SO SLOWWWWW!! HELP!
Hi and Happy Holidays,
My PC and every application associated with it seems to be crawling. This seems to have started after my PC crashed and I had to do a restore. However, I'm really not sure if it is a restore problem or a virus/hijack/whoknowswhat problem.
I've run AdAware, Spybot and SpyBlaster. I don't seem to have anything major going on. Then again, what do I know. I'm attaching a Hijack This report (see below) , and would greatly appreciated it if you could take a look and see if anything jumps out at you as a problem.
If you see nothing, maybe I just need more memory? Currently 512. Again, thanks for your time and efforts on my behalf. Awaiting your reply. Thanks!!
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:20:22 PM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\MDM.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\bfgclient\bfggameservices.exe
C:\Program Files\Verizon\McciBrowser.exe
C:\Documents and Settings\Owner\My Documents\Mom\popups\hijack this software\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [USB] C:\WINDOWS\system32\usb.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 10815 bytes
My PC and every application associated with it seems to be crawling. This seems to have started after my PC crashed and I had to do a restore. However, I'm really not sure if it is a restore problem or a virus/hijack/whoknowswhat problem.
I've run AdAware, Spybot and SpyBlaster. I don't seem to have anything major going on. Then again, what do I know. I'm attaching a Hijack This report (see below) , and would greatly appreciated it if you could take a look and see if anything jumps out at you as a problem.
If you see nothing, maybe I just need more memory? Currently 512. Again, thanks for your time and efforts on my behalf. Awaiting your reply. Thanks!!
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:20:22 PM, on 12/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\MDM.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\bfgclient\bfggameservices.exe
C:\Program Files\Verizon\McciBrowser.exe
C:\Documents and Settings\Owner\My Documents\Mom\popups\hijack this software\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [USB] C:\WINDOWS\system32\usb.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 10815 bytes
0
Comments
Please run HijackThis and place a tick by the following entry:
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
Then close all other windows except HijackThis and press "Fix Checked". Next restart the computer.
Now, please go HERE to run Panda ActiveScan 2.0
;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-01-03 20:18:34
PROTECTIONS: 2
MALWARE: 21
SUSPECTS: 7
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
McAfee Internet Security Suite 2007 8.1 No Yes
McAfee VirusScan Plus 12.1 No No
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00018331 adware/gator Adware No 0 Yes No c:\gatorpatch.log
00020302 adware/ncase Adware No 0 Yes No c:\temp\salm_kyf.dat
00020302 adware/ncase Adware No 0 Yes No c:\temp\salmau.dat
00020302 adware/ncase Adware No 0 Yes No c:\temp\fleok
00027660 adware/savenow Adware No 0 Yes No c:\windows\system32\wsxsvc
00029767 adware/delfinmedia Adware No 1 Yes No c:\windows\system32\vmss
00029767 adware/delfinmedia Adware No 1 Yes No c:\keys.ini
00041904 adware/sidesearch Adware No 0 Yes No c:\program files\lycos
00064331 adware/msview Adware No 0 Yes No c:\windows\inf\msview.inf
00140418 Adware/ISearch Adware No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc19\build2.exe
00144935 Adware/IPInsight Adware No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc28.tmp\farmmext.inf
00162730 Cookie/Belnk TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@dist.belnk[2].txt
00167690 Cookie/Rightmedia TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@rightmedia[2].txt
00167776 Cookie/Kount TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@kount[1].txt
00170087 Cookie/Hbmediapro TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@adopt.hbmediapro[1].txt
00171718 Cookie/Enhance TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@c.enhance[1].txt
00176502 Cookie/Media-motor TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@mmm.media-motor[1].txt
00188480 Cookie/Paypopup TrackingCookie No 0 Yes No C:\RECYCLER\S-1-5-21-3657561249-74049757-2802022764-500\Dc20\owner@paypopup[1].txt
00521370 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP150\A0022886.dll
00521370 Spyware/Iehelp Spyware No 1 No No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinGamesHookIE.dll]
02893773 Spyware/Iehelp Spyware No 1 Yes No C:\Program Files\iWin Games\AdminWorker.exe
02893774 Spyware/Iehelp Spyware No 1 Yes No C:\Program Files\iWin Games\WebInstaller.exe
02893775 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP150\A0022885.exe
02893775 Spyware/Iehelp Spyware No 1 No No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinArcadeLauncher.exe]
04262614 Bck/Ciadoor.FQ Virus/Trojan No 1 No No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP142\A0022130.exe[α
Ç.]
04262614 Bck/Ciadoor.FQ Virus/Trojan No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP142\A0022121.exe
04396338 W32/Gaobot.OXI.worm Virus/Worm No 1 Yes No C:\Program Files\Dream Day Wedding - Married in Manhattan\vcwcmrq.exe
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
No C:\hp\bin\ProcessLogger.exe
No C:\Program Files\Discovery - A Seek and Find Adventure\Discovery.exe
No C:\Program Files\Discovery - A Seek and Find Adventure\npqxpgj.exe
No C:\Program Files\Hidden Expedition - Amazon\vdztdsj.exe
No C:\Program Files\Hidden Secrets - The Nightmare\wnhbdgs.exe
No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinGames.exe]
No C:\Program Files\Mystery Case Files - Return to Ravenhearst\dppxxpn.exe
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
;===================================================================================================================================================================================
;===================================================================================================================================================================================
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:20:50 PM, on 1/3/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\My Documents\Mom\popups\hijack this software\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [USB] C:\WINDOWS\system32\usb.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 10849 bytes
http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
Post a new HijackThis log.
Hi......Deleted old HijackThis and installed new per your link. New log follows:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:25:26 PM, on 1/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [USB] C:\WINDOWS\system32\usb.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 10603 bytes
gator
ncase
savenow
delfinmedia
sidesearch
msview
ISearch
IPInsight
iWin Games
iWin.com
Do not worry if some of the above are not listed, just remove whatever you can find.
After the uninstallation, reboot your computer. We now need to get into the Safe Mode. As the computer is booting up, press and hold your "F8 Key" which should bring up the "Windows Advanced Options Menu" as shown below. Use your arrow keys to move to "Safe Mode" and press your Enter key. Do note that in Safe Mode internet connection is not available, so it is advisable to copy and paste my entire post to a Notepad file or to print it out.
For more help on booting into Safe Mode, check out:
http://www.computerhope.com/issues/chsafe.htm
Once you're in Safe Mode, please run HijackThis again and place a tick by the following entry:
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
Press the "Fix Checked" button, then close HijackThis and restart the computer again, but this time normally.
Finally, I need you to download ComboFix.exe. Please download from one of these webpages:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.forospyware.com/sUBs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe
* IMPORTANT !!! Save ComboFix.exe to your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right-click on the System Tray icon. They may otherwise interfere with our tools. You may need to re-enable them after we are done here.
Double-click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.Recovery Console can be installed from your disc if you have Vista if you wish.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
Click on Yes to continue scanning for malware.
When finished, it shall produce a log for you. Please include the ComboFix and the HijackThis logs in your new reply.
I did everything you asked and the outcome and logs you requested follow:
1. Found none of the files you listed in the Ctrl Panel.
2. In safe mode, checked the "04 -.Default user startup......" file but I see its still there in the report. Hijackthis unable to fix?
3. PC still slowwwwwwww.
Here are the logs:
ComboFix 09-01-05.01 - Owner 2009-01-05 10:38:32.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.230 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\inf\MSView.inf
c:\windows\system\oeminfo.ini
c:\windows\system32\mdm.exe
c:\windows\system32\packet.dll
c:\windows\system32\usb.exe
c:\windows\system32\vmss
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((( Files Created from 2008-12-05 to 2009-01-05 )))))))))))))))))))))))))))))))
.
2009-01-04 13:22 . 2009-01-04 13:22 <DIR> d
c:\program files\Trend Micro
2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d
c:\program files\Panda Security
2009-01-03 17:50 . 2008-06-19 17:24 28,544 --a
c:\windows\SYSTEM32\drivers\pavboot.sys
2009-01-03 17:19 . 2009-01-03 17:19 <DIR> d
c:\program files\Heartwild Solitaire
2009-01-03 17:12 . 2009-01-03 17:13 <DIR> d
c:\program files\Haunted Hotel II - Believe the Lies
2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
c:\documents and settings\Owner\Application Data\blg
2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
c:\documents and settings\All Users\Application Data\blg
2009-01-01 14:28 . 2009-01-01 14:28 <DIR> d
c:\program files\Lost Realms - Legacy of the Sun Princess
2008-12-29 20:26 . 2008-12-29 20:26 <DIR> d
c:\documents and settings\Owner\Freeze Tag - Dream Machine
2008-12-29 16:42 . 2008-12-29 16:44 <DIR> d
c:\program files\Mystery in London
2008-12-27 19:52 . 2008-12-27 19:52 <DIR> d
c:\documents and settings\Owner\Application Data\Cat's Eye Games
2008-12-27 19:44 . 2008-12-27 19:44 <DIR> d
c:\documents and settings\All Users\Application Data\Arkadium
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\Suspects and Clues Prefs
2008-12-27 19:26 . 2008-12-27 19:27 <DIR> d
c:\documents and settings\Owner\Application Data\Suspects and Clues Players
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\Spinapse
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\IOMediaSupport6SZZ001s
2008-12-27 15:27 . 2008-12-27 15:28 <DIR> d
c:\program files\Suspects and Clues
2008-12-27 09:15 . 2008-12-27 09:15 <DIR> d
c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-12-27 09:15 . 2009-01-05 10:27 6,651 --a
c:\windows\SYSTEM32\Config.MPF
2008-12-27 09:10 . 2007-11-22 06:44 201,320 --a
c:\windows\SYSTEM32\drivers\mfehidk.sys
2008-12-27 09:10 . 2007-07-13 06:20 113,952 --a
c:\windows\SYSTEM32\drivers\Mpfp.sys
2008-12-27 09:10 . 2007-11-22 06:44 79,304 --a
c:\windows\SYSTEM32\drivers\mfeavfk.sys
2008-12-27 09:10 . 2007-12-02 12:51 40,488 --a
c:\windows\SYSTEM32\drivers\mfesmfk.sys
2008-12-27 09:10 . 2007-11-22 06:44 35,240 --a
c:\windows\SYSTEM32\drivers\mfebopk.sys
2008-12-27 09:10 . 2007-11-22 06:44 33,832 --a
c:\windows\SYSTEM32\drivers\mferkdk.sys
2008-12-27 09:09 . 2008-12-27 09:09 <DIR> d
c:\program files\McAfee.com
2008-12-27 09:08 . 2008-12-27 09:14 <DIR> d
c:\program files\McAfee
2008-12-27 09:08 . 2008-12-27 09:10 <DIR> d
c:\program files\Common Files\McAfee
2008-12-26 20:19 . 2008-12-27 09:15 <DIR> d
c:\documents and settings\All Users\Application Data\McAfee
2008-12-24 16:01 . 2009-01-02 14:30 <DIR> d
c:\program files\Mystery Case Files - Return to Ravenhearst
2008-12-20 20:18 . 2006-10-22 12:22 208,896 --a
c:\windows\SYSTEM32\nvudisp.exe
2008-12-20 20:18 . 2009-01-05 10:23 88,566 --a
c:\windows\SYSTEM32\nvapps.xml
2008-12-20 20:18 . 2006-10-22 12:22 17,056 --a
c:\windows\SYSTEM32\nvdisp.nvu
2008-12-20 20:17 . 2008-12-20 20:17 <DIR> d
C:\NVIDIA
2008-12-20 20:17 . 2006-10-22 15:06 208,896 --a
c:\windows\SYSTEM32\NVUNINST.EXE
2008-12-20 20:14 . 2008-12-20 20:14 <DIR> d
c:\program files\SystemRequirementsLab
2008-12-20 19:56 . 2008-05-30 14:11 3,850,760 --a
c:\windows\SYSTEM32\D3DX9_38.dll
2008-12-20 19:55 . 2005-05-26 15:34 2,297,552 --a
c:\windows\SYSTEM32\d3dx9_26.dll
2008-12-20 19:49 . 2008-12-20 19:49 <DIR> d
c:\windows\Logs
2008-12-20 18:55 . 2008-12-20 18:55 <DIR> d
c:\documents and settings\All Users\Application Data\AdventureChronicles1
2008-12-20 18:35 . 2008-12-20 18:35 <DIR> d
c:\documents and settings\All Users\Application Data\PlayPond
2008-12-12 19:25 . 2008-12-12 19:25 <DIR> d
c:\program files\Caere
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-05 15:23
d
w c:\program files\lg_fwupdate
2009-01-03 22:19
d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 22:10
d
w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-01-03 00:34
d
w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-02 00:52
d
w c:\program files\SpywareBlaster
2008-12-21 23:52
d
w c:\program files\Google
2008-12-21 18:27
d
w c:\documents and settings\LocalService\Application Data\SACore
2008-12-13 06:40 3,593,216
w c:\windows\SYSTEM32\dllcache\mshtml.dll
2008-12-13 00:43
d
w c:\program files\RealArcade
2008-12-10 21:42
d
w c:\program files\Val`Gor
2008-12-10 21:00
d
w c:\documents and settings\Owner\Application Data\Games
2008-12-09 00:19
d
w c:\program files\iWin Games
2008-12-05 23:28
d
w c:\documents and settings\Owner\Application Data\PlayFirst
2008-12-05 23:28
d
w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-03 23:48
d
w c:\documents and settings\All Users\Application Data\NeptunesAdve
2008-12-03 23:26
d
w c:\documents and settings\Owner\Application Data\Shape games
2008-12-03 21:15
d
w c:\documents and settings\Owner\Application Data\MysteryStudio
2008-12-03 00:28
d
w c:\documents and settings\All Users\Application Data\Alawar Stargaze
2008-11-25 00:10
d
w c:\program files\Escape The Museum
2008-11-23 19:30
d
w c:\documents and settings\Owner\Application Data\Gold Casual Games
2008-11-23 19:30
d
w c:\documents and settings\All Users\Application Data\Gold Casual Games
2008-11-23 16:28
d
w c:\program files\Spybot - Search & Destroy
2008-11-21 20:59
d
w c:\documents and settings\Owner\Application Data\Gogii Games
2008-11-21 20:59
d
w c:\documents and settings\All Users\Application Data\Gogii Games
2008-11-18 21:36
d
w c:\documents and settings\Owner\Application Data\Artogon
2008-11-17 01:17
d
w c:\documents and settings\Owner\Application Data\cerasus.media
2008-11-05 21:34
d
w c:\program files\bfgclient
2008-10-27 15:04 70,992 ----a-w c:\windows\SYSTEM32\XAPOFX1_2.dll
2008-10-27 15:04 514,384 ----a-w c:\windows\SYSTEM32\XAudio2_3.dll
2008-10-27 15:04 235,856 ----a-w c:\windows\SYSTEM32\xactengine3_3.dll
2008-10-27 15:04 23,376 ----a-w c:\windows\SYSTEM32\X3DAudio1_5.dll
2008-10-24 11:21 455,296
w c:\windows\SYSTEM32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720
w c:\windows\SYSTEM32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\dllcache\cdm.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\dllcache\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
2008-10-16 13:11 70,656
w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824
w c:\windows\SYSTEM32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408
w c:\windows\SYSTEM32\dllcache\netapi32.dll
2008-10-15 07:06 633,632
w c:\windows\SYSTEM32\dllcache\iexplore.exe
2008-10-15 07:04 161,792
w c:\windows\SYSTEM32\dllcache\ieakui.dll
2008-10-10 09:52 452,440 ----a-w c:\windows\SYSTEM32\d3dx10_40.dll
2008-10-10 09:52 4,379,984 ----a-w c:\windows\SYSTEM32\D3DX9_40.dll
2008-10-10 09:52 2,036,576 ----a-w c:\windows\SYSTEM32\D3DCompiler_40.dll
2008-07-08 02:12 774,144 -c--a-w c:\program files\RngInterstitial.dll
2008-02-26 19:53 0 -c--a-w c:\program files\temp01
2006-06-16 00:24 308 -c--a-w c:\documents and settings\Owner\Application Data\bbbconfig.dat
2005-03-28 16:42 284 -c--a-w c:\documents and settings\Owner\Application Data\ViewerApp.dat
2002-05-20 12:19 61,440 -c--a-w c:\windows\INF\i386\onetUSD.dll
2002-05-16 12:22 36,864 -c--a-w c:\windows\INF\i386\Vizmicro.dll
2002-05-16 12:21 286,720 -c--a-w c:\windows\INF\i386\rtscan.dll
2002-05-16 12:20 172,032 -c--a-w c:\windows\INF\i386\viceo.dll
2001-08-03 22:29 13,824 -c--a-w c:\windows\INF\i386\Usbscan.sys
1998-12-09 02:53 99,840 -c--a-w c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 70,144 -c--a-w c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 48,640 -c--a-w c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 31,744 -c--a-w c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 186,368 -c--a-w c:\program files\Common Files\IRAREG.DLL
1998-12-09 02:53 17,920 -c--a-w c:\program files\Common Files\IRASRIAL.DLL
2007-09-16 06:35 66,408 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
2007-09-16 06:35 54,112 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-09-16 06:35 34,688 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
2007-09-16 06:35 46,456 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-09-16 06:35 171,880 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-08-26 16:52 32,768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082620080827\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~2\PSFree.exe" [2005-03-17 536576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
"PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-04 196608]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-07-08 249856]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
"DDCActiveMenu"="c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2001-10-02 94208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"S3TRAY2"="S3tray2.exe" [2001-10-04 c:\windows\SYSTEM32\S3tray2.exe]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\SYSTEM32\nwiz.exe]
c:\documents and settings\Administrator.YOUR-W92P4BHLZG\Start Menu\Programs\Startup\
AutoPlay.exe [2001-09-17 36864]
c:\documents and settings\Administrator.YOUR-W92P4BHLZG.000\Start Menu\Programs\Startup\
AutoPlay.exe [2001-09-17 36864]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-11-13 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= vdrcodec.dll
"VIDC.DVSD"= miroDV2avi.DLL
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
backup=c:\windows\pss\hp center UI.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
backup=c:\windows\pss\hp center.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a
2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCActiveMenu]
2001-10-02 22:23 94208 c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCM]
c--- 2001-10-02 22:21 155648 c:\program files\WildTangent\DDC\DDCManager\DDCMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
c--- 2001-07-25 13:00 184376 c:\program files\Microsoft Money\System\Money Express.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a
2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage]
--a
1999-10-14 11:50 53248 c:\program files\Caere\OmniPagePro10.0\OPware32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneTouch Monitor]
--a
2002-05-20 07:17 86016 c:\program files\Visioneer OneTouch\OneTouchMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 pavboot;pavboot;c:\windows\SYSTEM32\drivers\pavboot.sys [2009-01-03 28544]
R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-27 203280]
S4 0040461230474749mcinstcleanup;McAfee Application Installer Cleanup (0040461230474749);c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - InCDrec
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2008-12-27 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-12-27 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-USB - c:\windows\system32\usb.exe
MSConfigStartUp-Zero Knowledge Freedom - c:\program files\Zero Knowledge\Freedom\AutoStarterR.exe
.
Supplementary Scan
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://srch-us4.hpwis.com/
mSearch Bar = hxxp://srch-us4.hpwis.com/
uInternet Settings,ProxyOverride = localhost
Trusted Zone: *.internet
Trusted Zone: *.mcafee.com
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
c:\windows\Downloaded Program Files\sysreqlab.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-05 10:41:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
DLLs Loaded Under Running Processes
- - - - - - - > 'winlogon.exe'(672)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2009-01-05 10:45:35
ComboFix-quarantined-files.txt 2009-01-05 15:44:17
Pre-Run: 83,093,610,496 bytes free
Post-Run: 83,058,831,360 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows Whistler Personal" /fastdetect /NoExecute=OptIn
287 --- E O F --- 2008-12-18 21:59:33
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:02:47 AM, on 1/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 10068 bytes
THANKS AGAIN FOR YOUR TIME AND ASSISTANCE!!!!!!!!
It's IMPORTANT to carry out the instructions in the sequence listed below.
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Open *notepad* and copy/paste the text in the quotebox below into it: Save this as CFScript.txt, in the same location as ComboFix.exe which is on the Desktop.
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh HijackThis log in your next reply please.
*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*
Followed your directions and the ComboFix and HijackThis logs follow (note: the "04........" still exists.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:13:44 AM, on 1/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\lg_fwupdate\fwupdate.exe
C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
C:\Program Files\Nero\Nero 7\InCD\InCD.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us4.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {56071E0D-C61B-11D3-B41C-00E02927A304} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Zero-Knowledge Freedom - {FA91B828-F937-4568-82C1-843627E63ED7} - C:\Program Files\Zero Knowledge\Freedom\BandObjs.dll (file missing)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [SecurDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [DDCActiveMenu] "C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" -boot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~2\PSFree.exe"
O4 - .DEFAULT User Startup: AutoPlay.exe (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1215367183045
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1215367351217
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: McAfee Application Installer Cleanup (0040461230474749) (0040461230474749mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\004046~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 10316 bytes
ComboFix 09-01-05.01 - Owner 2009-01-06 9:51:04.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.275 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
FILE ::
c:\documents and settings\Administrator.YOUR-W92P4BHLZG.000\Start Menu\Programs\Startup\AutoPlay.exe
c:\documents and settings\Administrator.YOUR-W92P4BHLZG\Start Menu\Programs\Startup\AutoPlay.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator.YOUR-W92P4BHLZG.000\Start Menu\Programs\Startup\AutoPlay.exe
c:\documents and settings\Administrator.YOUR-W92P4BHLZG\Start Menu\Programs\Startup\AutoPlay.exe
c:\program files\temp01\
.
((((((((((((((((((((((((( Files Created from 2008-12-06 to 2009-01-06 )))))))))))))))))))))))))))))))
.
2009-01-04 13:22 . 2009-01-04 13:22 <DIR> d
c:\program files\Trend Micro
2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d
c:\program files\Panda Security
2009-01-03 17:50 . 2008-06-19 17:24 28,544 --a
c:\windows\SYSTEM32\drivers\pavboot.sys
2009-01-03 17:19 . 2009-01-03 17:19 <DIR> d
c:\program files\Heartwild Solitaire
2009-01-03 17:12 . 2009-01-03 17:13 <DIR> d
c:\program files\Haunted Hotel II - Believe the Lies
2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
c:\documents and settings\Owner\Application Data\blg
2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
c:\documents and settings\All Users\Application Data\blg
2009-01-01 14:28 . 2009-01-01 14:28 <DIR> d
c:\program files\Lost Realms - Legacy of the Sun Princess
2008-12-29 20:26 . 2008-12-29 20:26 <DIR> d
c:\documents and settings\Owner\Freeze Tag - Dream Machine
2008-12-29 16:42 . 2008-12-29 16:44 <DIR> d
c:\program files\Mystery in London
2008-12-27 19:52 . 2008-12-27 19:52 <DIR> d
c:\documents and settings\Owner\Application Data\Cat's Eye Games
2008-12-27 19:44 . 2008-12-27 19:44 <DIR> d
c:\documents and settings\All Users\Application Data\Arkadium
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\Suspects and Clues Prefs
2008-12-27 19:26 . 2008-12-27 19:27 <DIR> d
c:\documents and settings\Owner\Application Data\Suspects and Clues Players
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\Spinapse
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\IOMediaSupport6SZZ001s
2008-12-27 15:27 . 2008-12-27 15:28 <DIR> d
c:\program files\Suspects and Clues
2008-12-27 09:15 . 2008-12-27 09:15 <DIR> d
c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-12-27 09:15 . 2009-01-06 09:28 7,113 --a
c:\windows\SYSTEM32\Config.MPF
2008-12-27 09:10 . 2007-11-22 06:44 201,320 --a
c:\windows\SYSTEM32\drivers\mfehidk.sys
2008-12-27 09:10 . 2007-07-13 06:20 113,952 --a
c:\windows\SYSTEM32\drivers\Mpfp.sys
2008-12-27 09:10 . 2007-11-22 06:44 79,304 --a
c:\windows\SYSTEM32\drivers\mfeavfk.sys
2008-12-27 09:10 . 2007-12-02 12:51 40,488 --a
c:\windows\SYSTEM32\drivers\mfesmfk.sys
2008-12-27 09:10 . 2007-11-22 06:44 35,240 --a
c:\windows\SYSTEM32\drivers\mfebopk.sys
2008-12-27 09:10 . 2007-11-22 06:44 33,832 --a
c:\windows\SYSTEM32\drivers\mferkdk.sys
2008-12-27 09:09 . 2008-12-27 09:09 <DIR> d
c:\program files\McAfee.com
2008-12-27 09:08 . 2008-12-27 09:14 <DIR> d
c:\program files\McAfee
2008-12-27 09:08 . 2008-12-27 09:10 <DIR> d
c:\program files\Common Files\McAfee
2008-12-26 20:19 . 2008-12-27 09:15 <DIR> d
c:\documents and settings\All Users\Application Data\McAfee
2008-12-24 16:01 . 2009-01-05 19:04 <DIR> d
c:\program files\Mystery Case Files - Return to Ravenhearst
2008-12-20 20:18 . 2006-10-22 12:22 208,896 --a
c:\windows\SYSTEM32\nvudisp.exe
2008-12-20 20:18 . 2009-01-06 09:24 88,566 --a
c:\windows\SYSTEM32\nvapps.xml
2008-12-20 20:18 . 2006-10-22 12:22 17,056 --a
c:\windows\SYSTEM32\nvdisp.nvu
2008-12-20 20:17 . 2008-12-20 20:17 <DIR> d
C:\NVIDIA
2008-12-20 20:17 . 2006-10-22 15:06 208,896 --a
c:\windows\SYSTEM32\NVUNINST.EXE
2008-12-20 20:14 . 2008-12-20 20:14 <DIR> d
c:\program files\SystemRequirementsLab
2008-12-20 19:56 . 2008-05-30 14:11 3,850,760 --a
c:\windows\SYSTEM32\D3DX9_38.dll
2008-12-20 19:55 . 2005-05-26 15:34 2,297,552 --a
c:\windows\SYSTEM32\d3dx9_26.dll
2008-12-20 19:49 . 2008-12-20 19:49 <DIR> d
c:\windows\Logs
2008-12-20 18:55 . 2008-12-20 18:55 <DIR> d
c:\documents and settings\All Users\Application Data\AdventureChronicles1
2008-12-20 18:35 . 2008-12-20 18:35 <DIR> d
c:\documents and settings\All Users\Application Data\PlayPond
2008-12-12 19:25 . 2008-12-12 19:25 <DIR> d
c:\program files\Caere
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 14:31
d
w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-06 14:25
d
w c:\program files\lg_fwupdate
2009-01-06 01:53
d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-06 01:53
d
w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-01-02 00:52
d
w c:\program files\SpywareBlaster
2008-12-21 23:52
d
w c:\program files\Google
2008-12-21 18:27
d
w c:\documents and settings\LocalService\Application Data\SACore
2008-12-13 06:40 3,593,216
w c:\windows\SYSTEM32\dllcache\mshtml.dll
2008-12-13 00:43
d
w c:\program files\RealArcade
2008-12-10 21:42
d
w c:\program files\Val`Gor
2008-12-10 21:00
d
w c:\documents and settings\Owner\Application Data\Games
2008-12-09 00:19
d
w c:\program files\iWin Games
2008-12-05 23:28
d
w c:\documents and settings\Owner\Application Data\PlayFirst
2008-12-05 23:28
d
w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-03 23:48
d
w c:\documents and settings\All Users\Application Data\NeptunesAdve
2008-12-03 23:26
d
w c:\documents and settings\Owner\Application Data\Shape games
2008-12-03 21:15
d
w c:\documents and settings\Owner\Application Data\MysteryStudio
2008-12-03 00:28
d
w c:\documents and settings\All Users\Application Data\Alawar Stargaze
2008-11-25 00:10
d
w c:\program files\Escape The Museum
2008-11-23 19:30
d
w c:\documents and settings\Owner\Application Data\Gold Casual Games
2008-11-23 19:30
d
w c:\documents and settings\All Users\Application Data\Gold Casual Games
2008-11-23 16:28
d
w c:\program files\Spybot - Search & Destroy
2008-11-21 20:59
d
w c:\documents and settings\Owner\Application Data\Gogii Games
2008-11-21 20:59
d
w c:\documents and settings\All Users\Application Data\Gogii Games
2008-11-18 21:36
d
w c:\documents and settings\Owner\Application Data\Artogon
2008-11-17 01:17
d
w c:\documents and settings\Owner\Application Data\cerasus.media
2008-10-27 15:04 70,992 ----a-w c:\windows\SYSTEM32\XAPOFX1_2.dll
2008-10-27 15:04 514,384 ----a-w c:\windows\SYSTEM32\XAudio2_3.dll
2008-10-27 15:04 235,856 ----a-w c:\windows\SYSTEM32\xactengine3_3.dll
2008-10-27 15:04 23,376 ----a-w c:\windows\SYSTEM32\X3DAudio1_5.dll
2008-10-24 11:21 455,296
w c:\windows\SYSTEM32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720
w c:\windows\SYSTEM32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\dllcache\cdm.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\dllcache\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
2008-10-16 13:11 70,656
w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824
w c:\windows\SYSTEM32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408
w c:\windows\SYSTEM32\dllcache\netapi32.dll
2008-10-15 07:06 633,632
w c:\windows\SYSTEM32\dllcache\iexplore.exe
2008-10-15 07:04 161,792
w c:\windows\SYSTEM32\dllcache\ieakui.dll
2008-10-10 09:52 452,440 ----a-w c:\windows\SYSTEM32\d3dx10_40.dll
2008-10-10 09:52 4,379,984 ----a-w c:\windows\SYSTEM32\D3DX9_40.dll
2008-10-10 09:52 2,036,576 ----a-w c:\windows\SYSTEM32\D3DCompiler_40.dll
2008-07-08 02:12 774,144 -c--a-w c:\program files\RngInterstitial.dll
2008-02-26 19:53 0 -c--a-w c:\program files\temp01
2006-06-16 00:24 308 -c--a-w c:\documents and settings\Owner\Application Data\bbbconfig.dat
2005-03-28 16:42 284 -c--a-w c:\documents and settings\Owner\Application Data\ViewerApp.dat
2002-05-20 12:19 61,440 -c--a-w c:\windows\INF\i386\onetUSD.dll
2002-05-16 12:22 36,864 -c--a-w c:\windows\INF\i386\Vizmicro.dll
2002-05-16 12:21 286,720 -c--a-w c:\windows\INF\i386\rtscan.dll
2002-05-16 12:20 172,032 -c--a-w c:\windows\INF\i386\viceo.dll
2001-08-03 22:29 13,824 -c--a-w c:\windows\INF\i386\Usbscan.sys
1998-12-09 02:53 99,840 -c--a-w c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 70,144 -c--a-w c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 48,640 -c--a-w c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 31,744 -c--a-w c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 186,368 -c--a-w c:\program files\Common Files\IRAREG.DLL
1998-12-09 02:53 17,920 -c--a-w c:\program files\Common Files\IRASRIAL.DLL
2007-09-16 06:35 66,408 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
2007-09-16 06:35 54,112 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-09-16 06:35 34,688 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
2007-09-16 06:35 46,456 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-09-16 06:35 171,880 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-08-26 16:52 32,768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082620080827\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-05_10.43.09.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2009-01-06 14:33:44 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
- 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-06 14:33:44 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~2\PSFree.exe" [2005-03-17 536576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
"PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-04 196608]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-07-08 249856]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
"DDCActiveMenu"="c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2001-10-02 94208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"S3TRAY2"="S3tray2.exe" [2001-10-04 c:\windows\SYSTEM32\S3tray2.exe]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\SYSTEM32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-11-13 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= vdrcodec.dll
"VIDC.DVSD"= miroDV2avi.DLL
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
backup=c:\windows\pss\hp center UI.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
backup=c:\windows\pss\hp center.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a
2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCActiveMenu]
2001-10-02 22:23 94208 c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCM]
c--- 2001-10-02 22:21 155648 c:\program files\WildTangent\DDC\DDCManager\DDCMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
c--- 2001-07-25 13:00 184376 c:\program files\Microsoft Money\System\Money Express.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a
2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage]
--a
1999-10-14 11:50 53248 c:\program files\Caere\OmniPagePro10.0\OPware32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneTouch Monitor]
--a
2002-05-20 07:17 86016 c:\program files\Visioneer OneTouch\OneTouchMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 pavboot;pavboot;c:\windows\SYSTEM32\drivers\pavboot.sys [2009-01-03 28544]
R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-27 203280]
S4 0040461230474749mcinstcleanup;McAfee Application Installer Cleanup (0040461230474749);c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - InCDrec
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2008-12-27 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-12-27 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
.
Supplementary Scan
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://srch-us4.hpwis.com/
mSearch Bar = hxxp://srch-us4.hpwis.com/
uInternet Settings,ProxyOverride = localhost
Trusted Zone: *.internet
Trusted Zone: *.mcafee.com
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
c:\windows\Downloaded Program Files\sysreqlab.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-06 09:57:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
DLLs Loaded Under Running Processes
- - - - - - - > 'winlogon.exe'(668)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2009-01-06 10:01:37
ComboFix-quarantined-files.txt 2009-01-06 15:00:19
ComboFix2.txt 2009-01-05 15:45:37
Pre-Run: 83,635,527,680 bytes free
Post-Run: 83,582,976,000 bytes free
281 --- E O F --- 2008-12-18 21:59:33
I need you to open Notepad again, and copy and paste the following:
Save this as CFScript2.txt, in the same location as ComboFix.exe which is on the Desktop.
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt along with a fresh Panda ActiveScan log in your next reply please.
*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*
ComboFix 09-01-05.01 - Owner 2009-01-07 10:25:45.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.211 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript2.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
FILE ::
c:\gatorpatch.log
c:\keys.ini
c:\temp\fleok
c:\temp\salm_kyf.dat
c:\temp\salmau.dat
c:\windows\inf\msview.inf
c:\windows\system32\vmss
c:\windows\system32\wsxsvc
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\gatorpatch.log
c:\keys.ini
c:\program files\Dream Day Wedding - Married in Manhattan\
c:\program files\Dream Day Wedding - Married in Manhattan\\activation_info.xml
c:\program files\Dream Day Wedding - Married in Manhattan\\Bathroom_a6.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Bedroom_a1.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\bfgstate.xml
c:\program files\Dream Day Wedding - Married in Manhattan\\Central_Park_s16.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Cloud_Nine_Travel_s6.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\data.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Desk_a2.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Dream Day Wedding - Married in Manhattan.exe
c:\program files\Dream Day Wedding - Married in Manhattan\\Empire_Bridal_Crisis_s12.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Empire_Bridal_s9.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\FeliCitySpa_escape_e1.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\FeliCitySpa_s2.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Flora_crisis_s11.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Flora_s5.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\fmodex.dll
c:\program files\Dream Day Wedding - Married in Manhattan\\Grand_Ballroom_s8.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Heirloom_Stationery_s10.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Honeymoon_Italy_s23.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bathroom_a6_7.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bathroom_a6_8.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bedroom_a1_1.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bedroom_a1_2.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Bedroom_a1_3.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Central_Park_s16.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Cloud_Nine_Travel_s6.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Desk_a2_4.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Desk_a2_5.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Desk_a2_6.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Empire_Bridal_Crisis_s12.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Empire_Bridal_s9.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\FeliCitySpa_escape_e1.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\FeliCitySpa_s2.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Flora_crisis_s11.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Flora_s5.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Grand_Ballroom_s8.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Heirloom_Stationery_s10.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Honeymoon_Italy_s23.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Kitchen_a4_7.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Kitchen_a4_8.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\La_Creme_Bakery_crisis_s7.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\La_Creme_Bakery_s1.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Living_room_A_a5_4.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Living_room_A_a5_5.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Living_room_A_a5_6.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\living_room_a3_1.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\living_room_a3_2.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\living_room_a3_3.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Lux_Photo_Design_s19.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Magician's_cabinet_escape_e2.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Party_Rentals_s3.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Pennys_Flowers_crisis_s18.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Pennys_Flowers_s14.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Sabrinas_Gown_Butique_s20.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Sabrinas_Wedding_Crisis_s22.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Savory_Catering_escape_e3.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Savory_Catering_s15.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Subway_escape_e4.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Subway_s4.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Sugarplum_Crisis_s21.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Sugarplum_s17.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\ambient\Tahiti_s13.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Attic_TutorialDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Attic_WinDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_afterBAIdialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_Before_Honeymoon.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_crisiswondialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Book_FocusTestOver.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_gamewondialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Book_HouseCompleteDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_levelwondialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_magazinedialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_tutorialcrisisdialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_tutorialcrisisdialogB.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_tutorialdialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\book_tutorialintrodialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CAS_ConfirmSkipDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CBook.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CBuildObject.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CGameSlotHold.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CIrp.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CIrpMan.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Con_GameMenuDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Con_LoseDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\con_tutorialdialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\con_tutorialmixerdialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Con_WinDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\connectionmap.xml
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\connections.xml
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\ConPanel.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CreditsDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CRollHoldChoice.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CTraceEffectMovie.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\CVector2.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\FloristTransition.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_BadClickDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\game_bluebirddialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_ConfirmPanicDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_GiftFoundDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_InApartmentDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_InApartmentDialogB.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_InEscapeDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_LoseDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_OutApartmentDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_OutEscapeDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_OverDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_PhoneDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_PhoneFoundDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_PhoneLostDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_RegistryIntroDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_SecretBluebirdDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TicketCloseDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialBigHintDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialBluebirdDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialCASItemDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialCASReminderDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialDogSlowDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialHintDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialHowToPlayAppDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialInventoryDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_TutorialSuperclueDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_WinDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Game_WrongItemUsageDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\GameMenuDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\helpdialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\ISpyPanel.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\ISpyPanel_esc.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\ItemMouseButton.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LevelIntroDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_LoseDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_TutorialDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_TutorialTwoDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_WinDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkGame_WinHoneymoonDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\LinkPanel.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\mainmenudialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\menu_confirmdeletedialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Menu_ConfirmInGameQuitDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\menu_confirmquitdialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\menu_highscoresdialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Menu_ProfileDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\menu_refusedeletedialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Minigame_ConfirmQuitDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Minigame_SolveDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\MiniGameEffects.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\OptionsDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\PartMouseButton.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\playdemodialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Refinish_TutorialDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Refinish_WinDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\RSVP_CardPlacingDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\RSVP_ConfirmResetDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\settings.xml
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\SlidersCell.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StandardMouseButton.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StandardRadioButton.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StateMachine.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StickMouseButton.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\story_tutorialdialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\story_tutorialdialogB.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Story_TutorialSpecialItemDialog.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\StoryEffects.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\Transitions.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\input\script\util.lua
c:\program files\Dream Day Wedding - Married in Manhattan\\items_animations.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Kitchen_a4.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\La_Creme_Bakery_crisis_s7.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\La_Creme_Bakery_s1.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\LaunchGame.bfg
c:\program files\Dream Day Wedding - Married in Manhattan\\Living_room_A_a5.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\living_room_a3.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Lux_Photo_Design_s19.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Magician_cabinet_escape_e2.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\MiniGameChooser.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\OberonSplash.dll
c:\program files\Dream Day Wedding - Married in Manhattan\\particles.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\partner_splash.jpg
c:\program files\Dream Day Wedding - Married in Manhattan\\Party_Rentals_s3.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Pennys_Flowers_crisis_s18.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Pennys_Flowers_s14.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\pics\60x40.jpg
c:\program files\Dream Day Wedding - Married in Manhattan\\pics\80x80.jpg
c:\program files\Dream Day Wedding - Married in Manhattan\\pics\feature.jpg
c:\program files\Dream Day Wedding - Married in Manhattan\\pipes.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\rsvp.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Sabrinas_Gown_Butique_s20.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Sabrinas_Wedding_Crisis_s22.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Savory_Catering_escape_e3.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Savory_Catering_s15.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Splash.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\storygame.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Subway_escape_e4.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Subway_s4.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Sugarplum_Crisis_s21.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Sugarplum_s17.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\SwiftShader.dll
c:\program files\Dream Day Wedding - Married in Manhattan\\SwiftShader.ini
c:\program files\Dream Day Wedding - Married in Manhattan\\Tahiti_s13.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\ui.dat
c:\program files\Dream Day Wedding - Married in Manhattan\\Uninstall.exe
c:\program files\Dream Day Wedding - Married in Manhattan\\UnlockGame.bfg
c:\program files\Dream Day Wedding - Married in Manhattan\\vcwcmrq.exe
c:\program files\iWin Games
c:\program files\iWin Games\AdminWorker.exe
c:\program files\iWin Games\DesktopAlerts.exe
c:\program files\iWin Games\firefox\chrome\iwinarcade.jar
c:\program files\iWin Games\firefox\install.rdf
c:\program files\iWin Games\ftdownload.dat
c:\program files\iWin Games\host.cfg
c:\program files\iWin Games\iWinGames.exe
c:\program files\iWin Games\pages\alert32x32.gif
c:\program files\iWin Games\pages\blank.html
c:\program files\iWin Games\pages\blank2.html
c:\program files\iWin Games\pages\error.html
c:\program files\iWin Games\pages\iwin_logo.gif
c:\program files\iWin Games\pages\login.html
c:\program files\iWin Games\pages\maintenance.html
c:\program files\iWin Games\pages\offline_tag.gif
c:\program files\iWin Games\pages\offlineBg.gif
c:\program files\iWin Games\sounds\animation.wav
c:\program files\iWin Games\sounds\animationBack.wav
c:\program files\iWin Games\sounds\button_click.wav
c:\program files\iWin Games\sounds\download_completed.wav
c:\program files\iWin Games\sounds\start.wav
c:\program files\iWin Games\Uninstall.exe
c:\program files\iWin Games\WebInstaller.exe
c:\program files\iWin Games\WebUpdater.bmp
c:\program files\iWin Games\WebUpdater.exe
c:\program files\iWin.com
c:\program files\iWin.com\Mystery of the Mummy\GLWorker.exe
c:\program files\lycos
c:\temp\salm_kyf.dat
c:\temp\salmau.dat
.
((((((((((( Files Created from 2008-12-07 to 2009-01-07 )))))))))))))))))
.
2009-01-06 19:03 . 2009-01-06 19:03 <DIR> d
c:\documents and settings\All Users\Application Data\SpecialBit
2009-01-04 13:22 . 2009-01-04 13:22 <DIR> d
c:\program files\Trend Micro
2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d
c:\program files\Panda Security
2009-01-03 17:50 . 2008-06-19 17:24 28,544 --a
c:\windows\SYSTEM32\drivers\pavboot.sys
2009-01-03 17:12 . 2009-01-03 17:13 <DIR> d
c:\program files\Haunted Hotel II - Believe the Lies
2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
c:\documents and settings\Owner\Application Data\blg
2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
c:\documents and settings\All Users\Application Data\blg
2008-12-29 20:26 . 2008-12-29 20:26 <DIR> d
c:\documents and settings\Owner\Freeze Tag - Dream Machine
2008-12-29 16:42 . 2008-12-29 16:44 <DIR> d
c:\program files\Mystery in London
2008-12-27 19:52 . 2008-12-27 19:52 <DIR> d
c:\documents and settings\Owner\Application Data\Cat's Eye Games
2008-12-27 19:44 . 2008-12-27 19:44 <DIR> d
c:\documents and settings\All Users\Application Data\Arkadium
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\Suspects and Clues Prefs
2008-12-27 19:26 . 2008-12-27 19:27 <DIR> d
c:\documents and settings\Owner\Application Data\Suspects and Clues Players
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\Spinapse
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\IOMediaSupport6SZZ001s
2008-12-27 15:27 . 2008-12-27 15:28 <DIR> d
c:\program files\Suspects and Clues
2008-12-27 09:15 . 2008-12-27 09:15 <DIR> d
c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-12-27 09:15 . 2009-01-07 09:03 7,113 --a
c:\windows\SYSTEM32\Config.MPF
2008-12-27 09:10 . 2007-11-22 06:44 201,320 --a
c:\windows\SYSTEM32\drivers\mfehidk.sys
2008-12-27 09:10 . 2007-07-13 06:20 113,952 --a
c:\windows\SYSTEM32\drivers\Mpfp.sys
2008-12-27 09:10 . 2007-11-22 06:44 79,304 --a
c:\windows\SYSTEM32\drivers\mfeavfk.sys
2008-12-27 09:10 . 2007-12-02 12:51 40,488 --a
c:\windows\SYSTEM32\drivers\mfesmfk.sys
2008-12-27 09:10 . 2007-11-22 06:44 35,240 --a
c:\windows\SYSTEM32\drivers\mfebopk.sys
2008-12-27 09:10 . 2007-11-22 06:44 33,832 --a
c:\windows\SYSTEM32\drivers\mferkdk.sys
2008-12-27 09:09 . 2008-12-27 09:09 <DIR> d
c:\program files\McAfee.com
2008-12-27 09:08 . 2008-12-27 09:14 <DIR> d
c:\program files\McAfee
2008-12-27 09:08 . 2008-12-27 09:10 <DIR> d
c:\program files\Common Files\McAfee
2008-12-26 20:19 . 2008-12-27 09:15 <DIR> d
c:\documents and settings\All Users\Application Data\McAfee
2008-12-24 16:01 . 2009-01-05 19:04 <DIR> d
c:\program files\Mystery Case Files - Return to Ravenhearst
2008-12-20 20:18 . 2006-10-22 12:22 208,896 --a
c:\windows\SYSTEM32\nvudisp.exe
2008-12-20 20:18 . 2009-01-07 09:00 88,566 --a
c:\windows\SYSTEM32\nvapps.xml
2008-12-20 20:18 . 2006-10-22 12:22 17,056 --a
c:\windows\SYSTEM32\nvdisp.nvu
2008-12-20 20:17 . 2008-12-20 20:17 <DIR> d
C:\NVIDIA
2008-12-20 20:17 . 2006-10-22 15:06 208,896 --a
c:\windows\SYSTEM32\NVUNINST.EXE
2008-12-20 20:14 . 2008-12-20 20:14 <DIR> d
c:\program files\SystemRequirementsLab
2008-12-20 19:56 . 2008-05-30 14:11 3,850,760 --a
c:\windows\SYSTEM32\D3DX9_38.dll
2008-12-20 19:55 . 2005-05-26 15:34 2,297,552 --a
c:\windows\SYSTEM32\d3dx9_26.dll
2008-12-20 19:49 . 2008-12-20 19:49 <DIR> d
c:\windows\Logs
2008-12-20 18:55 . 2008-12-20 18:55 <DIR> d
c:\documents and settings\All Users\Application Data\AdventureChronicles1
2008-12-20 18:35 . 2008-12-20 18:35 <DIR> d
c:\documents and settings\All Users\Application Data\PlayPond
2008-12-12 19:25 . 2008-12-12 19:25 <DIR> d
c:\program files\Caere
.
((((((((((((((((((( Find3M Report )))))))))))))))))))))))
.
2009-01-07 14:00
d
w c:\program files\lg_fwupdate
2009-01-07 00:47
d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-07 00:32
d
w c:\documents and settings\All Users\Application Data\Sandlot Games
2009-01-06 14:31
d
w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-06 01:53
d
w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2009-01-02 00:52
d
w c:\program files\SpywareBlaster
2008-12-21 23:52
d
w c:\program files\Google
2008-12-21 18:27
d
w c:\documents and settings\LocalService\Application Data\SACore
2008-12-13 06:40 3,593,216
w c:\windows\SYSTEM32\dllcache\mshtml.dll
2008-12-13 00:43
d
w c:\program files\RealArcade
2008-12-10 21:42
d
w c:\program files\Val`Gor
2008-12-10 21:00
d
w c:\documents and settings\Owner\Application Data\Games
2008-12-05 23:28
d
w c:\documents and settings\Owner\Application Data\PlayFirst
2008-12-05 23:28
d
w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-03 23:48
d
w c:\documents and settings\All Users\Application Data\NeptunesAdve
2008-12-03 23:26
d
w c:\documents and settings\Owner\Application Data\Shape games
2008-12-03 21:15
d
w c:\documents and settings\Owner\Application Data\MysteryStudio
2008-12-03 00:28
d
w c:\documents and settings\All Users\Application Data\Alawar Stargaze
2008-11-25 00:10
d
w c:\program files\Escape The Museum
2008-11-23 19:30
d
w c:\documents and settings\Owner\Application Data\Gold Casual Games
2008-11-23 19:30
d
w c:\documents and settings\All Users\Application Data\Gold Casual Games
2008-11-23 16:28
d
w c:\program files\Spybot - Search & Destroy
2008-11-21 20:59
d
w c:\documents and settings\Owner\Application Data\Gogii Games
2008-11-21 20:59
d
w c:\documents and settings\All Users\Application Data\Gogii Games
2008-11-18 21:36
d
w c:\documents and settings\Owner\Application Data\Artogon
2008-11-17 01:17
d
w c:\documents and settings\Owner\Application Data\cerasus.media
2008-10-27 15:04 70,992 ----a-w c:\windows\SYSTEM32\XAPOFX1_2.dll
2008-10-27 15:04 514,384 ----a-w c:\windows\SYSTEM32\XAudio2_3.dll
2008-10-27 15:04 235,856 ----a-w c:\windows\SYSTEM32\xactengine3_3.dll
2008-10-27 15:04 23,376 ----a-w c:\windows\SYSTEM32\X3DAudio1_5.dll
2008-10-24 11:21 455,296
w c:\windows\SYSTEM32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720
w c:\windows\SYSTEM32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\dllcache\cdm.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\dllcache\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
2008-10-16 13:11 70,656
w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824
w c:\windows\SYSTEM32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408
w c:\windows\SYSTEM32\dllcache\netapi32.dll
2008-10-15 07:06 633,632
w c:\windows\SYSTEM32\dllcache\iexplore.exe
2008-10-15 07:04 161,792
w c:\windows\SYSTEM32\dllcache\ieakui.dll
2008-10-10 09:52 452,440 ----a-w c:\windows\SYSTEM32\d3dx10_40.dll
2008-10-10 09:52 4,379,984 ----a-w c:\windows\SYSTEM32\D3DX9_40.dll
2008-10-10 09:52 2,036,576 ----a-w c:\windows\SYSTEM32\D3DCompiler_40.dll
2008-07-08 02:12 774,144 -c--a-w c:\program files\RngInterstitial.dll
2008-02-26 19:53 0 -c--a-w c:\program files\temp01
2006-06-16 00:24 308 -c--a-w c:\documents and settings\Owner\Application Data\bbbconfig.dat
2005-03-28 16:42 284 -c--a-w c:\documents and settings\Owner\Application Data\ViewerApp.dat
2002-05-20 12:19 61,440 -c--a-w c:\windows\INF\i386\onetUSD.dll
2002-05-16 12:22 36,864 -c--a-w c:\windows\INF\i386\Vizmicro.dll
2002-05-16 12:21 286,720 -c--a-w c:\windows\INF\i386\rtscan.dll
2002-05-16 12:20 172,032 -c--a-w c:\windows\INF\i386\viceo.dll
2001-08-03 22:29 13,824 -c--a-w c:\windows\INF\i386\Usbscan.sys
1998-12-09 02:53 99,840 -c--a-w c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 70,144 -c--a-w c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 48,640 -c--a-w c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 31,744 -c--a-w c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 186,368 -c--a-w c:\program files\Common Files\IRAREG.DLL
1998-12-09 02:53 17,920 -c--a-w c:\program files\Common Files\IRASRIAL.DLL
2007-09-16 06:35 66,408 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
2007-09-16 06:35 54,112 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-09-16 06:35 34,688 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
2007-09-16 06:35 46,456 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-09-16 06:35 171,880 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-08-26 16:52 32,768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082620080827\index.dat
.
((((((((((((((( snapshot@2009-01-05_10.43.09.82 )))))))))))))
.
- 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2009-01-07 14:07:00 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
- 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-07 14:07:00 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
(((((((((((((((( Reg Loading Points ))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~2\PSFree.exe" [2005-03-17 536576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
"PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-04 196608]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-07-08 249856]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
"DDCActiveMenu"="c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2001-10-02 94208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"S3TRAY2"="S3tray2.exe" [2001-10-04 c:\windows\SYSTEM32\S3tray2.exe]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\SYSTEM32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-11-13 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= vdrcodec.dll
"VIDC.DVSD"= miroDV2avi.DLL
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
backup=c:\windows\pss\hp center UI.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
backup=c:\windows\pss\hp center.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a
2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCActiveMenu]
2001-10-02 22:23 94208 c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCM]
c--- 2001-10-02 22:21 155648 c:\program files\WildTangent\DDC\DDCManager\DDCMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
c--- 2001-07-25 13:00 184376 c:\program files\Microsoft Money\System\Money Express.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a
2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage]
--a
1999-10-14 11:50 53248 c:\program files\Caere\OmniPagePro10.0\OPware32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneTouch Monitor]
--a
2002-05-20 07:17 86016 c:\program files\Visioneer OneTouch\OneTouchMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 pavboot;pavboot;c:\windows\SYSTEM32\drivers\pavboot.sys [2009-01-03 28544]
R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-27 203280]
S4 0040461230474749mcinstcleanup;McAfee Application Installer Cleanup (0040461230474749);c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - InCDrec
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2008-12-27 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-12-27 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
.
Supplementary Scan
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://srch-us4.hpwis.com/
mSearch Bar = hxxp://srch-us4.hpwis.com/
uInternet Settings,ProxyOverride = localhost
Trusted Zone: *.internet
Trusted Zone: *.mcafee.com
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
c:\windows\Downloaded Program Files\sysreqlab.osd
.
*********************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-07 10:32:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
********************
DLLs Loaded Under Running Processes
- - - - - - - > 'winlogon.exe'(676)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2009-01-07 10:40:09
ComboFix-quarantined-files.txt 2009-01-07 15:38:13
ComboFix2.txt 2009-01-06 15:01:40
ComboFix3.txt 2009-01-05 15:45:37
Pre-Run: 83,703,099,392 bytes free
Post-Run: 83,633,156,096 bytes free
521 --- E O F --- 2008-12-18 21:59:33
;****************************************************************
ANALYSIS: 2009-01-07 15:39:41
PROTECTIONS: 2
MALWARE: 9
SUSPECTS: 7
;*******************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;=========================================================================================================================================McAFee Internet Security Suite 2007 8.1 No Yes
McAfee VirusScan Plus 12.1 No No
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00020302 adware/ncase Adware No 0 Yes No c:\temp\fleok
00027660 adware/savenow Adware No 0 Yes No c:\windows\system32\wsxsvc
00144935 Adware/IPInsight Adware No 0 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP171\A0028098.inf
00521370 Spyware/Iehelp Spyware No 1 No No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinGamesHookIE.dll]
00521370 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP150\A0022886.dll
02893773 Spyware/Iehelp Spyware No 1 Yes No C:\Qoobox\Quarantine\C\Program Files\iWin Games\AdminWorker.exe.vir
02893773 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP173\A0028392.exe
02893774 Spyware/Iehelp Spyware No 1 Yes No C:\Qoobox\Quarantine\C\Program Files\iWin Games\WebInstaller.exe.vir
02893774 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP173\A0028397.exe
02893775 Spyware/Iehelp Spyware No 1 No No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinArcadeLauncher.exe]
02893775 Spyware/Iehelp Spyware No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP150\A0022885.exe
03074964 Trj/CI.A Virus/Trojan No 0 Yes No C:\Documents and Settings\Owner\Desktop\ComboFix.exe
04396338 W32/Gaobot.OXI.worm Virus/Worm No 1 Yes No C:\System Volume Information\_restore{0A438C3B-A487-4C6D-850C-C76CC3327FD0}\RP173\A0028391.exe
04396338 W32/Gaobot.OXI.worm Virus/Worm No 1 Yes No C:\Qoobox\Quarantine\C\Program Files\Dream Day Wedding - Married in Manhattan\vcwcmrq.exe.vir
;===================================================================================================================================================================================
SUSPECTS
Sent Location `}
;===================================================================================================================================================================================
No C:\hp\bin\ProcessLogger.exe `}
No C:\Program Files\Discovery - A Seek and Find Adventure\Discovery.exe `}
No C:\Program Files\Discovery - A Seek and Find Adventure\npqxpgj.exe `}
No C:\Program Files\Hidden Expedition - Amazon\vdztdsj.exe `}
No C:\Program Files\Hidden Secrets - The Nightmare\wnhbdgs.exe `}
No C:\Program Files\iWin.com Games\Mysteryville\iWinGamesSetupR.exe[iWinGames.exe] `}
No C:\Program Files\Mystery Case Files - Return to Ravenhearst\dppxxpn.exe `}
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description `}
;=========================================================================================================================================================================================================================================
Save this as CFScript3.txt, in the same location as ComboFix.exe which is on the Desktop.
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt
Please copy and paste the ComboFix.txt in your next reply please.
*Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.Altering this script in any way could damage your computer*\
How's your PC running now?
Performed the scan and am posting the ComboFix log below. The PC appears to be running a little quicker, but maybe I just want to believe that it is. Need a little time to tell. However, I've encountered a few things since starting all these scans, et al. For example:
(1) I have two (paid for) games that now no longer run. When I checked them out, I see that they have an extension of ".vir" rather than the typical "exe". The Combo logs indicate that both these games were worked on in the logs. Were these games infected? How do I get them back? If I remove the .vir extension and the game gets executed, do I reinfect, or maybe it won't work at all?
(2) A few directories have been created that I'm not familiar with. Was this part of the cleanup? Can I delete them once I get resolved?
(3) Does ComboFix reset my restore point or will I have to do that?
(4) My antivirus is picking up the file "Tool-NirCmd" as a PUP and it wants me to respond to remove, ignore or quarantine. I researched this file and apparently its part of ComboFix? How should I respond to McAfee's question?
Combo Log follows:
ComboFix 09-01-05.01 - Owner 2009-01-08 13:37:24.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.512.221 [GMT -5:00]
Running from: c:\documents and settings\Owner\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript3.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\iWin.com Games\
c:\program files\iWin.com Games\\Mysteryville\BASS.DLL
c:\program files\iWin.com Games\\Mysteryville\data\backs\back01.jpg
c:\program files\iWin.com Games\\Mysteryville\data\backs\back02.jpg
c:\program files\iWin.com Games\\Mysteryville\data\backs\back03.jpg
c:\program files\iWin.com Games\\Mysteryville\data\backs\back04.jpg
c:\program files\iWin.com Games\\Mysteryville\data\backs\back05.jpg
c:\program files\iWin.com Games\\Mysteryville\data\backs\back06.jpg
c:\program files\iWin.com Games\\Mysteryville\data\backs\back07.jpg
c:\program files\iWin.com Games\\Mysteryville\data\backs\back08.jpg
c:\program files\iWin.com Games\\Mysteryville\data\backs\back09.jpg
c:\program files\iWin.com Games\\Mysteryville\data\effects\click.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\effect01.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\effect02.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\endtime1.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\fieldeffect.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\gametip.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\gametip2.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\gametipclick.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\levelc.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\miss.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\ring1.par
c:\program files\iWin.com Games\\Mysteryville\data\effects\timebegin.par
c:\program files\iWin.com Games\\Mysteryville\data\font.dat
c:\program files\iWin.com Games\\Mysteryville\data\jpeg.dat
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage01\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage01\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage02\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage02\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage03\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage03\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage04\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage04\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage05\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage05\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage06\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage06\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage07\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage07\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage08\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage08\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage09\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage09\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage10\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage10\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage11\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage11\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage12\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage12\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage13\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage13\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage14\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage14\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage15\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage15\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage16\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage16\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage17\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage17\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage18\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage18\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage19\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage19\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage20\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage20\level_02.lev
c:\program files\iWin.com Games\\Mysteryville\data\levels\stage21\level_01.lev
c:\program files\iWin.com Games\\Mysteryville\data\loadbar.jpg
c:\program files\iWin.com Games\\Mysteryville\data\loadscreen.jpg
c:\program files\iWin.com Games\\Mysteryville\data\map_mask.dat
c:\program files\iWin.com Games\\Mysteryville\data\music\dialog1.ogg
c:\program files\iWin.com Games\\Mysteryville\data\music\dialog2.ogg
c:\program files\iWin.com Games\\Mysteryville\data\music\dialog3.ogg
c:\program files\iWin.com Games\\Mysteryville\data\music\music1.ogg
c:\program files\iWin.com Games\\Mysteryville\data\music\music2.ogg
c:\program files\iWin.com Games\\Mysteryville\data\music\music3.ogg
c:\program files\iWin.com Games\\Mysteryville\data\music\music4.ogg
c:\program files\iWin.com Games\\Mysteryville\data\objects\objects.dat
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_badagent.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_barwoman.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_chinee.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_curator.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_fortuneteller.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_ghost.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_goodagent.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_monk.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_pilot.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_professor.jpg
c:\program files\iWin.com Games\\Mysteryville\data\pers\_a_sheriff.jpg
c:\program files\iWin.com Games\\Mysteryville\data\settings.txt
c:\program files\iWin.com Games\\Mysteryville\data\settings\hiscore.dat
c:\program files\iWin.com Games\\Mysteryville\data\settings\profiles.dat
c:\program files\iWin.com Games\\Mysteryville\data\settings\records.dat
c:\program files\iWin.com Games\\Mysteryville\data\settings\settings.dat
c:\program files\iWin.com Games\\Mysteryville\data\sounds\chpok1.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\defeat.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\find.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\levelcomplete.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\menu.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\menu2.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\miss_full.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\miss_one.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\timeup.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\tip_full.ogg
c:\program files\iWin.com Games\\Mysteryville\data\sounds\tip_use.ogg
c:\program files\iWin.com Games\\Mysteryville\data\splash1.jpg
c:\program files\iWin.com Games\\Mysteryville\data\splash2.jpg
c:\program files\iWin.com Games\\Mysteryville\data\targa.dat
c:\program files\iWin.com Games\\Mysteryville\data\texts.dat
c:\program files\iWin.com Games\\Mysteryville\data\txt\1\classicnames.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\1\comics.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\1\credits.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\1\menutext.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\1\persdesc.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\1\strings.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\1\tips.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\2\classicnames.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\2\comics.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\2\credits.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\2\menutext.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\2\persdesc.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\2\strings.txt
c:\program files\iWin.com Games\\Mysteryville\data\txt\2\tips.txt
c:\program files\iWin.com Games\\Mysteryville\iWinGamesSetupR.exe
c:\program files\iWin.com Games\\Mysteryville\mysteryville.exe
c:\program files\iWin.com Games\\Mysteryville\Uninstall.exe
c:\temp\fleok
c:\windows\system32\wsxsvc
c:\windows\system32\wsxsvc\License.txt
c:\windows\system32\wsxsvc\uninstall.html
.
((((((((((((((((((((((((( Files Created from 2008-12-08 to 2009-01-08 )))))))))))))))))))))))))))))))
.
2009-01-06 19:03 . 2009-01-06 19:03 <DIR> d
c:\documents and settings\All Users\Application Data\SpecialBit
2009-01-04 13:22 . 2009-01-04 13:22 <DIR> d
c:\program files\Trend Micro
2009-01-03 17:50 . 2009-01-03 17:50 <DIR> d
c:\program files\Panda Security
2009-01-03 17:50 . 2008-06-19 17:24 28,544 --a
c:\windows\SYSTEM32\drivers\pavboot.sys
2009-01-03 17:12 . 2009-01-03 17:13 <DIR> d
c:\program files\Haunted Hotel II - Believe the Lies
2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
c:\documents and settings\Owner\Application Data\blg
2009-01-01 14:31 . 2009-01-01 14:31 <DIR> d
c:\documents and settings\All Users\Application Data\blg
2008-12-29 20:26 . 2008-12-29 20:26 <DIR> d
c:\documents and settings\Owner\Freeze Tag - Dream Machine
2008-12-29 16:42 . 2008-12-29 16:44 <DIR> d
c:\program files\Mystery in London
2008-12-27 19:52 . 2008-12-27 19:52 <DIR> d
c:\documents and settings\Owner\Application Data\Cat's Eye Games
2008-12-27 19:44 . 2008-12-27 19:44 <DIR> d
c:\documents and settings\All Users\Application Data\Arkadium
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\Suspects and Clues Prefs
2008-12-27 19:26 . 2008-12-27 19:27 <DIR> d
c:\documents and settings\Owner\Application Data\Suspects and Clues Players
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\Spinapse
2008-12-27 19:26 . 2008-12-27 19:26 <DIR> d
c:\documents and settings\Owner\Application Data\IOMediaSupport6SZZ001s
2008-12-27 15:27 . 2008-12-27 15:28 <DIR> d
c:\program files\Suspects and Clues
2008-12-27 09:15 . 2008-12-27 09:15 <DIR> d
c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-12-27 09:15 . 2009-01-08 08:41 7,113 --a
c:\windows\SYSTEM32\Config.MPF
2008-12-27 09:10 . 2007-11-22 06:44 201,320 --a
c:\windows\SYSTEM32\drivers\mfehidk.sys
2008-12-27 09:10 . 2007-07-13 06:20 113,952 --a
c:\windows\SYSTEM32\drivers\Mpfp.sys
2008-12-27 09:10 . 2007-11-22 06:44 79,304 --a
c:\windows\SYSTEM32\drivers\mfeavfk.sys
2008-12-27 09:10 . 2007-12-02 12:51 40,488 --a
c:\windows\SYSTEM32\drivers\mfesmfk.sys
2008-12-27 09:10 . 2007-11-22 06:44 35,240 --a
c:\windows\SYSTEM32\drivers\mfebopk.sys
2008-12-27 09:10 . 2007-11-22 06:44 33,832 --a
c:\windows\SYSTEM32\drivers\mferkdk.sys
2008-12-27 09:09 . 2008-12-27 09:09 <DIR> d
c:\program files\McAfee.com
2008-12-27 09:08 . 2008-12-27 09:14 <DIR> d
c:\program files\McAfee
2008-12-27 09:08 . 2008-12-27 09:10 <DIR> d
c:\program files\Common Files\McAfee
2008-12-26 20:19 . 2008-12-27 09:15 <DIR> d
c:\documents and settings\All Users\Application Data\McAfee
2008-12-24 16:01 . 2009-01-05 19:04 <DIR> d
c:\program files\Mystery Case Files - Return to Ravenhearst
2008-12-20 20:18 . 2006-10-22 12:22 208,896 --a
c:\windows\SYSTEM32\nvudisp.exe
2008-12-20 20:18 . 2009-01-08 08:38 88,566 --a
c:\windows\SYSTEM32\nvapps.xml
2008-12-20 20:18 . 2006-10-22 12:22 17,056 --a
c:\windows\SYSTEM32\nvdisp.nvu
2008-12-20 20:17 . 2008-12-20 20:17 <DIR> d
C:\NVIDIA
2008-12-20 20:17 . 2006-10-22 15:06 208,896 --a
c:\windows\SYSTEM32\NVUNINST.EXE
2008-12-20 20:14 . 2008-12-20 20:14 <DIR> d
c:\program files\SystemRequirementsLab
2008-12-20 19:56 . 2008-05-30 14:11 3,850,760 --a
c:\windows\SYSTEM32\D3DX9_38.dll
2008-12-20 19:55 . 2005-05-26 15:34 2,297,552 --a
c:\windows\SYSTEM32\d3dx9_26.dll
2008-12-20 19:49 . 2008-12-20 19:49 <DIR> d
c:\windows\Logs
2008-12-20 18:55 . 2008-12-20 18:55 <DIR> d
c:\documents and settings\All Users\Application Data\AdventureChronicles1
2008-12-20 18:35 . 2008-12-20 18:35 <DIR> d
c:\documents and settings\All Users\Application Data\PlayPond
2008-12-12 19:25 . 2008-12-12 19:25 <DIR> d
c:\program files\Caere
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-08 16:31
d
w c:\documents and settings\All Users\Application Data\Google Updater
2009-01-08 13:38
d
w c:\program files\lg_fwupdate
2009-01-08 01:14
d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-08 01:13
d
w c:\program files\SpywareBlaster
2009-01-07 00:32
d
w c:\documents and settings\All Users\Application Data\Sandlot Games
2009-01-06 01:53
d
w c:\documents and settings\All Users\Application Data\BigFishGamesCache
2008-12-21 23:52
d
w c:\program files\Google
2008-12-21 18:27
d
w c:\documents and settings\LocalService\Application Data\SACore
2008-12-13 06:40 3,593,216
w c:\windows\SYSTEM32\dllcache\mshtml.dll
2008-12-13 00:43
d
w c:\program files\RealArcade
2008-12-10 21:42
d
w c:\program files\Val`Gor
2008-12-10 21:00
d
w c:\documents and settings\Owner\Application Data\Games
2008-12-05 23:28
d
w c:\documents and settings\Owner\Application Data\PlayFirst
2008-12-05 23:28
d
w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-03 23:48
d
w c:\documents and settings\All Users\Application Data\NeptunesAdve
2008-12-03 23:26
d
w c:\documents and settings\Owner\Application Data\Shape games
2008-12-03 21:15
d
w c:\documents and settings\Owner\Application Data\MysteryStudio
2008-12-03 00:28
d
w c:\documents and settings\All Users\Application Data\Alawar Stargaze
2008-11-25 00:10
d
w c:\program files\Escape The Museum
2008-11-23 19:30
d
w c:\documents and settings\Owner\Application Data\Gold Casual Games
2008-11-23 19:30
d
w c:\documents and settings\All Users\Application Data\Gold Casual Games
2008-11-23 16:28
d
w c:\program files\Spybot - Search & Destroy
2008-11-21 20:59
d
w c:\documents and settings\Owner\Application Data\Gogii Games
2008-11-21 20:59
d
w c:\documents and settings\All Users\Application Data\Gogii Games
2008-11-18 21:36
d
w c:\documents and settings\Owner\Application Data\Artogon
2008-11-17 01:17
d
w c:\documents and settings\Owner\Application Data\cerasus.media
2008-10-27 15:04 70,992 ----a-w c:\windows\SYSTEM32\XAPOFX1_2.dll
2008-10-27 15:04 514,384 ----a-w c:\windows\SYSTEM32\XAudio2_3.dll
2008-10-27 15:04 235,856 ----a-w c:\windows\SYSTEM32\xactengine3_3.dll
2008-10-27 15:04 23,376 ----a-w c:\windows\SYSTEM32\X3DAudio1_5.dll
2008-10-24 11:21 455,296
w c:\windows\SYSTEM32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720
w c:\windows\SYSTEM32\dllcache\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\SYSTEM32\dllcache\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\SYSTEM32\dllcache\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\SYSTEM32\dllcache\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\SYSTEM32\dllcache\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\dllcache\cdm.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 19:09 51,224 ----a-w c:\windows\SYSTEM32\dllcache\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\SYSTEM32\dllcache\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
2008-10-16 13:11 70,656
w c:\windows\SYSTEM32\dllcache\ie4uinit.exe
2008-10-16 13:11 13,824
w c:\windows\SYSTEM32\dllcache\ieudinit.exe
2008-10-15 16:34 337,408
w c:\windows\SYSTEM32\dllcache\netapi32.dll
2008-10-15 07:06 633,632
w c:\windows\SYSTEM32\dllcache\iexplore.exe
2008-10-15 07:04 161,792
w c:\windows\SYSTEM32\dllcache\ieakui.dll
2008-10-10 09:52 452,440 ----a-w c:\windows\SYSTEM32\d3dx10_40.dll
2008-10-10 09:52 4,379,984 ----a-w c:\windows\SYSTEM32\D3DX9_40.dll
2008-10-10 09:52 2,036,576 ----a-w c:\windows\SYSTEM32\D3DCompiler_40.dll
2008-07-08 02:12 774,144 -c--a-w c:\program files\RngInterstitial.dll
2008-02-26 19:53 0 -c--a-w c:\program files\temp01
2006-06-16 00:24 308 -c--a-w c:\documents and settings\Owner\Application Data\bbbconfig.dat
2005-03-28 16:42 284 -c--a-w c:\documents and settings\Owner\Application Data\ViewerApp.dat
2002-05-20 12:19 61,440 -c--a-w c:\windows\INF\i386\onetUSD.dll
2002-05-16 12:22 36,864 -c--a-w c:\windows\INF\i386\Vizmicro.dll
2002-05-16 12:21 286,720 -c--a-w c:\windows\INF\i386\rtscan.dll
2002-05-16 12:20 172,032 -c--a-w c:\windows\INF\i386\viceo.dll
2001-08-03 22:29 13,824 -c--a-w c:\windows\INF\i386\Usbscan.sys
1998-12-09 02:53 99,840 -c--a-w c:\program files\Common Files\IRAABOUT.DLL
1998-12-09 02:53 70,144 -c--a-w c:\program files\Common Files\IRAMDMTR.DLL
1998-12-09 02:53 48,640 -c--a-w c:\program files\Common Files\IRALPTTR.DLL
1998-12-09 02:53 31,744 -c--a-w c:\program files\Common Files\IRAWEBTR.DLL
1998-12-09 02:53 186,368 -c--a-w c:\program files\Common Files\IRAREG.DLL
1998-12-09 02:53 17,920 -c--a-w c:\program files\Common Files\IRASRIAL.DLL
2007-09-16 06:35 66,408 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
2007-09-16 06:35 54,112 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-09-16 06:35 34,688 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
2007-09-16 06:35 46,456 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-09-16 06:35 171,880 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-08-26 16:52 32,768 --sha-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008082620080827\index.dat
.
((((((((((((((((((((((((((((( snapshot@2009-01-05_10.43.09.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
+ 2009-01-08 18:34:24 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Cookies\index.dat
- 2009-01-05 14:32:17 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-01-08 18:34:24 32,768 -c--a-w c:\windows\SYSTEM32\config\systemprofile\Local Settings\History\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"PopUpStopperFreeEdition"="c:\progra~1\PANICW~1\POP-UP~2\PSFree.exe" [2005-03-17 536576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"KBD"="c:\hp\KBD\KBD.EXE" [2001-07-06 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2001-06-15 212992]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2001-08-07 143360]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2001-08-07 90112]
"PS2"="c:\windows\system32\ps2.exe" [2001-07-03 81920]
"HPDJ Taskbar Utility"="c:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-04 196608]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-07-08 249856]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2007-03-11 936960]
"DDCActiveMenu"="c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2001-10-02 94208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"S3TRAY2"="S3tray2.exe" [2001-10-04 c:\windows\SYSTEM32\S3tray2.exe]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\SYSTEM32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-11-13 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= vdrcodec.dll
"VIDC.DVSD"= miroDV2avi.DLL
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center UI.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center UI.lnk
backup=c:\windows\pss\hp center UI.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^hp center.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\hp center.lnk
backup=c:\windows\pss\hp center.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Symantec Fax Starter Edition Port.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Symantec Fax Starter Edition Port.lnk
backup=c:\windows\pss\Symantec Fax Starter Edition Port.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a
2008-06-12 01:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCActiveMenu]
2001-10-02 22:23 94208 c:\program files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDCM]
c--- 2001-10-02 22:21 155648 c:\program files\WildTangent\DDC\DDCManager\DDCMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MoneyAgent]
c--- 2001-07-25 13:00 184376 c:\program files\Microsoft Money\System\Money Express.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a
2008-04-13 19:12 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OmniPage]
--a
1999-10-14 11:50 53248 c:\program files\Caere\OmniPagePro10.0\OPware32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneTouch Monitor]
--a
2002-05-20 07:17 86016 c:\program files\Visioneer OneTouch\OneTouchMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R0 pavboot;pavboot;c:\windows\SYSTEM32\drivers\pavboot.sys [2009-01-03 28544]
R4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-27 203280]
S4 0040461230474749mcinstcleanup;McAfee Application Installer Cleanup (0040461230474749);c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\windows\TEMP\004046~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
--- Other Services/Drivers In Memory ---
*Deregistered* - InCDrec
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
2008-12-27 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-12-27 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
.
Supplementary Scan
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://srch-us4.hpwis.com/
mSearch Bar = hxxp://srch-us4.hpwis.com/
uInternet Settings,ProxyOverride = localhost
Trusted Zone: *.internet
Trusted Zone: *.mcafee.com
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\sysreqlab_srl.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
c:\windows\Downloaded Program Files\sysreqlab.osd
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-08 13:44:10
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
DLLs Loaded Under Running Processes
- - - - - - - > 'winlogon.exe'(672)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll
.
Completion time: 2009-01-08 13:48:33
ComboFix-quarantined-files.txt 2009-01-08 18:47:15
ComboFix2.txt 2009-01-07 15:40:15
ComboFix3.txt 2009-01-06 15:01:40
ComboFix4.txt 2009-01-05 15:45:37
Pre-Run: 83,663,224,832 bytes free
Post-Run: 83,605,852,160 bytes free
405 --- E O F --- 2008-12-18 21:59:33
They were detected by Panda ActiveScan as being spyware. However, if you would like to get them back, you can simply move those files back, and change the extension back to .exe.
After we are done with our work here, I will direct you to cleanup the tools that we have used during the fix. ComboFix creates a new System Restore point when it is run. So after everything is done here, you will need to go to System Restore and flush your Restore points.
Yes it is part of ComboFix. You can choose the ignore option as ComboFix is a legitimate tool.
Run your computer for a couple of days, and let me know if any issues remain. Then I'll direct you to clean up all the tools.
OK. Will run PC couple of days and will report back to you on Sunday. FYI: Did a Spybot scan today and found "Virtumonde". I fixed it and hope this helps too. Will talk on Sunday. Thanks!
Hi Chiaz,
I have run the PC for a couple of days and I see a slight improvement. It's not as fast as it was , but it seems better. Per my last text to you, Spybot found Virtumonde, which was removed and that may have caused some of the slowness too? Not totally convinced that something is still not lurking, but.............
If, based on my logs, you feel I'm good to go then I guess we can move forward and remove the tools and do a new system restore point (could use help on these). I'm pretty sure some additional memory wouldn't hurt either.\
What do you think?
Thanks, Gail
This will clear away any of the files and folders that were created by ComboFix.
Go to :
Start > Run then copy and paste the following highlighted text below and click OK.
When ComboFix receives such an instruction, it will do the following:
a) Deletes the following files/folders:
* ComboFix.exe
* %system%\swxcacls.exe
* %system%\swsc.exe
* %system%\VFind.exe
* %system%\moveex.exe
* %system%\swreg.exe
* %systemroot%\catchme.exe
* \ComboFix
* \Qoobox
* \VundoFix Backups
* \Deckard
* \_OTMoveIt
* %systemroot%\erdnt\subs
b) Resets the clock settings.
c) Hides file extensions
d) Hides System/Hidden files
e) Clears System Restore cache and create new Restore point
TeaTimer can sometimes take up lots of resources. If it's bugging you, then I will say disable the feature. I really see no need on having an anti-spyware real-time protection, just have your anti-virus program on whenever you are connected to the internet. Do keep one or two anti-spyware programs on your computer, keep them updated and run a scan with them occasionally.
Just wanted to thank you so much for all your time and assistance. I don't know what we would do without you and others at Icrontic. Thanks again and have a happy and healthy new year! Gail
This topic is now closed. If you wish it reopened, please send a Private Message to Trogan with a link to your thread.
If you are not the user who started this thread, you must start your own Thread instead
_______________________________
Have we helped you with any issues you have had with your PCs or other items? If so, you can now help us by Joining Team 93 and fold for a cure.