Missing Menu Bar & Desktop Icons [CLOSED], HP Pavilion 733n Desktop |
![]() ![]() |
Missing Menu Bar & Desktop Icons [CLOSED], HP Pavilion 733n Desktop |
Nov 25 2007, 07:08 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
Hello, I am helping my friend out and helping him fix his computer. It is a HP Pavilion 733n Desktop. It has a AMD Athlon XP 2400+ 2.00GHz CPU and 480MB or ram. It is running Microsoft Windows XP Home Edition Version 2002 Service Pack 2. My friend says that about a year, his computer will start up with no Menu bar(The bar at the bottom of the screen that has the start button button) or desktop icons. Everything I do has to be ran through Windows Task Manager (alt + ctrl + del). I cannot access the control panel by typing "control" or "control panel" under a new task. I can not access run either (I think that task manager is the same thing, sort of?). I have downloaded Norton 360 and ran a complete antivirus/spyware test. There was a total of 1036290 files, 10759 threats and 10748 were resolved(I'm going to run another one soon.) I'm currently using Registry First aid to try and fix it. I have searched google and many other forums in hope of someone with the same problem, but no luck (I'm sure there are, I just can't Find them.) So the main thing I'd like to do is get the menu bar and Icons back. I have talked to Hp, they gave me a registry file, but that didn't help. My friend said it was a virus. While Norton was scanning the files, I noticed that there were traces of Kazaa and Lime-wire (that's a big no-no, especially with no antivirus software) I would appreciate clear instructions and I would like to thank you in advance. Thanks! (I feel like I'm Forgetting Something, but I can't remember it, I'll post or edit when I remember)Thanks, and I look forward to becoming an active member.
|
|
|
Nov 25 2007, 07:35 PM
Post
#2
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
Here is the log:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:43:38 PM, on 11/25/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE C:\WINDOWS\system32\ScsiAccess.EXE C:\Program Files\Spyware Doctor\svcntaux.exe C:\Program Files\Spyware Doctor\swdsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Norton 360\ScanStub.exe C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE C:\Program Files\Symantec\LiveUpdate\luall.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\System32\wbem\wmiprvse.exe C:\PROGRA~1\Symantec\LIVEUP~1\LUUPDATE.EXE C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\LIVEUP~1\DOWNLO~1\Updt42\Sevinst.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,onepisy.exe O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\5.bin\MWSBAR.DLL O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O2 - BHO: Zango Toolbar - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - C:\Program Files\ZangoToolbar\Bin\4.8.3.0\ZbHostIE.dll O2 - BHO: TTB000000 Class - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - C:\WINDOWS\COUPON~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O3 - Toolbar: CouponBar - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C:\WINDOWS\CouponBarIE.dll O3 - Toolbar: Zango Toolbar - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - C:\Program Files\ZangoToolbar\Bin\4.8.3.0\ZbHostIE.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O3 - Toolbar: (no name) - {84938242-5C5B-4A55-B6B9-A1507543B418} - (no file) O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe" O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [WinUpdate.exe] (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [WinUpdate.exe] (User 'Default user') O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZJxdm035YYUS O8 - Extra context menu item: Crawler Search - tbr:iemenu O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download...ne_Inst_Win.cab O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp...02/cpbrkpie.cab O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{6C7C0137-6063-477A-943C-E6E98157D0DF}: Domain = hsd1.il.comcast.net. O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll O18 - Filter hijack: text/html - (no CLSID) - (no file) O20 - Winlogon Notify: DateTime - C:\WINDOWS\ O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\ O20 - Winlogon Notify: Nls - C:\WINDOWS\ O20 - Winlogon Notify: RunOnce - C:\WINDOWS\ O20 - Winlogon Notify: Telephony - C:\WINDOWS\ O20 - Winlogon Notify: URL - C:\WINDOWS\ O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\ O22 - SharedTaskScheduler: homina - {df8c3aed-b58e-4bcb-96b3-aa1b7bbdbbd4} - (no file) O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- End of file - 10560 bytes |
|
|
Nov 28 2007, 04:33 PM
Post
#3
|
|
|
GeekU Moderator Posts: 14,119 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Hi there sorry for the delay, lets see what I can do to help
First, Download LSPFix.exe to a convenient location. Do NOT run this program. This is only to be used if you lose Internet Access after removing NewDotNet. To Get rid of NewDotNet, go to: Start > Control Panel > Add or Remove Programs and remove the following: New.Net Applications or New.Net Domains (anything that says New.Net) If it is not there, go here and follow Procedure 4: NewDotNet Removal Procedure 4. In the event that you lose Internet access after removing New.Net, please double-click LSPFix.exe that you downloaded earlier. Check the "I know what I'm doing" button. You will see 2 panels. If there is any file listed in the "Remove" panel on the right-side, leave it as is and just click "Finish>>" then reboot your computer and you should now have access to the Internet. If nothing is listed under the "Remove Panel", do NOT do anything - just close the program. You will need to use another computer to come back here for further instructions on what to do. NEXT Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,onepisy.exe O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll O2 - BHO: Zango Toolbar - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - C:\Program Files\ZangoToolbar\Bin\4.8.3.0\ZbHostIE.dll O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\5.bin\MWSBAR.DLL O2 - BHO: TTB000000 Class - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - C:\WINDOWS\COUPON~1.DLL O3 - Toolbar: CouponBar - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C:\WINDOWS\CouponBarIE.dll O3 - Toolbar: Zango Toolbar - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - C:\Program Files\ZangoToolbar\Bin\4.8.3.0\ZbHostIE.dll O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [WinUpdate.exe] (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [WinUpdate.exe] (User 'Default user') O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZJxdm035YYUS O18 - Filter hijack: text/html - (no CLSID) - (no file) O20 - Winlogon Notify: DateTime - C:\WINDOWS\ O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\ O20 - Winlogon Notify: Nls - C:\WINDOWS\ O20 - Winlogon Notify: RunOnce - C:\WINDOWS\ O20 - Winlogon Notify: Telephony - C:\WINDOWS\ O20 - Winlogon Notify: URL - C:\WINDOWS\ O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\ O22 - SharedTaskScheduler: homina - {df8c3aed-b58e-4bcb-96b3-aa1b7bbdbbd4} - (no file) Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot into safe mode. Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode. Please go to Start > Control Panel > Add/Remove Programs and remove the following (if present): Mywebsearch Please note any other programs that you dont recognize in that list in your next response THEN Please download the OTMoveIt by OldTimer.
*If a file or folder cannot be moved immediately, you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine, choose Yes. **If a reboot was necessary or you needed to Exit before posting the log, you will find a copy of the log at the root of the drive where OTMoveIt is installed, usually at : C:\_OTMoveIt\MovedFiles\********_******.log (where "********_******" is the "date_time") Click "Exit" to close OTMoveIt. FINALLY FOR NOW Download ComboFix from Here or Here to your Desktop.
Logs required : OTMoveit and Combofix |
|
|
Nov 28 2007, 06:22 PM
Post
#4
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
Thank You,
I went to the Control Panel and deleted "new.net domains 7.48" then, I tried to uninstall my websearch but if gave me this "Error loading C:\progra~1\MYWEBS~1\bar\s.bin\mwsbar.dll The specified module could not be found" Old Timer log C:\Program Files\MyWebSearch\SrchAstt moved successfully. C:\Program Files\MyWebSearch\bar\Settings moved successfully. C:\Program Files\MyWebSearch\bar\Notifier moved successfully. C:\Program Files\MyWebSearch\bar\Message moved successfully. C:\Program Files\MyWebSearch\bar\icons moved successfully. Folder move failed. C:\Program Files\MyWebSearch\bar\History\search2 scheduled to be moved on reboot. Folder move failed. C:\Program Files\MyWebSearch\bar\History\search scheduled to be moved on reboot. C:\Program Files\MyWebSearch\bar\History moved successfully. C:\Program Files\MyWebSearch\bar\Game moved successfully. Folder move failed. C:\Program Files\MyWebSearch\bar\Cache\02E71DCB scheduled to be moved on reboot. Folder move failed. C:\Program Files\MyWebSearch\bar\Cache\02A4A62B scheduled to be moved on reboot. Folder move failed. C:\Program Files\MyWebSearch\bar\Cache\02A4A3BA scheduled to be moved on reboot. Folder move failed. C:\Program Files\MyWebSearch\bar\Cache\01B8A00C scheduled to be moved on reboot. Folder move failed. C:\Program Files\MyWebSearch\bar\Cache\01B87D80 scheduled to be moved on reboot. Folder move failed. C:\Program Files\MyWebSearch\bar\Cache\002483B7 scheduled to be moved on reboot. C:\Program Files\MyWebSearch\bar\Cache moved successfully. C:\Program Files\MyWebSearch\bar\Avatar\COMMON moved successfully. C:\Program Files\MyWebSearch\bar\Avatar moved successfully. C:\Program Files\MyWebSearch\bar moved successfully. C:\Program Files\MyWebSearch moved successfully. File/Folder C:\Program Files\NewDotNet not found. C:\Program Files\ZangoToolbar\Bin moved successfully. C:\Program Files\ZangoToolbar moved successfully. File/Folder C:\WINDOWS\COUPON~1.DLL not found. File/Folder C:\WINDOWS\CouponBarIE.dll not found. Created on 11/28/2007 18:13:15 I couldn't get a combo fix log because I'd run it and it would shut he window, open one, say acess denied, preparing to run, acess denied then it shut I ran this in both safe and noramal mode here is the hijack this log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:31:50 PM, on 11/28/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE C:\WINDOWS\system32\ScsiAccess.EXE C:\Program Files\Spyware Doctor\svcntaux.exe C:\Program Files\Spyware Doctor\swdsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Spyware Doctor\SDTrayApp.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\System32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe" O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download...ne_Inst_Win.cab O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp...02/cpbrkpie.cab O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{6C7C0137-6063-477A-943C-E6E98157D0DF}: Domain = hsd1.il.comcast.net. O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll (file missing) O18 - Filter hijack: text/html - (no CLSID) - (no file) O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- End of file - 6027 bytes |
|
|
Nov 29 2007, 12:13 PM
Post
#5
|
|
|
GeekU Moderator Posts: 14,119 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
No problem on combofix I will take another route
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab O18 - Filter hijack: text/html - (no CLSID) - (no file) Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. THEN Please download Deckard's System Scanner (DSS) and save it to your Desktop.
If you could also let me know your current situation |
|
|
Nov 29 2007, 03:12 PM
Post
#6
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
extra
Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Home Edition (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: AMD Athlon XP 2400+ Percentage of Memory in Use: 73% Physical Memory (total/avail): 479.48 MiB / 125.52 MiB Pagefile Memory (total/avail): 1125.64 MiB / 761.71 MiB Virtual Memory (total/avail): 2047.88 MiB / 1948.98 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 106.76 GiB total, 79.01 GiB free. D: is Fixed (FAT32) - 5.02 GiB total, 0 GiB free. E: is CDROM (No Media) F: is CDROM (No Media) G: is CDROM (CDFS) H: is Removable (FAT32) \\.\PHYSICALDRIVE0 - WDC WD1200AB-22CBA1 - 111.79 GiB - 2 partitions \PARTITION0 - Unknown - 5.03 GiB - D: \PARTITION1 (bootable) - Installable File System - 106.76 GiB - C: \\.\PHYSICALDRIVE1 - SanDisk U3 Cruzer Micro USB Device - 1945.37 MiB - 1 partition \PARTITION0 - Unknown - 1952.79 MiB - H: -- Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. Windows Internal Firewall is disabled. UpdatesDisableNotify is set. FW: Norton 360 v2007 (SYMANTEC Corporation) AV: Spyware Doctor with AntiVirus v (PC Tools) AV: Norton 360 v2007 (SYMANTEC Corperation) [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:Disabled:Microsoft Fax Console" "C:\\My Games\\Wheel of Fortune\\Wheel of Fortune.exe"="C:\\My Games\\Wheel of Fortune\\Wheel of Fortune.exe:*:Enabled:Wheel of Fortune" "C:\\Program Files\\Kazaa\\kazaa.exe"="C:\\Program Files\\Kazaa\\kazaa.exe:*:Enabled:Kazaa" "C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer" "C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe:*:Enabled:Kodak Software Updater" "C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare" "C:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"="C:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe:*:Disabled:BackWeb-137903" "C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Owner\Application Data CLASSPATH=.;C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=WINXPHOME ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Owner LOGONSERVER=\\WINXPHOME NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;c:\Python22;C:\Program Files\QuickTime\QTSystem PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 8 Stepping 1, AuthenticAMD PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0801 ProgramFiles=C:\Program Files PROMPT=$P$G QTJAVA=C:\Program Files\Java\jre1.6.0_01\lib\ext\QTJava.zip SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\Owner\LOCALS~1\Temp TMP=C:\DOCUME~1\Owner\LOCALS~1\Temp USERDOMAIN=WINXPHOME USERNAME=Owner USERPROFILE=C:\Documents and Settings\Owner windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Owner (admin) Matt Kole (admin) Administrator.WINXPHOME (admin) -- Add/Remove Programs --------------------------------------------------------- --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu --> C:\WINDOWS\System32\\MSIEXEC.EXE /x {09DA4F91-2A09-4232-AB8C-6BC740096DE3} --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {1206EF92-2E83-4859-ACCB-2048C3CB7DA6} --> c:\WINDOWS\System32\\MSIEXEC.EXE /x {8214CC02-6271-4DC8-B8DD-779933450264} --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Action Replay Code Manager --> "C:\Program Files\Datel\Action Replay Code Manager\unins000.exe" Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Program Files\Common Files\Adobe\Acrobat 5.0\NT\Uninst.dll" Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log advertismen --> rundll32.exe C:\WINDOWS\system32\pushow63.dll Uninstall AOL Instant Messenger --> C:\Program Files\AIM\uninstll.exe -LOG= C:\Program Files\AIM\install.log -OEM= AppCore --> MsiExec.exe /I{EFB5B3B5-A280-4E25-BE1C-634EEFE32C1B} Apple Software Update --> MsiExec.exe /I{A260B422-70E1-41E2-957D-F76FA21266D5} ArcSoft ShowBiz --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Arcsoft\Showbiz\Uninst.isu" ArcSoft Software Suite --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\ArcSoft\Software Suite\Uninst.isu" AT&T Global Network Client --> C:\PROGRA~1\AT&T Global Network Client\NetUN.exe Attachmate Custom Component Downloader --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\aucpdnld.inf,DefaultUninstall,5 Audition --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6CB9AF08-79AE-4020-84A8-29CF15C67BD5}\Setup.exe" -l0x9 AV --> MsiExec.exe /I{F4DB525F-A986-4249-B98B-42A8066251CA} Battle.net --> C:\WINDOWS\bnetunin.exe Bejeweled 2 Deluxe 1.0 --> C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Bejeweled 2 Deluxe\Install.log" Belarc Advisor 7.0 --> C:\PROGRA~1\Belarc\Advisor\Uninstall.exe C:\PROGRA~1\Belarc\Advisor\INSTALL.LOG Big Fish Games Client --> C:\Program Files\bfgclient\Uninstall.exe BoontyBox 2.1 --> "C:\WINDOWS\unins000.exe" ccCommon --> MsiExec.exe /I{3CCAD2EF-CFF2-4637-82AA-AABF370282D3} CCScore --> MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992} Cheat Engine 5.2 --> "C:\Program Files\Cheat Engine\unins001.exe" Cheat Engine 5.3 --> "C:\Program Files\Cheat Engine\unins000.exe" Comcast PhotoShow Deluxe 4 --> "C:\Program Files\Comcast\Comcast PhotoShow 4\data\Xtras\Uninstall.exe" Comcast Rhapsody --> C:\PROGRA~1\COMCAS~2\Unwise32.exe /A C:\PROGRA~1\COMCAS~2\install.log Comcast Toolbar --> C:\Program Files\comcasttoolbar\uninstall.exe -uninstall -prompt Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE} Coupon Printer with CouponBar --> "C:\WINDOWS\Coupon Printer with CouponBar\uninstall.exe" "/U:C:\Program Files\Coupons\Uninstall\uninstall.xml" CouponBar --> regsvr32 /u /s "C:\WINDOWS\CouponBarIE.dll" CR2 --> MsiExec.exe /I{432C3720-37BF-4BD7-8E49-F38E090246D0} Crawler Toolbar --> C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe uninst Cue Club --> "C:\Program Files\Oberon Media\Cue Club\Uninstall.exe" "C:\Program Files\Oberon Media\Cue Club\install.log" Diablo --> C:\WINDOWS\diabunin.exe Disney's Toontown Online --> C:\PROGRA~1\Disney\DISNEY~1\Toontown\UNWISE.EXE /A C:\PROGRA~1\Disney\DISNEY~1\Toontown\INSTALL.LOG DLA --> MsiExec.exe /I{1206EF92-2E83-4859-ACCB-2048C3CB7DA6} Dynasty --> "C:\Program Files\Comcast Play Games\Dynasty\Uninstall.exe" "C:\Program Files\Comcast Play Games\Dynasty\install.log" Easter Crack Up Screen Saver --> sstunst2.exe Easter Crack Up ESSBrwr --> MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6} ESSCDBK --> MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD} ESScore --> MsiExec.exe /I{9D8FEE90-0377-49A9-AEFB-525BDE549BA4} ESSCT --> MsiExec.exe /I{8BB4B58A-A402-4DE8-8FCD-287E60B88DD8} ESSEMAIL --> MsiExec.exe /I{FEDE2483-87B7-44C1-A5BB-D75AEB8B6340} ESSgui --> MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A} ESShelp --> MsiExec.exe /I{87843A41-7808-4F2E-B13F-25C1E67CF2FD} ESSini --> MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765} ESSPCD --> MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5} ESSPDock --> MsiExec.exe /I{FCDB1C92-03C6-4C76-8625-371224256091} ESSSONIC --> MsiExec.exe /I{4F677FC7-7AA8-412B-A957-F13CBE1C7331} ESSTOOLS --> MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589} essvatgt --> MsiExec.exe /I{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F} essvcpt --> MsiExec.exe /I{D1973749-F5E7-40EB-B528-F2B78685B9FF} ESSvpaht --> MsiExec.exe /I{A5B3EB8A-4071-42F0-8E8E-7A8342AA8E69} ESSvpot --> MsiExec.exe /I{48C82F7A-F100-4DAB-A310-8E18BF2159E1} FirstClassÆ Client --> C:\Program Files\InstallShield Installation Information\{5B35C417-2649-11D6-83D1-0050FC01225C}\setup.exe -runfromtemp -l0x0009 -uninst -removeonly Frets On Fire --> "C:\Program Files\Frets on Fire\Uninstall.exe" GearDrvs --> MsiExec.exe /I{206FD69B-F9FE-4164-81BD-D52552BC9C23} Google Earth --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}\setup.exe" -l0x9 -removeonly Hammer Heads 1.0 --> C:\Program Files\PopCap Games\Hammer Heads Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Hammer Heads Deluxe\Install.log" Hammer Heads en --> "C:\Program Files\BoontyGames\Hammer Heads\unins000.exe" Hero Editor V0.90 --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\Hero Editor\ST6UNST.001" Hero Editor V0.95 --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\Hero Editor\ST6UNST.LOG" Hero Editor V0.95 (C:\Program Files\Hero Editor\) --> C:\WINDOWS\st6unst.exe -n "C:\Program Files\Hero Editor\ST6UNST.000" Hex Workshop v4.23 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\BreakPoint Software\Hex Workshop 4.2\hw41unin.isu" HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall HLPIndex --> MsiExec.exe /I{38441BE7-79B0-42B8-8297-833704F949FE} HLPPDOCK --> MsiExec.exe /I{154508C0-07C5-4659-A7A0-E49968750D21} HLPSFO --> MsiExec.exe /I{8DD94CA3-BCD2-49C0-B537-F3B5D95FF0C8} Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" hp center --> C:\WINDOWS\BWUnin-6.1.0.153.exe -AppId 137903 HP Instant Support --> C:\PROGRA~1\HPINST~1\UNWISE.EXE C:\PROGRA~1\HPINST~1\INSTALL.LOG HP Memories Disc --> MsiExec.exe /X{FF384BDE-429B-45AD-A0C6-E593393D9D1C} HP Photo and Imaging 1.1 - Photosmart Cameras --> MsiExec.exe /X{1EEE2A9F-6471-42fa-8923-E8879168CE26} hp toolkit --> c:\Windows\HPTK\unhptkit.exe IGN Download Manager 2.2.2 --> C:\Program Files\IGN\Download Manager\uninst.exe ijji --> C:\ijji\ENGLISH\ijjiUninstall.exe ijji Auto Installer --> "C:\Program Files\InstallShield Installation Information\{1DCC7418-2089-4BDD-B321-3771956160FC}\setup.exe" -runfromtemp -l0x0009 -removeonly IMVU Avatar chat software (BETA) --> C:\Program Files\IMVU\Uninstall.exe Inactive HP Printer Drivers (Remove only) --> RunDll32 hpuninst.dll,InstallHinfSection UninstDefault 132 prntunin.inf Intel® 845G Chipset Graphics Driver Software --> RUNDLL32.EXE C:\WINDOWS\System32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2562 InterVideo WinDVD --> "C:\Program Files\InstallShield Installation Information\{C1939820-A945-11D4-86F6-0001031E5712}\setup.exe" REMOVEALL iPod for Windows 2005-10-12 --> C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{D9F4A9F8-92C5-4289-9D04-F0F8F02D580A} /l1033 iTunes --> MsiExec.exe /I{3592F5CB-B524-43AA-92F2-2377268199CC} iWin Games (remove only) --> "C:\Program Files\iWin Games\Uninstall.exe" J2SE Runtime Environment 5.0 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030} Java SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010} KBD --> C:\HP\KBD\KBD.EXE uninstalled Kodak EasyShare software --> C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_460007_132de9\Setup.exe /APR-REMOVE KSU --> MsiExec.exe /I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267} Kublox --> "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -UninstallItem {F7A4D9BE-D989-45B9-BB49-2C0EA34B9991} Lernout & Hauspie TruVoice American English TTS Engine --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\tv_enua.inf, Uninstall LiveUpdate 3.2 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U MapleStory --> MsiExec.exe /I{F99C5427-4D78-43E2-B97E-F4C4E622D612} Mega Manager --> C:\Program Files\InstallShield Installation Information\{3B6E3FC6-274C-4B6C-BC85-5C3B15DE18E2}\setup.exe -runfromtemp -l0x0009 -removeonly MegaUpload Toolbar --> C:\Program Files\MegauploadToolbar\uninstall.exe Microsoft Color Control Panel Applet for Windows XP --> MsiExec.exe /X{CE378F36-E404-4244-A33F-F50A2A6D31BD} Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe" Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9} Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe" Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7} Microsoft Zoo Tycoon --> "C:\Program Files\Microsoft Games\Zoo Tycoon\UNINSTAL.EXE" /runtemp /addremove Mozilla Firefox (2.0.0.6) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe Mozilla Firefox (2.0.0.7) --> C:\PROGRA~1\Mozilla Firefox\uninstall\helper.exe MSN --> C:\Program Files\MSN\MsnInstaller\msniadm.exe /Action:ARP MUSICMATCH Jukebox --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\Uninst.isu" -cC:\PROGRA~1\MUSICM~1\MUSICM~1\unmatch.dll My Web Search (Zwinky) --> rundll32 C:\PROGRA~1\MYWEBS~1\bar\5.bin\mwsbar.dll,O NetBattle --> "C:\Program Files\NetBattle\unins000.exe" Nintendo DS - GBA Max Drive --> "C:\Program Files\Datel\Nintendo DS - GBA Max Drive\unins000.exe" Norton 360 --> MsiExec.exe /I{21829177-4DED-4209-AD08-490B3AC9C01A} Norton 360 --> MsiExec.exe /I{2D617065-1C52-4240-B5BC-C0AE12157777} Norton 360 --> MsiExec.exe /I{63A6E9A9-A190-46D4-9430-2DB28654AFD8} Norton 360 (Symantec Corporation) --> "C:\Program Files\Common Files\Symantec Shared\SymSetup\{2D617065-1C52-4240-B5BC-C0AE12157777}_1_3_0_24\{2D617065-1C52-4240-B5BC-C0AE12157777}.exe" /X Norton 360 Help --> MsiExec.exe /I{1CA941F1-5006-487E-9FD4-09F812A7D6B8} Norton Confidential Browser Component --> MsiExec.exe /I{4843B611-8FCB-4428-8C23-31D0A5EAE164} Norton Confidential Web Authentification Component --> MsiExec.exe /I{3074EB89-1BCA-4AEF-AFF4-EFB4634C1923} Norton Confidential Web Protection Component --> MsiExec.exe /I{D353CC51-430D-4C6F-9B7E-52003DA1E05A} Notifier --> MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2} OfotoXMI --> MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45} OpenMG Secure Module 4.2.00 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{849ABF1A-6AE3-45E1-B260-D5447B2F29F5} UNINSTALL OTtBP --> MsiExec.exe /I{F71760CD-0F8B-4DCC-B7B7-6B223CC3843C} OTtBPSDK --> MsiExec.exe /I{3CA39B0C-BA85-4D42-AC0F-1FF5F60C3353} PigPen --> "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -UninstallItem {B279B0DA-6F60-4FBD-9847-0C9AB79A3674} Quicken Financial Center --> C:\PROGRA~1\QUICKE~1\rem\UNWISE.EXE /s C:\PROGRA~1\QUICKE~1\rem\INSTALL.LOG QuickTime --> MsiExec.exe /I{08094E03-AFE4-4853-9D31-6D0743DF5328} QuickTime for Windows (32-bit) --> C:\WINDOWS\QTW32DEL.EXE RealArcade --> C:\Program Files\Real\RealArcade\Update\rnuninst.exe RealNetworks|RealArcade|1.2 RealPlayer Basic --> C:\Program Files\Common Files\Real\Update\\rnuninst.exe RealNetworks|RealPlayer|6.0 RecordNow --> MsiExec.exe /I{8214CC02-6271-4DC8-B8DD-779933450264} RecordNow Update Manager --> MsiExec.exe /I{09DA4F91-2A09-4232-AB8C-6BC740096DE3} RegCure 1.5.0.0 --> C:\Program Files\RegCure\uninst.exe Registry First Aid --> "C:\Program Files\RFA\unins000.exe" Registry Mechanic 5.2 --> "C:\Program Files\Registry Mechanic\unins000.exe" Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} Roll --> C:\WINDOWS\UniFish3.exe C:\Program Files\Hasbro Interactive\RollerCoaster Tycoon\RollerCoaster Tycoon.log S3Display --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Display' S3Gamma2 --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Gamma2' S3Info2 --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Info2' S3Overlay --> s3uninst.exe -reg 5 'HKLM\Software\S3\S3Uninst\S3Overlay' SabreWing 2 --> "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -UninstallItem {922B6E62-57DC-4153-97E3-12443BB5F9AE} Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe" SFR --> MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B} SFR2 --> MsiExec.exe /I{A0AF08BA-3630-4505-BFB2-A41F3837B0D0} SHASTA --> MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237} SKIN0001 --> MsiExec.exe /I{FDF9943A-3D5C-46B3-9679-586BD237DDEE} SKINXSDK --> MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F} Slingo --> "C:\Program Files\Oberon Media\Slingo\Uninstall.exe" "C:\Program Files\Oberon Media\Slingo\install.log" SmartDraw 2007 --> C:\PROGRA~1\SMARTD~1\UNWISE.EXE C:\PROGRA~1\SMARTD~1\install.log Snail Mail (remove only) --> C:\Program Files\Snail Mail\Uninstall.exe SonicStage 3.2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A0EB195B-5876-48E6-879D-33D4B2102610}\setup.exe" -l0x9 UNINSTALL -removeonly SPBBC 32bit --> MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56} Spyware Doctor 5.1 --> C:\Program Files\Spyware Doctor\unins000.exe /LOG Starcraft --> C:\WINDOWS\scunin.exe C:\WINDOWS\scunin.dat SuppSoft --> MsiExec.exe /I{022DA2C3-81C7-4003-A6BC-1BB147B20097} Symantec Technical Support Controls --> MsiExec.exe /I{92B1B3CC-EC78-45B8-96D0-8B3F11495864} SymNet --> MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2} The Adventures of Bleeposaurus - Dragonfire (remove only) --> C:\Program Files\The Adventures of Bleeposaurus - Dragonfire\Uninstall.exe The Legend of El Dorado Deluxe --> C:\PROGRA~1\GAMEHO~1\THELEG~1\UNWISE.EXE /U C:\PROGRA~1\GAMEHO~1\THELEG~1\INSTALL.LOG Tropix --> "C:\Program Files\Tropix\ReflexiveArcade\unins000.exe" Unreal --> C:\WINDOWS\IsUninst.exe -fC:\Unreal\System\Uninst.isu URGE --> MsiExec.exe /I{8BBF6DFD-0AD9-43A7-9FBD-BF065E3866AF} Viewpoint Manager (Remove Only) --> C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgrInstaller.exe /u /k Viewpoint Media Player --> C:\Program Files\Viewpoint\Viewpoint Media Player\mtsAxInstaller.exe /u Virtools 3D Life Player --> C:\Program Files\Virtools\3D Life Player\WebplayerConfig.exe -u Virtual Warfare --> "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -UninstallItem {4F0AE1FB-4082-4A27-8363-05D292D92FB0} VPRINTOL --> MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370} WildTangent Channel Manager --> C:\Program Files\WildTangent\DDC\DDCManager\Uninstall.exe WildTangent Web Driver --> C:\Program Files\WildTangent\Apps\CDA\CDAUninstall.exe Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe WIRELESS --> MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F} WordPerfect Productivity Pack --> C:\WINDOWS\Corel\uninst32.exe WordPerfect Productivity Pack --> C:\WINDOWS\Corel\Uninst32.exe Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe Zuma Deluxe 1.0 --> C:\Program Files\PopCap Games\Zuma Deluxe\PopUninstall.exe "C:\Program Files\PopCap Games\Zuma Deluxe\Install.log" -- Application Event Log ------------------------------------------------------- Event Record #/Type573 / Error Event Submitted/Written: 11/28/2007 05:06:54 PM Event ID/Source: 1024 / MsiInstaller Event Description: Product: Microsoft Office Professional Edition 2003 - Update 'Update for Outlook 2003: Junk E-mail Filter (KB943552): OUTLFLTR' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127 Event Record #/Type572 / Error Event Submitted/Written: 11/28/2007 05:06:54 PM Event ID/Source: 11311 / MsiInstaller Event Description: Product: Microsoft Office Professional Edition 2003 -- Error 1311. Source file not found(cabinet): C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\PA561401.CAB. Verify that the file exists and that you can access it. Event Record #/Type230 / Error Event Submitted/Written: 11/27/2007 05:07:16 PM Event ID/Source: 1024 / MsiInstaller Event Description: Product: Microsoft Office Professional Edition 2003 - Update 'Update for Outlook 2003: Junk E-mail Filter (KB943552): OUTLFLTR' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127 Event Record #/Type229 / Error Event Submitted/Written: 11/27/2007 05:07:15 PM Event ID/Source: 11311 / MsiInstaller Event Description: Product: Microsoft Office Professional Edition 2003 -- Error 1311. Source file not found(cabinet): C:\MSOCache\All Users\90000409-6000-11D3-8CFE-0150048383C9\PA561401.CAB. Verify that the file exists and that you can access it. Event Record #/Type225 / Error Event Submitted/Written: 11/27/2007 04:17:49 PM Event ID/Source: 1024 / MsiInstaller Event Description: Product: Microsoft Office Professional Edition 2003 - Update 'Update for Outlook 2003: Junk E-mail Filter (KB943552): OUTLFLTR' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127 -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type34070 / Error Event Submitted/Written: 11/29/2007 03:09:34 PM Event ID/Source: 1 / sr Event Description: The System Restore filter encountered the unexpected error '0xC000007F' while processing the file 'desktop.ini' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume. Event Record #/Type33945 / Warning Event Submitted/Written: 11/29/2007 11:50:00 AM Event ID/Source: 36 / W32Time Event Description: The time service has not been able to synchronize the system time for 49152 seconds because none of the time providers has been able to provide a usable time stamp. The system clock is unsynchronized. Event Record #/Type33315 / Error Event Submitted/Written: 11/28/2007 06:47:09 PM Event ID/Source: 20033 / Rasman Event Description: Remote Access Connection Manager failed to start because it could not register with the local security authority. Restart the computer. Incorrect function. Event Record #/Type33314 / Error Event Submitted/Written: 11/28/2007 06:46:37 PM Event ID/Source: 20033 / Rasman Event Description: Remote Access Connection Manager failed to start because it could not register with the local security authority. Restart the computer. Incorrect function. Event Record #/Type33312 / Error Event Submitted/Written: 11/28/2007 06:46:21 PM Event ID/Source: 20033 / Rasman Event Description: Remote Access Connection Manager failed to start because it could not register with the local security authority. Restart the computer. Incorrect function. -- End of Deckard's System Scanner: finished at 2007-11-29 15:11:04 ------------ main Deckard's System Scanner v20071014.68 Run by Owner on 2007-11-29 15:07:46 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- System Restore is disabled; attempting to re-enable...success. -- Last 1 Restore Point(s) -- 1: 2007-11-29 21:07:48 UTC - RP1 - System Checkpoint Backed up registry hives. Performed disk cleanup. Total Physical Memory: 480 MiB (512 MiB recommended). -- HijackThis (run as Owner.exe) ----------------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:09:44 PM, on 11/29/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE C:\WINDOWS\system32\ScsiAccess.EXE C:\Program Files\Spyware Doctor\svcntaux.exe C:\Program Files\Spyware Doctor\swdsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Spyware Doctor\SDTrayApp.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe H:\dss.exe C:\WINDOWS\System32\wbem\wmiprvse.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\Owner.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com/avcenter/fix_homepage R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe" O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download...ne_Inst_Win.cab O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp...02/cpbrkpie.cab O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{6C7C0137-6063-477A-943C-E6E98157D0DF}: Domain = hsd1.il.comcast.net. O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll (file missing) O18 - Filter hijack: text/html - (no CLSID) - (no file) O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- End of file - 5729 bytes -- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) ----------- backup-20071126-014521-760 O3 - Toolbar: Zango Toolbar - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - C:\Program Files\ZangoToolbar\Bin\4.8.3.0\ZbHostIE.dll backup-20071128-162722-285 O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\5.bin\MWSBAR.DLL backup-20071128-162722-586 O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL backup-20071128-162722-814 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll backup-20071128-162722-868 O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll backup-20071128-162723-447 O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll backup-20071128-162723-519 O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Program Files\NewDotNet\newdotnet7_48.dll backup-20071128-162723-780 O2 - BHO: Zango Toolbar - {5CBE2611-C31B-401F-89BC-4CBB25E853D7} - C:\Program Files\ZangoToolbar\Bin\4.8.3.0\ZbHostIE.dll backup-20071128-162724-931 O2 - BHO: TTB000000 Class - {62960D20-6D0D-1AB4-4BF1-95B0B5B8783A} - C:\WINDOWS\COUPON~1.DLL backup-20071128-162725-309 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll backup-20071128-162725-799 O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file) backup-20071128-162725-805 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll backup-20071128-162725-847 O3 - Toolbar: CouponBar - {5BED3930-2E9E-76D8-BACC-80DF2188D455} - C:\WINDOWS\CouponBarIE.dll backup-20071128-162725-920 O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL backup-20071128-162726-182 O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll backup-20071128-162726-289 O8 - Extra context menu item: Crawler Search - tbr:iemenu backup-20071128-162726-368 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 backup-20071128-162726-373 O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/...?p=ZJxdm035YYUS backup-20071128-162726-457 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" backup-20071128-162726-866 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL backup-20071128-162726-940 O3 - Toolbar: (no name) - {84938242-5C5B-4A55-B6B9-A1507543B418} - (no file) backup-20071128-162729-232 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe backup-20071128-162729-423 O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe backup-20071128-162729-440 O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Owner\Start Menu\Programs\IMVU\Run IMVU.lnk backup-20071128-162729-617 O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll backup-20071128-162730-502 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe backup-20071128-162730-863 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe backup-20071128-162849-633 O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe backup-20071128-162849-746 O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe backup-20071128-180214-181 O20 - Winlogon Notify: DateTime - C:\WINDOWS\ backup-20071128-180214-244 O20 - Winlogon Notify: Telephony - C:\WINDOWS\ backup-20071128-180214-336 O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [WinUpdate.exe] (User 'SYSTEM') backup-20071128-180214-483 O18 - Filter hijack: text/html - (no CLSID) - (no file) backup-20071128-180214-619 F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,onepisy.exe backup-20071128-180214-641 O20 - Winlogon Notify: Nls - C:\WINDOWS\ backup-20071128-180214-669 O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [WinUpdate.exe] (User 'Default user') backup-20071128-180214-812 O20 - Winlogon Notify: RunOnce - C:\WINDOWS\ backup-20071128-180214-941 O20 - Winlogon Notify: Internet Settings - C:\WINDOWS\ backup-20071128-180214-951 R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL (file missing) backup-20071128-180215-454 O22 - SharedTaskScheduler: homina - {df8c3aed-b58e-4bcb-96b3-aa1b7bbdbbd4} - (no file) backup-20071128-180215-574 O20 - Winlogon Notify: URL - C:\WINDOWS\ backup-20071128-180215-875 O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\ backup-20071129-150614-164 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = backup-20071129-150614-561 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\PCHEALTH\HELPCTR\System\panels\blank.htm backup-20071129-150614-944 O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f...p1.0.0.15-3.cab backup-20071129-150615-977 O18 - Filter hijack: text/html - (no CLSID) - (no file) -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R0 drvmcdb - c:\windows\system32\drivers\drvmcdb.sys <Not Verified; VERITAS Software, Inc.; > R1 AFS2K - c:\windows\system32\drivers\afs2k.sys <Not Verified; Oak Technology Inc.; AFS> R1 BANTExt (Belarc SMBios Access) - c:\windows\system32\drivers\bantext.sys R1 sscdbhk5 - c:\windows\system32\drivers\sscdbhk5.sys <Not Verified; VERITAS Software, Inc.; > R1 ssrtln - c:\windows\system32\drivers\ssrtln.sys <Not Verified; VERITAS Software, Inc.; > R2 ASCTRM - c:\windows\system32\drivers\asctrm.sys <Not Verified; Windows ® 2000 DDK provider; Windows ® 2000 DDK driver> R2 drvnddm - c:\windows\system32\drivers\drvnddm.sys <Not Verified; VERITAS Software, Inc.; > R2 MCSTRM - c:\windows\system32\drivers\mcstrm.sys <Not Verified; RealNetworks, Inc.; RealNetworks Virtual Path ManagerÆ (32-bit)> R2 npkcrypt - c:\nexon\maplestory\npkcrypt.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver> R2 tfsnboio - c:\windows\system32\dla\tfsnboio.sys <Not Verified; VERITAS Software, Inc.; > R2 tfsncofs - c:\windows\system32\dla\tfsncofs.sys <Not Verified; VERITAS Software, Inc.; > R2 tfsndrct - c:\windows\system32\dla\tfsndrct.sys <Not Verified; VERITAS Software, Inc.; > R2 tfsndres - c:\windows\system32\dla\tfsndres.sys <Not Verified; VERITAS Software, Inc.; > R2 tfsnifs - c:\windows\system32\dla\tfsnifs.sys <Not Verified; VERITAS Software, Inc.; > R2 tfsnopio - c:\windows\system32\dla\tfsnopio.sys <Not Verified; VERITAS Software, Inc.; > R2 tfsnpool - c:\windows\system32\dla\tfsnpool.sys <Not Verified; VERITAS Software, Inc.; > R2 tfsnudf - c:\windows\system32\dla\tfsnudf.sys <Not Verified; VERITAS Software, Inc.; > R2 tfsnudfa - c:\windows\system32\dla\tfsnudfa.sys <Not Verified; VERITAS Software, Inc.; > R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell> S3 dsreader (MaxDrive Driver (dsreader.sys)) - c:\windows\system32\drivers\dsreader.sys <Not Verified; Thesycon GmbH, Germany; Universal USB Device Driver> S3 NPPTNT2 - c:\windows\system32\npptnt2.sys <Not Verified; INCA Internet Co., Ltd.; nProtect NPSC Kernel Mode Driver for NT> S3 USBIO (USBIO Driver (usbio.sys)) - c:\windows\system32\drivers\usbio.sys <Not Verified; Thesycon GmbH, Germany; Universal USB Device Driver> -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 NetCfgSvr (Network Configuration Service) - c:\progra~1\at&tgl~1\netcfgsv.exe <Not Verified; AT&T; NetCfgSvr Module> R2 ScsiAccess - c:\windows\system32\scsiaccess.exe S2 LogonNT (NT Logon Service) - -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2007-11-29 15:01:14 372 --a------ C:\WINDOWS\Tasks\RegCure.job 2007-11-29 03:00:00 488 --a------ C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job 2007-11-28 22:10:59 438 --a------ C:\WINDOWS\Tasks\RegCure Program Check.job 2007-09-22 06:14:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -- Files created between 2007-10-29 and 2007-11-29 ----------------------------- 2007-11-28 16:20:31 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Mozilla 2007-11-27 16:09:15 0 d-------- C:\Documents and Settings\Owner\Application Data\Thinstall 2007-11-25 20:07:29 0 d-------- C:\Documents and Settings\Default User\Application Data\Apple Computer 2007-11-25 19:42:38 0 d-------- C:\Program Files\Trend Micro 2007-11-25 17:38:43 0 d-------- C:\Program Files\RegCure 2007-11-25 17:22:42 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2 2007-11-25 16:24:19 0 d-------- C:\Documents and Settings\All Users\Application Data\RFA_Backups 2007-11-25 16:23:43 0 d-------- C:\Program Files\RFA 2007-11-25 11:00:13 0 d-------- C:\Documents and Settings\Owner\Application Data\Webroot 2007-11-25 01:30:51 0 d-------- C:\Program Files\Norton 360 2007-11-24 23:35:23 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira 2007-11-24 21:50:51 0 d-------- C:\Program Files\Spyware Doctor 2007-11-24 21:50:51 0 d-------- C:\Documents and Settings\Owner\Application Data\PC Tools 2007-11-24 18:40:18 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Adobe 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Macromedia 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Learn2.com 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\InterTrust 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Incredible Ink 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Identities 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Hulabee 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Help 2007-11-24 18:40:17 0 d--h----- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\GTek 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\ArcSoft 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\AOL 2007-11-24 18:40:17 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Aim 2007-11-24 18:40:16 0 dr------- C:\Documents and Settings\Administrator.WINXPHOME\Favorites 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Desktop 2007-11-24 18:40:16 0 d---s---- C:\Documents and Settings\Administrator.WINXPHOME\Cookies 2007-11-24 18:40:16 0 dr-h----- C:\Documents and Settings\Administrator.WINXPHOME\Application Data 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\WeatherBug 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\VERITAS 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Symantec 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Share-to-Web Upload Folder 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Registry Cleaner 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\rawh 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\MSN6 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Motive 2007-11-24 18:40:16 0 d---s---- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\Microsoft 2007-11-24 18:40:16 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\Application Data\{12EE7A5E-0674-42f9-A76B-000000004D00} 2007-11-24 18:40:14 0 dr-h----- C:\Documents and Settings\Administrator.WINXPHOME\SendTo 2007-11-24 18:40:14 0 dr-h----- C:\Documents and Settings\Administrator.WINXPHOME\Recent 2007-11-24 18:40:14 0 d--h----- C:\Documents and Settings\Administrator.WINXPHOME\PrintHood 2007-11-24 18:40:14 0 d--h----- C:\Documents and Settings\Administrator.WINXPHOME\NetHood 2007-11-24 18:40:14 0 dr------- C:\Documents and Settings\Administrator.WINXPHOME\My Documents 2007-11-24 18:40:14 0 d--h----- C:\Documents and Settings\Administrator.WINXPHOME\Local Settings 2007-11-24 18:40:13 0 d-------- C:\Documents and Settings\Administrator.WINXPHOME\WINDOWS 2007-11-24 18:40:13 0 d---s---- C:\Documents and Settings\Administrator.WINXPHOME\UserData 2007-11-24 18:40:13 0 d--h----- C:\Documents and Settings\Administrator.WINXPHOME\Templates 2007-11-24 18:40:13 0 dr------- C:\Documents and Settings\Administrator.WINXPHOME\Start Menu 2007-11-24 18:40:13 786432 --ah----- C:\Documents and Settings\Administrator.WINXPHOME\NTUSER.DAT -- Find3M Report --------------------------------------------------------------- 2007-11-27 16:11:37 0 d-------- C:\Program Files\Common Files\Symantec Shared 2007-11-25 20:09:57 0 d-------- C:\Documents and Settings\Owner\Application Data\Symantec 2007-11-25 19:45:02 0 d-------- C:\Program Files\Symantec 2007-11-25 19:43:45 0 d-------- C:\Program Files\Common Files 2007-11-25 11:12:18 0 d-------- C:\Program Files\Windows 2007-11-25 00:36:54 0 d-------- C:\Program Files\Symantec AntiVirus 2007-11-25 00:34:31 0 d-------- C:\Documents and Settings\Owner\Application Data\SpywareBot 2007-11-25 00:34:14 0 d-------- C:\Program Files\Ultimate Hack Pack 2007-11-24 23:42:40 0 d-------- C:\Program Files\TClock 2007-11-24 22:30:34 172 --a------ C:\WINDOWS\popcinfo.dat 2007-11-18 19:36:08 664 --a------ C:\WINDOWS\system32\d3d9caps.dat 2007-10-19 19:42:07 0 d--h----- C:\Documents and Settings\Owner\Application Data\ijjigame 2007-10-19 19:41:27 0 d-------- C:\Program Files\NHN USA 2007-10-19 19:41:24 0 d--h----- C:\Program Files\InstallShield Installation Information 2007-10-01 18:39:59 0 d-------- C:\Program Files\HPSelect 2007-09-27 11:08:06 692224 --a------ C:\WINDOWS\system32\ijjiSetup.exe <Not Verified; NHN USA; ijjiSetup Application> 2007-08-31 07:59:28 164 --a------ C:\install.dat -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [11/02/2007 05:24 PM] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [07/17/2007 07:54 PM] -- End of Deckard's System Scanner: finished at 2007-11-29 15:11:04 ------------ My current situation is there is no task bar and no desktop icons (it also takes Forever to start up) |
|
|
Nov 29 2007, 03:40 PM
Post
#7
|
|
|
GeekU Moderator Posts: 14,119 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Not a lot showing there So........
Download and then run SuperAntispyware
ON COMPLETION or you can do this first Start Superantispyware Select the preferences button (bottom right) Select the repair tab Select Enable system tray Click perform repair Select Reset desktop policies Click perform repair THEN Download WinPFind3u.exe to your Desktop and double-click on it to extract the files. It will create a folder named WinPFind3u on your desktop.
Regards the task bar has anyone been playing and reduced the size of the task bar ? If that is a possibility look here http://www.petermartinconsult.supanet.com/...ows/taskbar.htm |
|
|
Nov 29 2007, 05:37 PM
Post
#8
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
SUPERAntiSpyware Scan Log
Generated 11/29/2007 at 05:17 PM Application Version : 3.6.1000 Core Rules Database Version : 3190 Trace Rules Database Version: 1200 Scan type : Complete Scan Total Scan Time : 01:19:51 Memory items scanned : 386 Memory threats detected : 0 Registry items scanned : 6814 Registry threats detected : 247 File items scanned : 60790 File threats detected : 39 Adware.MyWebSearch HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D} HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D} HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32 HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\InprocServer32#ThreadingModel HKCR\CLSID\{00A6FAF6-072E-44CF-8957-5838F569A31D}\Programmable C:\PROGRAM FILES\MYWEBSEARCH\SRCHASTT\3.BIN\MWSSRCAS.DLL HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32 HKCR\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\InprocServer32#ThreadingModel C:\PROGRAM FILES\MYWEBSEARCH\BAR\5.BIN\MWSBAR.DLL Adware.CouponBar HKLM\Software\Classes\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455} HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455} HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455} HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Implemented Categories HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\InprocServer32 HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\InprocServer32#ThreadingModel HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\ProgID HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\Programmable HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\TypeLib HKCR\CLSID\{5BED3930-2E9E-76D8-BACC-80DF2188D455}\VersionIndependentProgID C:\WINDOWS\COUPONBARIE.DLL Adware.MovieLand/MediaPipe C:\Program Files\MovieLand Terms.html Adware.180solutions/Search Assistant HKCR\Interface\{2B0ECEAC-F597-4858-A542-D966B49055B9} HKCR\Interface\{2B0ECEAC-F597-4858-A542-D966B49055B9}\ProxyStubClsid HKCR\Interface\{2B0ECEAC-F597-4858-A542-D966B49055B9}\ProxyStubClsid32 HKCR\Interface\{2B0ECEAC-F597-4858-A542-D966B49055B9}\TypeLib HKCR\Interface\{2B0ECEAC-F597-4858-A542-D966B49055B9}\TypeLib#Version HKCR\Interface\{DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD} HKCR\Interface\{DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD}\ProxyStubClsid HKCR\Interface\{DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD}\ProxyStubClsid32 HKCR\Interface\{DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD}\TypeLib HKCR\Interface\{DDEA2E1D-8555-45E5-AF09-EC9AA4EA27AD}\TypeLib#Version HKCR\Interface\{F1F1E775-1B21-454D-8D38-7C16519969E5} HKCR\Interface\{F1F1E775-1B21-454D-8D38-7C16519969E5}\ProxyStubClsid HKCR\Interface\{F1F1E775-1B21-454D-8D38-7C16519969E5}\ProxyStubClsid32 HKCR\Interface\{F1F1E775-1B21-454D-8D38-7C16519969E5}\TypeLib HKCR\Interface\{F1F1E775-1B21-454D-8D38-7C16519969E5}\TypeLib#Version Adware.Apropos Media C:\WINDOWS\system32\auto_update_uninstall.log Adware.Avenue Media/Internet Optimizer HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001} HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}\ProxyStubClsid HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}\ProxyStubClsid32 HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}\TypeLib HKCR\Interface\{1C01D150-91A4-4DE0-9BF8-A35D1BDF1001}\TypeLib#Version HKU\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks#_{CFBFAE00-17A6-11D0-99CB-00C04FD64497} HKU\S-1-5-18\Software\Microsoft\Internet Explorer\URLSearchHooks#_{CFBFAE00-17A6-11D0-99CB-00C04FD64497} Registry Cleaner Trial C:\Documents and Settings\Owner\Application Data\Registry Cleaner\Backups\2004-12-19,16-52 44 796.zip C:\Documents and Settings\Owner\Application Data\Registry Cleaner\Backups C:\Documents and Settings\Owner\Application Data\Registry Cleaner\RegClean.ini C:\Documents and Settings\Owner\Application Data\Registry Cleaner Trojan.NetMon/DNSChange HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR#NextInstance HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000 HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Service HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Legacy HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ConfigFlags HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#Class HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#ClassGUID HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR\0000#DeviceDesc Trojan.Security Toolbar C:\Documents and Settings\All Users\Start Menu\Online Security Guide.url C:\Documents and Settings\All Users\Start Menu\Security Troubleshooting.url C:\Documents and Settings\All Users\Desktop\Security Troubleshooting.url C:\Documents and Settings\All Users\Desktop\Online Security Guide.url Adware.SearchClickAds HKCR\KBBar.KBBarBand HKCR\KBBar.KBBarBand\CurVer HKCR\KBBar.KBBarBand.1 HKCR\Interface\{41E74C20-8BBD-4B15-8C24-95BAC7B3BAC1} HKCR\Interface\{41E74C20-8BBD-4B15-8C24-95BAC7B3BAC1}\ProxyStubClsid HKCR\Interface\{41E74C20-8BBD-4B15-8C24-95BAC7B3BAC1}\ProxyStubClsid32 HKCR\Interface\{41E74C20-8BBD-4B15-8C24-95BAC7B3BAC1}\TypeLib HKCR\Interface\{41E74C20-8BBD-4B15-8C24-95BAC7B3BAC1}\TypeLib#Version Trojan.DollarRevenue C:\WINDOWS\newname.dat C:\WINDOWS\keyboard1.dat Adware.IST/ISTBar (Slotch Bar) HKU\S-1-5-21-247674877-1981001023-514352727-1003\Software\Microsoft\Internet Explorer\Main#BandRest [ Never ] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main#BandRest [ Never ] Browser Hijacker.Deskbar HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D} HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\ProxyStubClsid32 HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib HKCR\Interface\{8F15B157-40D9-4B20-8D3B-B1F8B475B58D}\TypeLib#Version HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C} HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\ProxyStubClsid32 HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib HKCR\Interface\{A0881AA1-68BE-41AC-9C0D-4C8A69C6C72C}\TypeLib#Version HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108} HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\ProxyStubClsid32 HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib HKCR\Interface\{E827FFD9-95D1-4B49-BEB3-5D49E688C108}\TypeLib#Version Adware.Advertisemen HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\advertismen HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\advertismen#DisplayName HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\advertismen#UninstallString Trojan.Media-Codec HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#user32.dll HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run#rare Malware.SpywareBot HKU\S-1-5-21-247674877-1981001023-514352727-1003\Software\SpywareBot Adware.Zango Toolbar/Hb HKCR\ZangoToolbar.ZbCommBand HKCR\ZangoToolbar.ZbCommBand\CLSID HKCR\ZangoToolbar.ZbCommBand\CurVer HKCR\ZangoToolbar.ZbCommBand.1 HKCR\ZangoToolbar.ZbCommBand.1\CLSID HKCR\ZbCoreSrv.LfgAx HKCR\ZbCoreSrv.LfgAx\CLSID HKCR\ZbCoreSrv.LfgAx\CurVer HKCR\ZbCoreSrv.LfgAx.1 HKCR\ZbCoreSrv.LfgAx.1\CLSID HKCR\ZbCoreSrv.ZbCoreServices HKCR\ZbCoreSrv.ZbCoreServices\CLSID HKCR\ZbCoreSrv.ZbCoreServices\CurVer HKCR\ZbCoreSrv.ZbCoreServices.1 HKCR\ZbCoreSrv.ZbCoreServices.1\CLSID HKCR\ZbHostIE.Bho HKCR\ZbHostIE.Bho\CLSID HKCR\ZbHostIE.Bho\CurVer HKCR\ZbHostIE.Bho.1 HKCR\ZbHostIE.Bho.1\CLSID HKCR\ZbSrv.ZbCoreServices HKCR\ZbSrv.ZbCoreServices\CLSID HKCR\ZbSrv.ZbCoreServices\CurVer HKCR\ZbSrv.ZbCoreServices.1 HKCR\ZbSrv.ZbCoreServices.1\CLSID HKCR\ZbToolbar.ZbHtmlMenuUI HKCR\ZbToolbar.ZbHtmlMenuUI\CLSID HKCR\ZbToolbar.ZbHtmlMenuUI\CurVer HKCR\ZbToolbar.ZbHtmlMenuUI.1 HKCR\ZbToolbar.ZbHtmlMenuUI.1\CLSID HKCR\ZbToolbar.ZbToolbarCtl HKCR\ZbToolbar.ZbToolbarCtl\CLSID HKCR\ZbToolbar.ZbToolbarCtl\CurVer HKCR\ZbToolbar.ZbToolbarCtl.1 HKCR\ZbToolbar.ZbToolbarCtl.1\CLSID HKCR\ZbTools.HbMain HKCR\ZbTools.HbMain\CLSID HKCR\ZbTools.HbMain\CurVer HKCR\ZbTools.HbMain.1 HKCR\ZbTools.HbMain.1\CLSID HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C} HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\Control HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\Implemented Categories HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\Implemented Categories\{00021494-0000-0000-C000-000000000046} HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\InprocServer32 HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\InprocServer32#ThreadingModel HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\Instance HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\Instance#CLSID HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\Instance\InitPropertyBag HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\Instance\InitPropertyBag#Url HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\MiscStatus HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\MiscStatus\1 HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\ProgID HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\Programmable HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\ToolboxBitmap32 HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\TypeLib HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\Version HKCR\CLSID\{0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C}\VersionIndependentProgID HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334} HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\InprocServer32 HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\InprocServer32#ThreadingModel HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\ProgID HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\TypeLib HKCR\CLSID\{37E5D130-E81C-43E5-A2AD-9C155467F334}\VersionIndependentProgID HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1} HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}#AppID HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Control HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Implemented Categories HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4} HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\InprocServer32 HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\InprocServer32#ThreadingModel HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\MiscStatus HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\MiscStatus\1 HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\ProgID HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Programmable HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\ToolboxBitmap32 HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\TypeLib HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\Version HKCR\CLSID\{7585AF6A-6D68-4896-A1A1-F23AA8FCF9F1}\VersionIndependentProgID HKCR\CLSID\{97CE9A1F-672E-4CF4-B483-9DE6BCB4CB1E} HKCR\CLSID\{97CE9A1F-672E-4CF4-B483-9DE6BCB4CB1E}\InprocServer32 HKCR\CLSID\{97CE9A1F-672E-4CF4-B483-9DE6BCB4CB1E}\InprocServer32#ThreadingModel HKCR\CLSID\{97CE9A1F-672E-4CF4-B483-9DE6BCB4CB1E}\ProgID HKCR\CLSID\{97CE9A1F-672E-4CF4-B483-9DE6BCB4CB1E}\Programmable HKCR\CLSID\{97CE9A1F-672E-4CF4-B483-9DE6BCB4CB1E}\TypeLib HKCR\CLSID\{97CE9A1F-672E-4CF4-B483-9DE6BCB4CB1E}\VersionIndependentProgID HKCR\CLSID\{AC17D2FB-6C7A-47B7-BB3D-EC879BC3C911} HKCR\CLSID\{AC17D2FB-6C7A-47B7-BB3D-EC879BC3C911}\InprocServer32 HKCR\CLSID\{AC17D2FB-6C7A-47B7-BB3D-EC879BC3C911}\InprocServer32#ThreadingModel HKCR\CLSID\{AC17D2FB-6C7A-47B7-BB3D-EC879BC3C911}\ProgID HKCR\CLSID\{AC17D2FB-6C7A-47B7-BB3D-EC879BC3C911}\Programmable HKCR\CLSID\{AC17D2FB-6C7A-47B7-BB3D-EC879BC3C911}\TypeLib HKCR\CLSID\{AC17D2FB-6C7A-47B7-BB3D-EC879BC3C911}\VersionIndependentProgID HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF} HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\LocalServer32 HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\ProgID HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\Programmable HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\TypeLib HKCR\CLSID\{CF1A5756-F372-463E-BC20-1D3D58F4B9AF}\VersionIndependentProgID HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E} HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\Control HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\InprocServer32 HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\InprocServer32#ThreadingModel HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\MiscStatus HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\MiscStatus\1 HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\ProgID HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\Programmable HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\ToolboxBitmap32 HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\TypeLib HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\Version HKCR\CLSID\{D318484F-1800-441A-8661-A1DEA5F8800E}\VersionIndependentProgID HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251} HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0 HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0\0 HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0\0\win32 HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0\FLAGS HKCR\TypeLib\{049B9813-C417-4A47-A893-604FAD16B251}\1.0\HELPDIR HKCR\TypeLib\{4DBE6B29-59FC-400C-915B-FB57A5CD533E} HKCR\TypeLib\{4DBE6B29-59FC-400C-915B-FB57A5CD533E}\1.0 HKCR\TypeLib\{4DBE6B29-59FC-400C-915B-FB57A5CD533E}\1.0\0 HKCR\TypeLib\{4DBE6B29-59FC-400C-915B-FB57A5CD533E}\1.0\0\win32 HKCR\TypeLib\{4DBE6B29-59FC-400C-915B-FB57A5CD533E}\1.0\FLAGS HKCR\TypeLib\{4DBE6B29-59FC-400C-915B-FB57A5CD533E}\1.0\HELPDIR HKCR\TypeLib\{7586A473-7A57-4641-8155-E87135D0E2F4} HKCR\TypeLib\{7586A473-7A57-4641-8155-E87135D0E2F4}\1.0 HKCR\TypeLib\{7586A473-7A57-4641-8155-E87135D0E2F4}\1.0\0 HKCR\TypeLib\{7586A473-7A57-4641-8155-E87135D0E2F4}\1.0\0\win32 HKCR\TypeLib\{7586A473-7A57-4641-8155-E87135D0E2F4}\1.0\FLAGS HKCR\TypeLib\{7586A473-7A57-4641-8155-E87135D0E2F4}\1.0\HELPDIR HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2} HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0 HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0\0 HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0\0\win32 HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0\FLAGS HKCR\TypeLib\{DC92EE2E-DF2D-4A80-A48B-17377C81CFC2}\1.0\HELPDIR HKU\S-1-5-21-247674877-1981001023-514352727-1003\Software\ZangoToolbar HKLM\Software\ZangoToolbar HKLM\Software\ZangoToolbar\Install HKLM\Software\ZangoToolbar\Install#IE HKLM\Software\ZangoToolbar\Install#OL HKLM\Software\ZangoToolbar\Install#WT HKLM\Software\ZangoToolbar\Install#WP HKLM\Software\ZangoToolbar\Install#Install_Dir HKLM\Software\ZangoToolbar\Install\CmpMap HKLM\Software\ZangoToolbar\Install\CmpMap#IE HKLM\Software\ZangoToolbar\Install\CmpMap#OL HKLM\Software\ZangoToolbar\Install\CmpMap#WT HKLM\Software\ZangoToolbar\Install\CmpMap#WP HKLM\Software\ZangoToolbar\ZangoToolbar HKLM\Software\ZangoToolbar\ZangoToolbar\Install HKLM\Software\ZangoToolbar\ZangoToolbar\Install#StartInstall HKLM\Software\ZangoToolbar\ZangoToolbar\Install#cookies_flag HKLM\Software\ZangoToolbar\ZangoToolbar\Install#IID HKLM\Software\ZangoToolbar\ZangoToolbar\Install#IID_prv HKLM\Software\ZangoToolbar\ZangoToolbar\Install#PrevVer HKLM\Software\ZangoToolbar\ZangoToolbar\Install#CurrentVer HKLM\Software\ZangoToolbar\ZangoToolbar\MachineInfo HKLM\Software\ZangoToolbar\ZangoToolbar\MachineInfo#CID HKLM\Software\ZangoToolbar\ZangoToolbar\MachineInfo#CID_prv HKLM\Software\ZangoToolbar\ZangoToolbar\PI HKLM\Software\ZangoToolbar\ZangoToolbar\PI\3.2 HKLM\Software\ZangoToolbar\ZangoToolbar\PI\3.2#PID00 Browser Hijacker.Favorites C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR.WINXPHOME\DESKTOP\CHEAP HOLIDAY TRAVEL.URL C:\DOCUMENTS AND SETTINGS\DEFAULT USER\DESKTOP\CHEAP HOLIDAY TRAVEL.URL C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\CHEAP HOLIDAY TRAVEL.URL C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\FREE ONLINE MUSIC.URL C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\ONLINE DATING.URL C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\DESKTOP\CHEAP HOLIDAY TRAVEL.URL D:\N360_BACKUP\DRIVE_C\DOCUMENTS AND SETTINGS\ADMINISTRATOR.WINXPHOME\DESKTOP\CHEAP HOLIDAY TRAVEL.URL Adware.Affiliate C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\REMOVE SPYWARE.URL Trojan.NewDotNet C:\PROGRAM FILES\TREND MICRO\HIJACKTHIS\BACKUPS\BACKUP-20071128-162723-519.DLL C:\WINDOWS\NDNUNINSTALL6_38-1.EXE C:\WINDOWS\NDNUNINSTALL6_38.EXE C:\WINDOWS\NDNUNINSTALL7_48.EXE Trojan.SmartLoad C:\WINDOWS\DRSMARTLOAD2.DAT Worm.Alcra Variant C:\WINDOWS\SYSTEM32\CMD.COM C:\WINDOWS\SYSTEM32\NETSTAT.COM C:\WINDOWS\SYSTEM32\PING.COM C:\WINDOWS\SYSTEM32\REGEDIT.COM C:\WINDOWS\SYSTEM32\TASKKILL.COM C:\WINDOWS\SYSTEM32\TASKLIST.COM C:\WINDOWS\SYSTEM32\TRACERT.COM Adware.Tracking Cookie C:\WINDOWS\system32\config\systemprofile\Cookies\owner@creativeby.viewpoint[1].txt Adware.NicTech Networks C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\10NGFXA6\APPWRAP[4].EXE C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\LOCAL SETTINGS\TEMPORARY INTERNET FILES\CONTENT.IE5\BFI8ZWE6\APPWRAP[5].EXE Trojan.Unknown Origin C:\WINDOWS\SYSTEM32\WCPSU.EXE WinPFind3U is not responding every time I open It, Thus, I can't get a log |
|
|
Nov 29 2007, 05:37 PM
Post
#9
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
also, I can't right click on the desktop to follow that link. (I don't know if this means anything but when ever I try to open the control pannel through new task by using "control" and "control panel" it pops up, but if just flashes) (i can't open the control panel either)
This post has been edited by DanZaMan4251: Nov 29 2007, 05:39 PM |
|
|
Nov 29 2007, 05:45 PM
Post
#10
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
it worked, i left it around for about 20 minuites and it popped up with this
WinPFind3 logfile created on: 11/29/2007 5:43:05 PM WinPFind3U by OldTimer - Version 1.0.44 Folder = C:\Documents and Settings\Owner\Desktop\WinPFind3u\WinPFind3u\ Microsoft Windows XP Service Pack 2 (Version = 5.1.2600) Internet Explorer (Version = 6.0.2900.2180) 479.48 Mb Total Physical Memory | 197.31 Mb Available Physical Memory | 41.15% Memory free 1.10 Gb Paging File | 0.72 Gb Available in Paging File | 65.76% Paging File free Paging file location(s): C:\pagefile.sys 720 1440; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 106.76 Gb Total Space | 78.98 Gb Free Space | 73.98% Space Free Drive D: | 5.02 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free E: Drive not present or media not loaded F: Drive not present or media not loaded Computer Name: WINXPHOME Current User Name: Owner Logged in as Administrator. Current Boot Mode: Normal [Processes - Non-Microsoft Only] aluschedulersvc.exe -> %ProgramFiles%\Symantec\LiveUpdate\ALUSchedulerSvc.exe -> Symantec Corporation [Ver = 3.2.0.68 | Size = 554352 bytes | Modified Date = 9/12/2007 6:27:26 PM | Attr = ] ccsvchst.exe -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.2.7 | Size = 108904 bytes | Modified Date = 7/17/2007 7:53:26 PM | Attr = ] netcfgsv.exe -> %ProgramFiles%\AT&T Global Network Client\NetCfgSv.EXE -> AT&T [Ver = 5.06 | Size = 73728 bytes | Modified Date = 9/25/2002 7:00:00 AM | Attr = ] scsiaccess.exe -> %System32%\ScsiAccess.EXE -> [Ver = | Size = 181312 bytes | Modified Date = 2/4/2003 7:22:30 AM | Attr = ] sdtrayapp.exe -> %ProgramFiles%\Spyware Doctor\SDTrayApp.exe -> PC Tools [Ver = 5.0.5.33 | Size = 1065800 bytes | Modified Date = 11/2/2007 5:24:56 PM | Attr = ] svcntaux.exe -> %ProgramFiles%\Spyware Doctor\svcntaux.exe -> PC Tools [Ver = 5.0.5.3 | Size = 311112 bytes | Modified Date = 11/2/2007 5:24:58 PM | Attr = ] swdsvc.exe -> %ProgramFiles%\Spyware Doctor\swdsvc.exe -> PC Tools [Ver = 5.0.5.24 | Size = 1418056 bytes | Modified Date = 11/2/2007 5:25:04 PM | Attr = ] winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.44.0 | Size = 371200 bytes | Modified Date = 11/21/2007 9:19:46 AM | Attr = ] [Win32 Services - Non-Microsoft Only] (Automatic LiveUpdate Scheduler) Automatic LiveUpdate Scheduler [Win32_Own | Auto | Running] -> %ProgramFiles%\Symantec\LiveUpdate\ALUSchedulerSvc.exe -> Symantec Corporation [Ver = 3.2.0.68 | Size = 554352 bytes | Modified Date = 9/12/2007 6:27:26 PM | Attr = ] (ccEvtMgr) Symantec Event Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.2.7 | Size = 108904 bytes | Modified Date = 7/17/2007 7:53:26 PM | Attr = ] (ccPwdSvc) Symantec Password Validation [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\ccPwdSvc.exe -> Symantec Corporation [Ver = 2.2.0.577 | Size = 87160 bytes | Modified Date = 2/29/2004 3:44:52 PM | Attr = ] (ccSetMgr) Symantec Settings Manager [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.2.7 | Size = 108904 bytes | Modified Date = 7/17/2007 7:53:26 PM | Attr = ] (CLTNetCnService) Symantec Lic NetConnect service [Win32_Shared | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSvcHst.exe -> Symantec Corporation [Ver = 106.3.2.7 | Size = 108904 bytes | Modified Date = 7/17/2007 7:53:26 PM | Attr = ] (comHost) COM Host [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\VAScanner\comHost.exe -> Symantec Corporation [Ver = 1.2.0.28 | Size = 49248 bytes | Modified Date = 1/12/2007 8:40:58 PM | Attr = ] (dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | On_Demand | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 12:56:50 AM | Attr = ] (IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\11\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.00.28844 | Size = 69632 bytes | Modified Date = 4/4/2005 12:41:10 AM | Attr = ] (iPod Service) iPod Service [Win32_Own | Disabled | Stopped] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.1.1.5 | Size = 500800 bytes | Modified Date = 4/27/2007 10:25:52 AM | Attr = ] (KodakCCS) Kodak Camera Connection Software [Win32_Own | On_Demand | Stopped] -> %System32%\drivers\KodakCCS.exe -> Eastman Kodak Company [Ver = 1.1.5100.4 | Size = 411920 bytes | Modified Date = 3/30/2005 4:46:56 PM | Attr = ] (LiveUpdate) LiveUpdate [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Symantec\LiveUpdate\LuComServer_3_2.EXE -> Symantec Corporation [Ver = 3.2.0.68 | Size = 2999664 bytes | Modified Date = 9/12/2007 6:27:26 PM | Attr = ] (LogonNT) NT Logon Service [Win32_Own | Auto | Stopped] -> -> File not found (MSCSPTISRV) MSCSPTISRV [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Sony Shared\AVLib\MSCSPTISRV.exe -> Sony Corporation [Ver = 4.2.00.06070 | Size = 53337 bytes | Modified Date = 6/7/2005 12:32:54 AM | Attr = ] (NetCfgSvr) Network Configuration Service [Win32_Own | Auto | Running] -> %ProgramFiles%\AT&T Global Network Client\NetCfgSv.EXE -> AT&T [Ver = 5.06 | Size = 73728 bytes | Modified Date = 9/25/2002 7:00:00 AM | Attr = ] (PACSPTISVR) PACSPTISVR [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Sony Shared\AVLib\PACSPTISVR.exe -> Sony Corporation [Ver = 4.2.00.06070 | Size = 53337 bytes | Modified Date = 6/7/2005 12:28:04 AM | Attr = ] (ScsiAccess) ScsiAccess [Win32_Own | Auto | Running] -> %System32%\ScsiAccess.EXE -> [Ver = | Size = 181312 bytes | Modified Date = 2/4/2003 7:22:30 AM | Attr = ] (sdAuxService) PC Tools Auxiliary Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Spyware Doctor\svcntaux.exe -> PC Tools [Ver = 5.0.5.3 | Size = 311112 bytes | Modified Date = 11/2/2007 5:24:58 PM | Attr = ] (sdCoreService) PC Tools Security Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Spyware Doctor\swdsvc.exe -> PC Tools [Ver = 5.0.5.24 | Size = 1418056 bytes | Modified Date = 11/2/2007 5:25:04 PM | Attr = ] (SPTISRV) Sony SPTI Service [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Sony Shared\AVLib\SPTISRV.exe -> Sony Corporation [Ver = 4.2.00.06070 | Size = 69718 bytes | Modified Date = 6/7/2005 12:22:34 AM | Attr = ] (Symantec Core LC) Symantec Core LC [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\CCPD-LC\symlcsvc.exe -> Symantec Corporation [Ver = 1.9.1.1088 | Size = 1174664 bytes | Modified Date = 11/25/2007 1:31:18 AM | Attr = ] [Registry - Non-Microsoft Only] < Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> ccApp -> %CommonProgramFiles%\Symantec Shared\ccApp.exe -> Symantec Corporation [Ver = 106.3.2.7 | Size = 116072 bytes | Modified Date = 7/17/2007 7:54:00 PM | Attr = ] SDTray -> %ProgramFiles%\Spyware Doctor\SDTrayApp.exe -> PC Tools [Ver = 5.0.5.33 | Size = 1065800 bytes | Modified Date = 11/2/2007 5:24:56 PM | Attr = ] Uninstall_CToolbar -> %SystemRoot%\Temp\CTun.exe -> Crawler.com [Ver = 4.5.0.182 | Size = 1184768 bytes | Modified Date = 6/20/2007 1:59:12 AM | Attr = ] < OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ -> IMAIL -> Installed = 1 -> MAPI -> Installed = 1 -> MSFS -> Installed = 1 -> < Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run -> AIM -> %ProgramFiles%\AIM\aim.exe -cnetwait.odl -> File not found SUPERAntiSpyware -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 6, 0, 1000 | Size = 1310720 bytes | Modified Date = 2/27/2007 11:39:26 AM | Attr = ] < ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks -> {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} [HKLM] -> %ProgramFiles%\SUPERAntiSpyware\SASSEH.DLL [] -> SuperAdBlocker.com [Ver = 1, 0, 0, 1008 | Size = 77824 bytes | Modified Date = 12/20/2006 12:55:48 PM | Attr = ] < SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders -> < Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon -> < Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ -> !SASWinLogon -> %ProgramFiles%\SUPERAntiSpyware\SASWINLO.dll -> SUPERAntiSpyware.com [Ver = 1, 0, 0, 1030 | Size = 282624 bytes | Modified Date = 2/27/2007 11:39:26 AM | Attr = ] igfxcui -> %System32%\igfxsrvc.dll -> Intel Corporation [Ver = 3,0,0,1607 | Size = 307200 bytes | Modified Date = 5/15/2002 4:20:14 AM | Attr = ] < CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoCDBurning -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 -> < CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\\LowRiskFileTypes -> .zip;.rar;.cab;.txt;.exe;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mov;.mp3;.wav -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoToolbarsOnTaskbar -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoSetTaskbar -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoBandCustomize -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoMovingBands -> 0 -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoCloseDragDropBands -> 0 -> < HOSTS File > -> -> -> Hosts file not found -> < Internet Explorer Settings > -> -> HKLM: Default_Page_URL -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome -> HKLM: Main\\Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKLM: Local Page -> C:\WINDOWS\SYSTEM32\blank.htm -> HKLM: Search Bar -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm -> HKLM: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKLM: Start Page -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome -> HKLM: CustomizeSearch -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm -> HKLM: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> HKCU: Default_Page_URL -> http://us6.hpwis.com/ -> HKCU: Default_Search_URL -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKCU: Local Page -> C:\WINDOWS\SYSTEM32\blank.htm -> HKCU: Search Bar -> http://search.msn.com/spbasic.htm -> HKCU: Search Page -> http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch -> HKCU: Start Page -> http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome -> HKCU: CustomizeSearch -> http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm -> HKCU: SearchAssistant -> http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm -> HKCU: ProxyEnable -> 0 -> HKCU: ProxyOverride -> localhost -> < Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> msn.com [ - ] -> -> < BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ -> {1E8A6170-7264-4D0F-BEAE-D42A53123C75} [HKLM] -> %CommonProgramFiles%\Symantec Shared\coShared\Browser\1.7\NppBHO.dll [Reg Data - Value does not exist] -> Symantec Corporation [Ver = 2007.1.7.20 | Size = 97696 bytes | Modified Date = 7/11/2007 7:49:20 PM | Attr = R ] {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKLM] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> [Ver = 4.0.3.338 | Size = 1799680 bytes | Modified Date = 9/6/2006 12:57:08 PM | Attr = ] < Internet Explorer Bars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found < Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ -> {0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found {32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found < Internet Explorer ToolBars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar -> {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} [HKLM] -> %ProgramFiles%\ComcastToolbar\comcasttoolbar.dll [Comcast Toolbar] -> [Ver = 4.0.3.338 | Size = 1799680 bytes | Modified Date = 9/6/2006 12:57:08 PM | Attr = ] {90222687-F593-4738-B738-FBEE9C7B26DF} [HKLM] -> %CommonProgramFiles%\Symantec Shared\coShared\Browser\1.7\UIBHO.dll [Show Norton Toolbar] -> Symantec Corporation [Ver = 2007.1.7.20 | Size = 608656 bytes | Modified Date = 7/11/2007 7:49:32 PM | Attr = R ] < Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ -> ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found ShellBrowser\\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} [HKLM] -> %SystemDrive%\hp\EXPLOREBAR\HPTOOLKT.DLL [hp toolkit] -> Hewlett-Packard Company [Ver = 1.0.0.3 | Size = 86016 bytes | Modified Date = 6/4/2002 11:03:12 PM | Attr = ] WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} [HKLM] -> Reg Data - Value does not exist [&Google] -> File not found WebBrowser\\{B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} [HKLM] -> %SystemDrive%\hp\EXPLOREBAR\HPTOOLKT.DLL [hp toolkit] -> Hewlett-Packard Company [Ver = 1.0.0.3 | Size = 86016 bytes | Modified Date = 6/4/2002 11:03:12 PM | Attr = ] WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> %ProgramFiles%\Yahoo!\Companion\Installs\cpn0\yt.dll [Yahoo! Toolbar] -> File not found < Internet Explorer Extensions [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\ -> {08B0E5C0-4FCB-11CF-AAA5-00401C608501} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\npjpi160_01.dll [MenuText: Sun Java Console] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 132760 bytes | Modified Date = 3/14/2007 2:43:42 AM | Attr = ] {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -> %ProgramFiles%\AIM\aim.exe [ButtonText: AIM] -> America Online, Inc. [Ver = 5.9.6089 | Size = 67112 bytes | Modified Date = 8/1/2006 2:35:36 PM | Attr = ] < Internet Explorer Menu Extensions [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\ -> &Google Search -> Reg Data - Value does not exist -> File not found Backward Links -> Reg Data - Value does not exist -> File not found Cached Snapshot of Page -> Reg Data - Value does not exist -> File not found Similar Pages -> Reg Data - Value does not exist -> File not found Translate into English -> Reg Data - Value does not exist -> File not found < Internet Explorer Plugins [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Plugins\Extension\ -> .spop -> %ProgramFiles%\Internet Explorer\PLUGINS\NPDocBox.dll [Reg Data - Value does not exist] -> InterTrust Technologies Corporation, Inc. [Ver = 1.0.30.95 | Size = 225280 bytes | Modified Date = 1/30/2001 9:56:24 PM | Attr = ] < User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform -> {5B05902B-4D20-4DAC-87E1-C9CCD4EC6229} -> -> FunWebProducts -> -> < DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ -> {2CF64F87-3A2E-42EC-BF5C-CB3A10864DD5} -> (1394 Net Adapter) -> {6C7C0137-6063-477A-943C-E6E98157D0DF} -> (Realtek RTL8139 Family PCI Fast Ethernet NIC) -> < Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ -> belarc -> %ProgramFiles%\Belarc\Advisor\System\BAVoilaX.dll -> Belarc, Inc. [Ver = 7.0t | Size = 33280 bytes | Modified Date = 7/29/2005 3:06:02 PM | Attr = ] ipp -> Reg Data - Key not found -> File not found msdaipp -> Reg Data - Key not found -> File not found < Protocol Filters [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\ -> text/html -> Reg Data - Key not found -> File not found < Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ -> {166B1BCA-3F9C-11CF-8075-444553540000} -> Shockwave ActiveX Control - CodeBase = http://fpdownload.macromedia.com/pub/shock...director/sw.cab -> {17492023-C23A-453E-A040-C7C580BBF700} -> Windows Genuine Advantage Validation Tool - CodeBase = http://go.microsoft.com/fwlink/?linkid=39204 -> {215B8138-A3CF-44C5-803F-8226143CFC0A} -> Trend Micro ActiveX Scan Agent 6.6 - CodeBase = http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab -> {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} -> - CodeBase = http://forms.real.com/real/player/download...ne_Inst_Win.cab -> {8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -> {9522B3FB-7A2B-4646-8AF6-36E7F593073C} -> cpbrkpie Control - CodeBase = http://a19.g.akamai.net/7/19/7125/1452/ftp...02/cpbrkpie.cab -> {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} -> TSEasyInstallX Control - CodeBase = http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB -> {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -> {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase = http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab -> {D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase = http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab -> Microsoft XML Parser for Java -> - CodeBase = -> [Files/Folders - Created Within 30 days] ComboFix -> %SystemDrive%\ComboFix -> [Folder | Created Date = 11/28/2007 6:17:06 PM | Attr = ] Deckard -> %SystemDrive%\Deckard -> [Folder | Created Date = 11/29/2007 3:07:39 PM | Attr = ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 502845440 bytes | Created Date = 1/1/1601 6:00:00 AM | Attr = HS] $NtUninstallKB918118$ -> %SystemRoot%\$NtUninstallKB918118$ -> [Folder | Created Date = 11/25/2007 5:15:56 PM | Attr = H ] $NtUninstallKB920213$ -> %SystemRoot%\$NtUninstallKB920213$ -> [Folder | Created Date = 11/25/2007 5:10:15 PM | Attr = H ] $NtUninstallKB921503$ -> %SystemRoot%\$NtUninstallKB921503$ -> [Folder | Created Date = 11/25/2007 5:31:22 PM | Attr = H ] $NtUninstallKB923723$ -> %SystemRoot%\$NtUninstallKB923723$ -> [Folder | Created Date = 11/25/2007 5:38:31 PM | Attr = H ] $NtUninstallKB923980$ -> %SystemRoot%\$NtUninstallKB923980$ -> [Folder | Created Date = 11/25/2007 5:37:12 PM | Attr = H ] $NtUninstallKB924270$ -> %SystemRoot%\$NtUninstallKB924270$ -> [Folder | Created Date = 11/25/2007 5:32:09 PM | Attr = H ] $NtUninstallKB924667$ -> %SystemRoot%\$NtUninstallKB924667$ -> [Folder | Created Date = 11/25/2007 5:32:28 PM | Attr = H ] $NtUninstallKB925398_WMP64$ -> %SystemRoot%\$NtUninstallKB925398_WMP64$ -> [Folder | Created Date = 11/25/2007 5:25:09 PM | Attr = H ] $NtUninstallKB925902$ -> %SystemRoot%\$NtUninstallKB925902$ -> [Folder | Created Date = 11/25/2007 5:22:23 PM | Attr = H ] $NtUninstallKB926255$ -> %SystemRoot%\$NtUninstallKB926255$ -> [Folder | Created Date = 11/25/2007 5:15:40 PM | Attr = H ] $NtUninstallKB926436$ -> %SystemRoot%\$NtUninstallKB926436$ -> [Folder | Created Date = 11/25/2007 5:17:08 PM | Attr = H ] $NtUninstallKB927779$ -> %SystemRoot%\$NtUninstallKB927779$ -> [Folder | Created Date = 11/25/2007 5:40:33 PM | Attr = H ] $NtUninstallKB927802$ -> %SystemRoot%\$NtUninstallKB927802$ -> [Folder | Created Date = 11/25/2007 5:40:08 PM | Attr = H ] $NtUninstallKB927891$ -> %SystemRoot%\$NtUninstallKB927891$ -> [Folder | Created Date = 11/25/2007 5:31:36 PM | Attr = H ] $NtUninstallKB928255$ -> %SystemRoot%\$NtUninstallKB928255$ -> [Folder | Created Date = 11/25/2007 5:38:59 PM | Attr = H ] $NtUninstallKB928843$ -> %SystemRoot%\$NtUninstallKB928843$ -> [Folder | Created Date = 11/25/2007 5:03:00 PM | Attr = H ] $NtUninstallKB929123$ -> %SystemRoot%\$NtUninstallKB929123$ -> [Folder | Created Date = 11/25/2007 5:21:45 PM | Attr = H ] $NtUninstallKB929399$ -> %SystemRoot%\$NtUninstallKB929399$ -> [Folder | Created Date = 11/25/2007 5:15:11 PM | Attr = H ] $NtUninstallKB930178$ -> %SystemRoot%\$NtUninstallKB930178$ -> [Folder | Created Date = 11/25/2007 5:16:52 PM | Attr = H ] $NtUninstallKB930916$ -> %SystemRoot%\$NtUninstallKB930916$ -> [Folder | Created Date = 11/25/2007 5:08:56 PM | Attr = H ] $NtUninstallKB931261$ -> %SystemRoot%\$NtUninstallKB931261$ -> [Folder | Created Date = 11/25/2007 5:31:52 PM | Attr = H ] $NtUninstallKB931784$ -> %SystemRoot%\$NtUninstallKB931784$ -> [Folder | Created Date = 11/27/2007 5:08:48 PM | Attr = H ] $NtUninstallKB932168$ -> %SystemRoot%\$NtUninstallKB932168$ -> [Folder | Created Date = 11/25/2007 5:16:35 PM | Attr = H ] $NtUninstallKB933360$ -> %SystemRoot%\$NtUninstallKB933360$ -> [Folder | Created Date = 11/25/2007 5:10:01 PM | Attr = H ] $NtUninstallKB933729$ -> %SystemRoot%\$NtUninstallKB933729$ -> [Folder | Created Date = 11/25/2007 5:38:08 PM | Attr = H ] $NtUninstallKB935839$ -> %SystemRoot%\$NtUninstallKB935839$ -> [Folder | Created Date = 11/25/2007 5:07:49 PM | Attr = H ] $NtUninstallKB935840$ -> %SystemRoot%\$NtUninstallKB935840$ -> [Folder | Created Date = 11/25/2007 5:09:25 PM | Attr = H ] $NtUninstallKB936021$ -> %SystemRoot%\$NtUninstallKB936021$ -> [Folder | Created Date = 11/25/2007 5:34:13 PM | Attr = H ] $NtUninstallKB936782_WMP11$ -> %SystemRoot%\$NtUninstallKB936782_WMP11$ -> [Folder | Created Date = 11/25/2007 5:07:14 PM | Attr = H ] $NtUninstallKB938127$ -> %SystemRoot%\$NtUninstallKB938127$ -> [Folder | Created Date = 11/25/2007 5:10:28 PM | Attr = H ] $NtUninstallKB938828$ -> %SystemRoot%\$NtUninstallKB938828$ -> [Folder | Created Date = 11/25/2007 5:33:52 PM | Attr = H ] $NtUninstallKB938829$ -> %SystemRoot%\$NtUninstallKB938829$ -> [Folder | Created Date = 11/25/2007 5:30:55 PM | Attr = H ] $NtUninstallKB939653$ -> %SystemRoot%\$NtUninstallKB939653$ -> [Folder | Created Date = 11/25/2007 5:33:12 PM | Attr = H ] $NtUninstallKB939683$ -> %SystemRoot%\$NtUninstallKB939683$ -> [Folder | Created Date = 11/25/2007 5:12:44 PM | Attr = H ] $NtUninstallKB941202$ -> %SystemRoot%\$NtUninstallKB941202$ -> [Folder | Created Date = 11/25/2007 5:16:16 PM | Attr = H ] $NtUninstallKB943460$ -> %SystemRoot%\$NtUninstallKB943460$ -> [Folder | Created Date = 11/25/2007 5:39:27 PM | Attr = H ] ERDNT -> %SystemRoot%\ERDNT -> [Folder | Created Date = 11/29/2007 3:07:56 PM | Attr = ] RegCure Program Check.job -> %SystemRoot%\tasks\RegCure Program Check.job -> [Ver = | Size = 438 bytes | Created Date = 11/25/2007 5:41:06 PM | Attr = ] RegCure.job -> %SystemRoot%\tasks\RegCure.job -> [Ver = | Size = 372 bytes | Created Date = 11/25/2007 5:41:00 PM | Attr = ] S32EVNT1.DLL -> %System32%\S32EVNT1.DLL -> Symantec Corporation [Ver = 12.5.2.2 | Size = 60800 bytes | Created Date = 11/25/2007 1:29:51 AM | Attr = ] COH_Mon.cat -> %System32%\drivers\COH_Mon.cat -> [Ver = | Size = 10592 bytes | Created Date = 11/25/2007 9:42:43 PM | Attr = R ] COH_Mon.inf -> %System32%\drivers\COH_Mon.inf -> [Ver = | Size = 705 bytes | Created Date = 11/25/2007 9:42:43 PM | Attr = R ] COH_Mon.sys -> %System32%\drivers\COH_Mon.sys -> Symantec Corporation [Ver = 6,1,2,3 | Size = 22112 bytes | Created Date = 11/25/2007 9:42:43 PM | Attr = R ] ikfilesec.sys -> %System32%\drivers\ikfilesec.sys -> PCTools Research Pty Ltd. [Ver = 5.0.2.1036 built by: WinDDK | Size = 41288 bytes | Created Date = 11/24/2007 9:51:08 PM | Attr = ] iksysflt.sys -> %System32%\drivers\iksysflt.sys -> PCTools Research Pty Ltd. [Ver = 5.0.2.1024 | Size = 62280 bytes | Created Date = 11/24/2007 9:51:08 PM | Attr = ] iksyssec.sys -> %System32%\drivers\iksyssec.sys -> PCTools Research Pty Ltd. [Ver = 5.0.2.1024 | Size = 79688 bytes | Created Date = 11/24/2007 9:51:08 PM | Attr = ] kcom.sys -> %System32%\drivers\kcom.sys -> PCTools Research Pty Ltd. [Ver = 5.0.2.1008 | Size = 29000 bytes | Created Date = 11/24/2007 9:51:08 PM | Attr = ] SYMEVENT.CAT -> %System32%\drivers\SYMEVENT.CAT -> [Ver = | Size = 10740 bytes | Created Date = 11/25/2007 1:29:51 AM | Attr = ] SYMEVENT.INF -> %System32%\drivers\SYMEVENT.INF -> [Ver = | Size = 805 bytes | Created Date = 11/25/2007 1:29:51 AM | Attr = ] SYMEVENT.SYS -> %System32%\drivers\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.5.2.1 | Size = 123952 bytes | Created Date = 11/25/2007 1:29:51 AM | Attr = ] [Files/Folders - Modified Within 30 days] ComboFix -> %SystemDrive%\ComboFix -> [Folder | Modified Date = 11/28/2007 6:25:12 PM | Attr = ] Deckard -> %SystemDrive%\Deckard -> [Folder | Modified Date = 11/29/2007 3:07:40 PM | Attr = ] Documents and Settings -> %SystemDrive%\Documents and Settings -> [Folder | Modified Date = 11/25/2007 1:23:54 AM | Attr = ] hiberfil.sys -> %SystemDrive%\hiberfil.sys -> [Ver = | Size = 502845440 bytes | Modified Date = 11/29/2007 5:36:06 PM | Attr = HS] Kole 2006 Budget.xls -> %SystemDrive%\Kole 2006 Budget.xls -> [Ver = | Size = 35328 bytes | Modified Date = 11/21/2007 3:11:50 PM | Attr = ] Program Files -> %ProgramFiles% -> [Folder | Modified Date = 11/29/2007 5:31:06 PM | Attr = ] System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 11/29/2007 3:07:48 PM | Attr = HS] WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 11/29/2007 5:31:08 PM | Attr = ] $hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 11/27/2007 3:55:34 PM | Attr = H ] $NtUninstallKB918118$ -> %SystemRoot%\$NtUninstallKB918118$ -> [Folder | Modified Date = 11/25/2007 5:16:00 PM | Attr = H ] $NtUninstallKB920213$ -> %SystemRoot%\$NtUninstallKB920213$ -> [Folder | Modified Date = 11/25/2007 5:10:18 PM | Attr = H ] $NtUninstallKB921503$ -> %SystemRoot%\$NtUninstallKB921503$ -> [Folder | Modified Date = 11/25/2007 5:31:24 PM | Attr = H ] $NtUninstallKB923723$ -> %SystemRoot%\$NtUninstallKB923723$ -> [Folder | Modified Date = 11/25/2007 5:38:34 PM | Attr = H ] $NtUninstallKB923980$ -> %SystemRoot%\$NtUninstallKB923980$ -> [Folder | Modified Date = 11/25/2007 5:37:14 PM | Attr = H ] $NtUninstallKB924270$ -> %SystemRoot%\$NtUninstallKB924270$ -> [Folder | Modified Date = 11/25/2007 5:32:12 PM | Attr = H ] $NtUninstallKB924667$ -> %SystemRoot%\$NtUninstallKB924667$ -> [Folder | Modified Date = 11/25/2007 5:32:30 PM | Attr = H ] $NtUninstallKB925398_WMP64$ -> %SystemRoot%\$NtUninstallKB925398_WMP64$ -> [Folder | Modified Date = 11/25/2007 5:25:14 PM | Attr = H ] $NtUninstallKB925902$ -> %SystemRoot%\$NtUninstallKB925902$ -> [Folder | Modified Date = 11/25/2007 5:22:26 PM | Attr = H ] $NtUninstallKB926255$ -> %SystemRoot%\$NtUninstallKB926255$ -> [Folder | Modified Date = 11/25/2007 5:15:42 PM | Attr = H ] $NtUninstallKB926436$ -> %SystemRoot%\$NtUninstallKB926436$ -> [Folder | Modified Date = 11/25/2007 5:17:10 PM | Attr = H ] $NtUninstallKB927779$ -> %SystemRoot%\$NtUninstallKB927779$ -> [Folder | Modified Date = 11/25/2007 5:40:36 PM | Attr = H ] $NtUninstallKB927802$ -> %SystemRoot%\$NtUninstallKB927802$ -> [Folder | Modified Date = 11/25/2007 5:40:10 PM | Attr = H ] $NtUninstallKB927891$ -> %SystemRoot%\$NtUninstallKB927891$ -> [Folder | Modified Date = 11/25/2007 5:31:38 PM | Attr = H ] $NtUninstallKB928255$ -> %SystemRoot%\$NtUninstallKB928255$ -> [Folder | Modified Date = 11/25/2007 5:39:02 PM | Attr = H ] $NtUninstallKB928843$ -> %SystemRoot%\$NtUninstallKB928843$ -> [Folder | Modified Date = 11/25/2007 5:03:04 PM | Attr = H ] $NtUninstallKB929123$ -> %SystemRoot%\$NtUninstallKB929123$ -> [Folder | Modified Date = 11/25/2007 5:21:48 PM | Attr = H ] $NtUninstallKB929399$ -> %SystemRoot%\$NtUninstallKB929399$ -> [Folder | Modified Date = 11/25/2007 5:15:14 PM | Attr = H ] $NtUninstallKB930178$ -> %SystemRoot%\$NtUninstallKB930178$ -> [Folder | Modified Date = 11/25/2007 5:16:54 PM | Attr = H ] $NtUninstallKB930916$ -> %SystemRoot%\$NtUninstallKB930916$ -> [Folder | Modified Date = 11/25/2007 5:08:58 PM | Attr = H ] $NtUninstallKB931261$ -> %SystemRoot%\$NtUninstallKB931261$ -> [Folder | Modified Date = 11/25/2007 5:31:54 PM | Attr = H ] $NtUninstallKB931784$ -> %SystemRoot%\$NtUninstallKB931784$ -> [Folder | Modified Date = 11/27/2007 5:08:52 PM | Attr = H ] $NtUninstallKB932168$ -> %SystemRoot%\$NtUninstallKB932168$ -> [Folder | Modified Date = 11/25/2007 5:16:38 PM | Attr = H ] $NtUninstallKB933360$ -> %SystemRoot%\$NtUninstallKB933360$ -> [Folder | Modified Date = 11/25/2007 5:10:02 PM | Attr = H ] $NtUninstallKB933729$ -> %SystemRoot%\$NtUninstallKB933729$ -> [Folder | Modified Date = 11/25/2007 5:38:12 PM | Attr = H ] $NtUninstallKB935839$ -> %SystemRoot%\$NtUninstallKB935839$ -> [Folder | Modified Date = 11/25/2007 5:07:52 PM | Attr = H ] $NtUninstallKB935840$ -> %SystemRoot%\$NtUninstallKB935840$ -> [Folder | Modified Date = 11/25/2007 5:09:28 PM | Attr = H ] $NtUninstallKB936021$ -> %SystemRoot%\$NtUninstallKB936021$ -> [Folder | Modified Date = 11/25/2007 5:34:16 PM | Attr = H ] $NtUninstallKB936782_WMP11$ -> %SystemRoot%\$NtUninstallKB936782_WMP11$ -> [Folder | Modified Date = 11/25/2007 5:07:18 PM | Attr = H ] $NtUninstallKB938127$ -> %SystemRoot%\$NtUninstallKB938127$ -> [Folder | Modified Date = 11/25/2007 5:10:30 PM | Attr = H ] $NtUninstallKB938828$ -> %SystemRoot%\$NtUninstallKB938828$ -> [Folder | Modified Date = 11/25/2007 5:33:54 PM | Attr = H ] $NtUninstallKB938829$ -> %SystemRoot%\$NtUninstallKB938829$ -> [Folder | Modified Date = 11/25/2007 5:30:58 PM | Attr = H ] $NtUninstallKB939653$ -> %SystemRoot%\$NtUninstallKB939653$ -> [Folder | Modified Date = 11/25/2007 5:33:20 PM | Attr = H ] $NtUninstallKB939683$ -> %SystemRoot%\$NtUninstallKB939683$ -> [Folder | Modified Date = 11/25/2007 5:12:48 PM | Attr = H ] $NtUninstallKB941202$ -> %SystemRoot%\$NtUninstallKB941202$ -> [Folder | Modified Date = 11/25/2007 5:16:18 PM | Attr = H ] $NtUninstallKB943460$ -> %SystemRoot%\$NtUninstallKB943460$ -> [Folder | Modified Date = 11/25/2007 5:39:30 PM | Attr = H ] bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 11/29/2007 5:36:08 PM | Attr = S] Debug -> %SystemRoot%\Debug -> [Folder | Modified Date = 11/25/2007 5:25:44 PM | Attr = ] Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 11/29/2007 3:09:34 PM | Attr = S] ERDNT -> %SystemRoot%\ERDNT -> [Folder | Modified Date = 11/29/2007 3:07:58 PM | Attr = ] Fonts -> %SystemRoot%\Fonts -> [Folder | Modified Date = 11/25/2007 11:39:54 AM | Attr = ] Help -> %SystemRoot%\Help -> [Folder | Modified Date = 11/25/2007 3:57:48 PM | Attr = ] imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1393 bytes | Modified Date = 11/25/2007 5:41:02 PM | Attr = ] inf -> %SystemRoot%\inf -> [Folder | Modified Date = 11/27/2007 5:09:04 PM | Attr = ] Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 11/29/2007 5:05:20 PM | Attr = HS] msagent -> %SystemRoot%\msagent -> [Folder | Modified Date = 11/25/2007 5:48:48 PM | Attr = ] popcinfo.dat -> %SystemRoot%\popcinfo.dat -> [Ver = | Size = 172 bytes | Modified Date = 11/24/2007 10:30:36 PM | Attr = ] Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 11/29/2007 5:41:06 PM | Attr = ] pss -> %SystemRoot%\pss -> [Folder | Modified Date = 11/25/2007 5:52:36 PM | Attr = ] system32 -> %System32% -> [Folder | Modified Date = 11/29/2007 5:31:08 PM | Attr = HS] Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 11/25/2007 5:41:08 PM | Attr = S] Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 11/29/2007 5:36:52 PM | Attr = ] WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 11/25/2007 5:32:36 PM | Attr = ] RegCure Program Check.job -> %SystemRoot%\tasks\RegCure Program Check.job -> [Ver = | Size = 438 bytes | Modified Date = 11/29/2007 5:36:32 PM | Attr = ] RegCure.job -> %SystemRoot%\tasks\RegCure.job -> [Ver = | Size = 372 bytes | Modified Date = 11/29/2007 3:01:16 PM | Attr = ] SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 11/29/2007 5:36:26 PM | Attr = H ] SpywareBot Scheduled Scan.job -> %SystemRoot%\tasks\SpywareBot Scheduled Scan.job -> [Ver = | Size = 488 bytes | Modified Date = 11/29/2007 3:00:02 AM | Attr = ] CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 11/29/2007 5:34:32 PM | Attr = ] d3d9caps.dat -> %System32%\d3d9caps.dat -> [Ver = | Size = 664 bytes | Modified Date = 11/18/2007 7:36:10 PM | Attr = ] dllcache -> %System32%\dllcache -> [Folder | Modified Date = 11/27/2007 5:08:56 PM | Attr = RHS] drivers -> %System32%\drivers -> [Folder | Modified Date = 11/29/2007 5:36:46 PM | Attr = ] FNTCACHE.DAT -> %System32%\FNTCACHE.DAT -> [Ver = | Size = 322728 bytes | Modified Date = 11/25/2007 5:49:26 PM | Attr = ] perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 54280 bytes | Modified Date = 11/24/2007 9:52:38 PM | Attr = ] perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 384596 bytes | Modified Date = 11/24/2007 9:52:38 PM | Attr = ] PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 445630 bytes | Modified Date = 11/24/2007 9:52:38 PM | Attr = ] Restore -> %System32%\Restore -> [Folder | Modified Date = 11/29/2007 3:09:36 PM | Attr = ] S32EVNT1.DLL -> %System32%\S32EVNT1.DLL -> Symantec Corporation [Ver = 12.5.2.2 | Size = 60800 bytes | Modified Date = 11/25/2007 7:45:02 PM | Attr = ] wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 1158 bytes | Modified Date = 11/29/2007 5:37:04 PM | Attr = ] etc -> %System32%\drivers\etc -> [Folder | Modified Date = 11/25/2007 12:33:54 AM | Attr = ] SYMEVENT.CAT -> %System32%\drivers\SYMEVENT.CAT -> [Ver = | Size = 10740 bytes | Modified Date = 11/25/2007 7:45:02 PM | Attr = ] SYMEVENT.INF -> %System32%\drivers\SYMEVENT.INF -> [Ver = | Size = 805 bytes | Modified Date = 11/25/2007 7:45:02 PM | Attr = ] SYMEVENT.SYS -> %System32%\drivers\SYMEVENT.SYS -> Symantec Corporation [Ver = 12.5.2.1 | Size = 123952 bytes | Modified Date = 11/25/2007 7:45:02 PM | Attr = ] [File String Scan - Non-Microsoft Only] @Alternate Data Stream - 26 bytes -> %SystemDrive%\Scorecards.pdf:Zone.Identifier -> WSUD , -> %SystemRoot%\cvnvwvc.exe -> [Ver = | Size = 500000 bytes | Modified Date = 12/12/1989 9:10:10 AM | Attr = RHS] WSUD , -> %SystemRoot%\frxvy.log -> [Ver = | Size = 11736 bytes | Modified Date = 2/28/2005 8:08:56 AM | Attr = ] qoologic , urllogic , urllogic , abetterinternet.com , -> %SystemRoot%\httktt.dll -> [Ver = | Size = 3086 bytes | Modified Date = 2/11/2005 10:57:02 AM | Attr = ] @Alternate Data Stream - 7471 bytes -> %SystemRoot%\KB828741.log:kronuj -> @Alternate Data Stream - 3567 bytes -> %SystemRoot%\KB835732.log:dszswu -> PEC2 , PECompact2 , -> %SystemRoot%\manager.exe -> Microsoft [Ver = 2. 