12-25 10:35:36 8413 --a------ F:\WINDOWS\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path Manager® (32-bit)> 2007-12-25 10:21:41 0 d-------- F:\Program Files\Best Buy Rhapsody 2007-12-25 10:16:55 0 d-------- F:\Program Files\Common Files\ArcSoft 2007-12-25 10:16:53 0 d-------- F:\Program Files\ArcSoft 2007-12-24 15:43:18 0 d-------- F:\Program Files\Common Files\ODBC -- Find3M Report --------------------------------------------------------------- 2008-01-16 13:30:04 0 d-------- F:\Program Files\Common Files 2008-01-10 20:45:31 0 d-------- F:\Program Files\Google 2008-01-10 16:27:45 0 d-------- F:\Documents and Settings\Franny\Application Data\LimeWire 2008-01-09 15:39:28 0 d--h----- F:\Program Files\InstallShield Installation Information 2007-12-29 11:08:59 0 d-------- F:\Documents and Settings\Franny\Application Data\U3 2007-12-25 11:26:49 0 d-------- F:\Documents and Settings\Franny\Application Data\Real 2007-12-25 10:24:45 0 d-------- F:\Program Files\Real 2007-12-24 14:19:41 0 d-------- F:\Program Files\Pure Networks 2007-12-24 01:32:51 0 d-------- F:\Program Files\QuickTime 2007-12-24 01:03:14 0 d-------- F:\Program Files\Microsoft AntiSpyware 2007-12-24 00:39:06 0 d-------- F:\Program Files\Creative 2007-12-24 00:39:03 0 d-------- F:\Program Files\Common Files\aolshare 2007-12-24 00:39:02 0 d-------- F:\Program Files\Common Files\AOL 2007-12-24 00:38:54 0 d-------- F:\Program Files\America Online 9.0 2007-12-24 00:36:43 0 d-------- F:\Program Files\Common Files\Adobe 2007-11-30 17:14:00 2 --a------ F:\WINDOWS\system32\faxwin32.bin 2007-11-04 17:30:02 714 --a------ F:\WINDOWS\eReg.dat -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Share-to-Web Namespace Daemon"="F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [07/03/2001 12:11 PM] "DIAGENT"="F:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.exe" [08/30/2001 04:00 AM] "AHQInit"="F:\Program Files\Creative\SBLive\Program\AHQInit.exe" [03/27/2001 08:00 PM] "VSOCheckTask"="f:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" [08/08/2003 09:02 PM] "VirusScan Online"="f:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" [08/18/2003 12:50 AM] "MCAgentExe"="f:\PROGRA~1\mcafee.com\agent\mcagent.exe" [08/27/2003 02:00 PM] "MCUpdateExe"="f:\PROGRA~1\mcafee.com\agent\McUpdate.exe" [08/21/2003 09:10 PM] "MPFExe"="F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe" [04/19/2004 10:29 AM] "AOLDialer"="F:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [10/23/2006 07:50 AM] "AOL Spyware Protection"="F:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe" [03/19/2004 01:17 PM] "HostManager"="F:\Program Files\Common Files\AOL\1124472623\ee\AOLSoftware.exe" [09/25/2006 07:52 PM] "TkBellExe"="F:\Program Files\Common Files\Real\Update_OB\realsched.exe" [07/04/2005 09:52 PM] "QuickTime Task"="F:\Program Files\QuickTime\qttask.exe" [10/25/2006 06:58 PM] "iTunesHelper"="F:\Program Files\iTunes\iTunesHelper.exe" [10/30/2006 09:36 AM] "ViewMgr"="F:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" [11/10/2004 11:15 PM] "CICache"="CICache.exe" [09/05/2002 02:21 PM F:\WINDOWS\CICache.exe] "Dit"="Dit.exe" [04/27/2004 02:34 PM F:\WINDOWS\Dit.exe] "Adobe Photo Downloader"="F:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [09/14/2006 07:55 AM] "SpySweeper"="F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [10/01/2007 04:40 PM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AIM"="F:\Program Files\AIM\aim.exe" [08/01/2006 02:35 PM] "MSMSGS"="F:\Program Files\Messenger\msmsgs.exe" [10/13/2004 11:24 AM] "Aim6"="F:\Program Files\AIM6\aim6.exe" [09/29/2007 03:22 PM] "swg"="F:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [04/08/2007 07:43 PM] "ctfmon.exe"="F:\WINDOWS\system32\ctfmon.exe" [08/03/2004 11:56 PM] F:\Documents and Settings\All Users\Start Menu\Programs\Startup\ HPAiODevice(hp officejet 7100 series) - 1.lnk - F:\Program Files\Hewlett-Packard\AiO\hp officejet 7100 series\Bin\hpogrp07.exe [11/23/2002 7:55:48 PM] Kodak EasyShare software.lnk - F:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [9/3/2005 6:45:28 AM] Kodak software updater.lnk - F:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2/13/2004 2:12:08 PM] Microsoft Office.lnk - F:\Program Files\Microsoft Office\Office10\OSA.EXE [2/13/2001 4:01:04 AM] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] @=0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}] @="Volume shadow copy" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] "F:\Program Files\Messenger\msmsgs.exe" /background -- End of Deckard's System Scanner: finished at 2008-01-19 12:01:52 ------------ |
