Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Think I have company? [CLOSED]


  • This topic is locked This topic is locked

#46
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Wow.. Your wife log looks clean to my eyes :)


2008-07-30 22:06:33 68096 --a------ C:\WINDOWS\zip.exe
2008-07-30 22:06:33 49152 --a------ C:\WINDOWS\VFind.exe
2008-07-30 22:06:33 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-07-30 22:06:33 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-07-30 22:06:33 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-07-30 22:06:33 98816 --a------ C:\WINDOWS\sed.exe
2008-07-30 22:06:33 80412 --a------ C:\WINDOWS\grep.exe
2008-07-30 22:06:33 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >


You might want to apply for GeekU class :) link below:
http://www.geekstogo...2286#entry22286

All above entries indicates you either has run ComboFix/DSS/SDFix/SmitfraudFix before.. And all above entries are legit and during our cleaning process, is needed.. :)


Ok.. DSS log from next account please (if any..) ;)
  • 0

Advertisements


#47
ScittS

ScittS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
I already have applied for Geek U :) ..... do you think I can do it though? :)

If you think I can handle it, maybe put in a good word??? :) ;)

I have one profile left.... I will switch users and post it....

Scott
  • 0

#48
ScittS

ScittS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
I have good news :) ...... and not so good news :) !!!!

Good News first:

Last one and I already have it!

Bad news is:

I alredy see a problem or two in this log! :)

DSS Log:

Deckard's System Scanner v20071014.68
Run by Torey on 2008-08-01 04:02:43
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Torey.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:02:44 AM, on 8/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\FCyberAlert\syslogin.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\Documents and Settings\Owner\My Documents\Software\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Torey.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FamilyCyberAlert] C:\WINDOWS\system32\FCyberAlert\syslogin.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [fufokoo] C:\Documents and Settings\Torey\Application Data\Microsoft\noucouzipyz.exe
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Owner')
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1003\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Owner')
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1003\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User 'Owner')
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1003\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (User 'Owner')
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1004\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" (User 'Tammy')
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1006\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (User 'Jordyn')
O4 - HKUS\S-1-5-21-746137067-839522115-725345543-1007\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (User 'Alyc')
O4 - Global Startup: Exif Launcher S.lnk = C:\Program Files\FinePixViewerS\QuickDCF2.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1211585209718
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn...ro.cab56649.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

--
End of file - 11807 bytes

-- Files created between 2008-07-01 and 2008-08-01 -----------------------------

2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-31 01:03:29 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-31 01:03:29 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-31 01:03:29 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-31 01:03:29 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-31 01:03:29 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-31 01:03:29 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-30 22:06:33 68096 --a------ C:\WINDOWS\zip.exe
2008-07-30 22:06:33 49152 --a------ C:\WINDOWS\VFind.exe
2008-07-30 22:06:33 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-07-30 22:06:33 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-07-30 22:06:33 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-07-30 22:06:33 98816 --a------ C:\WINDOWS\sed.exe
2008-07-30 22:06:33 80412 --a------ C:\WINDOWS\grep.exe
2008-07-30 22:06:33 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-07-30 22:04:39 0 dr-hs---- C:\cmdcons
2008-07-30 22:04:38 0 d-------- C:\WINDOWS\setup.pss
2008-07-30 22:03:06 0 d-------- C:\WINDOWS\setupupd
2008-07-30 21:49:37 0 d-------- C:\Documents and Settings\Owner\Application Data\Windows Search
2008-07-29 22:12:47 0 d-------- C:\Program Files\Norton 360
2008-07-29 22:11:55 0 d-------- C:\Program Files\Symantec
2008-07-29 22:09:37 0 d-------- C:\Documents and Settings\Owner\Application Data\Symantec
2008-07-29 18:48:02 0 d-------- C:\Documents and Settings\Torey\Application Data\Windows Desktop Search
2008-07-29 18:46:47 0 d-------- C:\Documents and Settings\Tammy\Application Data\Windows Desktop Search
2008-07-29 15:30:32 0 d-------- C:\Program Files\Trend Micro
2008-07-28 21:46:23 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Windows Desktop Search
2008-07-28 21:42:48 0 d-------- C:\Documents and Settings\Alyc\Application Data\SUPERAntiSpyware.com
2008-07-28 21:27:53 0 d-------- C:\Documents and Settings\Alyc\Application Data\Windows Desktop Search
2008-07-28 21:20:46 0 d-------- C:\Documents and Settings\Owner\Application Data\Windows Desktop Search
2008-07-28 21:20:27 0 d-------- C:\Program Files\Windows Desktop Search
2008-07-28 21:20:26 0 d-------- C:\WINDOWS\system32\GroupPolicy
2008-07-28 18:25:53 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-28 17:44:45 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-28 17:44:42 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-28 17:44:41 0 d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-07-28 17:44:23 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-28 17:40:35 0 d-------- C:\Program Files\SpywareBlaster
2008-07-28 15:24:42 0 d-------- C:\Documents and Settings\Owner\.housecall6.6
2008-07-28 11:31:58 0 d-------- C:\Documents and Settings\Torey\Application Data\Malwarebytes
2008-07-28 11:31:00 0 d-------- C:\Documents and Settings\Torey\Application Data\Mozilla
2008-07-28 11:06:42 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Malwarebytes
2008-07-28 11:05:48 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Mozilla
2008-07-27 21:40:28 0 d-------- C:\Documents and Settings\Tammy\Application Data\Mozilla
2008-07-27 21:40:09 0 d-------- C:\Documents and Settings\Tammy\Application Data\Malwarebytes
2008-07-27 21:32:45 0 d-------- C:\Documents and Settings\Alyc\Application Data\Mozilla
2008-07-27 21:31:18 0 dr-h----- C:\Documents and Settings\Alyc\Recent
2008-07-27 21:15:30 0 d-------- C:\WINDOWS\pss
2008-07-27 20:53:48 0 d-------- C:\Documents and Settings\Alyc\Application Data\Malwarebytes
2008-07-27 19:58:35 0 dr-h----- C:\Documents and Settings\Owner\Recent
2008-07-27 18:11:35 0 d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-07-27 18:11:33 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-27 18:11:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-27 18:11:01 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-27 15:31:43 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-27 15:31:36 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-07-26 12:36:48 0 d-------- C:\Documents and Settings\Jordyn\Application Data\FUJIFILM
2008-07-21 15:50:55 0 d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
2008-07-21 14:24:07 0 d-------- C:\Documents and Settings\Owner\Application Data\HouseCall 6.6
2008-07-19 14:26:52 0 d-------- C:\Documents and Settings\Torey\Contacts
2008-07-18 15:23:40 0 d-------- C:\Documents and Settings\Alyc\Contacts
2008-07-18 11:02:58 0 d-------- C:\Documents and Settings\Owner\Contacts
2008-07-18 07:11:23 0 d-------- C:\Documents and Settings\Jordyn\Contacts
2008-07-17 10:13:45 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-17 10:13:41 0 d-------- C:\Program Files\Windows Live
2008-07-17 10:13:27 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-05 05:04:19 0 d-------- C:\Documents and Settings\Tammy\Application Data\Macromedia


-- Find3M Report ---------------------------------------------------------------

2008-08-01 00:23:04 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-31 13:30:07 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-07-30 22:08:01 0 d-------- C:\Program Files\Common Files
2008-07-19 18:08:32 0 d-------- C:\Program Files\Java
2008-06-25 19:08:36 0 d-------- C:\Documents and Settings\Torey\Application Data\Adobe
2008-06-24 20:33:35 0 --a------ C:\WINDOWS\PowerReg.dat
2008-06-24 20:31:47 0 d-------- C:\Program Files\Infogrames Interactive
2008-06-24 20:31:46 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-20 14:01:01 0 d-------- C:\Documents and Settings\Torey\Application Data\Symantec
2008-06-17 17:25:38 2528 --a------ C:\Documents and Settings\Torey\Application Data\$_hpcst$.hpc
2008-06-17 16:42:31 0 d-------- C:\Documents and Settings\Torey\Application Data\FUJIFILM
2008-06-17 16:13:48 0 d-------- C:\Documents and Settings\Torey\Application Data\Macromedia
2008-06-05 04:50:36 0 d-------- C:\Program Files\Logitech
2008-06-05 04:49:27 0 d-------- C:\Program Files\Common Files\Logitech
2008-05-24 10:41:49 139264 --a------ C:\WINDOWS\system32\hpzjrd01.dll <Not Verified; Hewlett Packard; Hewlett Packard Rediscovery Library>
2008-05-24 10:38:12 89277 --a------ C:\WINDOWS\hpoins06.dat
2008-05-24 02:52:04 934607 --a------ C:\WINDOWS\system32\JGScreensaver_3.scr <Not Verified; Axialis Software; Axialis Screen Saver Producer>
2008-05-23 19:48:00 1076 --a------ C:\WINDOWS\checkip.dat
2008-05-23 14:26:04 22 --a------ C:\WINDOWS\FileName
2008-05-23 14:18:26 0 -rahs---- C:\MSDOS.SYS
2008-05-23 14:18:26 0 -rahs---- C:\IO.SYS
2008-05-23 14:18:26 0 --a------ C:\CONFIG.SYS
2008-05-23 14:18:26 0 --a------ C:\AUTOEXEC.BAT
2008-05-23 14:16:27 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-23 08:43:36 62 --ahs---- C:\Documents and Settings\Torey\Application Data\desktop.ini


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
06/30/2008 01:44 PM 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
07/29/2008 10:13 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll [06/30/2008 01:44 PM 349552]

[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [11/14/2006 04:21 AM C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [05/16/2006 05:04 AM C:\WINDOWS\SkyTel.exe]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [10/30/2006 07:44 AM]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidSetup.exe" [10/30/2006 07:44 AM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [09/17/2007 01:07 AM]
"nwiz"="nwiz.exe" [09/17/2007 01:07 AM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [09/17/2007 01:07 AM]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe" [11/14/2006 01:25 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/15/2007 09:02 PM]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [05/07/2007 11:32 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [05/08/2007 04:24 PM]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [07/09/2002 09:45 PM]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [09/06/2007 02:53 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"FamilyCyberAlert"="C:\WINDOWS\system32\FCyberAlert\syslogin.exe" [04/22/2008 12:20 PM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/18/2008 02:37 PM]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [02/26/2008 09:50 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [05/07/2007 11:40 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 07:00 AM]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" []
"fufokoo"="C:\Documents and Settings\Torey\Application Data\Microsoft\noucouzipyz.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher S.lnk - C:\Program Files\FinePixViewerS\QuickDCF2.exe [5/24/2008 11:07:32 AM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [5/11/2005 11:23:26 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2/17/1999 3:05:56 PM]
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [5/26/2008 10:19:14 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [05/13/2008 10:13 AM 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [05/26/2008 10:19 PM 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"

*Newly Created Service* - COMHOST



-- End of Deckard's System Scanner: finished at 2008-08-01 04:03:18 ------------
  • 0

#49
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Don't worry about it :) We'll nuke em all.. (Yeah.. same step same script :) )


Please save this instruction in a Notepad or MS-Word as we have to do the next step in Safe Mode..



Please disable your Norton 360 prior to our fix.. Please visit below websites if you do not know how.. Don't forget to re-enable them back when you restart into Normal Mode..
http://service1.syma...003071515220236
http://service1.syma...d/1997121131456



Do below in Safe Mode..


Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
[*]Let the Unregister Dll's and Ocx's remain ticked and Zip Files After Moves remain unticked..
[*]Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

[kill explorer]
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\fufokoo
C:\Documents and Settings\Alyc\Application Data\Microsoft\noucouzipyz.exe
[start explorer]

[*] Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
[*]Click the red Moveit! button.
[*]A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
[*]Close OTMoveIt2
[/list]If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.




NEXT



1. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Begin copying here:
Drivers to disable:
e96ctimjhi4euho

Drivers to delete:
e96ctimjhi4euho

Files to delete:
C:\WINDOWS\system32\wennouwibas.exe
C:\WINDOWS\system32\noucouzipyz.exe

Registry values to delete:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run | fufokoo
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices | fufokoo

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


2. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
3. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
4. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh DSS log .



Post this log in your next reply.. Each log in separate post..

1. OTMoveIt2
2. The Avenger
3. DSS of this account..


I already have applied for Geek U :) ..... do you think I can do it though? ;)

If you think I can handle it, maybe put in a good word??? :) :)

I have one profile left.... I will switch users and post it....

Scott



If I can do it, why not you :)

It may daunting at first but believe me, when you go at your own pace, and take your every time to read each line, every logs you do will serve you better.. Its full of knowledge and the most important is, it is fun!! :D

Edited by fenzodahl512, 01 August 2008 - 03:26 AM.

  • 0

#50
ScittS

ScittS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
Hello.... I'm back again! :)

Here are those logs:

Move It:

Explorer killed successfully
< HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\fufokoo >
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\fufokoo deleted successfully.
File/Folder C:\Documents and Settings\Alyc\Application Data\Microsoft\noucouzipyz.exe not found.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08012008_071353

Avenger:

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!


Error: could not open driver "e96ctimjhi4euho"
Disablement of driver "e96ctimjhi4euho" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: registry key "\Registry\Machine\System\CurrentControlSet\Services\e96ctimjhi4euho" not found!
Deletion of driver "e96ctimjhi4euho" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\wennouwibas.exe" not found!
Deletion of file "C:\WINDOWS\system32\wennouwibas.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: file "C:\WINDOWS\system32\noucouzipyz.exe" not found!
Deletion of file "C:\WINDOWS\system32\noucouzipyz.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|fufokoo"
Deletion of registry value "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|fufokoo" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not delete registry value "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices|fufokoo"
Deletion of registry value "HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices|fufokoo" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.

Finally I will post DSS in new reply!!!! :)
  • 0

#51
ScittS

ScittS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
And finally here is torey's DSS log:

Deckard's System Scanner v20071014.68
Run by Torey on 2008-08-01 07:25:38
Computer is in Normal Mode.
--------------------------------------------------------------------------------



-- HijackThis (run as Torey.exe) -----------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:25:41 AM, on 8/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\FCyberAlert\syslogin.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\FinePixViewerS\QuickDCF2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\HPZinw12.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Torey\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Torey.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [JMB36X Configure] C:\WINDOWS\system32\JMRaidSetup.exe boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FamilyCyberAlert] C:\WINDOWS\system32\FCyberAlert\syslogin.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Global Startup: Exif Launcher S.lnk = C:\Program Files\FinePixViewerS\QuickDCF2.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.mi...b?1211585209718
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn...ro.cab56649.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe

--
End of file - 10595 bytes

-- Files created between 2008-07-01 and 2008-08-01 -----------------------------

2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-07-31 01:03:29 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-07-31 01:03:29 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-07-31 01:03:29 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-07-31 01:03:29 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-07-31 01:03:29 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-07-31 01:03:29 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-07-31 01:03:29 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-07-31 01:03:29 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-07-30 22:06:33 68096 --a------ C:\WINDOWS\zip.exe
2008-07-30 22:06:33 49152 --a------ C:\WINDOWS\VFind.exe
2008-07-30 22:06:33 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-07-30 22:06:33 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-07-30 22:06:33 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-07-30 22:06:33 98816 --a------ C:\WINDOWS\sed.exe
2008-07-30 22:06:33 80412 --a------ C:\WINDOWS\grep.exe
2008-07-30 22:06:33 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-07-30 22:04:39 0 dr-hs---- C:\cmdcons
2008-07-30 22:04:38 0 d-------- C:\WINDOWS\setup.pss
2008-07-30 22:03:06 0 d-------- C:\WINDOWS\setupupd
2008-07-30 21:49:37 0 d-------- C:\Documents and Settings\Owner\Application Data\Windows Search
2008-07-29 22:12:47 0 d-------- C:\Program Files\Norton 360
2008-07-29 22:11:55 0 d-------- C:\Program Files\Symantec
2008-07-29 22:09:37 0 d-------- C:\Documents and Settings\Owner\Application Data\Symantec
2008-07-29 18:48:02 0 d-------- C:\Documents and Settings\Torey\Application Data\Windows Desktop Search
2008-07-29 18:46:47 0 d-------- C:\Documents and Settings\Tammy\Application Data\Windows Desktop Search
2008-07-29 15:30:32 0 d-------- C:\Program Files\Trend Micro
2008-07-28 21:46:23 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Windows Desktop Search
2008-07-28 21:42:48 0 d-------- C:\Documents and Settings\Alyc\Application Data\SUPERAntiSpyware.com
2008-07-28 21:27:53 0 d-------- C:\Documents and Settings\Alyc\Application Data\Windows Desktop Search
2008-07-28 21:20:46 0 d-------- C:\Documents and Settings\Owner\Application Data\Windows Desktop Search
2008-07-28 21:20:27 0 d-------- C:\Program Files\Windows Desktop Search
2008-07-28 21:20:26 0 d-------- C:\WINDOWS\system32\GroupPolicy
2008-07-28 18:25:53 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-28 17:44:45 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-07-28 17:44:42 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-07-28 17:44:41 0 d-------- C:\Documents and Settings\Owner\Application Data\SUPERAntiSpyware.com
2008-07-28 17:44:23 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-07-28 17:40:35 0 d-------- C:\Program Files\SpywareBlaster
2008-07-28 15:24:42 0 d-------- C:\Documents and Settings\Owner\.housecall6.6
2008-07-28 11:31:58 0 d-------- C:\Documents and Settings\Torey\Application Data\Malwarebytes
2008-07-28 11:31:00 0 d-------- C:\Documents and Settings\Torey\Application Data\Mozilla
2008-07-28 11:06:42 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Malwarebytes
2008-07-28 11:05:48 0 d-------- C:\Documents and Settings\Jordyn\Application Data\Mozilla
2008-07-27 21:40:28 0 d-------- C:\Documents and Settings\Tammy\Application Data\Mozilla
2008-07-27 21:40:09 0 d-------- C:\Documents and Settings\Tammy\Application Data\Malwarebytes
2008-07-27 21:32:45 0 d-------- C:\Documents and Settings\Alyc\Application Data\Mozilla
2008-07-27 21:31:18 0 dr-h----- C:\Documents and Settings\Alyc\Recent
2008-07-27 21:15:30 0 d-------- C:\WINDOWS\pss
2008-07-27 20:53:48 0 d-------- C:\Documents and Settings\Alyc\Application Data\Malwarebytes
2008-07-27 19:58:35 0 dr-h----- C:\Documents and Settings\Owner\Recent
2008-07-27 18:11:35 0 d-------- C:\Documents and Settings\Owner\Application Data\Malwarebytes
2008-07-27 18:11:33 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-27 18:11:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-27 18:11:01 0 d-------- C:\Program Files\Common Files\Download Manager
2008-07-27 15:31:43 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-27 15:31:36 0 d-------- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-07-26 12:36:48 0 d-------- C:\Documents and Settings\Jordyn\Application Data\FUJIFILM
2008-07-21 15:50:55 0 d-------- C:\Documents and Settings\Owner\Application Data\Uniblue
2008-07-21 14:24:07 0 d-------- C:\Documents and Settings\Owner\Application Data\HouseCall 6.6
2008-07-19 14:26:52 0 d-------- C:\Documents and Settings\Torey\Contacts
2008-07-18 15:23:40 0 d-------- C:\Documents and Settings\Alyc\Contacts
2008-07-18 11:02:58 0 d-------- C:\Documents and Settings\Owner\Contacts
2008-07-18 07:11:23 0 d-------- C:\Documents and Settings\Jordyn\Contacts
2008-07-17 10:13:45 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-17 10:13:41 0 d-------- C:\Program Files\Windows Live
2008-07-17 10:13:27 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-05 05:04:19 0 d-------- C:\Documents and Settings\Tammy\Application Data\Macromedia


-- Find3M Report ---------------------------------------------------------------

2008-08-01 07:17:37 0 d-------- C:\Program Files\Common Files\Symantec Shared
2008-07-31 13:30:07 0 d-------- C:\Program Files\Microsoft ActiveSync
2008-07-30 22:08:01 0 d-------- C:\Program Files\Common Files
2008-07-19 18:08:32 0 d-------- C:\Program Files\Java
2008-06-25 19:08:36 0 d-------- C:\Documents and Settings\Torey\Application Data\Adobe
2008-06-24 20:33:35 0 --a------ C:\WINDOWS\PowerReg.dat
2008-06-24 20:31:47 0 d-------- C:\Program Files\Infogrames Interactive
2008-06-24 20:31:46 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-06-20 14:01:01 0 d-------- C:\Documents and Settings\Torey\Application Data\Symantec
2008-06-17 17:25:38 2528 --a------ C:\Documents and Settings\Torey\Application Data\$_hpcst$.hpc
2008-06-17 16:42:31 0 d-------- C:\Documents and Settings\Torey\Application Data\FUJIFILM
2008-06-17 16:13:48 0 d-------- C:\Documents and Settings\Torey\Application Data\Macromedia
2008-06-05 04:50:36 0 d-------- C:\Program Files\Logitech
2008-06-05 04:49:27 0 d-------- C:\Program Files\Common Files\Logitech
2008-05-24 10:41:49 139264 --a------ C:\WINDOWS\system32\hpzjrd01.dll <Not Verified; Hewlett Packard; Hewlett Packard Rediscovery Library>
2008-05-24 10:38:12 89277 --a------ C:\WINDOWS\hpoins06.dat
2008-05-24 02:52:04 934607 --a------ C:\WINDOWS\system32\JGScreensaver_3.scr <Not Verified; Axialis Software; Axialis Screen Saver Producer>
2008-05-23 19:48:00 1076 --a------ C:\WINDOWS\checkip.dat
2008-05-23 14:26:04 22 --a------ C:\WINDOWS\FileName
2008-05-23 14:18:26 0 -rahs---- C:\MSDOS.SYS
2008-05-23 14:18:26 0 -rahs---- C:\IO.SYS
2008-05-23 14:18:26 0 --a------ C:\CONFIG.SYS
2008-05-23 14:18:26 0 --a------ C:\AUTOEXEC.BAT
2008-05-23 14:16:27 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-23 08:43:36 62 --ahs---- C:\Documents and Settings\Torey\Application Data\desktop.ini


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
06/30/2008 01:44 PM 349552 --a------ C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
07/29/2008 10:13 PM 116088 --a------ C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}"= C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll [06/30/2008 01:44 PM 349552]

[-HKEY_CLASSES_ROOT\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar.1]
[HKEY_CLASSES_ROOT\CoIEPlg.CoToolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [11/14/2006 04:21 AM C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [05/16/2006 05:04 AM C:\WINDOWS\SkyTel.exe]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [10/30/2006 07:44 AM]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidSetup.exe" [10/30/2006 07:44 AM]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [09/17/2007 01:07 AM]
"nwiz"="nwiz.exe" [09/17/2007 01:07 AM C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [09/17/2007 01:07 AM]
"AsusStartupHelp"="C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe" [11/14/2006 01:25 AM]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [06/10/2008 04:27 AM]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [03/15/2007 09:02 PM]
"InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [05/07/2007 11:32 AM]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [05/08/2007 04:24 PM]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [07/09/2002 09:45 PM]
"mxomssmenu"="C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [09/06/2007 02:53 PM]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [03/30/2008 10:36 AM]
"FamilyCyberAlert"="C:\WINDOWS\system32\FCyberAlert\syslogin.exe" [04/22/2008 12:20 PM]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [02/18/2008 02:37 PM]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [02/26/2008 09:50 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [03/28/2008 11:37 PM]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [05/07/2007 11:40 AM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 07:00 AM]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [10/18/2007 11:34 AM]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" []

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Exif Launcher S.lnk - C:\Program Files\FinePixViewerS\QuickDCF2.exe [5/24/2008 11:07:32 AM]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [5/11/2005 11:23:26 PM]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2/17/1999 3:05:56 PM]
Windows Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [5/26/2008 10:19:14 PM]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [05/13/2008 10:13 AM 77824]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [05/26/2008 10:19 PM 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
@="Service"

*Newly Created Service* - COMHOST



-- End of Deckard's System Scanner: finished at 2008-08-01 07:26:07 ------------


Gawd I hope we got them.......... :)
  • 0

#52
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Yup.. I think we got em all.. Lets do an online scan to verify that.. Do this in whatever account that you wish :)


Please do an online scan with Kaspersky WebScanner

Click on Accept

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


How is the computer now? :)
  • 0

#53
ScittS

ScittS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
Well, what can I say. :(

Where do I start? :)

Working on scan now.... i'm on my laptop.

A few things I've noticed..... Norton loaded automatically in all profiles except MINE!!!!! ;) :angry:

Task manager STILL closes as soon as I open it. :wacko:

My clock is stuck on 24 hr format. :woot:

Seems like somthin' is still lurking amidst my lil' world!!! :) :)

Scuse me whilst I vent!!!! :) :D

On a positive note..... :) :cool: :D

Check the tag!!!! :rockon: Thats right we have a :geek: :prop: in the making!!!! :)

I'll post as soon as it's done!! ;)
  • 0

#54
ScittS

ScittS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
And....... as I suspected........ #&%#&^ thing just won't give in! :) :) ;) :)
Sorry I got sidetracked!! :)

Ok(slips boxing gloves on) "Let's kick this thing to the moon Ethel!!"

Here is the scan log:

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, August 1, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Saturday, August 02, 2008 03:07:57
Records in database: 1043321
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
Z:\

Scan statistics:
Files scanned: 81872
Threat name: 1
Infected objects: 3
Suspicious objects: 0
Duration of the scan: 00:39:14


File name / Threat name / Threats count
F:\System Volume Information\_restore{DEDAB486-699E-4B0A-AAB7-A1340D9CCE98}\RP5\A0002276.exe Infected: Trojan-Downloader.Win32.Agent.wkr 1
G:\System Volume Information\_restore{DEDAB486-699E-4B0A-AAB7-A1340D9CCE98}\RP5\A0002274.exe Infected: Trojan-Downloader.Win32.Agent.wkr 1
G:\System Volume Information\_restore{DEDAB486-699E-4B0A-AAB7-A1340D9CCE98}\RP5\A0002275.exe Infected: Trojan-Downloader.Win32.Agent.wkr 1

The selected area was scanned.

If all else fails I can format these two drives I have this stuff backed up! Er...... I should say these are my backups of what is on my main drive. I have a vast music library and some pictures I have 2 backups of the same content. I'm just not sure that the main files are clean I guess Kaspersky would have said so right? :D :)

I ain't giving up yet!!!! :D Kick some A--! :)

Edited by ScittS, 01 August 2008 - 10:49 PM.

  • 0

#55
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Wow.. Don't rush..

F:\System Volume Information\_restore{DEDAB486-699E-4B0A-AAB7-A1340D9CCE98}\RP5\A0002276.exe Infected: Trojan-Downloader.Win32.Agent.wkr 1


That bolded folder is in System Restore.. Nothing to worry about..

Some questions.. About Task Manager, does it close only on your account or on every account.. And that Norton thingy, didn't load automatically only in your account right? :)
  • 0

Advertisements


#56
ScittS

ScittS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
The task manager thing appears to be OK in my acct. the rest aren't working correctly.

As for the Norton thing ...It appears to be working in all but mine.

Although I haven't restarted since the last scan.
  • 0

#57
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Uh.. That is extremely odd.. This week I got lots of weird logs :)


Do you actually but that Norton or it's just a trial?


Lets solve your Task Manager problem first... I'm thinking of two freeware for you to try.. After that, please report to me about your Task Manager..

TaskManagerFix

Infiltration Recovery Tool
  • 0

#58
ScittS

ScittS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
OK.... I have tried both applications in all users..... in random order..... I even went and looked at the registry permissions....... it's not disabled!!!

:) :) ;) :) :)

:D :rockon: :) :wacko: :D :angry:

Scitts is near the end of his rope...... :)

Mine works perfectly.....I think it would stay on forever.

ALL the other profiles behave exactly the same...... ctrl,alt-del..... Flash on and off....green box remains in sys tray until you scroll towards it then wooosh its gone.... !@&$*%!&) doesn't make one good bit of sense!!!!

[bleep] I even ran another DSS just for S**** and Grins .... it looks perfect from where I stand!

How can I fix someone elses when I can't even figure my own out!

Sorry I'm not really mad or even upset....just really baffled/puzzled!
  • 0

#59
fenzodahl512

fenzodahl512

  • Malware Removal
  • 9,863 posts
Cool down mate.. Let me crash my head for this..

lets do this on one of your account that couldn't get Task Manager to run..


The steps that I am about to suggest involve modifying the registry. Modfying the registry can be dangerous so we will make a backup of the registry first.
Modification of the registry can be EXTREMELY dangerous if you do not know exactly what you are doing so follow the steps that are listed below EXACTLY. if you cannot perform some of these steps or if you have ANY questions please ask BEFORE proceeding.

Backing Up Your Registry
  • Go Here and download ERUNT
    (ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)
  • Install ERUNT by following the prompts
    (use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)
  • Start ERUNT
    (either by double clicking on the desktop icon or choosing to start the program at the end of the setup)
  • Choose a location for the backup
    (the default location is C:\WINDOWS\ERDNT which is acceptable).
  • Make sure that at least the first two check boxes are ticked
  • Press OK
  • Press YES to create the folder.

For detailed instruction on how to back-up registry via ERUNT, please visit HERE




NEXT


Please download GVR 4.1 by DisplinX and save it to your Desktop.
  • Please unzip it to your Desktop. A GVR4.1 folder will be created on your Desktop.
  • Please open GVR4.1 folder and then double-click GVR. It will run preliminary background scan.
  • Go to Option tab and choose Update Definition >> click on Update
  • Next, go to Tool and click Kill All Process. Wait until it says successful
  • Next, go to the main window, click on Scan button. Choose Scan System >> press Scan Now button
  • Please Delete everything that it found..
  • Please repeat above step with Scan Drive/Folder option. Please choose one drive at a time. Do for all drives
  • After finish all scanning process, go to Tool choose Repair Registry
  • After finished all steps, close the program and find its log at GVR4.1 folder (log.txt). Post the log here

Remember to let your firewall to allow the GVR4.1 process.



Then tell me about your Task Manager.. :)
  • 0

#60
ScittS

ScittS

    Member

  • Topic Starter
  • Member
  • PipPip
  • 65 posts
OK this isn't funny anymore...we certainly have a problem. I got clear to the kill processes step..... then wham... a quick flash of a blue screen with really big type and then a reboot to a serious error recovery message.

A dump in the lake for boat anchor is looking better all the time! :)

Tried several times..... always the same result. :)

:) :) ;) :)

Edited by ScittS, 02 August 2008 - 02:36 AM.

  • 0






Similar Topics

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP