Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Winfixer, byteverify, virtumonde... oh, my


  • This topic is locked This topic is locked

#1
SumMom

SumMom

    Member

  • Member
  • PipPip
  • 69 posts
Can't get rid of these pop-ups. Help? I've tried a lot of things over the last 5 days. Here is my most recent HJT:

Logfile of HijackThis v1.99.1
Scan saved at 3:33:53 PM, on 11/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\The Cleaner\tcm.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://epicenter.carlson.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://epicenter.carlson.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://epicenter.carlson.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.carlson.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Carlson Companies
O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkhef.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\fccde.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\poyqwq.exe reg_run
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Program Files\Advanced JPEG Compressor\ajcieex.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O14 - IERESET.INF: START_PAGE_URL=http://epicenter.carlson.com/
O15 - Trusted Zone: http://*.achieversclub.com
O15 - Trusted Zone: http://*.amadeusproweb.com
O15 - Trusted Zone: http://awards.cmg.carlson.com
O15 - Trusted Zone: http://compaq.cmg.carlson.com
O15 - Trusted Zone: http://epicenter.carlson.com
O15 - Trusted Zone: http://eps.carlson.com
O15 - Trusted Zone: http://home.carlson.com
O15 - Trusted Zone: http://home.cmg.carlson.com
O15 - Trusted Zone: http://itf.carlson.com
O15 - Trusted Zone: http://knowledgenet.carlson.com
O15 - Trusted Zone: http://oracle.cmg.carlson.com
O15 - Trusted Zone: http://rmdf.cmg.carlson.com
O15 - Trusted Zone: http://security.carlson.com
O15 - Trusted Zone: http://sr.cci.carlson.com
O15 - Trusted Zone: http://stretch.cmg.carlson.com
O15 - Trusted Zone: http://summit98.carlson.com
O15 - Trusted Zone: http://toservices.cci.carlson.com
O15 - Trusted Zone: http://www.carlson.com
O15 - Trusted Zone: http://www.awardsdemo.cmg.carlson.com
O15 - Trusted Zone: http://www.chw.carlson.com
O15 - Trusted Zone: http://www.cmg.carlson.com
O15 - Trusted Zone: http://www.demo.cmg.carlson.com
O15 - Trusted Zone: http://www.carlsonrewards.com
O15 - Trusted Zone: http://home.carlsonwagonlit.com
O15 - Trusted Zone: http://*.carlsonwagonlit.com
O15 - Trusted Zone: http://*.chw-knet.co
O15 - Trusted Zone: http://*.chw-knet.com
O15 - Trusted Zone: http://mail.clgagent.com
O15 - Trusted Zone: http://vq2ua217.corio.com
O15 - Trusted Zone: http://vq2ua218.corio.com
O15 - Trusted Zone: http://*.countryinns-suites.com
O15 - Trusted Zone: http://*.countryinns.com
O15 - Trusted Zone: http://www.datamartsuites.com
O15 - Trusted Zone: http://www.demographicsnow.com
O15 - Trusted Zone: http://ems00806.egain.net
O15 - Trusted Zone: http://*.focus97.com
O15 - Trusted Zone: http://*.goldcrowncard.com
O15 - Trusted Zone: http://*.goldcrowncard.staging
O15 - Trusted Zone: http://www.hprsvp.com
O15 - Trusted Zone: http://www.impact97.com
O15 - Trusted Zone: http://*.intelmdf.com
O15 - Trusted Zone: http://www.mlgold.com
O15 - Trusted Zone: http://*.nwa.com
O15 - Trusted Zone: http://www.oracle-east.com
O15 - Trusted Zone: http://*.oracle-presidents.com
O15 - Trusted Zone: http://es0126.oracle.com
O15 - Trusted Zone: http://*.parkhtls.com
O15 - Trusted Zone: http://*.parkinns.com
O15 - Trusted Zone: http://www.pfgcdc.com
O15 - Trusted Zone: http://*.radisson.com
O15 - Trusted Zone: http://*.regenthotels.com
O15 - Trusted Zone: http://*.solutions98.com
O15 - Trusted Zone: http://*.swsng1xb00021
O15 - Trusted Zone: http://www.tandemrewards.com
O15 - Trusted Zone: http://*.tgifridays.com
O15 - Trusted Zone: http://go.worldspan.com
O15 - Trusted Zone: http://go.wspan.com
O15 - Trusted Zone: http://goprivate.wspan.com
O15 - Trusted Zone: http://gopublic.wspan.com
O15 - Trusted Zone: http://*.achieversclub.com (HKLM)
O15 - Trusted Zone: http://*.amadeusproweb.com (HKLM)
O15 - Trusted Zone: http://awards.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://compaq.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://epicenter.carlson.com (HKLM)
O15 - Trusted Zone: http://eps.carlson.com (HKLM)
O15 - Trusted Zone: http://home.carlson.com (HKLM)
O15 - Trusted Zone: http://home.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://itf.carlson.com (HKLM)
O15 - Trusted Zone: http://knowledgenet.carlson.com (HKLM)
O15 - Trusted Zone: http://oracle.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://rmdf.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://security.carlson.com (HKLM)
O15 - Trusted Zone: http://sr.cci.carlson.com (HKLM)
O15 - Trusted Zone: http://stretch.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://summit98.carlson.com (HKLM)
O15 - Trusted Zone: http://toservices.cci.carlson.com (HKLM)
O15 - Trusted Zone: http://www.carlson.com (HKLM)
O15 - Trusted Zone: http://www.awardsdemo.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://www.chw.carlson.com (HKLM)
O15 - Trusted Zone: http://www.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://www.demo.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://www.carlsonrewards.com (HKLM)
O15 - Trusted Zone: http://home.carlsonwagonlit.com (HKLM)
O15 - Trusted Zone: http://*.carlsonwagonlit.com (HKLM)
O15 - Trusted Zone: http://*.chw-knet.co (HKLM)
O15 - Trusted Zone: http://*.chw-knet.com (HKLM)
O15 - Trusted Zone: http://mail.clgagent.com (HKLM)
O15 - Trusted Zone: http://vq2ua217.corio.com (HKLM)
O15 - Trusted Zone: http://vq2ua218.corio.com (HKLM)
O15 - Trusted Zone: http://*.countryinns-suites.com (HKLM)
O15 - Trusted Zone: http://*.countryinns.com (HKLM)
O15 - Trusted Zone: http://www.datamartsuites.com (HKLM)
O15 - Trusted Zone: http://www.demographicsnow.com (HKLM)
O15 - Trusted Zone: http://ems00806.egain.net (HKLM)
O15 - Trusted Zone: http://*.focus97.com (HKLM)
O15 - Trusted Zone: http://*.goldcrowncard.com (HKLM)
O15 - Trusted Zone: http://*.goldcrowncard.staging (HKLM)
O15 - Trusted Zone: http://www.hprsvp.com (HKLM)
O15 - Trusted Zone: http://www.impact97.com (HKLM)
O15 - Trusted Zone: http://*.intelmdf.com (HKLM)
O15 - Trusted Zone: http://www.mlgold.com (HKLM)
O15 - Trusted Zone: http://*.nwa.com (HKLM)
O15 - Trusted Zone: http://www.oracle-east.com (HKLM)
O15 - Trusted Zone: http://*.oracle-presidents.com (HKLM)
O15 - Trusted Zone: http://es0126.oracle.com (HKLM)
O15 - Trusted Zone: http://*.parkhtls.com (HKLM)
O15 - Trusted Zone: http://*.parkinns.com (HKLM)
O15 - Trusted Zone: http://www.pfgcdc.com (HKLM)
O15 - Trusted Zone: http://*.radisson.com (HKLM)
O15 - Trusted Zone: http://*.regenthotels.com (HKLM)
O15 - Trusted Zone: http://*.solutions98.com (HKLM)
O15 - Trusted Zone: http://*.swsng1xb00021 (HKLM)
O15 - Trusted Zone: http://www.tandemrewards.com (HKLM)
O15 - Trusted Zone: http://*.tgifridays.com (HKLM)
O15 - Trusted Zone: http://go.worldspan.com (HKLM)
O15 - Trusted Zone: http://go.wspan.com (HKLM)
O15 - Trusted Zone: http://goprivate.wspan.com (HKLM)
O15 - Trusted Zone: http://gopublic.wspan.com (HKLM)
O15 - Trusted IP range: http://139.72.190.*
O15 - Trusted IP range: http://207.68.137.*
O15 - Trusted IP range: http://207.68.143.*
O15 - Trusted IP range: http://207.68.156.*
O15 - Trusted IP range: http://206.145.126.*
O15 - Trusted IP range: http://139.72.190.* (HKLM)
O15 - Trusted IP range: http://207.68.137.* (HKLM)
O15 - Trusted IP range: http://207.68.143.* (HKLM)
O15 - Trusted IP range: http://207.68.156.* (HKLM)
O15 - Trusted IP range: http://206.145.126.* (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - http://support2.char...oad/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://ca.carlson.c...ol/xenrlinf.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab30149.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.co...ALStreaming.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_1_0_0_44.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab30149.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.infuzer.c...ayer/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivi...n/ravonline.cab
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://econference.c...aDownloader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O16 - DPF: {D9EA64B2-B966-E177-332C-78B69886526D} - http://download.newa...formerSetup.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://galileo.webe...ing/ieatgpc.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - https://music.msn.co...snmusax2602.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = amer.carlson.com
O17 - HKLM\Software\..\Telephony: DomainName = amer.carlson.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = amer.carlson.com
O20 - Winlogon Notify: fccde - C:\WINDOWS\System32\fccde.dll
O20 - Winlogon Notify: jkhef - C:\WINDOWS\SYSTEM32\jkhef.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: SMS Agent Host (CcmExec) - Unknown owner - C:\WINDOWS\System32\CCM\CcmExec.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