|
|
Jan 18 2008, 11:46 AM
Post
#10
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
Do this instead
Download and scan with SUPERAntiSpyware Free for Home Users
Also tell me how your PC is running |
|
|
Jan 18 2008, 01:51 PM
Post
#11
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
It said there was no detections but i remember that when i ran Kaspersky scan there was. My computer is working pretty well. There is no pop-ups telling me i have TrojandDownloader.NX and task manager works again.
Heres the Log anyway.... SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 01/19/2008 at 01:37 PM Application Version : 3.9.1008 Core Rules Database Version : 3143 Trace Rules Database Version: 1159 Scan type : Complete Scan Total Scan Time : 00:19:14 Memory items scanned : 582 Memory threats detected : 0 Registry items scanned : 5751 Registry threats detected : 0 File items scanned : 9927 File threats detected : 0 |
|
|
Jan 18 2008, 01:53 PM
Post
#12
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
Your logs look good ! We need to do a few things
You can delete the tools that we used Now we need to create a new System Restore point. Click Start Menu > Run > type (or copy and paste) %SystemRoot%\System32\restore\rstrui.exe Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close. Next goto Start Menu > Run > type cleanmgr Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created. To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window. You now need to update your Java and remove your older versions. Please follow these steps to remove older version Java components. * Click Start > Control Panel. * Click Add/Remove Programs. * Check any item with Java Runtime Environment (JRE) in the name. * Click the Remove or Change/Remove button. Download the latest version of Java Runtime Environment (JRE), and install it to your computer from here Below I have included a number of recommendations for how to protect your computer against malware infections. * Keep Windows updated by regularly checking their website at : http://windowsupdate.microsoft.com/ This will ensure your computer has always the latest security updates available installed on your computer. * To reduce re-infection for malware in the future, I strongly recommend installing these free programs: SpywareBlaster protects against bad ActiveX IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all Have a look at this tutorial for IE-Spyad here * SpywareGuard offers realtime protection from spyware installation attempts. Make Internet Explorer more secure
* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future. * Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from Here * Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place' Here Thank you for your patience, and performing all of the procedures requested. |
|
|
Jan 18 2008, 02:41 PM
Post
#13
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
I got a question. Can i uninstall the SUPERAntiSpyware program we used or do i need to keep it. Also, do i need to download all the free programs you told me to?
Thanks |
|
|
Jan 18 2008, 06:35 PM
Post
#14
|
|
![]() GeekU Teacher Posts: 34,385 From: Dublin OS: XP |
You can uninstall SUPERAntiSpyware if you want, however that would not be a smart idea.
QUOTE Also, do i need to download all the free programs you told me to? Well do you want to be infected in the future ? |
|
|
Jan 18 2008, 08:49 PM
Post
#15
|
|
|
Member ![]() ![]() Posts: 12 OS: Windows XP |
Ok. Just checking. You been a big help the last couple of days. Thank you so much for fixing my computer. Your the man!!!
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
28 / 11,524 | 19th April 2005 - 12:19 PM panaceabeachbum started - last by ScHwErV |
|||||
![]() |
9 / 888 | 19th July 2005 - 08:22 AM phooey started - last by tampabelle |
|||||
![]() |
10 / 416 | 12th September 2006 - 02:13 AM getz started - last by Crustyoldbloke |
|||||
![]() |
3 / 525 | 25th June 2009 - 04:17 PM Slink started - last by Rorschach112 |
|||||
|
Time is now: 8th November 2009 - 01:14 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising