Options

Symantec antivirus can't delete gnida[1].swf, help

my symantec antivirus gave me a message saying it can't delete or remove this gnida[1].swf anybody know what to do?
«1

Comments

  • edited January 2008
    matt weber wrote:
    my symantec antivirus gave me a message saying it can't delete or remove this gnida[1].swf anybody know what to do?
    here is all the info. thanks


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:18:27 PM, on 1/30/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16574)
    Boot mode: Normal
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
    C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
    C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
    C:\Program Files\Dell Network Assistant\hnm_svc.exe
    C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2071213
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2071213
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKCU\..\Run: [DellAutomatedPCTuneUp] "C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Dell Network Assistant.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
    O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
    O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    --
    End of file - 8849 bytes
  • TroganTrogan London, UK
    edited February 2008
    Hi matt weber,

    Please do the following...

    1. I need to see another log from HijackThis.
    • Run Hijackthis.
    • Click on Open the Misc Tools section.
    • Next click on Open uninstall manager.
    • Press the Save list button.
    • Save the file to your desktop, with the default name of uninstall_list
    • Copy & Paste the entire contents of that file in your in your next post.
    2. Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be promted to install an ActiveX component from Kaspersky, Click Yes.

    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
        Extended (if available otherwise Standard)
      • Scan Options:
        Scan Archives
        Scan Mail Bases

        [*]Click OK
        [*]Now under select a target to scan:
          Select
        My Computer
        [*]This will program will start and scan your system.
        [*]The scan will take a while so be patient and let it run.
        [*]Once the scan is complete it will display if your system has been infected.
        • Now click on the Save as Text button:
        [*]Save the file to your desktop.
        3. Please post the Uninstall list, along with the Kaspersky report.
      • edited February 2008
        here is the hijackthis report
        but the kaspersky didnt not report any thing nothing to save as text
        thanks

        Adobe Flash Player ActiveX
        Adobe Reader 8.1.0
        Browser Address Error Redirector
        Dell Automated PC TuneUp
        Dell Driver Reset Tool
        Dell Network Assistant
        Dell Support Center
        Google Desktop
        Google Toolbar for Internet Explorer
        Google Toolbar for Internet Explorer
        High Definition Audio Driver Package - KB835221
        HijackThis 2.0.2
        Hotfix for Windows Media Format 11 SDK (KB929399)
        Hotfix for Windows Media Player 11 (KB939683)
        Hotfix for Windows XP (KB914440)
        Hotfix for Windows XP (KB915865)
        Hotfix for Windows XP (KB926239)
        HP Customer Participation Program 7.0
        HP Imaging Device Functions 7.0
        HP Photosmart Essential
        HP Photosmart, Officejet and Deskjet 7.0.A
        HP Software Update
        HP Solution Center 7.0
        Intel(R) Graphics Media Accelerator Driver
        Intel(R) PRO Network Connections 12.1.8.0
        J2SE Runtime Environment 5.0 Update 6
        Java(TM) 6 Update 3
        Kaspersky Anti-Virus 6.0 SOS
        Kaspersky Anti-Virus 6.0 SOS
        LiveUpdate 1.7 (Symantec Corporation)
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1
        Microsoft .NET Framework 1.1 Hotfix (KB928366)
        Microsoft Compression Client Pack 1.0 for Windows XP
        Microsoft Internationalized Domain Names Mitigation APIs
        Microsoft National Language Support Downlevel APIs
        Microsoft User-Mode Driver Framework Feature Pack 1.0
        Microsoft Works
        MSXML 4.0 SP2 (KB936181)
        MSXML 6.0 Parser (KB933579)
        OCR Software by I.R.I.S 7.0
        PowerDVD
        QualxServ Service Agreement
        Realtek High Definition Audio Driver
        Roxio Creator Audio
        Roxio Creator BDAV Plugin
        Roxio Creator Copy
        Roxio Creator Data
        Roxio Creator DE
        Roxio Creator Tools
        Roxio Drag-to-Disc
        Roxio Express Labeler
        Roxio MyDVD DE
        Roxio Update Manager
        SearchAssist
        Security Update for Step By Step Interactive Training (KB923723)
        Security Update for Windows Internet Explorer 7 (KB938127)
        Security Update for Windows Internet Explorer 7 (KB942615)
        Security Update for Windows Media Player 11 (KB936782)
        Security Update for Windows XP (KB893756)
        Security Update for Windows XP (KB896428)
        Security Update for Windows XP (KB899587)
        Security Update for Windows XP (KB900725)
        Security Update for Windows XP (KB901017)
        Security Update for Windows XP (KB902400)
        Security Update for Windows XP (KB905414)
        Security Update for Windows XP (KB905749)
        Security Update for Windows XP (KB911927)
        Security Update for Windows XP (KB913580)
        Security Update for Windows XP (KB914389)
        Security Update for Windows XP (KB917953)
        Security Update for Windows XP (KB922819)
        Security Update for Windows XP (KB923980)
        Security Update for Windows XP (KB927779)
        Security Update for Windows XP (KB931784)
        Security Update for Windows XP (KB933729)
        Security Update for Windows XP (KB937143)
        Security Update for Windows XP (KB941202)
        Security Update for Windows XP (KB941568)
        Security Update for Windows XP (KB941569)
        Security Update for Windows XP (KB941644)
        Security Update for Windows XP (KB942615)
        Security Update for Windows XP (KB943460)
        Security Update for Windows XP (KB943485)
        Security Update for Windows XP (KB944653)
        Sonic Activation Module
        Symantec AntiVirus Client
        Update for Windows XP (KB894391)
        Update for Windows XP (KB898461)
        Update for Windows XP (KB900485)
        Update for Windows XP (KB904942)
        Update for Windows XP (KB910437)
        Update for Windows XP (KB911280)
        Update for Windows XP (KB916595)
        Update for Windows XP (KB920872)
        Update for Windows XP (KB922582)
        Update for Windows XP (KB927891)
        Update for Windows XP (KB930916)
        Update for Windows XP (KB936357)
        Update for Windows XP (KB942763)
        Update for Windows XP (KB942840)
        Windows Internet Explorer 7
        Windows Media Format 11 runtime
        Windows Media Format 11 runtime
        Windows Media Player 11
        Windows Media Player 11
        Windows XP Hotfix - KB885836
        Windows XP Hotfix - KB886185
        Windows XP Hotfix - KB888302
        Windows XP Hotfix - KB890859
        Yahoo! Browser Services
        Yahoo! Install Manager
        Yahoo! Internet Mail
        Yahoo! Messenger
        Yahoo! Toolbar
      • TroganTrogan London, UK
        edited February 2008
        Hi Matt,

        Please do the following...

        1. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version...

        Updating Java:
        • Download the latest version of Java Runtime Environment (JRE) 6 update4.
        • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications."
        • Click the "Download" button to the right.
        • Check the box that says: "Accept License Agreement."
        • The page will refresh.
        • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
        • Close any programs you may have running - especially your web browser.
        • Go to Start > Control Panel double-click on Add/Remove programs and remove the following...
          • J2SE Runtime Environment 5.0 Update 6
          • Java(TM) 6 Update 3
          • SearchAssist
        • Reboot your computer once all Java components are removed.
        • Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.
        2. Please download Deckard's System Scanner (DSS) to your desktop.
        • Close all applications and windows.
        • Double-click on dss.exe to run it, and follow the prompts.
        • When the scan is complete, a text file will open - Main.txt
        • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of Main.txt in your thread in the HijackThis Log Help Forum.
        • A folder, C:\Deckard\System Scanner, will also open. In it will be another text file, Extra.txt.
        • Please also copy the contents of Extra.txt to your post as well.
        • Note: some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.
        • What DSS will do:
        • create a new System Restore point in Windows XP and Vista.
        • clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
        • check some important areas of your system and produce a report for your analyst to review. DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.
      • edited February 2008
        hi trogan
        i hope this is what you are looking for
        matt




        Deckard's System Scanner v20071014.68
        Run by Matt Weber on 2008-02-02 11:22:14
        Computer is in Normal Mode.
        -- System Restore
        Successfully created a Deckard's System Scanner Restore Point.

        -- Last 5 Restore Point(s) --
        57: 2008-02-02 17:22:16 UTC - RP57 - Deckard's System Scanner Restore Point
        56: 2008-02-02 17:20:14 UTC - RP56 - Installed Java(TM) 6 Update 4
        55: 2008-02-02 17:19:41 UTC - RP55 - Removed Java(TM) 6 Update 4
        54: 2008-02-02 17:04:42 UTC - RP54 - Removed Java(TM) 6 Update 3
        53: 2008-02-02 17:04:07 UTC - RP53 - Removed J2SE Runtime Environment 5.0 Update 6

        -- First Restore Point --
        1: 2007-12-18 00:48:22 UTC - RP1 - System Checkpoint

        Backed up registry hives.
        Performed disk cleanup.

        -- HijackThis (run as Matt Weber.exe)
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:22:48 AM, on 2/2/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16574)
        Boot mode: Normal
        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\system32\igfxpers.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\WINDOWS\system32\igfxsrvc.exe
        C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
        C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
        C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
        C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
        C:\Program Files\Dell Support Center\bin\sprtcmd.exe
        C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
        C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
        C:\Program Files\Dell Network Assistant\hnm_svc.exe
        C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
        C:\Program Files\Dell Support Center\bin\sprtsvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
        C:\WINDOWS\system32\msiexec.exe
        C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\SANM4LO2\dss[1].exe
        C:\PROGRA~1\TRENDM~1\HIJACK~1\Matt Weber.exe
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2071213
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2071213
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
        O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
        O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
        O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
        O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe"
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
        O4 - HKCU\..\Run: [DellAutomatedPCTuneUp] "C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" /startup
        O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
        O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - Global Startup: Dell Network Assistant.lnk = ?
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
        O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
        O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
        O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
        O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
        O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
        --
        End of file - 9248 bytes
        -- File Associations
        All associations okay.

        -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
        R2 Packet (Auto Internet Protocol) - c:\windows\system32\drivers\packet.sys <Not Verified; SingleClick Systems; Auto IP Protocol Driver>
        R3 PTproct - c:\program files\dellautomatedpctuneup\gtaction\triggers\ptproct.sys <Not Verified; Gteko Ltd.; processt>

        -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled
        R2 sprtsvc_dellsupportcenter (SupportSoft Sprocket Service (dellsupportcenter)) - c:\program files\dell support center\bin\sprtsvc.exe /service /p dellsupportcenter
        S3 stllssvr - "c:\program files\common files\surething shared\stllssvr.exe" <Not Verified; MicroVision Development, Inc.; SureThing CD Labeler>

        -- Device Manager: Disabled
        No disabled devices found.

        -- Scheduled Tasks
        2008-01-27 06:13:56 304 --a
        C:\WINDOWS\Tasks\WebReg psc C3100 series.job

        -- Files created between 2008-01-02 and 2008-02-02
        2008-02-02 11:20:16 0 d
        C:\Program Files\Java
        2008-02-02 11:20:15 0 d
        C:\Program Files\Common Files\Java
        2008-02-01 19:26:33 155680 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
        2008-02-01 19:26:33 1899552 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
        2008-02-01 19:24:21 0 d
        C:\Program Files\Kaspersky Lab
        2008-02-01 19:24:21 0 d
        C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
        2008-02-01 19:23:04 0 d
        C:\KAV
        2008-01-30 20:17:49 0 d
        C:\Documents and Settings\LocalService\Application Data\Help
        2008-01-30 19:18:24 0 d
        C:\Program Files\Trend Micro
        2008-01-27 20:57:19 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Help

        -- Find3M Report
        2008-02-02 11:20:15 0 d
        C:\Program Files\Common Files
        2008-01-27 10:50:02 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Image Zone Express
        2007-12-31 15:40:35 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Roxio
        2007-12-31 11:24:23 0 d
        C:\Documents and Settings\Matt Weber\Application Data\HP
        2007-12-31 11:20:45 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Printer Info Cache
        2007-12-31 11:20:29 0 d
        C:\Program Files\Common Files\HP
        2007-12-29 22:20:55 117132 --a
        C:\WINDOWS\hpoins11.dat
        2007-12-29 22:13:09 0 d
        C:\Program Files\HP
        2007-12-29 22:11:15 0 d
        C:\Program Files\Hewlett-Packard
        2007-12-29 22:10:30 0 d
        C:\Program Files\Common Files\Hewlett-Packard
        2007-12-25 00:01:54 0 d
        C:\Program Files\Windows Media Connect 2
        2007-12-22 18:12:08 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Sun
        2007-12-18 17:00:53 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Adobe
        2007-12-17 21:29:59 0 d
        C:\Program Files\MSXML 4.0
        2007-12-17 21:16:38 0 d--h
        C:\Documents and Settings\Matt Weber\Application Data\GTek
        2007-12-17 20:05:21 0 d
        C:\Documents and Settings\Matt Weber\Application Data\CyberLink
        2007-12-17 20:03:26 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Template
        2007-12-17 19:59:34 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Yahoo!
        2007-12-17 19:53:56 0 d
        C:\Program Files\Yahoo!
        2007-12-17 19:47:02 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Google
        2007-12-17 19:38:38 0 d
        C:\Documents and Settings\Matt Weber\Application Data\Macromedia
        2007-12-17 19:14:43 0 d
        C:\Program Files\Symantec
        2007-12-17 19:14:41 0 d
        C:\Program Files\Common Files\Symantec Shared
        2007-12-17 19:14:25 0 d
        C:\Program Files\Symantec_Client_Security
        2007-12-17 18:51:34 0 --a
        C:\Documents and Settings\Matt Weber\Application Data\wklnhst.dat
        2007-12-13 03:04:11 0 d
        C:\Program Files\Microsoft Works
        2007-12-13 03:03:57 0 d
        C:\Program Files\DellAutomatedPCTuneUp
        2007-12-13 03:03:45 0 d
        C:\Program Files\Dell Support Center
        2007-12-13 03:03:43 0 d
        C:\Program Files\Common Files\supportsoft
        2007-12-13 03:02:30 0 d
        C:\Program Files\Dell Network Assistant
        2007-12-13 03:02:12 0 d
        C:\Program Files\Common Files\Adobe
        2007-12-13 03:01:22 0 d
        C:\Program Files\Google
        2007-12-13 03:01:18 0 d
        C:\Program Files\Dell
        2007-12-13 03:01:05 0 d--h
        C:\Program Files\InstallShield Installation Information
        2007-12-13 03:01:05 0 d
        C:\Program Files\CyberLink
        2007-12-13 03:01:03 0 d
        C:\Program Files\Common Files\InstallShield
        2007-12-13 03:00:55 0 d
        C:\Program Files\Roxio
        2007-12-13 03:00:05 0 d
        C:\Program Files\Common Files\Sonic Shared
        2007-12-13 02:58:32 0 d
        C:\Program Files\Common Files\SureThing Shared
        2007-12-13 02:58:19 0 d
        C:\Program Files\Common Files\Roxio Shared
        2007-12-13 02:56:34 0 d
        C:\Program Files\Intel
        2007-12-13 02:56:18 0 d
        C:\Documents and Settings\Matt Weber\Application Data\InstallShield
        2007-12-13 02:55:14 0 d
        C:\Program Files\Messenger
        2007-12-13 02:53:01 0 d
        C:\Program Files\MSXML 6.0

        -- Registry Dump
        *Note* empty entries & legit default entries are not shown

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06/13/2007 07:21 PM]
        "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06/13/2007 07:21 PM]
        "Persistence"="C:\WINDOWS\system32\igfxpers.exe" [06/13/2007 07:21 PM]
        "RTHDCPL"="RTHDCPL.EXE" [06/13/2007 08:41 PM C:\WINDOWS\RTHDCPL.EXE]
        "Alcmtr"="ALCMTR.EXE" [06/13/2007 08:41 PM C:\WINDOWS\ALCMTR.EXE]
        "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [10/03/2006 11:35 AM]
        "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [10/03/2006 11:37 AM]
        "@=" []
        "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [11/05/2006 11:22 AM]
        "RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [08/17/2006 09:00 AM]
        "PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [10/20/2006 05:23 PM]
        "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [12/13/2007 03:01 AM]
        "ECenter"="C:\Dell\E-Center\EULALauncher.exe" [05/24/2007 07:03 AM]
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM]
        "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [10/09/2007 06:57 PM]
        "vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [01/14/2003 06:02 PM]
        "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [02/19/2006 02:41 AM]
        "AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe" [11/19/2007 02:40 PM]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [12/14/2007 03:42 AM]
        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "DellAutomatedPCTuneUp"="C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" [10/11/2007 09:49 AM]
        "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [10/09/2007 06:56 PM]
        "Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/30/2007 05:43 PM]
        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 05:00 AM]
        "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/13/2004 10:24 AM]
        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
        Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [12/13/2007 3:02:35 AM]
        HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2/19/2006 4:21:22 AM]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
        "appinit_dlls"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL


        -- End of Deckard's System Scanner: finished at 2008-02-02 11:23:23
      • TroganTrogan London, UK
        edited February 2008
        Can you go into the C:\Deckard\System Scanner folder and post the contents of Extra.txt to your post as well.
      • edited February 2008
        sorry about that here you go
        thanks

        Deckard's System Scanner v20071014.68
        Extra logfile - please post this as an attachment with your post.
        -- System Information
        Microsoft Windows XP Home Edition (build 2600) SP 2.0
        Architecture: X86; Language: English
        CPU 0: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz
        CPU 1: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz
        Percentage of Memory in Use: 32%
        Physical Memory (total/avail): 2037.1 MiB / 1369.44 MiB
        Pagefile Memory (total/avail): 3929.37 MiB / 3459.06 MiB
        Virtual Memory (total/avail): 2047.88 MiB / 1926.79 MiB
        C: is Fixed (NTFS) - 74.45 GiB total, 64.09 GiB free.
        D: is CDROM (Unformatted)
        E: is CDROM (Unformatted)
        F: is Removable (No Media)
        Z: is Fixed (NTFS) - 465.76 GiB total, 463.71 GiB free.
        [URL="file://\\.\PHYSICALDRIVE1"]\\.\PHYSICALDRIVE1[/URL] - WDC WD5000AAKS-00YGA0 - 465.76 GiB - 1 partition
        \PARTITION0 - Installable File System - 465.76 GiB - Z:
        [URL="file://\\.\PHYSICALDRIVE0"]\\.\PHYSICALDRIVE0[/URL] - WDC WD800JD-75MSA3 - 74.5 GiB - 2 partitions
        \PARTITION0 - Unknown - 47.03 MiB
        \PARTITION1 (bootable) - Installable File System - 74.45 GiB - C:
        [URL="file://\\.\PHYSICALDRIVE2"]\\.\PHYSICALDRIVE2[/URL] - HP Photosmart C3180 USB Device

        -- Security Center
        AUOptions is scheduled to auto-install.
        Windows Internal Firewall is enabled.
        FirstRunDisabled is set.
        AntivirusOverride is set.

        [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
        "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
        "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
        "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
        "C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"="C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe:*:Enabled:Dell Network Assistant"

        -- Environment Variables
        ALLUSERSPROFILE=C:\Documents and Settings\All Users
        APPDATA=C:\Documents and Settings\Matt Weber\Application Data
        CLIENTNAME=Console
        CommonProgramFiles=C:\Program Files\Common Files
        COMPUTERNAME=BLAZER
        ComSpec=C:\WINDOWS\system32\cmd.exe
        FP_NO_HOST_CHECK=NO
        HOMEDRIVE=C:
        HOMEPATH=\Documents and Settings\Matt Weber
        LOGONSERVER=\\BLAZER
        NUMBER_OF_PROCESSORS=2
        OS=Windows_NT
        Path=C:\Program Files\Internet Explorer;;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Intel\DMIX;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\
        PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
        PROCESSOR_ARCHITECTURE=x86
        PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 13, GenuineIntel
        PROCESSOR_LEVEL=6
        PROCESSOR_REVISION=0f0d
        ProgramFiles=C:\Program Files
        PROMPT=$P$G
        RoxioCentral=C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
        SESSIONNAME=Console
        SystemDrive=C:
        SystemRoot=C:\WINDOWS
        TEMP=C:\DOCUME~1\MATTWE~1\LOCALS~1\Temp
        TMP=C:\DOCUME~1\MATTWE~1\LOCALS~1\Temp
        USERDOMAIN=BLAZER
        USERNAME=Matt Weber
        USERPROFILE=C:\Documents and Settings\Matt Weber
        windir=C:\WINDOWS

        -- User Profiles
        Matt Weber (admin)

        -- Add/Remove Programs
        --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu
        --> MsiExec.exe /I{403EF592-953B-4794-BCEF-ECAB835C2095}
        --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
        Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
        Adobe Reader 8.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}
        Browser Address Error Redirector --> MsiExec.exe /I{62230596-37E5-4618-A329-0D21F529A86F}
        Dell Automated PC TuneUp --> MsiExec.exe /X{FE34691C-4298-4667-9758-D7F534DD0B94}
        Dell Driver Reset Tool --> MsiExec.exe /I{5905F42D-3F5F-4916-ADA6-94A3646AEE76}
        Dell Network Assistant --> MsiExec.exe /I{0240BDFB-2995-4A3F-8C96-18D41282B716}
        Dell Support Center --> MsiExec.exe /X{E3BFEE55-39E2-4BE0-B966-89FE583822C1}
        Google Desktop --> C:\Program Files\Google\Google Desktop Search\GoogleDesktopSetup.exe -uninstall
        Google Toolbar for Internet Explorer --> MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
        Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
        High Definition Audio Driver Package - KB835221 --> C:\WINDOWS\$NtUninstallKB835221WXP$\spuninst\spuninst.exe
        HijackThis 2.0.2 --> "C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\1XNMUNSC\HijackThis.exe" /uninstall
        Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
        HP Customer Participation Program 7.0 --> C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
        HP Imaging Device Functions 7.0 --> C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
        HP Photosmart Essential --> MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
        HP Photosmart, Officejet and Deskjet 7.0.A --> C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\setup\hpzscr01.exe -datfile hposcr11.dat
        HP Software Update --> MsiExec.exe /X{BB85ED9C-AFC9-43BD-B8DC-258C3C7DF72E}
        HP Solution Center 7.0 --> C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
        Intel(R) Graphics Media Accelerator Driver --> C:\WINDOWS\system32\igxpun.exe -uninstall
        Intel(R) PRO Network Connections 12.1.8.0 --> MsiExec.exe /i{777CA40C-0206-4EF6-A0FC-618BF06BF8D0} ARPREMOVE=1
        Java(TM) 6 Update 4 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
        Kaspersky Anti-Virus 6.0 SOS --> MsiExec.exe /I{3AD203DE-D2DE-47F3-B319-76C411E465AC}
        Kaspersky Anti-Virus 6.0 SOS --> MsiExec.exe /I{3AD203DE-D2DE-47F3-B319-76C411E465AC}
        LiveUpdate 1.7 (Symantec Corporation) --> C:\Program Files\\Symantec\LiveUpdate\LSETUP.EXE /U
        Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
        Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
        Microsoft Works --> MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
        MSXML 6.0 Parser (KB933579) --> MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
        OCR Software by I.R.I.S 7.0 --> C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
        PowerDVD --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{281ECE39-F043-492B-8337-F2E546B5604A}\Setup.exe" -l0x9 -cluninstall
        QualxServ Service Agreement --> MsiExec.exe /X{0F756CD9-4A1E-409B-B101-601DDC4C03AA}
        Realtek High Definition Audio Driver --> RtlUpd.exe -r -m
        Roxio Creator Audio --> MsiExec.exe /I{83FFCFC7-88C6-41c6-8752-958A45325C82}
        Roxio Creator BDAV Plugin --> MsiExec.exe /I{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}
        Roxio Creator Copy --> MsiExec.exe /I{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
        Roxio Creator Data --> MsiExec.exe /I{0D397393-9B50-4c52-84D5-77E344289F87}
        Roxio Creator DE --> MsiExec.exe /I{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
        Roxio Creator Tools --> MsiExec.exe /I{0394CDC8-FABD-4ed8-B104-03393876DFDF}
        Roxio Drag-to-Disc --> MsiExec.exe /I{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}
        Roxio Express Labeler --> MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
        Roxio MyDVD DE --> MsiExec.exe /I{D639085F-4B6E-4105-9F37-A0DBB023E2FB}
        Roxio Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}
        Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
        Sonic Activation Module --> MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
        Symantec AntiVirus Client --> MsiExec.exe /X{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}
        Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
        Yahoo! Browser Services --> C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
        Yahoo! Install Manager --> C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
        Yahoo! Internet Mail --> C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
        Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
        Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe

        -- Application Event Log
        Event Record #/Type868 / Warning
        Event Submitted/Written: 02/02/2008 11:07:28 AM
        Event ID/Source: 32068 / Microsoft Fax
        Event Description:
        The outgoing routing rule is not valid because it cannot find a valid device. The outgoing faxes that use this rule will not be routed. Verify that the targeted device or devices (if routed to a group of devices) is connected and installed correctly, and turned on. If routed to a group, verify that the group is configured correctly.
        Country/region code: '*'
        Area code: '*'
        Event Record #/Type867 / Warning
        Event Submitted/Written: 02/02/2008 11:07:28 AM
        Event ID/Source: 32026 / Microsoft Fax
        Event Description:
        Fax Service failed to initialize any assigned fax devices (virtual or TAPI).
        No faxes can be sent or received until a fax device is installed.
        Event Record #/Type863 / Warning
        Event Submitted/Written: 02/02/2008 11:06:20 AM
        Event ID/Source: 1524 / Userenv
        Event Description:
        Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.
        Event Record #/Type862 / Error
        Event Submitted/Written: 02/02/2008 11:06:11 AM
        Event ID/Source: 1000 / Application Error
        Event Description:
        Faulting application , version 0.0.0.0, faulting module unknown, version 0.0.0.0, fault address 0x00000000.
        Processing media-specific event for [!ws!]
        Event Record #/Type858 / Error
        Event Submitted/Written: 02/02/2008 07:53:02 AM
        Event ID/Source: 1002 / Application Hang
        Event Description:
        Hanging application DrgToDsc.exe, version 9.0.0.53, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

        -- Security Event Log
        No Errors/Warnings found.

        -- System Event Log
        Event Record #/Type106771 / Warning
        Event Submitted/Written: 02/02/2008 11:06:22 AM
        Event ID/Source: 31240 / Windows File Protection
        Event Description:
        The protected system file c:\windows\system32\uxtheme.dll could not be verified as valid because Windows
        File Protection is terminating.
        Use the SFC utility to verify the integrity of the file at a later time.
        Event Record #/Type106769 / Error
        Event Submitted/Written: 02/02/2008 11:05:10 AM
        Event ID/Source: 7023 / Service Control Manager
        Event Description:
        The Application Management service terminated with the following error:
        %%126
        Event Record #/Type106766 / Error
        Event Submitted/Written: 02/02/2008 11:05:10 AM
        Event ID/Source: 7023 / Service Control Manager
        Event Description:
        The Application Management service terminated with the following error:
        %%126
        Event Record #/Type106763 / Error
        Event Submitted/Written: 02/02/2008 11:05:10 AM
        Event ID/Source: 7023 / Service Control Manager
        Event Description:
        The Application Management service terminated with the following error:
        %%126
        Event Record #/Type106760 / Error
        Event Submitted/Written: 02/02/2008 11:05:10 AM
        Event ID/Source: 7023 / Service Control Manager
        Event Description:
        The Application Management service terminated with the following error:
        %%126

        -- End of Deckard's System Scanner: finished at 2008-02-02 11:23:23
      • TroganTrogan London, UK
        edited February 2008
        Hi Matt,

        I see you have installed Kaspersky. Please uninstall it via Add/Remove programs in Control Panel. Having multiple Anti-Virus programs is not a good idea and can cause all sorts of problems. Please do this now.

        The DSS logs are clean. Is Symantec still finding gnida[1].swf? If so, can you tell me the file location?
      • edited February 2008
        trogan
        here it is

        Date,Filename,Virus Name,Virus Type,Action Taken,Computer,User,Original Location,Status,Current Location,Primary Action,Secondary Action,Scan Type
        1/25/2008 5:33:04 AM,gnida[1].swf,Downloader,File,Left alone,BLAZER,Matt Weber,C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\KJ6IKZK2\,Infected,C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\KJ6IKZK2\,Clean virus from file,Quarantine infected file,Realtime scan
      • TroganTrogan London, UK
        edited February 2008
        OK, lets try this...

        1. Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.
        This program is for XP and Windows 2000 only!
        • Double-click ATF Cleaner.exe to open it.
        • Under Main select the following:
          • Windows Temp
          • Current User Temp
          • All Users Temp
          • Temporary Internet Files
          • Java Cache
        *The other boxes are optional*
        Then click the Empty Selected button.

        Click Exit on the Main menu to close the program.

        2. Run HijackThis and click on Open the Misc Tools section.
        Click on Delete a file on reboot...
        Copy and paste the following into the "File name:" text box and then click Open:

        C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\KJ6IKZK2\gnida[1].swf

        When you are asked "Do you want to restart your computer now?", click OK.

        Your PC MUST reboot to delete the file!

        3. Let me know if gnida[1].swf is still being detected.
      • edited February 2008
        hi trogan
        its still there
        gnida[1].swf
        do you have anymore advise?

        thanks
      • TroganTrogan London, UK
        edited February 2008
        Had a feeling that wouldn't work.

        Please download ComboFix to your Desktop.
        • Double click on Combofix.exe & follow the prompts.
        • When the scan has finished, it shall produce a log for you. Post that log in your next reply
        Note:
        Do not mouseclick combofix's window whilst it's running. That may cause it to stall
      • edited February 2008
        here it is trogan

        ComboFix 08-02.03.1 - Matt Weber 2008-02-02 14:50:32.1 - NTFSx86
        Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1450 [GMT -6:00]
        Running from: C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\38L1CKPZ\ComboFix[1].exe
        * Created a new restore point
        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .
        ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
        .
        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
        C:\WINDOWS\system32\x64
        BITS: Possible infected sites
        hxxp://www.dellsupportcenter.coõj+|Cü¤Ì›v÷+È@™;JŸ:®½‰NêGD_©½ºD˜QÄ{¶ÀzÎtçÒ»ÌHžG†.XóÆÊID¸ÑJ„ª‹ê¤]Å>SprtSyncJob(dellsupportcenter)
        hxxp://www.dellsupportcenter.co
        .
        ((((((((((((((((((((((((( Files Created from 2008-01-02 to 2008-02-02 )))))))))))))))))))))))))))))))
        .
        2008-02-02 11:21 . 2008-02-02 11:21 <DIR> d
        C:\Deckard
        2008-02-02 11:20 . 2008-02-02 11:20 <DIR> d
        C:\Program Files\Java
        2008-02-02 11:20 . 2008-02-02 11:20 <DIR> d
        C:\Program Files\Common Files\Java
        2008-02-02 11:20 . 2007-12-14 01:59 69,632 --a
        C:\WINDOWS\system32\javacpl.cpl
        2008-02-01 19:26 . 2008-02-02 12:26 2,016,032 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
        2008-02-01 19:26 . 2008-02-02 12:26 179,488 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
        2008-02-01 19:26 . 2008-02-02 12:26 31,208 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
        2008-02-01 19:26 . 2008-02-02 12:26 19,988 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
        2008-02-01 19:23 . 2008-02-01 19:23 <DIR> d
        C:\KAV
        2008-01-30 19:18 . 2008-01-30 19:18 <DIR> d
        C:\Program Files\Trend Micro
        .
        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-02-02 20:32
        d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
        2008-01-27 16:50
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Image Zone Express
        2007-12-31 21:40
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Roxio
        2007-12-31 17:24
        d
        w C:\Documents and Settings\Matt Weber\Application Data\HP
        2007-12-31 17:20
        d
        w C:\Program Files\Common Files\HP
        2007-12-31 17:20
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Printer Info Cache
        2007-12-30 04:13
        d
        w C:\Program Files\HP
        2007-12-30 04:13
        d
        w C:\Documents and Settings\All Users\Application Data\HP
        2007-12-30 04:11
        d
        w C:\Program Files\Hewlett-Packard
        2007-12-30 04:10
        d
        w C:\Program Files\Common Files\Hewlett-Packard
        2007-12-25 06:01
        d
        w C:\Program Files\Windows Media Connect 2
        2007-12-18 03:29
        d
        w C:\Program Files\MSXML 4.0
        2007-12-18 03:16
        d--h--w C:\Documents and Settings\Matt Weber\Application Data\GTek
        2007-12-18 02:05
        d
        w C:\Documents and Settings\Matt Weber\Application Data\CyberLink
        2007-12-18 02:05
        d
        w C:\Documents and Settings\All Users\Application Data\CyberLink
        2007-12-18 02:03
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Template
        2007-12-18 01:59
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Yahoo!
        2007-12-18 01:58
        d
        w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
        2007-12-18 01:54
        d
        w C:\Documents and Settings\All Users\Application Data\Yahoo!
        2007-12-18 01:53
        d
        w C:\Program Files\Yahoo!
        2007-12-18 01:33
        d
        w C:\Documents and Settings\All Users\Application Data\Dell
        2007-12-18 01:14
        d
        w C:\Program Files\Symantec_Client_Security
        2007-12-18 01:14
        d
        w C:\Program Files\Symantec
        2007-12-18 01:14
        d
        w C:\Program Files\Common Files\Symantec Shared
        2007-12-18 01:14
        d
        w C:\Documents and Settings\All Users\Application Data\Symantec
        2007-12-18 01:13 83,672 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
        2007-12-18 01:13 73,224 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
        2007-12-18 00:51 0 ----a-w C:\Documents and Settings\Matt Weber\Application Data\wklnhst.dat
        2007-12-13 09:05
        d
        w C:\Documents and Settings\LocalService\Application Data\Roxio
        2007-12-13 09:04
        d
        w C:\Program Files\Microsoft Works
        2007-12-13 09:03
        d
        w C:\Program Files\DellAutomatedPCTuneUp
        2007-12-13 09:03
        d
        w C:\Program Files\Dell Support Center
        2007-12-13 09:03
        d
        w C:\Program Files\Common Files\supportsoft
        2007-12-13 09:03
        d
        w C:\Documents and Settings\All Users\Application Data\SupportSoft
        2007-12-13 09:03
        d
        w C:\Documents and Settings\All Users\Application Data\Gtek
        2007-12-13 09:02
        d
        w C:\Program Files\Dell Network Assistant
        2007-12-13 09:02
        d
        w C:\Program Files\Common Files\Adobe
        2007-12-13 09:02
        d
        w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
        2007-12-13 09:01
        d--h--w C:\Program Files\InstallShield Installation Information
        2007-12-13 09:01
        d
        w C:\Program Files\Google
        2007-12-13 09:01
        d
        w C:\Program Files\Dell
        2007-12-13 09:01
        d
        w C:\Program Files\CyberLink
        2007-12-13 09:01
        d
        w C:\Program Files\Common Files\InstallShield
        2007-12-13 09:00
        d
        w C:\Program Files\Roxio
        2007-12-13 09:00
        d
        w C:\Program Files\Common Files\Sonic Shared
        2007-12-13 09:00
        d
        w C:\Documents and Settings\All Users\Application Data\Sonic
        2007-12-13 09:00
        d
        w C:\Documents and Settings\All Users\Application Data\Roxio
        2007-12-13 08:58
        d
        w C:\Program Files\Common Files\SureThing Shared
        2007-12-13 08:58
        d
        w C:\Program Files\Common Files\Roxio Shared
        2007-12-13 08:58
        d
        w C:\Documents and Settings\All Users\Application Data\InstallShield
        2007-12-13 08:56
        d
        w C:\Program Files\Intel
        2007-12-13 08:56
        d
        w C:\Documents and Settings\Matt Weber\Application Data\InstallShield
        2007-12-13 08:53
        d
        w C:\Program Files\MSXML 6.0
        2007-12-13 08:38 6,876 ----a-w C:\WINDOWS\system32\drivers\1028_Dell_VOS_VOSTRO_200.mrk
        2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
        2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
        .
        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4
        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "DellAutomatedPCTuneUp"="C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 09:49 465136]
        "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 18:56 202544]
        "Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
        "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-06-13 19:21 142104]
        "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-06-13 19:21 162584]
        "Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-06-13 19:21 138008]
        "RTHDCPL"="RTHDCPL.EXE" [2007-06-13 20:41 16132608 C:\WINDOWS\RTHDCPL.EXE]
        "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]
        "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]
        "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184]
        "RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 09:00 1116920]
        "PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 17:23 118784]
        "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-13 03:01 1838592]
        "ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-24 07:03 17920]
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
        "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 18:57 16384]
        "vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-01-14 18:02 77824]
        "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
        Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-12-13 03:02:35 7168]
        HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
        "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
        R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 10:35]
        R2 datunidr;DellAutomatedPCTuneUp UniDriver;C:\WINDOWS\system32\DRIVERS\datunidr.sys [2007-08-23 18:29]
        R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
        R3 PTproct;PTproct;C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys [2006-10-05 16:07]
        S3 DellAMBrokerService;DellAMBrokerService;"C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe" [2007-10-11 09:49]
        .
        Contents of the 'Scheduled Tasks' folder
        "2008-01-27 12:13:56 C:\WINDOWS\Tasks\WebReg psc C3100 series.job"
        - C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
        .
        **************************************************************************
        catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-02-02 14:51:24
        Windows 5.1.2600 Service Pack 2 NTFS
        scanning hidden processes ...
        scanning hidden autostart entries ...
        scanning hidden files ...
        scan completed successfully
        hidden files: 0
        **************************************************************************
        .
        DLLs Loaded Under Running Processes
        PROCESS: C:\WINDOWS\system32\winlogon.exe
        -> C:\WINDOWS\system32\NavLogon.dll
        PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
        -> C:\WINDOWS\system32\DLAAPI_W.DLL
        .
        Completion time: 2008-02-02 14:51:52
        ComboFix-quarantined-files.txt 2008-02-02 20:51:37
        .
        2008-01-09 01:25:23 --- E O F ---
      • TroganTrogan London, UK
        edited February 2008
        A few files I would like scanned:
        • Go to VirusTotal
        • Copy and paste the following file path into the Search Box in the middle of the page:
        • C:\WINDOWS\system32\DRIVERS\datunidr.sys
        • Now, click on the Send File button
        • Save a copy of the Anti-Virus results. Post the results in your next reply.
        Do the same for the following file:

        C:\WINDOWS\system32\DLAAPI_W.DLL

        Please post the results back here.
      • edited February 2008




        dfeabb7cfffadea4a912ab95bdc3177aFile has already been analysed:


        MD5:dfeabb7cfffadea4a912ab95bdc3177aDate:02.03.2008 00:57:59 (CET) [<1D]Results:0/32Permalink:analisis/8fc14712597cb024f325570932d4463d02.03.2008 00:57:59 (CET) [<1D]0/32File DLAAPI_W.DLL received on 02.03.2008 01:18:36 (CET)
        Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
        loader.gif
        Result: 0/32 (0%)

        Loading server information...
        Your file is queued in position: 2.
        Estimated start time is between 41 and 59 seconds.
        Do not close the window until scan is complete.
        The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
        If you are waiting for more than five minutes you have to resend your file.
        Your file is being scanned by VirusTotal in this moment,
        results will be shown as they're generated.
        compress-icon.pngCompact
        [URL="javascript:window.print()"]Print results[/URL] print-icon.png

        Your file has expired or does not exists.
        Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time. You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished. Email:


        AntivirusVersionLast UpdateResultAhnLab-V32008.2.3.102008.02.02-AntiVir7.6.0.612008.02.01-Authentium4.93.82008.02.01-Avast4.7.1098.02008.02.02-AVG7.5.0.5162008.02.02-BitDefender7.22008.02.03-CAT-QuickHeal9.002008.02.01-ClamAV0.922008.02.03-DrWeb4.44.0.091702008.02.02-eSafe7.0.15.02008.01.28-eTrust-Vet31.3.55042008.02.01-Ewido4.02008.02.02-FileAdvisor12008.02.03-Fortinet3.14.0.02008.02.02-F-Prot4.4.2.542008.02.02-F-Secure6.70.13260.02008.02.01-IkarusT3.1.1.202008.02.02-Kaspersky7.0.0.1252008.02.03-McAfee52212008.02.01-Microsoft1.32042008.02.03-NOD32v228452008.02.02-Norman5.80.022008.02.01-Panda9.0.0.42008.02.02-Prevx1V22008.02.03-Rising20.29.22.002008.01.30-Sophos4.26.02008.02.02-Sunbelt2.2.907.02008.02.02-Symantec102008.02.02-TheHacker6.2.9.2062008.02.02-VBA323.12.6.02008.02.02-VirusBuster4.3.26:92008.02.02-Webwasher-Gateway6.6.22008.02.03-Additional informationFile size: 56056 bytesMD5: 378894e833489c07aae541be974cb59bSHA1: e74f01a324320e6636e2fa68a0abd4535f6c2fc0PEiD: -
        analisis/8fc14712597cb024f325570932d4463d
      • TroganTrogan London, UK
        edited February 2008
        Hi, sorry for the delay.

        Can you scan those files again please, but this time save the results to Notepad and attach them to the post.
      • edited February 2008
        hi trogan
        i hope this is what you need
        thanks

        AhnLab-V3 2008.2.3.10 2008.02.02 -
        AntiVir 7.6.0.61 2008.02.01 -
        Authentium 4.93.8 2008.02.01 -
        Avast 4.7.1098.0 2008.02.02 -
        AVG 7.5.0.516 2008.02.02 -
        BitDefender 7.2 2008.02.03 -
        CAT-QuickHeal 9.00 2008.02.01 -
        ClamAV 0.92 2008.02.03 -
        DrWeb 4.44.0.09170 2008.02.02 -
        eSafe 7.0.15.0 2008.01.28 -
        eTrust-Vet 31.3.5504 2008.02.01 -
        Ewido 4.0 2008.02.02 -
        FileAdvisor 1 2008.02.03 -
        Fortinet 3.14.0.0 2008.02.02 -
        F-Prot 4.4.2.54 2008.02.02 -
        F-Secure 6.70.13260.0 2008.02.01 -
        Ikarus T3.1.1.20 2008.02.02 -
        Kaspersky 7.0.0.125 2008.02.03 -
        McAfee 5221 2008.02.01 -
        Microsoft 1.3204 2008.02.03 -
        NOD32v2 2845 2008.02.02 -
        Norman 5.80.02 2008.02.01 -
        Panda 9.0.0.4 2008.02.02 -
        Prevx1 V2 2008.02.03 -
        Rising 20.29.22.00 2008.01.30 -
        Sophos 4.26.0 2008.02.02 -
        Sunbelt 2.2.907.0 2008.02.02 -
        Symantec 10 2008.02.02 -
        TheHacker 6.2.9.206 2008.02.02 -
        VBA32 3.12.6.0 2008.02.02 -
        VirusBuster 4.3.26:9 2008.02.02 -
        Webwasher-Gateway 6.6.2 2008.02.03 -
        Additional information
        File size: 56056 bytes
        MD5: 378894e833489c07aae541be974cb59b
        SHA1: e74f01a324320e6636e2fa68a0abd4535f6c2fc0
        PEiD: -

        File dsunidrv.sys received on 02.03.2008 00:53:52 (CET)
        Current status: finished
        Result: 0/32 (0.00%)
        Compact Print results
        Antivirus Version Last Update Result
        AhnLab-V3 2008.2.3.10 2008.02.02 -
        AntiVir 7.6.0.61 2008.02.01 -
        Authentium 4.93.8 2008.02.01 -
        Avast 4.7.1098.0 2008.02.02 -
        AVG 7.5.0.516 2008.02.02 -
        BitDefender 7.2 2008.02.02 -
        CAT-QuickHeal 9.00 2008.02.01 -
        ClamAV 0.92 2008.02.02 -
        DrWeb 4.44.0.09170 2008.02.02 -
        eSafe 7.0.15.0 2008.01.28 -
        eTrust-Vet 31.3.5504 2008.02.01 -
        Ewido 4.0 2008.02.02 -
        FileAdvisor 1 2008.02.03 -
        Fortinet 3.14.0.0 2008.02.02 -
        F-Prot 4.4.2.54 2008.02.02 -
        F-Secure 6.70.13260.0 2008.02.01 -
        Ikarus T3.1.1.20 2008.02.02 -
        Kaspersky 7.0.0.125 2008.02.03 -
        McAfee 5221 2008.02.01 -
        Microsoft 1.3204 2008.02.03 -
        NOD32v2 2845 2008.02.02 -
        Norman 5.80.02 2008.02.01 -
        Panda 9.0.0.4 2008.02.02 -
        Prevx1 V2 2008.02.03 -
        Rising 20.29.22.00 2008.01.30 -
        Sophos 4.26.0 2008.02.02 -
        Sunbelt 2.2.907.0 2008.02.02 -
        Symantec 10 2008.02.02 -
        TheHacker 6.2.9.206 2008.02.02 -
        VBA32 3.12.6.0 2008.02.02 -
        VirusBuster 4.3.26:9 2008.02.02 -
        Webwasher-Gateway 6.6.2 2008.02.02 -
        Additional information
        File size: 5376 bytes
        MD5: dfeabb7cfffadea4a912ab95bdc3177a
        SHA1: e5f7923519e361280c3b6fea8af7bcb789706714
        PEiD: -
      • TroganTrogan London, UK
        edited February 2008
        Yes, it is.

        Please do the following...

        Open Notepad and copy/paste the text in the Quote Box below into it:
        File::
        C:\Documents and Settings\Matt Weber\Application Data\wklnhst.dat
        C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\KJ6IKZK2\gnida[1].swf

        FileLook::
        C:\WINDOWS\system32\DRIVERS\datunidr.sys
        C:\WINDOWS\system32\DLAAPI_W.DLL

        Save this as CFScript.txt to your Desktop

        CFScript.gif

        Referring to the picture above, drag CFScript.txt into ComboFix.exe

        This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.
      • edited February 2008
        here you go trogan

        ComboFix 08-02.03.1 - Matt Weber 2008-02-03 9:56:14.3 - NTFSx86
        Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1405 [GMT -6:00]
        Running from: C:\Documents and Settings\Matt Weber\Desktop\ComboFix.exe
        Command switches used :: C:\Documents and Settings\Matt Weber\Desktop\CFScript.txt
        * Created a new restore point
        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .
        ((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
        .
        2008-02-02 15:54 . 2008-02-02 15:54 <DIR> d--hs---- C:\WINDOWS\ftpcache
        2008-02-02 11:21 . 2008-02-02 11:21 <DIR> d
        C:\Deckard
        2008-02-02 11:20 . 2008-02-02 11:20 <DIR> d
        C:\Program Files\Java
        2008-02-02 11:20 . 2008-02-02 11:20 <DIR> d
        C:\Program Files\Common Files\Java
        2008-02-02 11:20 . 2007-12-14 01:59 69,632 --a
        C:\WINDOWS\system32\javacpl.cpl
        2008-02-01 19:26 . 2008-02-02 12:26 2,016,032 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
        2008-02-01 19:26 . 2008-02-02 12:26 179,488 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
        2008-02-01 19:26 . 2008-02-02 12:26 31,208 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
        2008-02-01 19:26 . 2008-02-02 12:26 19,988 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
        2008-02-01 19:23 . 2008-02-01 19:23 <DIR> d
        C:\KAV
        2008-01-30 19:18 . 2008-01-30 19:18 <DIR> d
        C:\Program Files\Trend Micro
        .
        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-02-03 12:48
        d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
        2008-01-27 16:50
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Image Zone Express
        2007-12-31 21:40
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Roxio
        2007-12-31 17:24
        d
        w C:\Documents and Settings\Matt Weber\Application Data\HP
        2007-12-31 17:20
        d
        w C:\Program Files\Common Files\HP
        2007-12-31 17:20
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Printer Info Cache
        2007-12-30 04:13
        d
        w C:\Program Files\HP
        2007-12-30 04:13
        d
        w C:\Documents and Settings\All Users\Application Data\HP
        2007-12-30 04:11
        d
        w C:\Program Files\Hewlett-Packard
        2007-12-30 04:10
        d
        w C:\Program Files\Common Files\Hewlett-Packard
        2007-12-25 06:01
        d
        w C:\Program Files\Windows Media Connect 2
        2007-12-18 03:29
        d
        w C:\Program Files\MSXML 4.0
        2007-12-18 03:16
        d--h--w C:\Documents and Settings\Matt Weber\Application Data\GTek
        2007-12-18 02:05
        d
        w C:\Documents and Settings\Matt Weber\Application Data\CyberLink
        2007-12-18 02:05
        d
        w C:\Documents and Settings\All Users\Application Data\CyberLink
        2007-12-18 02:03
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Template
        2007-12-18 01:59
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Yahoo!
        2007-12-18 01:58
        d
        w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
        2007-12-18 01:54
        d
        w C:\Documents and Settings\All Users\Application Data\Yahoo!
        2007-12-18 01:53
        d
        w C:\Program Files\Yahoo!
        2007-12-18 01:33
        d
        w C:\Documents and Settings\All Users\Application Data\Dell
        2007-12-18 01:14
        d
        w C:\Program Files\Symantec_Client_Security
        2007-12-18 01:14
        d
        w C:\Program Files\Symantec
        2007-12-18 01:14
        d
        w C:\Program Files\Common Files\Symantec Shared
        2007-12-18 01:14
        d
        w C:\Documents and Settings\All Users\Application Data\Symantec
        2007-12-18 01:13 83,672 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
        2007-12-18 01:13 73,224 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
        2007-12-18 00:51 0 ----a-w C:\Documents and Settings\Matt Weber\Application Data\wklnhst.dat
        2007-12-13 09:05
        d
        w C:\Documents and Settings\LocalService\Application Data\Roxio
        2007-12-13 09:04
        d
        w C:\Program Files\Microsoft Works
        2007-12-13 09:03
        d
        w C:\Program Files\DellAutomatedPCTuneUp
        2007-12-13 09:03
        d
        w C:\Program Files\Dell Support Center
        2007-12-13 09:03
        d
        w C:\Program Files\Common Files\supportsoft
        2007-12-13 09:03
        d
        w C:\Documents and Settings\All Users\Application Data\SupportSoft
        2007-12-13 09:03
        d
        w C:\Documents and Settings\All Users\Application Data\Gtek
        2007-12-13 09:02
        d
        w C:\Program Files\Dell Network Assistant
        2007-12-13 09:02
        d
        w C:\Program Files\Common Files\Adobe
        2007-12-13 09:02
        d
        w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
        2007-12-13 09:01
        d--h--w C:\Program Files\InstallShield Installation Information
        2007-12-13 09:01
        d
        w C:\Program Files\Google
        2007-12-13 09:01
        d
        w C:\Program Files\Dell
        2007-12-13 09:01
        d
        w C:\Program Files\CyberLink
        2007-12-13 09:01
        d
        w C:\Program Files\Common Files\InstallShield
        2007-12-13 09:00
        d
        w C:\Program Files\Roxio
        2007-12-13 09:00
        d
        w C:\Program Files\Common Files\Sonic Shared
        2007-12-13 09:00
        d
        w C:\Documents and Settings\All Users\Application Data\Sonic
        2007-12-13 09:00
        d
        w C:\Documents and Settings\All Users\Application Data\Roxio
        2007-12-13 08:58
        d
        w C:\Program Files\Common Files\SureThing Shared
        2007-12-13 08:58
        d
        w C:\Program Files\Common Files\Roxio Shared
        2007-12-13 08:58
        d
        w C:\Documents and Settings\All Users\Application Data\InstallShield
        2007-12-13 08:56
        d
        w C:\Program Files\Intel
        2007-12-13 08:56
        d
        w C:\Documents and Settings\Matt Weber\Application Data\InstallShield
        2007-12-13 08:53
        d
        w C:\Program Files\MSXML 6.0
        2007-12-13 08:38 6,876 ----a-w C:\WINDOWS\system32\drivers\1028_Dell_VOS_VOSTRO_200.mrk
        2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
        2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
        .
        (((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        - Unable to find Resource table header in file.
        ---- C:\WINDOWS\system32\DRIVERS\datunidr.sys ----
        Company: Gteko Ltd.
        File Description: GUniDriver
        File Version: 1, 0, 0, 12
        Product Name: Gteko Diagnostics
        Copyright: Copyright (C) 2004 - 2007 Gteko Ltd.
        Original file name: GUniDriver.sys

        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4
        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "DellAutomatedPCTuneUp"="C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 09:49 465136]
        "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 18:56 202544]
        "Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
        "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-06-13 19:21 142104]
        "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-06-13 19:21 162584]
        "Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-06-13 19:21 138008]
        "RTHDCPL"="RTHDCPL.EXE" [2007-06-13 20:41 16132608 C:\WINDOWS\RTHDCPL.EXE]
        "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]
        "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]
        "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184]
        "RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 09:00 1116920]
        "PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 17:23 118784]
        "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-13 03:01 1838592]
        "ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-24 07:03 17920]
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
        "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 18:57 16384]
        "vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-01-14 18:02 77824]
        "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
        Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-12-13 03:02:35 7168]
        HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
        "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
        R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 10:35]
        R2 datunidr;DellAutomatedPCTuneUp UniDriver;C:\WINDOWS\system32\DRIVERS\datunidr.sys [2007-08-23 18:29]
        R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
        R3 PTproct;PTproct;C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys [2006-10-05 16:07]
        S3 DellAMBrokerService;DellAMBrokerService;"C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe" [2007-10-11 09:49]
        .
        Contents of the 'Scheduled Tasks' folder
        "2008-01-27 12:13:56 C:\WINDOWS\Tasks\WebReg psc C3100 series.job"
        - C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
        .
        **************************************************************************
        catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-02-03 09:56:40
        Windows 5.1.2600 Service Pack 2 NTFS
        scanning hidden processes ...
        scanning hidden autostart entries ...
        scanning hidden files ...
        scan completed successfully
        hidden files: 0
        **************************************************************************
        .
        DLLs Loaded Under Running Processes
        PROCESS: C:\WINDOWS\system32\winlogon.exe
        -> C:\WINDOWS\system32\NavLogon.dll
        PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
        -> C:\WINDOWS\system32\DLAAPI_W.DLL
        .
        Completion time: 2008-02-03 9:57:01
        ComboFix-quarantined-files.txt 2008-02-03 15:56:53
        ComboFix2.txt 2008-02-03 15:48:08
        ComboFix3.txt 2008-02-02 20:51:53
        .
        2008-01-09 01:25:23 --- E O F ---

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 9:57:47 AM, on 2/3/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16574)
        Boot mode: Normal
        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\hkcmd.exe
        C:\WINDOWS\system32\igfxpers.exe
        C:\WINDOWS\system32\igfxsrvc.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
        C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
        C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
        C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
        C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
        C:\Program Files\Dell Support Center\bin\sprtcmd.exe
        C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
        C:\Program Files\Dell Network Assistant\hnm_svc.exe
        C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
        C:\Program Files\Dell Support Center\bin\sprtsvc.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\WINDOWS\system32\notepad.exe
        C:\WINDOWS\system32\notepad.exe
        C:\WINDOWS\explorer.exe
        C:\WINDOWS\system32\notepad.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=2071213
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
        O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
        O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
        O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
        O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
        O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
        O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
        O4 - HKCU\..\Run: [DellAutomatedPCTuneUp] "C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" /startup
        O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
        O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - Global Startup: Dell Network Assistant.lnk = ?
        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
        O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
        O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
        O23 - Service: DellAMBrokerService - Unknown owner - C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe
        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
        O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
        --
        End of file - 8674 bytes
      • TroganTrogan London, UK
        edited February 2008
        Is gnida[1].swf still being detected?
      • edited February 2008
        hi trogan
        i just ran a scan on my computer with symantec and it found know viruses but in my virus history gnida[1].swf is still there.
        and its seems today my computer is running real slow.
        any suggestions?
        thanks
      • TroganTrogan London, UK
        edited February 2008
        Hi Matt,

        Are you saying that gnida[1].swf is in Quarantine? Let me know.

        We will remove the tools we downloaded and see if that helps the speed.
      • edited February 2008
        hi trogan
        no its not in quarantin.
        i try to put it there and it wont allow me to.
      • TroganTrogan London, UK
        edited February 2008
        So, what do you mean "virus history"? What is the exact file location? This is important.
      • edited February 2008
        hi trogan
        when i open up symantec there is a place where i can look up historys
        and gnida[1].swf is in there.
        i exported it and copied it for you
        Date,Filename,Virus Name,Virus Type,Action Taken,Computer,User,Original Location,Status,Current Location,Primary Action,Secondary Action,Scan Type
        1/25/2008 5:33:04 AM,gnida[1].swf,Downloader,File,Left alone,BLAZER,Matt Weber,C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\KJ6IKZK2\,Infected,C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\KJ6IKZK2\,Clean virus from file,Quarantine infected file,Realtime scan

        i hope this is what yyou want
        thanks
      • TroganTrogan London, UK
        edited February 2008
        OK, lets try ComboFix one more time and see what happens...

        Delete the previous CFScript.txt please.

        Open Notepad and copy/paste the text in the Quote Box below into it:
        File::
        C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\KJ6IKZK2\gnida[1].swf
        Save this as CFScript.txt to your Desktop

        CFScript.gif

        Referring to the picture above, drag CFScript.txt into ComboFix.exe

        This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.
      • edited February 2008
        here it is trogan

        ComboFix 08-02.03.1 - Matt Weber 2008-02-03 12:58:28.4 - NTFSx86
        Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1389 [GMT -6:00]
        Running from: C:\Documents and Settings\Matt Weber\Desktop\ComboFix.exe
        Command switches used :: C:\Documents and Settings\Matt Weber\Desktop\CFScript.txt
        * Created a new restore point
        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .
        ((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
        .
        2008-02-02 15:54 . 2008-02-02 15:54 <DIR> d--hs---- C:\WINDOWS\ftpcache
        2008-02-02 11:21 . 2008-02-02 11:21 <DIR> d
        C:\Deckard
        2008-02-02 11:20 . 2008-02-02 11:20 <DIR> d
        C:\Program Files\Java
        2008-02-02 11:20 . 2008-02-02 11:20 <DIR> d
        C:\Program Files\Common Files\Java
        2008-02-02 11:20 . 2007-12-14 01:59 69,632 --a
        C:\WINDOWS\system32\javacpl.cpl
        2008-02-01 19:26 . 2008-02-02 12:26 2,016,032 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
        2008-02-01 19:26 . 2008-02-02 12:26 179,488 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
        2008-02-01 19:26 . 2008-02-02 12:26 31,208 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
        2008-02-01 19:26 . 2008-02-02 12:26 19,988 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
        2008-02-01 19:23 . 2008-02-01 19:23 <DIR> d
        C:\KAV
        2008-01-30 19:18 . 2008-01-30 19:18 <DIR> d
        C:\Program Files\Trend Micro
        .
        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-02-03 17:08
        d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
        2008-01-27 16:50
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Image Zone Express
        2007-12-31 21:40
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Roxio
        2007-12-31 17:24
        d
        w C:\Documents and Settings\Matt Weber\Application Data\HP
        2007-12-31 17:20
        d
        w C:\Program Files\Common Files\HP
        2007-12-31 17:20
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Printer Info Cache
        2007-12-30 04:13
        d
        w C:\Program Files\HP
        2007-12-30 04:13
        d
        w C:\Documents and Settings\All Users\Application Data\HP
        2007-12-30 04:11
        d
        w C:\Program Files\Hewlett-Packard
        2007-12-30 04:10
        d
        w C:\Program Files\Common Files\Hewlett-Packard
        2007-12-25 06:01
        d
        w C:\Program Files\Windows Media Connect 2
        2007-12-18 03:29
        d
        w C:\Program Files\MSXML 4.0
        2007-12-18 03:16
        d--h--w C:\Documents and Settings\Matt Weber\Application Data\GTek
        2007-12-18 02:05
        d
        w C:\Documents and Settings\Matt Weber\Application Data\CyberLink
        2007-12-18 02:05
        d
        w C:\Documents and Settings\All Users\Application Data\CyberLink
        2007-12-18 02:03
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Template
        2007-12-18 01:59
        d
        w C:\Documents and Settings\Matt Weber\Application Data\Yahoo!
        2007-12-18 01:58
        d
        w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
        2007-12-18 01:54
        d
        w C:\Documents and Settings\All Users\Application Data\Yahoo!
        2007-12-18 01:53
        d
        w C:\Program Files\Yahoo!
        2007-12-18 01:33
        d
        w C:\Documents and Settings\All Users\Application Data\Dell
        2007-12-18 01:14
        d
        w C:\Program Files\Symantec_Client_Security
        2007-12-18 01:14
        d
        w C:\Program Files\Symantec
        2007-12-18 01:14
        d
        w C:\Program Files\Common Files\Symantec Shared
        2007-12-18 01:14
        d
        w C:\Documents and Settings\All Users\Application Data\Symantec
        2007-12-18 01:13 83,672 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
        2007-12-18 01:13 73,224 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
        2007-12-18 00:51 0 ----a-w C:\Documents and Settings\Matt Weber\Application Data\wklnhst.dat
        2007-12-13 09:05
        d
        w C:\Documents and Settings\LocalService\Application Data\Roxio
        2007-12-13 09:04
        d
        w C:\Program Files\Microsoft Works
        2007-12-13 09:03
        d
        w C:\Program Files\DellAutomatedPCTuneUp
        2007-12-13 09:03
        d
        w C:\Program Files\Dell Support Center
        2007-12-13 09:03
        d
        w C:\Program Files\Common Files\supportsoft
        2007-12-13 09:03
        d
        w C:\Documents and Settings\All Users\Application Data\SupportSoft
        2007-12-13 09:03
        d
        w C:\Documents and Settings\All Users\Application Data\Gtek
        2007-12-13 09:02
        d
        w C:\Program Files\Dell Network Assistant
        2007-12-13 09:02
        d
        w C:\Program Files\Common Files\Adobe
        2007-12-13 09:02
        d
        w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
        2007-12-13 09:01
        d--h--w C:\Program Files\InstallShield Installation Information
        2007-12-13 09:01
        d
        w C:\Program Files\Google
        2007-12-13 09:01
        d
        w C:\Program Files\Dell
        2007-12-13 09:01
        d
        w C:\Program Files\CyberLink
        2007-12-13 09:01
        d
        w C:\Program Files\Common Files\InstallShield
        2007-12-13 09:00
        d
        w C:\Program Files\Roxio
        2007-12-13 09:00
        d
        w C:\Program Files\Common Files\Sonic Shared
        2007-12-13 09:00
        d
        w C:\Documents and Settings\All Users\Application Data\Sonic
        2007-12-13 09:00
        d
        w C:\Documents and Settings\All Users\Application Data\Roxio
        2007-12-13 08:58
        d
        w C:\Program Files\Common Files\SureThing Shared
        2007-12-13 08:58
        d
        w C:\Program Files\Common Files\Roxio Shared
        2007-12-13 08:58
        d
        w C:\Documents and Settings\All Users\Application Data\InstallShield
        2007-12-13 08:56
        d
        w C:\Program Files\Intel
        2007-12-13 08:56
        d
        w C:\Documents and Settings\Matt Weber\Application Data\InstallShield
        2007-12-13 08:53
        d
        w C:\Program Files\MSXML 6.0
        2007-12-13 08:38 6,876 ----a-w C:\WINDOWS\system32\drivers\1028_Dell_VOS_VOSTRO_200.mrk
        2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
        2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
        .
        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4
        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "DellAutomatedPCTuneUp"="C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 09:49 465136]
        "DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-10-09 18:56 202544]
        "Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 17:43 4670704]
        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00 15360]
        "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 10:24 1694208]
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-06-13 19:21 142104]
        "HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-06-13 19:21 162584]
        "Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-06-13 19:21 138008]
        "RTHDCPL"="RTHDCPL.EXE" [2007-06-13 20:41 16132608 C:\WINDOWS\RTHDCPL.EXE]
        "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 11:35 221184]
        "ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 11:37 81920]
        "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 11:22 221184]
        "RoxioDragToDisc"="C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 09:00 1116920]
        "PDVDDXSrv"="C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 17:23 118784]
        "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-12-13 03:01 1838592]
        "ECenter"="C:\Dell\E-Center\EULALauncher.exe" [2007-05-24 07:03 17920]
        "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
        "dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-10-09 18:57 16384]
        "vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" [2003-01-14 18:02 77824]
        "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
        Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2007-12-13 03:02:35 7168]
        HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 04:21:22 288472]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
        "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
        R1 DLARTL_M;DLARTL_M;C:\WINDOWS\system32\Drivers\DLARTL_M.SYS [2006-08-11 10:35]
        R2 datunidr;DellAutomatedPCTuneUp UniDriver;C:\WINDOWS\system32\DRIVERS\datunidr.sys [2007-08-23 18:29]
        R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
        R3 PTproct;PTproct;C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys [2006-10-05 16:07]
        S3 DellAMBrokerService;DellAMBrokerService;"C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe" [2007-10-11 09:49]
        .
        Contents of the 'Scheduled Tasks' folder
        "2008-01-27 12:13:56 C:\WINDOWS\Tasks\WebReg psc C3100 series.job"
        - C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exe
        .
        **************************************************************************
        catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-02-03 12:59:08
        Windows 5.1.2600 Service Pack 2 NTFS
        scanning hidden processes ...
        scanning hidden autostart entries ...
        scanning hidden files ...
        scan completed successfully
        hidden files: 0
        **************************************************************************
        .
        DLLs Loaded Under Running Processes
        PROCESS: C:\WINDOWS\system32\winlogon.exe
        -> C:\WINDOWS\system32\NavLogon.dll
        PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
        -> C:\WINDOWS\system32\DLAAPI_W.DLL
        .
        Completion time: 2008-02-03 12:59:28
        ComboFix-quarantined-files.txt 2008-02-03 18:59:19
        ComboFix2.txt 2008-02-03 15:57:01
        ComboFix3.txt 2008-02-03 15:48:08
        ComboFix4.txt 2008-02-02 20:51:53
        .
        2008-01-09 01:25:23 --- E O F ---
      • TroganTrogan London, UK
        edited February 2008
        Hmm...not sure why CFScript is not working.

        Please download the OTMoveIt2 by OldTimer.
        • Save it to your desktop.
        • Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
        • Copy the lines in the Quote Box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
          C:\Documents and Settings\Matt Weber\Application Data\wklnhst.dat
          C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\KJ6IKZK2\gnida[1].swf
        • Return to OTMoveIt2, right click in the "Paste Standard List of Files/Folders to Move" window (under the light blue bar) and choose Paste.
        • Click the red Moveit! button.
        • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
        • Close OTMoveIt2
        Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
      • edited February 2008
        hi trogan
        here it is

        C:\Documents and Settings\Matt Weber\Application Data\wklnhst.dat moved successfully.
        File/Folder C:\Documents and Settings\Matt Weber\Local Settings\Temporary Internet Files\Content.IE5\KJ6IKZK2\gnida[1].swf not found.

        OTMoveIt2 v1.0.17 log created on 02032008_151303
      • TroganTrogan London, UK
        edited February 2008
        Hi Matt,

        OTMoveIt2 did not find gnida[1].swf. I'm not sure what Norton's history is but the computer is clean of the infection. And you said Norton does not detect anything now, correct?

        Click Start > Run > type: combofix /u > Press OK. This will uninstall ComboFix.

        Let me know how the computer at the moment.
      Sign In or Register to comment.