Thank you so much for the assist!
  • 0

Advertisements


#2
John_L

John_L

    Visiting Staff

  • Member
  • PipPipPipPip
  • 1,398 posts
Hello SumMom and welcome to Geeks To Go :tazz:

As its been few days since this was posted, are you still needing help with this?
  • 0

#3
SumMom

SumMom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 69 posts
Hi John L,

I am still in need. Yes. Don't know if you need or want this, but here's a more recent HJT:

Logfile of HijackThis v1.99.1
Scan saved at 2:15:52 PM, on 11/15/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\The Cleaner\tcm.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\iPass\iPassConnect\IPassConnectGUI.exe
C:\Program Files\Nortel Networks\Extranet.Exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://epicenter.carlson.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://epicenter.carlson.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://epicenter.carlson.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.carlson.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Carlson Companies
O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkhef.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSEvents Object - {B313D637-F405-4052-AC37-E2119AB3C8F8} - C:\WINDOWS\System32\fccde.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\System32\poyqwq.exe reg_run
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Open using &Advanced JPEG Compressor - C:\Program Files\Advanced JPEG Compressor\ajcieex.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O14 - IERESET.INF: START_PAGE_URL=http://epicenter.carlson.com/
O15 - Trusted Zone: http://*.achieversclub.com
O15 - Trusted Zone: http://*.amadeusproweb.com
O15 - Trusted Zone: http://awards.cmg.carlson.com
O15 - Trusted Zone: http://compaq.cmg.carlson.com
O15 - Trusted Zone: http://epicenter.carlson.com
O15 - Trusted Zone: http://eps.carlson.com
O15 - Trusted Zone: http://home.carlson.com
O15 - Trusted Zone: http://home.cmg.carlson.com
O15 - Trusted Zone: http://itf.carlson.com
O15 - Trusted Zone: http://knowledgenet.carlson.com
O15 - Trusted Zone: http://oracle.cmg.carlson.com
O15 - Trusted Zone: http://rmdf.cmg.carlson.com
O15 - Trusted Zone: http://security.carlson.com
O15 - Trusted Zone: http://sr.cci.carlson.com
O15 - Trusted Zone: http://stretch.cmg.carlson.com
O15 - Trusted Zone: http://summit98.carlson.com
O15 - Trusted Zone: http://toservices.cci.carlson.com
O15 - Trusted Zone: http://www.carlson.com
O15 - Trusted Zone: http://www.awardsdemo.cmg.carlson.com
O15 - Trusted Zone: http://www.chw.carlson.com
O15 - Trusted Zone: http://www.cmg.carlson.com
O15 - Trusted Zone: http://www.demo.cmg.carlson.com
O15 - Trusted Zone: http://www.carlsonrewards.com
O15 - Trusted Zone: http://home.carlsonwagonlit.com
O15 - Trusted Zone: http://*.carlsonwagonlit.com
O15 - Trusted Zone: http://*.chw-knet.co
O15 - Trusted Zone: http://*.chw-knet.com
O15 - Trusted Zone: http://mail.clgagent.com
O15 - Trusted Zone: http://vq2ua217.corio.com
O15 - Trusted Zone: http://vq2ua218.corio.com
O15 - Trusted Zone: http://*.countryinns-suites.com
O15 - Trusted Zone: http://*.countryinns.com
O15 - Trusted Zone: http://www.datamartsuites.com
O15 - Trusted Zone: http://www.demographicsnow.com
O15 - Trusted Zone: http://ems00806.egain.net
O15 - Trusted Zone: http://*.focus97.com
O15 - Trusted Zone: http://*.goldcrowncard.com
O15 - Trusted Zone: http://*.goldcrowncard.staging
O15 - Trusted Zone: http://www.hprsvp.com
O15 - Trusted Zone: http://www.impact97.com
O15 - Trusted Zone: http://*.intelmdf.com
O15 - Trusted Zone: http://www.mlgold.com
O15 - Trusted Zone: http://*.nwa.com
O15 - Trusted Zone: http://www.oracle-east.com
O15 - Trusted Zone: http://*.oracle-presidents.com
O15 - Trusted Zone: http://es0126.oracle.com