0. 0. 0 | Size = 98222 bytes | Modified Date = 6/10/2006 3:47:10 PM | Attr = ] @Alternate Data Stream - 7471 bytes -> %SystemRoot%\Q309521.log:vzaqfn -> @Alternate Data Stream - 3567 bytes -> %SystemRoot%\Q311889.log:nakezq -> @Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable -> WSUD , -> %SystemRoot%\~GLH0014.TMP -> [Ver = 1, 4, 0, 0 | Size = 2306048 bytes | Modified Date = 2/13/2007 2:32:12 PM | Attr = ] PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 8/18/2001 6:00:00 AM | Attr = ] Thawte Consulting , -> %System32%\ijjiPlugin2.dll -> TODO: <Company name> [Ver = 2.0.0.0 | Size = 58776 bytes | Modified Date = 6/21/2007 5:59:50 PM | Attr = ] WSUD , -> %System32%\jdkyo.dat -> [Ver = | Size = 3567 bytes | Modified Date = 2/24/2005 12:57:10 AM | Attr = ] WSUD , -> %System32%\qsjou.txt -> [Ver = | Size = 3567 bytes | Modified Date = 2/21/2005 10:50:34 PM | Attr = ] aspack , PTech , -> %System32%\saie_kyf.dat -> [Ver = | Size = 8812834 bytes | Modified Date = 12/21/2004 10:28:10 PM | Attr = ] @Alternate Data Stream - 0 bytes -> %System32%\Thumbs.db:encryptable -> winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 8/18/2001 6:00:00 AM | Attr = ] WSUD , -> %System32%\xrqis.log -> [Ver = | Size = 7471 bytes | Modified Date = 2/21/2005 11:12:02 PM | Attr = ] WSUD , -> %System32%\ykhfs.txt -> [Ver = | Size = 7471 bytes | Modified Date = 2/6/2005 3:14:14 AM | Attr = ] WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 8/18/2001 6:00:00 AM | Attr = ] PTech , -> %System32%\dllcache\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 8/3/2004 10:41:38 PM | Attr = ] PTech , -> %System32%\drivers\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 8/3/2004 10:41:38 PM | Attr = ] < End of report > |
|
|
Nov 30 2007, 12:32 PM
Post
#11
|
|
|
GeekU Moderator Posts: 14,119 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
After the Winpfind fix I would like you to re-run the Combofix programme
Start WinPFind3U. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button. QUOTE [Registry - Non-Microsoft Only] < Internet Explorer Bars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ YN -> {0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] < Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ YN -> {0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] YN -> {32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] < User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform YN -> {5B05902B-4D20-4DAC-87E1-C9CCD4EC6229} -> YN -> FunWebProducts -> < Protocol Filters [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\ YN -> text/html -> Reg Data - Key not found [Files/Folders - Modified Within 30 days] NY -> popcinfo.dat -> %SystemRoot%\popcinfo.dat NY -> SpywareBot Scheduled Scan.job -> %SystemRoot%\tasks\SpywareBot Scheduled Scan.job NY -> d3d9caps.dat -> %System32%\d3d9caps.dat [File String Scan - Non-Microsoft Only] NY -> @Alternate Data Stream - 26 bytes -> %SystemDrive%\Scorecards.pdf:Zone.Identifier NY -> WSUD , -> %SystemRoot%\cvnvwvc.exe NY -> WSUD , -> %SystemRoot%\frxvy.log NY -> qoologic , urllogic , urllogic , abetterinternet.com , -> %SystemRoot%\httktt.dll NY -> @Alternate Data Stream - 7471 bytes -> %SystemRoot%\KB828741.log:kronuj NY -> @Alternate Data Stream - 3567 bytes -> %SystemRoot%\KB835732.log:dszswu NY -> PEC2 , PECompact2 , -> %SystemRoot%\manager.exe NY -> @Alternate Data Stream - 7471 bytes -> %SystemRoot%\Q309521.log:vzaqfn NY -> @Alternate Data Stream - 3567 bytes -> %SystemRoot%\Q311889.log:nakezq NY -> @Alternate Data Stream - 0 bytes -> %SystemRoot%\Thumbs.db:encryptable NY -> WSUD , -> %SystemRoot%\~GLH0014.TMP NY -> WSUD , -> %System32%\jdkyo.dat NY -> WSUD , -> %System32%\qsjou.txt NY -> aspack , PTech , -> %System32%\saie_kyf.dat NY -> @Alternate Data Stream - 0 bytes -> %System32%\Thumbs.db:encryptable NY -> WSUD , -> %System32%\xrqis.log NY -> WSUD , -> %System32%\ykhfs.txt The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new Hijackthis log. I will review the information when it comes back in. Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer. NEXT Download ComboFix from Here or Here to your Desktop.
Could you let me know exactly what does not work at the moment on your system. Logs required : Winpfind result, Combofix and a new Hijackthis log |
|
|
Nov 30 2007, 03:02 PM
Post
#12
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
I still am getting an access denied error when I try to run combofix
hijack this log Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:11:00 PM, on 11/30/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE C:\WINDOWS\system32\ScsiAccess.EXE C:\Program Files\Spyware Doctor\svcntaux.exe C:\Program Files\Spyware Doctor\swdsvc.exe C:\Program Files\Spyware Doctor\SDTrayApp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\System32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe" O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [Uninstall_CToolbar] "C:\WINDOWS\Temp\CTun.exe" "/remove" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download...ne_Inst_Win.cab O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp...02/cpbrkpie.cab O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{6C7C0137-6063-477A-943C-E6E98157D0DF}: Domain = hsd1.il.comcast.net. O18 - Filter hijack: text/html - (no CLSID) - (no file) O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- End of file - 6087 bytes windpfind it [Registry - Non-Microsoft Only] < Internet Explorer Bars [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ YN -> {0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] < Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ YN -> {0EBACAF2-E0F9-47A9-98CF-0ECCE30B654C} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] YN -> {32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] < User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform YN -> {5B05902B-4D20-4DAC-87E1-C9CCD4EC6229} -> YN -> FunWebProducts -> < Protocol Filters [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\ YN -> text/html -> Reg Data - Key not found [Files/Folders - Modified Within 30 days] NY -> popcinfo.dat -> %SystemRoot%\popcinfo.dat NY -> SpywareBot Sch < End of log > Created on 11/30/2007 15:07:57 |
|
|
Nov 30 2007, 03:13 PM
Post
#13
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
sorry i forgot to put this in my last post but there is no noticible difference
|
|
|
Nov 30 2007, 04:39 PM
Post
#14
|
|
|
GeekU Moderator Posts: 14,119 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
OK while I continue to research the task bar could you do the following
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. O4 - HKLM\..\Run: [Uninstall_CToolbar] "C:\WINDOWS\Temp\CTun.exe" "/remove" O18 - Filter hijack: text/html - (no CLSID) - (no file) Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. THEN Download and run ERUNT http://www.larshederer.homepage.t-online.de/erunt/ Start ERUNT, confirm the Welcome message. Type in the name of a restore folder where the backed up registry files should be saved, or click "..." to browse your computer's drives and select a folder. You can also simply leave the default, which is a folder named ERDNT inside your Windows folder, the advantage being that you have access to this folder from the Windows Recovery Console in case Windows does not boot anymore. Next, select the backup options: - System registry: - Current user registy: . - Other open user registries: Click "OK" and wait until the backup process is complete. (Note that depending on your system configuration this may take some time, and that the first bar is NOT a progress bar, just an indicator that the program is still running.) The ERDNT program for later restoration of the registry is automatically copied to the restore folder. WARNING these fixes are designed for this user only and may cause damage if run on an uninfected machine REGISTRY FIX QUOTE REGEDIT4 [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StuckRects2] Next you will need to create the repair registry fix to do that copy and paste ALL of the above in the quote box to a notepad file. Ensure there is no space above the REGEDIT4. Then in notepad go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES Then in the FILE NAME box type fix.reg This will create a fix.reg file on your desktop ![]() To use this file you will need to right click the icon and select merge, accept the warning if it appears and you are done. Reboot your system and see if the task bar has returned If that should fail then download and run this small VBS file http://www.kellys-korner-xp.com/regs_edits...ktop_fixall.vbs This post has been edited by Essexboy: Nov 30 2007, 04:41 PM |
|
|
Nov 30 2007, 07:43 PM
Post
#15
|
|
|
Member ![]() ![]() Posts: 36 OS: Mac OS X, Vista |
still no luck with anything
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:52:54 PM, on 11/30/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE C:\WINDOWS\system32\ScsiAccess.EXE C:\Program Files\Spyware Doctor\svcntaux.exe C:\Program Files\Spyware Doctor\swdsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Spyware Doctor\SDTrayApp.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\System32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us6.hpwis.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll O2 - BHO: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O3 - Toolbar: Comcast Toolbar - {4E7BD74F-2B8D-469E-93BE-BE2DF4D9AE29} - C:\PROGRA~1\COMCAS~4\COMCAS~1.DLL O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe" O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] C:\Program Files\PCPitstop\Optimize\PCPOptimize.exe -boot O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal...ivex/hcImpl.cab O16 - DPF: {2DFF31F9-7893-4922-AF66-C9A1EB4EBB31} (Rhapsody Player Engine) - http://forms.real.com/real/player/download...ne_Inst_Win.cab O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1452/ftp...02/cpbrkpie.cab O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_a...asyInstallX.CAB O17 - HKLM\System\CCS\Services\Tcpip\..\{6C7C0137-6063-477A-943C-E6E98157D0DF}: Domain = hsd1.il.comcast.net. O18 - Filter hijack: text/html - (no CLSID) - (no file) O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe -- End of file - 6084 bytes |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
2 / 333 | 25th September 2005 - 08:49 AM lugu07 started - last by Buckeye_Sam |
|||||
![]() |
0 / 245 | 14th November 2005 - 12:34 PM Bigglesbutcha started - last by Bigglesbutcha |
|||||
![]() |
0 / 600 | 13th November 2007 - 03:06 AM rengganis started - last by rengganis |
|||||
![]() |
24 / 1,204 | 10th June 2008 - 06:43 AM dressydoll started - last by sage5 |
|||||
|
Time is now: 4th July 2009 - 04:09 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.