O15 - Trusted Zone: http://*.parkhtls.com
O15 - Trusted Zone: http://*.parkinns.com
O15 - Trusted Zone: http://www.pfgcdc.com
O15 - Trusted Zone: http://*.radisson.com
O15 - Trusted Zone: http://*.regenthotels.com
O15 - Trusted Zone: http://*.solutions98.com
O15 - Trusted Zone: http://*.swsng1xb00021
O15 - Trusted Zone: http://www.tandemrewards.com
O15 - Trusted Zone: http://*.tgifridays.com
O15 - Trusted Zone: http://go.worldspan.com
O15 - Trusted Zone: http://go.wspan.com
O15 - Trusted Zone: http://goprivate.wspan.com
O15 - Trusted Zone: http://gopublic.wspan.com
O15 - Trusted Zone: http://*.achieversclub.com (HKLM)
O15 - Trusted Zone: http://*.amadeusproweb.com (HKLM)
O15 - Trusted Zone: http://awards.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://compaq.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://epicenter.carlson.com (HKLM)
O15 - Trusted Zone: http://eps.carlson.com (HKLM)
O15 - Trusted Zone: http://home.carlson.com (HKLM)
O15 - Trusted Zone: http://home.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://itf.carlson.com (HKLM)
O15 - Trusted Zone: http://knowledgenet.carlson.com (HKLM)
O15 - Trusted Zone: http://oracle.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://rmdf.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://security.carlson.com (HKLM)
O15 - Trusted Zone: http://sr.cci.carlson.com (HKLM)
O15 - Trusted Zone: http://stretch.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://summit98.carlson.com (HKLM)
O15 - Trusted Zone: http://toservices.cci.carlson.com (HKLM)
O15 - Trusted Zone: http://www.carlson.com (HKLM)
O15 - Trusted Zone: http://www.awardsdemo.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://www.chw.carlson.com (HKLM)
O15 - Trusted Zone: http://www.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://www.demo.cmg.carlson.com (HKLM)
O15 - Trusted Zone: http://www.carlsonrewards.com (HKLM)
O15 - Trusted Zone: http://home.carlsonwagonlit.com (HKLM)
O15 - Trusted Zone: http://*.carlsonwagonlit.com (HKLM)
O15 - Trusted Zone: http://*.chw-knet.co (HKLM)
O15 - Trusted Zone: http://*.chw-knet.com (HKLM)
O15 - Trusted Zone: http://mail.clgagent.com (HKLM)
O15 - Trusted Zone: http://vq2ua217.corio.com (HKLM)
O15 - Trusted Zone: http://vq2ua218.corio.com (HKLM)
O15 - Trusted Zone: http://*.countryinns-suites.com (HKLM)
O15 - Trusted Zone: http://*.countryinns.com (HKLM)
O15 - Trusted Zone: http://www.datamartsuites.com (HKLM)
O15 - Trusted Zone: http://www.demographicsnow.com (HKLM)
O15 - Trusted Zone: http://ems00806.egain.net (HKLM)
O15 - Trusted Zone: http://*.focus97.com (HKLM)
O15 - Trusted Zone: http://*.goldcrowncard.com (HKLM)
O15 - Trusted Zone: http://*.goldcrowncard.staging (HKLM)
O15 - Trusted Zone: http://www.hprsvp.com (HKLM)
O15 - Trusted Zone: http://www.impact97.com (HKLM)
O15 - Trusted Zone: http://*.intelmdf.com (HKLM)
O15 - Trusted Zone: http://www.mlgold.com (HKLM)
O15 - Trusted Zone: http://*.nwa.com (HKLM)
O15 - Trusted Zone: http://www.oracle-east.com (HKLM)
O15 - Trusted Zone: http://*.oracle-presidents.com (HKLM)
O15 - Trusted Zone: http://es0126.oracle.com (HKLM)
O15 - Trusted Zone: http://*.parkhtls.com (HKLM)
O15 - Trusted Zone: http://*.parkinns.com (HKLM)
O15 - Trusted Zone: http://www.pfgcdc.com (HKLM)
O15 - Trusted Zone: http://*.radisson.com (HKLM)
O15 - Trusted Zone: http://*.regenthotels.com (HKLM)
O15 - Trusted Zone: http://*.solutions98.com (HKLM)
O15 - Trusted Zone: http://*.swsng1xb00021 (HKLM)
O15 - Trusted Zone: http://www.tandemrewards.com (HKLM)
O15 - Trusted Zone: http://*.tgifridays.com (HKLM)
O15 - Trusted Zone: http://go.worldspan.com (HKLM)
O15 - Trusted Zone: http://go.wspan.com (HKLM)
O15 - Trusted Zone: http://goprivate.wspan.com (HKLM)
O15 - Trusted Zone: http://gopublic.wspan.com (HKLM)
O15 - Trusted IP range: http://139.72.190.*
O15 - Trusted IP range: http://207.68.137.*
O15 - Trusted IP range: http://207.68.143.*
O15 - Trusted IP range: http://207.68.156.*
O15 - Trusted IP range: http://206.145.126.*
O15 - Trusted IP range: http://139.72.190.* (HKLM)
O15 - Trusted IP range: http://207.68.137.* (HKLM)
O15 - Trusted IP range: http://207.68.143.* (HKLM)
O15 - Trusted IP range: http://207.68.156.* (HKLM)
O15 - Trusted IP range: http://206.145.126.* (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} - http://support2.char...oad/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://ca.carlson.c...ol/xenrlinf.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....sa/LSSupCtl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab30149.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {341FF14B-00CB-49F5-A427-A164DF1D5E1F} (MALPlaybackCtrl Class) - http://musicstore.co...ALStreaming.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_1_0_0_44.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/s...nfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab30149.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.infuzer.c...ayer/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivi...n/ravonline.cab
O16 - DPF: {B24F0664-7DDA-40B6-B38C-A4FD68DE8685} (CentraDownloaderCtl Class) - http://econference.c...aDownloader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (ASquaredScanForm Element) - http://www.windowsec...scan/axscan.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....sa/SymAData.cab
O16 - DPF: {D9EA64B2-B966-E177-332C-78B69886526D} - http://download.newa...formerSetup.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://galileo.webe...ing/ieatgpc.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - https://music.msn.co...snmusax2602.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalci...illama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = amer.carlson.com
O17 - HKLM\Software\..\Telephony: DomainName = amer.carlson.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{0066BBA0-B9E9-464E-B9A1-6187229639FF}: NameServer = 172.25.128.128,172.26.128.128
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = amer.carlson.com
O17 - HKLM\System\CS1\Services\Tcpip\..\{0066BBA0-B9E9-464E-B9A1-6187229639FF}: NameServer = 172.25.128.128,172.26.128.128
O20 - Winlogon Notify: fccde - C:\WINDOWS\System32\fccde.dll
O20 - Winlogon Notify: jkhef - C:\WINDOWS\SYSTEM32\jkhef.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: SMS Agent Host (CcmExec) - Unknown owner - C:\WINDOWS\System32\CCM\CcmExec.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect\iPassConnectEngine.exe
O23 - Service: iPCAgent - iPass, Inc. - C:\Program Files\iPass\iPassConnect\iPCAgent.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

Thank you!
  • 0

#4
John_L

John_L

    Visiting Staff

  • Member
  • PipPipPipPip
  • 1,398 posts
Hello again :tazz:

I need to ask a question, did you set all those trusted zones yourself? If not then i think we should unload them first.

Let me know and we will get to beating on this log. :)
  • 0

#5
SumMom

SumMom

    Member

  • Topic Starter
  • Member
  • PipPip
  • 69 posts
Many of them are set by my company, but not all of them.

What's next?
  • 0

#6
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hello. From our terms of service, which you agreed to when you joined the site:

Geeks to Go Support Forum Rules, Policies and Disclaimers
• We offer free computer help and tech support for home and personal use. We are not here to support others that work for profit, or to support/replace your company's IT department.


We cannot offer support to you. This thread is being closed.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP