rohangpatil Posted October 4, 2007 Report Share Posted October 4, 2007 I've been getting Security warning window.. and when i click on the close button IE 7 opens and site opens.even this site..computing is becoming very irksome..HijackThis (2.0.2) log fileLogfile of Trend Micro HijackThis v2.0.2Scan saved at 11:53:57 PM, on 10/4/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Common Files\Protexis\License Service\PSIService.exeC:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Java\jre1.6.0_02\bin\jusched.exeC:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\HP\QuickPlay\QPService.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exeC:\PROGRA~1\Sony\SONICS~1\SsAAD.exeC:\Program Files\Common Files\InstallShield\UpdateService\issch.exeC:\WINDOWS\system32\igfxtray.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\Program Files\PowerISO\PWRISOVM.EXEC:\WINDOWS\system32\igfxsrvc.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeC:\Program Files\Hp\HP Software Update\HPWuSchd2.exeC:\Program Files\Microsoft Office\Office12\GrooveMonitor.exeC:\Program Files\Winamp\winampa.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\AvaFind\AvaFind.exeC:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exeC:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXEC:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exeC:\Program Files\VisualTaskTips\VisualTaskTips.exeC:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exeC:\Program Files\Google\Google Talk\googletalk.exeC:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exeC:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeC:\PROGRA~1\MOZILL~1\FIREFOX.EXEC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...o&pf=laptopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dllO2 - BHO: MSVPS System - {3ADCBC16-19FA-4C59-9C22-E17C71B5FD7A} - C:\WINDOWS\bndsrwlq.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLLO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dllO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exeO4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exeO4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /StartO4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exeO4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exeO4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [iMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXEO4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNCO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"O4 - HKLM\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exeO4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startupO4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -startO4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostartO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exeO4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXEO4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [AvaFind] "C:\Program Files\AvaFind\AvaFind.exe" /minimizedO4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"O4 - Global Startup: Bluetooth.lnk = ?O4 - Global Startup: VisualTaskTips.lnk = C:\Program Files\VisualTaskTips\VisualTaskTips.exeO8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htmO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dllO9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLLO9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_SG&c=Q306&bd=presario&pf=laptopO16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer...DataManager.CABO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/...tail/DASAct.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{E8C7CA81-1E6D-4D0C-BE56-E5381BE5D0DA}: NameServer = 192.168.1.1O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLLO20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dllO21 - SSODL: msvb - {9CD13CF8-2B77-45E1-9C0D-40B559E3BED3} - C:\WINDOWS\msvb.dllO21 - SSODL: sysdx - {F6B0F9C4-B12D-45B2-ACE4-06C415122EBD} - C:\WINDOWS\sysdx.dllO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeO23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeO23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exeO23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exeO23 - Service: Norton Protection Center Service (NSCService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE (file missing)O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exeO23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exeO23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe--End of file - 13307 bytes Link to post Share on other sites
Andro1d Posted October 9, 2007 Report Share Posted October 9, 2007 Hello and Welcome to BT. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. Sorry for the delay!Step 1Download ComboFix from Here or Here to your Desktop.Double click combofix.exe and follow the prompts.When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next replyNote: Do not mouseclick combofix's window while its running. That may cause it to stallStep 2Download Deckard's System Scanner (DSS) to your Desktop.Close all applications and windows.Double-click on DSS.exe to run it, and follow the prompts.When it has finished, dss will open two Notepads main.txt and extra.txt -- please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply along with the combofix log.Extra Note: When running DSS, some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so. Also, it may happen that your Antivirus flags DSS as suspicious. Please allow the Deckard's System Scanner to run and don't let your Antivirus delete it. (In this case, it may be better to temporary disable your Antivirus) Link to post Share on other sites
rohangpatil Posted October 9, 2007 Author Report Share Posted October 9, 2007 Hi Again!Thanks For the reply!I used to use the laptop with explorer.exe closed. It used to solve my problem partially.. Done as instructed..ComboFix Log File.ComboFix 07-10-09.3 - Rohan 2007-10-09 20:32:07.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.97 [GMT 5.5:30]Running from: C:\Documents and Settings\Rohan\Desktop\ComboFix.exe * Created a new restore point.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).C:\Documents and Settings\Rohan\Desktop\Error Cleaner.urlC:\Documents and Settings\Rohan\Desktop\Privacy Protector.urlC:\Documents and Settings\Rohan\Desktop\Spyware&Malware Protection.urlC:\Documents and Settings\Rohan\Favorites\Error Cleaner.urlC:\Documents and Settings\Rohan\Favorites\Privacy Protector.urlC:\Documents and Settings\Rohan\Favorites\Spyware&Malware Protection.urlC:\Documents and Settings\Rohan\My Documents\Vth sem\sudhakar\Database Management System (ISE-CSE)\100 Q's\Desktop_.iniC:\Documents and Settings\Rohan\My Documents\Vth sem\sudhakar\Database Management System (ISE-CSE)\Desktop_.iniC:\Documents and Settings\Rohan\My Documents\Vth sem\sudhakar\Database Management System (ISE-CSE)\Lesson Plan\Desktop_.iniC:\Documents and Settings\Rohan\My Documents\Vth sem\sudhakar\Database Management System (ISE-CSE)\Notes\Desktop_.iniC:\Documents and Settings\Rohan\My Documents\Vth sem\sudhakar\Lesson Plan\Desktop_.iniC:\Program Files\VideoAccessCodecC:\Program Files\VideoAccessCodec\install.icoC:\Program Files\VideoAccessCodec\Uninstall.exeC:\Program Files\VideoAccessCodec\VideoAccessCodec.ocxC:\WINDOWS\bndsrwlq.dllC:\WINDOWS\dat.txtC:\WINDOWS\main_uninstaller.exeC:\WINDOWS\msvb.dllC:\WINDOWS\netadv.dllC:\WINDOWS\rs.txtC:\WINDOWS\search_res.txtC:\WINDOWS\sysdx.dll.((((((((((((((((((((((((( Files Created from 2007-09-09 to 2007-10-09 ))))))))))))))))))))))))))))))).2007-10-09 20:31 51,200 --a------ C:\WINDOWS\NirCmd.exe2007-10-05 12:54 <DIR> d-------- C:\.Trash-guest2007-10-05 10:20 <DIR> d-------- C:\Program Files\Webroot2007-10-05 09:29 <DIR> d-------- C:\Program Files\Lavasoft2007-10-05 09:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft2007-10-05 09:27 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard2007-10-05 03:58 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys2007-10-04 18:45 <DIR> d-------- C:\Documents and Settings\Rohan\Application Data\Styler2007-10-04 18:40 <DIR> d-------- C:\Program Files\VisualTaskTips2007-10-04 18:40 218,624 --a------ C:\WINDOWS\system32\dllcache\uxtheme.dll2007-10-04 18:18 <DIR> d-------- C:\temp2007-10-04 18:18 <DIR> d-------- C:\Program Files\Common Files\Download Manager2007-10-04 18:18 <DIR> d-------- C:\Program Files\Avex2007-10-04 18:07 <DIR> d-------- C:\Program Files\SystemDefender2007-10-03 20:38 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\WinRAR2007-10-02 22:15 <DIR> d-------- C:\Program Files\TopCoder UML Tool2007-10-02 12:11 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Google2007-10-02 12:08 <DIR> d-------- C:\Documents and Settings\Guest\Application Data\Real2007-09-27 21:38 <DIR> d-------- C:\Program Files\DFX2007-09-27 21:38 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DFX2007-09-27 21:35 <DIR> d-------- C:\Program Files\Winamp2007-09-27 21:35 <DIR> d-------- C:\Documents and Settings\Rohan\Application Data\Winamp2007-09-27 21:35 129,784 --------- C:\WINDOWS\system32\pxafs.dll2007-09-27 21:35 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys2007-09-27 21:35 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys2007-09-27 13:37 <DIR> d-------- C:\Program Files\Trend Micro2007-09-27 13:29 <DIR> d-------- C:\Program Files\ABC Amber LIT Converter2007-09-27 12:20 <DIR> d-------- C:\Program Files\Microsoft Reader2007-09-27 12:20 60,944 --a------ C:\WINDOWS\DASShp.dll2007-09-27 12:17 <DIR> d-------- C:\Documents and Settings\Rohan\Application Data\WinRAR2007-09-26 19:06 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.22007-09-24 00:40 271,224 --a------ C:\WINDOWS\system32\mucltui.dll2007-09-24 00:40 207,736 --a------ C:\WINDOWS\system32\muweb.dll2007-09-23 03:21 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll2007-09-23 03:19 <DIR> d-------- C:\Program Files\MSBuild2007-09-23 03:16 <DIR> d-------- C:\Program Files\Microsoft.NET2007-09-23 03:12 <DIR> d-------- C:\WINDOWS\SHELLNEW2007-09-23 03:09 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help2007-09-23 03:06 <DIR> dr-h----- C:\MSOCache2007-09-21 19:04 <DIR> d-------- C:\Program Files\The KMPlayer2007-09-20 22:21 <DIR> d-------- C:\Documents and Settings\Rohan\Application Data\VMware2007-09-20 22:19 <DIR> d-------- C:\Program Files\VMware2007-09-14 10:53 <DIR> d-------- C:\Program Files\Common Files\Macromedia Shared2007-09-14 10:32 <DIR> d-------- C:\WINDOWS\system32\QuickTime2007-09-14 09:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet2007-09-14 09:45 <DIR> d-------- C:\Program Files\Bonjour2007-09-14 09:29 <DIR> d-------- C:\Program Files\Common Files\Macrovision Shared2007-09-13 19:30 <DIR> d-------- C:\Program Files\Kaspersky Lab2007-09-13 19:30 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab2007-09-13 19:30 19,204,896 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat2007-09-13 19:30 386,592 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat2007-09-13 19:30 82,061 --a------ C:\WINDOWS\system32\drivers\klick.dat2007-09-13 19:30 81,549 --a------ C:\WINDOWS\system32\drivers\klin.dat.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2007-10-09 15:17 37,292 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx2007-10-09 15:17 258,260 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx2007-10-09 12:41 --------- d-----w C:\Documents and Settings\Rohan\Application Data\AvaFind Data2007-10-05 03:51 --------- d-----w C:\Documents and Settings\Rohan\Application Data\uTorrent2007-10-04 13:18 --------- d-----w C:\Program Files\EasyEclipse Expert Java 1.3.02007-09-27 06:50 --------- d--h--w C:\Program Files\InstallShield Installation Information2007-09-22 21:49 --------- d-----w C:\Program Files\Microsoft Works2007-09-15 18:03 --------- d-----w C:\Program Files\Hp2007-09-15 18:02 --------- d-----w C:\Program Files\Hewlett-Packard2007-09-13 13:58 --------- d-----w C:\Program Files\Common Files\Symantec Shared2007-09-13 13:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec2007-09-08 15:38 --------- d-----w C:\Program Files\DAMN NFO Viewer2007-09-08 15:37 --------- d-----w C:\Program Files\BitTyrant2007-09-08 15:22 --------- d-----w C:\Documents and Settings\Rohan\Application Data\BitTyrant2007-09-08 15:22 --------- d-----w C:\Documents and Settings\Rohan\Application Data\Azureus2007-09-08 15:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus2007-09-07 17:55 --------- d-----w C:\Program Files\Common Files\xing shared2007-09-07 17:55 --------- d-----w C:\Program Files\Common Files\Real2007-09-07 17:32 --------- d-----w C:\Documents and Settings\Rohan\Application Data\Real2007-09-07 17:26 --------- d-----w C:\Program Files\Real2007-09-04 14:14 --------- d-----w C:\Documents and Settings\Rohan\Application Data\Subversion2007-08-30 14:23 --------- d-----w C:\Documents and Settings\Rohan\Application Data\Help2007-08-29 10:52 --------- d-----w C:\Program Files\EA SPORTS2007-08-27 16:57 296 ----a-w C:\Documents and Settings\Rohan\Application Data\wklnhst.dat2007-08-25 16:19 --------- d-----w C:\Documents and Settings\Rohan\Application Data\dvdcss2007-08-14 15:41 317,712 ------w C:\MASMsetup.EXE2007-08-14 15:40 2,686,232 ------w C:\vcredist_x86.exe2007-08-10 17:27 --------- d-----w C:\Documents and Settings\Rohan\Application Data\Ahead2007-08-10 09:02 --------- d-----w C:\Program Files\Common Files\LightScribe2007-08-10 08:58 --------- d-----w C:\Program Files\Common Files\Ahead2007-08-10 08:54 --------- d-----w C:\Program Files\Nero2007-08-10 05:50 --------- d-----w C:\Program Files\PowerISO2007-08-10 03:01 --------- d-----w C:\Documents and Settings\Rohan\Application Data\Sonic2007-08-10 03:00 --------- d-----w C:\Documents and Settings\Rohan\Application Data\Leadertech2004-06-01 07:18 295,936 ----a-w C:\Documents and Settings\Rohan\AvaFind.exe.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-02-15 08:19]"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-18 01:59 C:\WINDOWS\system32\CHDAudPropShortcut.exe]"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 10:31]"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-04-11 19:24]"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-23 09:08]"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2006-01-26 13:48]"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 07:53]"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 18:30]"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-04 18:30]"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 18:30]"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2007-10-05 19:14]"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2007-10-05 19:14]"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" []"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 02:36]"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-16 16:15]"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 16:15]"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [2007-01-02 02:52]"LFAgent"="" []"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-06-22 08:32]"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-06-22 08:32]"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-06-22 08:32]"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-01-20 12:39]"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 15:40]"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-09-07 23:24]"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [2007-06-28 12:51]"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47]"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-05-15 03:52]"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 14:55][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-09 23:53]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 02:30]"AvaFind"="C:\Program Files\AvaFind\AvaFind.exe" [2004-06-01 12:48]"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 19:04][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]"DisableRegistryTools"=0 (0x0)[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]"appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dllR2 LF30FS;LF30FS;\??\C:\Program Files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sysR3 HBtnKey;HBtnKey;C:\WINDOWS\system32\DRIVERS\cpqbttn.sysR3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3b4628b-3471-11dc-b0da-806d6172696f}]AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480.**************************************************************************catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2007-10-09 20:49:18Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ... scanning hidden autostart entries ...HKLM\Software\Microsoft\Windows\CurrentVersion\Run Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe?????? ???@???????????????@? ???hX????????@???????@ scanning hidden files ... scan completed successfully hidden files: 0 **************************************************************************.Completion time: 2007-10-09 20:53:22 - machine was rebooted C:\ComboFix-quarantined-files.txt ... 2007-10-09 20:53. --- E O F ---HijackThis Log File.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 9:00:56 PM, on 10/9/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Common Files\Protexis\License Service\PSIService.exeC:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeC:\Program Files\Java\jre1.6.0_02\bin\jusched.exeC:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\HP\QuickPlay\QPService.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exeC:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXEC:\PROGRA~1\Sony\SONICS~1\SsAAD.exeC:\Program Files\Common Files\InstallShield\UpdateService\issch.exeC:\WINDOWS\system32\igfxtray.exeC:\WINDOWS\system32\igfxsrvc.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\Program Files\PowerISO\PWRISOVM.EXEC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeC:\Program Files\Hp\HP Software Update\HPWuSchd2.exeC:\Program Files\Microsoft Office\Office12\GrooveMonitor.exeC:\Program Files\Winamp\winampa.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\AvaFind\AvaFind.exeC:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exeC:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exeC:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...o&pf=laptopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLLO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"O4 - HKLM\..\Run: [hpWirelessAssistant] "C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe"O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exeO4 - HKLM\..\Run: [synTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"O4 - HKLM\..\Run: [QlbCtrl] "C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /StartO4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exeO4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exeO4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [iMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXEO4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNCO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"O4 - HKLM\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exeO4 - HKLM\..\Run: [iSUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startupO4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -startO4 - HKLM\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostartO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exeO4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimizedO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [AvaFind] "C:\Program Files\AvaFind\AvaFind.exe" /minimizedO4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"O4 - Global Startup: Bluetooth.lnk = ?O4 - Global Startup: VisualTaskTips.lnk = C:\Program Files\VisualTaskTips\VisualTaskTips.exeO8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htmO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dllO9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLLO9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_SG&c=Q306&bd=presario&pf=laptopO16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer...DataManager.CABO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/...tail/DASAct.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{E8C7CA81-1E6D-4D0C-BE56-E5381BE5D0DA}: NameServer = 192.168.1.1O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLLO20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dllO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeO23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeO23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exeO23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exeO23 - Service: Norton Protection Center Service (NSCService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE (file missing)O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exeO23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exeO23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe--End of file - 13140 bytes Link to post Share on other sites
rohangpatil Posted October 9, 2007 Author Report Share Posted October 9, 2007 Main.Txt Log file Of DSS.EXEDeckard's System Scanner v20070905.67Run by Rohan on 2007-10-09 21:02:22Computer is in Normal Mode.---------------------------------------------------------------------------------- System Restore --------------------------------------------------------------Successfully created a Deckard's System Scanner Restore Point.-- Last 5 Restore Point(s) --31: 2007-10-09 15:32:30 UTC - RP99 - Deckard's System Scanner Restore Point30: 2007-10-09 15:02:41 UTC - RP98 - Software Distribution Service 3.029: 2007-10-09 15:01:30 UTC - RP97 - ComboFix created restore point28: 2007-10-05 03:59:22 UTC - RP96 - Installed Ad-Aware 200727: 2007-10-04 13:02:53 UTC - RP95 - Automatic Restore Point-- First Restore Point -- 1: 2007-09-08 23:07:25 UTC - RP69 - System CheckpointBacked up registry hives.Performed disk cleanup.Total Physical Memory: 503 MiB (512 MiB recommended).System Drive C: has 6.1 GiB (less than 15%) free.-- HijackThis (run as Rohan.exe) -----------------------------------------------Logfile of Trend Micro HijackThis v2.0.2Scan saved at 9:04:07 PM, on 10/9/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeC:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Common Files\Protexis\License Service\PSIService.exeC:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeC:\Program Files\Java\jre1.6.0_02\bin\jusched.exeC:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\HP\QuickPlay\QPService.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exeC:\PROGRA~1\HPQ\Shared\HPQTOA~1.EXEC:\PROGRA~1\Sony\SONICS~1\SsAAD.exeC:\Program Files\Common Files\InstallShield\UpdateService\issch.exeC:\WINDOWS\system32\igfxtray.exeC:\WINDOWS\system32\igfxsrvc.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\Program Files\PowerISO\PWRISOVM.EXEC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeC:\Program Files\Hp\HP Software Update\HPWuSchd2.exeC:\Program Files\Microsoft Office\Office12\GrooveMonitor.exeC:\Program Files\Winamp\winampa.exeC:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\AvaFind\AvaFind.exeC:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exeC:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exeC:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exeC:\Documents and Settings\Rohan\Desktop\dss.exeC:\PROGRA~1\TRENDM~1\HIJACK~1\Rohan.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...o&pf=laptopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLLO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"O4 - HKLM\..\Run: [hpWirelessAssistant] "C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe"O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exeO4 - HKLM\..\Run: [synTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"O4 - HKLM\..\Run: [QlbCtrl] "C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" /StartO4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exeO4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exeO4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [iMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXEO4 - HKLM\..\Run: [MSPY2002] "C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" /SYNCO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"O4 - HKLM\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exeO4 - HKLM\..\Run: [iSUSPM Startup] "C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" -startupO4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -startO4 - HKLM\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostartO4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exeO4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files\PowerISO\PWRISOVM.EXE"O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe"O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimizedO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [AvaFind] "C:\Program Files\AvaFind\AvaFind.exe" /minimizedO4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"O4 - Global Startup: Bluetooth.lnk = ?O4 - Global Startup: VisualTaskTips.lnk = C:\Program Files\VisualTaskTips\VisualTaskTips.exeO8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htmO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dllO9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLLO9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_SG&c=Q306&bd=presario&pf=laptopO16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h50203.www5.hp.com/HPISWeb/Customer...DataManager.CABO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/...tail/DASAct.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{E8C7CA81-1E6D-4D0C-BE56-E5381BE5D0DA}: NameServer = 192.168.1.1O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLLO20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dllO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeO23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exeO23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exeO23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exeO23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (file missing)O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (file missing)O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (file missing)O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exeO23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exeO23 - Service: Norton Protection Center Service (NSCService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE (file missing)O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exeO23 - Service: ProtexisLicensing - Unknown owner - C:\Program Files\Common Files\Protexis\License Service\PSIService.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exeO23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe--End of file - 13128 bytes-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------backup-20070927-133925-781 O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"backup-20071004-233229-109 O3 - Toolbar: The netadv - {ABF529BE-6245-465A-BBD4-238C4EAB0F0A} - C:\WINDOWS\netadv.dllbackup-20071006-114627-290 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2-- File Associations -----------------------------------------------------------All associations okay.-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------R1 PQNTDrv - c:\windows\system32\drivers\pqntdrv.sys <Not Verified; PowerQuest Corporation; PowerQuest product>R1 SCDEmu - c:\windows\system32\drivers\scdemu.sys <Not Verified; PowerISO Computing, Inc.; scdemu>R2 LF30FS - c:\program files\everstrike software\lock folder xp 3.6\lf30xp.sysR3 catchme - c:\docume~1\rohan\locals~1\temp\catchme.sys (file missing)S3 btwmodem (Bluetooth Modem) - c:\windows\system32\drivers\btwmodem.sys <Not Verified; Broadcom Corporation.; Bluetooth Software 4.0.1.3500>S3 EraserUtilRebootDrv - c:\program files\common files\symantec shared\eengine\eraserutilrebootdrv.sys (file missing)-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------R2 Bonjour Service (##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##) - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Computer, Inc.; Bonjour>S2 ccEvtMgr (Symantec Event Manager) - "c:\program files\common files\symantec shared\ccevtmgr.exe" (file missing)S2 ccSetMgr (Symantec Settings Manager) - "c:\program files\common files\symantec shared\ccsetmgr.exe" (file missing)S2 LiveUpdate Notice Service - "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifeng.dll" (file missing)S2 NSCService (Norton Protection Center Service) - c:\program files\common files\symantec shared\security console\nscsrvce.exe (file missing)S2 ProtexisLicensing - "c:\program files\common files\protexis\license service\psiservice.exe" <Not Verified; ; PSIService>S2 SNDSrvc (Symantec Network Drivers Service) - "c:\program files\common files\symantec shared\sndsrvc.exe" (file missing)S3 FLEXnet Licensing Service - "c:\program files\common files\macrovision shared\flexnet publisher\fnplicensingservice.exe" <Not Verified; Macrovision Europe Ltd.; FLEXnet Publisher (32 bit)>-- Device Manager: Disabled ----------------------------------------------------No disabled devices found.-- Files created between 2007-09-09 and 2007-10-09 -----------------------------2007-10-09 14:40:48 0 d-------- C:\Documents and Settings\Guest\Application Data\Grisoft2007-10-05 14:09:50 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities2007-10-05 14:09:49 0 d--h----- C:\Documents and Settings\Administrator\Templates2007-10-05 14:09:49 0 dr------- C:\Documents and Settings\Administrator\Start Menu2007-10-05 14:09:49 0 dr-h----- C:\Documents and Settings\Administrator\SendTo2007-10-05 14:09:49 0 dr-h----- C:\Documents and Settings\Administrator\Recent2007-10-05 14:09:49 0 d--h----- C:\Documents and Settings\Administrator\PrintHood2007-10-05 14:09:49 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT2007-10-05 14:09:49 0 d--h----- C:\Documents and Settings\Administrator\NetHood2007-10-05 14:09:49 0 dr------- C:\Documents and Settings\Administrator\My Documents2007-10-05 14:09:49 0 d--h----- C:\Documents and Settings\Administrator\Local Settings2007-10-05 14:09:49 0 dr------- C:\Documents and Settings\Administrator\Favorites2007-10-05 14:09:49 0 d-------- C:\Documents and Settings\Administrator\Desktop2007-10-05 14:09:49 0 d--hs---- C:\Documents and Settings\Administrator\Cookies2007-10-05 14:09:49 0 dr-h----- C:\Documents and Settings\Administrator\Application Data2007-10-05 14:09:49 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft2007-10-05 12:54:50 0 d-------- C:\.Trash-guest2007-10-05 10:20:43 0 d-------- C:\Program Files\Webroot2007-10-05 09:29:33 0 d-------- C:\Program Files\Lavasoft2007-10-05 09:29:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft2007-10-05 09:27:44 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard2007-10-05 03:58:58 0 d-------- C:\Documents and Settings\Rohan\Application Data\Grisoft2007-10-05 03:58:33 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft2007-10-04 18:45:05 0 d-------- C:\Documents and Settings\Rohan\Application Data\Styler2007-10-04 18:40:40 0 d-------- C:\Program Files\VisualTaskTips2007-10-04 18:18:38 0 d-------- C:\temp2007-10-04 18:18:07 0 d-------- C:\Program Files\Avex2007-10-04 18:18:00 0 d-------- C:\Program Files\Common Files\Download Manager2007-10-04 18:07:12 0 d-------- C:\Program Files\SystemDefender2007-10-03 21:02:47 764416 --a------ C:\WINDOWS\system32\NCTRMFile.dll <Not Verified; NCT Company Ltd.; NCTRMFile ActiveX DLL>2007-10-03 21:02:47 249856 --a------ C:\WINDOWS\system32\NCTQuickTimeFile.dll <Not Verified; Online Media Technologies Company Ltd.; NCTQuickTimeFile Module>2007-10-03 21:02:47 626688 --a------ C:\WINDOWS\system32\NCTImageFile.dll <Not Verified; Online Media Technologies Ltd.; NCTImageFile ActiveX DLL>2007-10-03 21:02:46 495104 --a------ C:\WINDOWS\system32\NCTVideoCoreM.dll <Not Verified; NCT Company Ltd.; NCTVideoCoreM ActiveX DLL>2007-10-03 21:02:46 780288 --a------ C:\WINDOWS\system32\NCTVideoCompress.dll <Not Verified; NCT Company Ltd.; NCTVideoCompress ActiveX DLL>2007-10-03 21:02:46 382464 --a------ C:\WINDOWS\system32\NCTAVIFile.dll <Not Verified; NCT Company Ltd.; NCTAVIFile ActiveX DLL>2007-10-03 21:02:46 90112 --a------ C:\WINDOWS\system32\NCTAudioFormatSettings3.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioFormatSettings3 Module>2007-10-03 21:02:46 2846720 --a------ C:\WINDOWS\system32\NCTAudioCompress3.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress3 Module>2007-10-03 21:02:45 215552 --a------ C:\WINDOWS\system32\NCTWMVFile.dll <Not Verified; NCT Company Ltd.; NCTWMVFile ActiveX DLL>2007-10-03 21:02:45 312320 --a------ C:\WINDOWS\system32\NCTVideoView.dll <Not Verified; Online Media Technologies Ltd.; NCTVideoView ActiveX DLL>2007-10-03 21:02:45 188416 --a------ C:\WINDOWS\system32\NCTVideoFile.dll <Not Verified; NCT Company Ltd.; NCTVideoFile ActiveX DLL>2007-10-03 21:02:45 778240 --a------ C:\WINDOWS\system32\NCTAudioCompress2.dll <Not Verified; Online Media Technologies Ltd.; NCTAudioCompress2 Module>2007-10-03 21:02:44 237568 --a------ C:\WINDOWS\system32\lame_enc.dll2007-10-03 21:02:38 0 d-------- C:\WINDOWS\system32\RMBin2007-10-03 21:02:37 139264 --a------ C:\WINDOWS\system32\viscomqtde.dll <Not Verified; Viscom Software www.viscomsoft.com; >2007-10-03 21:02:36 81920 --a------ C:\WINDOWS\system32\viscomwave.dll <Not Verified; Viscom Software; >2007-10-03 21:02:35 147456 --a------ C:\WINDOWS\system32\viscomqtenc.dll <Not Verified; Viscom Software www.viscomsoft.com; >2007-10-03 20:38:33 0 d-------- C:\Documents and Settings\Guest\Application Data\WinRAR2007-10-02 22:15:58 0 d-------- C:\Program Files\TopCoder UML Tool2007-10-02 16:29:20 0 dr-h----- C:\Documents and Settings\Rohan\Recent2007-10-02 12:17:54 0 d-------- C:\Documents and Settings\Guest\Application Data\Adobe2007-10-02 12:11:27 0 d-------- C:\Documents and Settings\Guest\Application Data\Google2007-10-02 12:09:58 0 d-------- C:\Documents and Settings\Guest\Application Data\Mozilla2007-10-02 12:08:05 0 d-------- C:\Microsoft2007-10-02 12:08:05 0 d-------- C:\Documents and Settings\Guest\Application Data\Macromedia2007-10-02 12:08:04 0 d-------- C:\Documents and Settings\Guest\Application Data\Real2007-10-02 12:07:23 0 d--h----- C:\Documents and Settings\Guest\Templates2007-10-02 12:07:23 0 dr------- C:\Documents and Settings\Guest\Start Menu2007-10-02 12:07:23 0 dr-h----- C:\Documents and Settings\Guest\SendTo2007-10-02 12:07:23 0 dr-h----- C:\Documents and Settings\Guest\Recent2007-10-02 12:07:23 0 d--h----- C:\Documents and Settings\Guest\PrintHood2007-10-02 12:07:23 0 d--h----- C:\Documents and Settings\Guest\NetHood2007-10-02 12:07:23 0 dr------- C:\Documents and Settings\Guest\My Documents2007-10-02 12:07:23 0 d--h----- C:\Documents and Settings\Guest\Local Settings2007-10-02 12:07:23 0 dr------- C:\Documents and Settings\Guest\Favorites2007-10-02 12:07:23 0 d-------- C:\Documents and Settings\Guest\Desktop2007-10-02 12:07:23 0 d---s---- C:\Documents and Settings\Guest\Cookies2007-10-02 12:07:23 0 dr-h----- C:\Documents and Settings\Guest\Application Data2007-10-02 12:07:23 0 d---s---- C:\Documents and Settings\Guest\Application Data\Microsoft2007-10-02 12:07:23 0 d-------- C:\Documents and Settings\Guest\Application Data\Identities2007-10-02 12:07:22 1310720 --ah----- C:\Documents and Settings\Guest\NTUSER.DAT2007-09-27 21:38:53 0 d-------- C:\Documents and Settings\All Users\Application Data\DFX2007-09-27 21:38:52 0 d-------- C:\Program Files\DFX2007-09-27 21:35:19 0 d-------- C:\Program Files\Winamp2007-09-27 21:35:19 0 d-------- C:\Documents and Settings\Rohan\Application Data\Winamp2007-09-27 13:37:49 0 d-------- C:\Program Files\Trend Micro2007-09-27 13:29:00 0 d-------- C:\Program Files\ABC Amber LIT Converter2007-09-27 12:20:32 60944 --a------ C:\WINDOWS\DASShp.dll <Not Verified; Microsoft Corporation; Microsoft® DAS Client Components>2007-09-27 12:20:30 0 d-------- C:\Program Files\Microsoft Reader2007-09-27 12:17:41 0 d-------- C:\Documents and Settings\Rohan\Application Data\WinRAR2007-09-26 19:06:52 0 d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.22007-09-23 03:19:27 0 d-------- C:\Program Files\MSBuild2007-09-23 03:16:09 0 d-------- C:\Program Files\Microsoft.NET2007-09-23 03:12:09 0 d-------- C:\WINDOWS\SHELLNEW2007-09-23 03:09:10 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help2007-09-23 03:06:57 0 dr-h----- C:\MSOCache2007-09-21 19:04:05 0 d-------- C:\Program Files\The KMPlayer2007-09-20 22:21:25 0 d-------- C:\Documents and Settings\Rohan\Application Data\VMware2007-09-20 22:19:56 0 d-------- C:\Program Files\VMware2007-09-14 10:53:51 0 d-------- C:\Program Files\Common Files\Macromedia Shared2007-09-14 10:53:27 1 --a------ C:\WINDOWS\system32\FlashPaper2PrinterPort2007-09-14 10:32:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Macromedia2007-09-14 10:32:08 0 d-------- C:\WINDOWS\system32\QuickTime2007-09-14 10:32:00 0 d-------- C:\Program Files\Macromedia2007-09-14 10:32:00 0 d-------- C:\Program Files\Common Files\Macromedia2007-09-14 10:30:21 0 d-------- C:\WINDOWS\Downloaded Installations2007-09-14 09:59:05 0 d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet2007-09-14 09:45:41 0 d-------- C:\Program Files\Bonjour2007-09-14 09:29:56 0 d-------- C:\Program Files\Common Files\Macrovision Shared2007-09-13 19:30:46 81549 --a------ C:\WINDOWS\system32\drivers\klin.dat2007-09-13 19:30:46 82061 --a------ C:\WINDOWS\system32\drivers\klick.dat2007-09-13 19:30:17 0 d-------- C:\Program Files\Kaspersky Lab2007-09-13 19:30:17 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab2007-09-13 19:30:15 388128 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat2007-09-13 19:30:15 19256864 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat-- Find3M Report ---------------------------------------------------------------2007-10-09 18:11:46 0 d-------- C:\Documents and Settings\Rohan\Application Data\AvaFind Data2007-10-06 11:39:36 0 d-------- C:\Program Files\Windows NT2007-10-06 11:39:32 0 d-------- C:\Program Files\Movie Maker2007-10-06 11:39:32 0 d-------- C:\Program Files\Messenger2007-10-05 09:27:44 0 d-------- C:\Program Files\Common Files2007-10-05 09:21:36 0 d-------- C:\Documents and Settings\Rohan\Application Data\uTorrent2007-10-04 18:48:27 0 d-------- C:\Program Files\EasyEclipse Expert Java 1.3.02007-09-27 12:20:30 0 d--h----- C:\Program Files\InstallShield Installation Information2007-09-26 21:35:03 0 d-------- C:\Documents and Settings\Rohan\Application Data\Adobe2007-09-23 23:21:59 3348 --ahs--c- C:\WINDOWS\system32\KGyGaAvL.sys2007-09-23 03:19:50 0 d-------- C:\Program Files\Microsoft Works2007-09-15 23:33:05 0 d-------- C:\Program Files\Hp2007-09-15 23:32:47 0 d-------- C:\Program Files\Hewlett-Packard2007-09-14 10:56:07 0 d-------- C:\Documents and Settings\Rohan\Application Data\Macromedia2007-09-14 09:45:37 0 d-------- C:\Program Files\Common Files\Adobe2007-09-13 19:28:37 0 d-------- C:\Program Files\Common Files\Symantec Shared2007-09-09 00:06:51 4045 --a------ C:\WINDOWS\mozver.dat2007-09-08 21:08:43 0 d-------- C:\Program Files\DAMN NFO Viewer2007-09-08 21:07:44 0 d-------- C:\Program Files\BitTyrant2007-09-08 20:52:44 0 d-------- C:\Documents and Settings\Rohan\Application Data\Azureus2007-09-08 20:52:18 0 d-------- C:\Documents and Settings\Rohan\Application Data\BitTyrant2007-09-07 23:25:31 0 d-------- C:\Program Files\Common Files\xing shared2007-09-07 23:25:17 0 d-------- C:\Program Files\Common Files\Real2007-09-07 23:02:21 0 d-------- C:\Documents and Settings\Rohan\Application Data\Real2007-09-07 22:58:49 0 --a------ C:\WINDOWS\nsreg.dat2007-09-07 22:58:38 0 d-------- C:\Documents and Settings\Rohan\Application Data\Mozilla2007-09-07 22:56:31 0 d-------- C:\Program Files\Real2007-09-04 19:44:24 0 d-------- C:\Documents and Settings\Rohan\Application Data\Subversion2007-08-30 19:53:59 0 d-------- C:\Documents and Settings\Rohan\Application Data\Help2007-08-29 16:22:19 0 d-------- C:\Program Files\EA SPORTS2007-08-27 22:29:33 0 -rahs---- C:\MSDOS.SYS2007-08-27 22:29:33 0 -rahs---- C:\IO.SYS2007-08-27 22:27:13 296 --a------ C:\Documents and Settings\Rohan\Application Data\wklnhst.dat2007-08-25 21:49:06 0 d-------- C:\Documents and Settings\Rohan\Application Data\dvdcss2007-08-10 22:57:26 0 d-------- C:\Documents and Settings\Rohan\Application Data\Ahead2007-08-10 14:32:35 0 d-------- C:\Program Files\Common Files\LightScribe2007-08-10 14:28:36 0 d-------- C:\Program Files\Common Files\Ahead2007-08-10 14:24:38 0 d-------- C:\Program Files\Nero2007-08-10 11:20:56 0 d-------- C:\Program Files\PowerISO2007-08-10 08:31:09 0 d-------- C:\Documents and Settings\Rohan\Application Data\Sonic2007-08-10 08:30:55 0 d-------- C:\Documents and Settings\Rohan\Application Data\Leadertech2007-07-27 08:21:26 393216 --a------ C:\WINDOWS\system32\igxpun.exe <Not Verified; Intel® Corporation; Intel® Graphics Media Accelerator Driver>2007-07-19 09:32:33 8 -r-hs---- C:\WINDOWS\system32\7881C6E694.sys2007-07-18 01:34:42 8 -r-hs---- C:\WINDOWS\system32\6A779F9613.sys-- Registry Dump ---------------------------------------------------------------*Note* empty entries & legit default entries are not shown[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 04:00 AM]"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [02/15/2006 08:19 AM]"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [04/18/2006 01:59 AM C:\WINDOWS\system32\CHDAudPropShortcut.exe]"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [04/01/2006 10:31 AM]"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [04/11/2006 07:24 PM]"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [03/23/2006 09:08 AM]"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [01/26/2006 01:48 PM]"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [10/11/2005 07:53 AM]"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/04/2004 06:30 PM]"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [08/04/2004 06:30 PM]"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [08/04/2004 06:30 PM]"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [10/05/2007 07:14 PM]"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [10/05/2007 07:14 PM]"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" []"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [01/07/2006 02:36 AM]"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [02/16/2005 04:15 PM]"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [02/16/2005 04:15 PM]"googletalk"="C:\Program Files\Google\Google Talk\googletalk.exe" [01/02/2007 02:52 AM]"LFAgent"="" []"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [06/22/2007 08:32 AM]"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [06/22/2007 08:32 AM]"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [06/22/2007 08:32 AM]"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [01/20/2007 12:39 PM]"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [01/12/2006 03:40 PM]"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [05/11/2007 03:06 AM]"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [09/07/2007 11:24 PM]"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [06/28/2007 12:51 PM]"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [02/16/2005 11:11 PM]"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [10/27/2006 12:47 AM]"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [05/15/2007 03:52 AM]"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/2007 02:55 PM][HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [08/09/2007 11:53 PM]"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/05/2004 02:30 AM]"AvaFind"="C:\Program Files\AvaFind\AvaFind.exe" [06/01/2004 12:48 PM]"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [11/16/2006 07:04 PM]C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [5/12/2006 1:33:22 PM][HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]"appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]@="Service"[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3b4628b-3471-11dc-b0da-806d6172696f}]AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480-- End of Deckard's System Scanner: finished at 2007-10-09 21:06:28 ------------extra.txt Log File Of DSS.EXEDeckard's System Scanner v20070905.67Extra logfile - please post this as an attachment with your post.---------------------------------------------------------------------------------- System Information ----------------------------------------------------------Microsoft Windows XP Home Edition (build 2600) SP 2.0Architecture: X86; Language: EnglishCPU 0: Genuine Intel® CPU T2250 @ 1.73GHzCPU 1: Genuine Intel® CPU T2250 @ 1.73GHzPercentage of Memory in Use: 73%Physical Memory (total/avail): 502.04 MiB / 134.87 MiBPagefile Memory (total/avail): 1226.2 MiB / 827.46 MiBVirtual Memory (total/avail): 2047.88 MiB / 1967.49 MiBC: is Fixed (NTFS) - 44.24 GiB total, 6.09 GiB free. D: is Fixed (FAT32) - 2.22 GiB total, 2.22 GiB free. E: is CDROM (No Media)F: is CDROM (No Media)\\.\PHYSICALDRIVE0 - FUJITSU MHV2080BH - 74.53 GiB - 5 partitions \PARTITION0 (bootable) - Installable File System - 44.24 GiB - C: \PARTITION1 - Extended w/Extended Int 13 - 30.29 GiB - D:-- Security Center -------------------------------------------------------------AUOptions is scheduled to auto-install.Windows Internal Firewall is disabled.FirstRunDisabled is set.AntiVirusDisableNotify is set.FW: Norton Internet Worm Protection v2006 (Symantec) DisabledFW: Norton Internet Security 2006 v2006 (Symantec Corporation)FW: Kaspersky Internet Security v7.0.0.125 (Kaspersky Lab)AV: Norton Internet Security 2006 v2006 (Symantec Corporation)AV: Kaspersky Internet Security v7.0.0.125 (Kaspersky Lab)[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List][HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]-- Environment Variables -------------------------------------------------------ALLUSERSPROFILE=C:\Documents and Settings\All UsersAPPDATA=C:\Documents and Settings\Rohan\Application DataCLIENTNAME=ConsoleCommonProgramFiles=C:\Program Files\Common FilesCOMPUTERNAME=MEAN-MACHINEComSpec=C:\WINDOWS\system32\cmd.exeFP_NO_HOST_CHECK=NOHOMEDRIVE=C:HOMEPATH=\Documents and Settings\RohanLOGONSERVER=\\MEAN-MACHINENUMBER_OF_PROCESSORS=2OS=Windows_NTPath=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\WbemPATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSHPCTYPE=PRESARIOPLATFORM=MCDPROCESSOR_ARCHITECTURE=x86PROCESSOR_IDENTIFIER=x86 Family 6 Model 14 Stepping 8, GenuineIntelPROCESSOR_LEVEL=6PROCESSOR_REVISION=0e08ProgramFiles=C:\Program FilesPROMPT=$P$GSESSIONNAME=ConsoleSonicCentral=C:\Program Files\Common Files\Sonic Shared\Sonic Central\SystemDrive=C:SystemRoot=C:\WINDOWSTEMP=C:\DOCUME~1\Rohan\LOCALS~1\TempTMP=C:\DOCUME~1\Rohan\LOCALS~1\TempUSERDOMAIN=MEAN-MACHINEUSERNAME=RohanUSERPROFILE=C:\Documents and Settings\Rohanwindir=C:\WINDOWS-- User Profiles ---------------------------------------------------------------Rohan (admin)Administrator (new local, admin)Guest (guest)-- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {075473F5-846A-448B-BCB3-104AA1760205} --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {AB708C9B-97C8-4AC9-899B-DBF226AC9382} --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {B12665F4-4E93-4AB4-B7FC-37053B524629} --> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL --> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL --> C:\WINDOWS\UNRecode.exe /UNINSTALL --> Dummy --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{88E5FCB8-5F25-11D5-B16F-0800460222F0}\setup.exe" -l0x9 UNINSTALL --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D76298C2-E532-4A11-BCFF-76F3F19DA84D}\setup.exe" UNINSTALL --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E47302B-8081-46D3-9FEA-BEB2E5F5C3EC}\Setup.exe" -l0x9 anything --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.infµTorrent --> "C:\Program Files\uTorrent\uTorrent.exe" /UNINSTALLABC Amber LIT Converter --> C:\PROGRA~1\ABCAMB~1\UNWISE.EXE C:\PROGRA~1\ABCAMB~1\INSTALL.LOGAd-Aware 2007 --> MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}Adobe Anchor Service CS3 --> MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}Adobe Asset Services CS3 --> MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}Adobe Bridge CS3 --> MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}Adobe Bridge Start Meeting --> MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}Adobe Camera Raw 4.0 --> MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}Adobe CMaps --> MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}Adobe Color - Photoshop Specific --> MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}Adobe Color Common Settings --> C:\Program Files\Common Files\Adobe\Installers\6c8e2cb4fd241c55406016127a6ab2e\Setup.exeAdobe Color Common Settings --> MsiExec.exe /I{6D4AC5A4-4CF9-4F90-8111-B9B53CE257BF}Adobe Color EU Extra Settings --> MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}Adobe Color JA Extra Settings --> MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}Adobe Color NA Recommended Settings --> MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}Adobe Default Language CS3 --> MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}Adobe Device Central CS3 --> MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}Adobe ExtendScript Toolkit 2 --> C:\Program Files\Common Files\Adobe\Installers\5bc0f8414ec36c555a3e7e5ec2e225e\Setup.exeAdobe ExtendScript Toolkit 2 --> MsiExec.exe /I{1BCEA516-B4C5-4B2D-BFA0-AB7910BAD862}Adobe Flash Player 9 ActiveX --> C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe -uninstallUnlockAdobe Fonts All --> MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}Adobe Help Viewer CS3 --> MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}Adobe Linguistics CS3 --> MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}Adobe PDF Library Files --> MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}Adobe Photoshop CS3 --> C:\Program Files\Common Files\Adobe\Installers\2ac78060bc5856b0c1cf873bb919b58\Setup.exeAdobe Photoshop CS3 --> MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}Adobe Reader 8.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81000000003}Adobe Setup --> MsiExec.exe /I{64C1FA9A-FA94-4B6E-B3E4-8573738E4AD1}Adobe Setup --> MsiExec.exe /I{D1BB4446-AE9C-4256-9A7F-4D46604D2462}Adobe Setup --> MsiExec.exe /I{D504303A-717D-414C-BA9F-FE01093E2EF8}Adobe Shockwave Player --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.logAdobe Stock Photos CS3 --> MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}Adobe Type Support --> MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}Adobe Update Manager CS3 --> MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}Adobe Version Cue CS3 Client --> MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}Adobe WinSoft Linguistics Plugin --> MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}Adobe XMP Panels CS3 --> MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}Album List for Winamp v2.06 (remove only) --> C:\Program Files\Winamp\Plugins\uninstall-AL.exeAva Find --> MsiExec.exe /X{909577E9-BFB5-48E2-8237-71DCA373F147}AVG Anti-Spyware 7.5 --> C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Uninstall.exeCC_ccProxyExt --> MsiExec.exe /I{2EBF25F1-F8A2-40EA-92BE-931C142A44E2}ccCommon --> MsiExec.exe /I{1248C09A-BD6B-47F5-BF3F-CD2B700D9FCB}ccPxyCore --> MsiExec.exe /I{30738666-9805-4926-A78F-91DA33B6C437}Competition Arena --> C:\WINDOWS\system32\javaws.exe -uninstall -prompt "http://www.topcoder.com/contest/arena/ContestAppletProd.jnlp"Conexant HD Audio --> C:\Program Files\CONEXANT\CNXT_HDAUDIO\UIU32a.exe -U -Iwis30B2a.infCorelDRAW Graphics Suite X3 --> C:\Program Files\Corel\CorelDRAW Graphics Suite 13\Programs\MSILauncher {63218538-4A69-497F-8455-904261B0E9E4} C:\DOCUME~1\Rohan\LOCALS~1\Temp\CGSX3.logCorelDRAW Graphics Suite X3 --> MsiExec.exe /I{63218538-4A69-497F-8455-904261B0E9E4}Customer Experience Enhancement --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{23012310-3E05-46A5-88A9-C6CBCABCAC79} /l1033 DFX 8 for Winamp --> "C:\Program Files\Winamp\uninstall_dfx.exe"EA SPORTS online 2007 --> C:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exeEasy Internet Sign-up --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\1050\INTEL3~1\IDriver.exe /M{8105684D-8CA6-440D-8F58-7E5FD67A499D} /l1033 EasyEclipse Expert Java 1.3.0 --> "C:\Program Files\EasyEclipse Expert Java 1.3.0\uninstall-easyeclipse-1.3.exe"EasyEclipse Plugin: EasyEclipse Eclipse J2EE tools 2.0.0 --> "C:\Program Files\EasyEclipse Expert Java 1.3.0\extensions\eclipse-wtp-j2ee-2.0.0\uninstall-eclipse-wtp-j2ee-2.0.0.exe"EasyEclipse Plugin: EasyEclipse Eclipse Web tools editors 2.0.0 --> "C:\Program Files\EasyEclipse Expert Java 1.3.0\extensions\eclipse-wtp-web-2.0.0\uninstall-eclipse-wtp-web-2.0.0.exe"EN --> MsiExec.exe /I{32A72502-BC2C-4C39-ACEA-BC3D463F0697}FairStars Audio Converter 1.55 --> "C:\Program Files\FairStars Audio Converter\unins000.exe"FIFA 07 --> C:\Program Files\EA SPORTS\FIFA 07\EAUninstall.exeFontNav --> MsiExec.exe /I{4E98F23B-1328-4322-A6EC-2EDC8FC3A4FE}Google Talk (remove only) --> "C:\Program Files\Google\Google Talk\uninstall.exe"Google Toolbar for Internet Explorer --> regsvr32 /u /s "c:\program files\google\googletoolbar2.dll"HDAUDIO Soft Data Fax Modem with SmartCP --> C:\Program Files\CONEXANT\CNXT_MODEM_HDAUDIO_wis30B2m\HXFSETUP.EXE -U -Iwis30B2m.INFHijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstallHotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"HP DVD Play 2.1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{45D707E9-F3C4-11D9-A373-0050BAE317E1}\setup.exe" -uninstallHP Help and Support --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A93C4E94-1005-489D-BEAA-B873C1AA6CFC}\setup.exe" -l0x9 -removeonlyHP Imaging Device Functions 6.0 --> C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.datHP Integrated Module with Bluetooth wireless technology --> MsiExec.exe /X{3F4EC965-28EF-45C3-B063-04B25D4E9679}HP Quick Launch Buttons 6.00 G2 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\110\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34D2AB40-150D-475D-AE32-BD23FB5EE355}\setup.exe" -l0x9 -removeonly uninstHP Update --> MsiExec.exe /X{8C6027FD-53DC-446D-BB75-CACD7028A134}HP User Guides 0027 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{63A3856B-5C0E-4BC1-B508-629AE74B6BBA}\setup.exe" -l0x9 -removeonlyHP Wireless Assistant 2.00 E1 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4302B2DD-D958-40E3-BAF3-B07FFE1978CE}\setup.exe" -l0x9 hpquninstIntel® Graphics Media Accelerator Driver --> C:\WINDOWS\system32\igxpun.exe -uninstallIntel® PRO Network Connections Drivers --> Prounstl.exeIsoBuster 2.0 --> "C:\Program Files\Smart Projects\IsoBuster\Uninst\unins000.exe"J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}Java 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}Kaspersky Internet Security 7.0 --> MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}Kaspersky Internet Security 7.0 --> MsiExec.exe /I{C774410D-3EF9-4DE7-AC01-332613163ECF}LiveUpdate 3.0 (Symantec Corporation) --> "C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /ULiveUpdate Notice (Symantec Corporation) --> MsiExec.exe /X{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}Lock Folder XP 3.6 --> "C:\Program Files\Everstrike Software\Lock Folder XP 3.6\Uninstall.exe" "C:\Program Files\Common Files\Everstrike Software\Lock Folder XP 3.6\install.log"Macromedia Extension Manager --> MsiExec.exe /I{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}Macromedia Fireworks 8 --> MsiExec.exe /I{4C24A8C1-7CFA-4650-AF15-732F5BD7B46D}Macromedia Flash 8 --> MsiExec.exe /I{2BD5C305-1B27-4D41-B690-7A61172D2FEB}Macromedia Flash 8 Video Encoder --> MsiExec.exe /X{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}Macromedia Flash Player 8 --> MsiExec.exe /X{6815FCDD-401D-481E-BA88-31B4754C2B46}Macromedia Flash Player 8 --> MsiExec.exe /X{885A63EA-382B-4DD4-A755-14809B8557D6}Macromedia Flash Player 8 Plugin --> MsiExec.exe /X{91057632-CA70-413C-B628-2D3CDBBB906B}Macromedia FlashPaper 2 --> MsiExec.exe /X{F977FD4B-C9A6-4BAA-B4BB-DE3023288253}Magic ISO Maker v5.4 (build 0239) --> C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOGMicrosoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"Microsoft Money --> C:\Program Files\Microsoft Money 2005\MNYCoreFiles\Setup\uninst.exe /s:120Microsoft Office Access MUI (English) 2007 --> MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}Microsoft Office Access Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}Microsoft Office Enterprise 2007 --> "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLLMicrosoft Office Enterprise 2007 --> MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}Microsoft Office Excel MUI (English) 2007 --> MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}Microsoft Office Groove MUI (English) 2007 --> MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}Microsoft Office Groove Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}Microsoft Office InfoPath MUI (English) 2007 --> MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}Microsoft Office OneNote MUI (English) 2007 --> MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}Microsoft Office Outlook MUI (English) 2007 --> MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}Microsoft Office PowerPoint MUI (English) 2007 --> MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}Microsoft Office Proof (English) 2007 --> MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}Microsoft Office Proof (French) 2007 --> MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}Microsoft Office Proof (Spanish) 2007 --> MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}Microsoft Office Proofing (English) 2007 --> MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}Microsoft Office Publisher MUI (English) 2007 --> MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}Microsoft Office Shared MUI (English) 2007 --> MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}Microsoft Office Shared Setup Metadata MUI (English) 2007 --> MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}Microsoft Office Word MUI (English) 2007 --> MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}Microsoft Reader --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B6F7DBE7-2FE2-458F-A738-B10832746036}\Setup.exe" -L0x9Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}Microsoft Windows Theme Nunavut --> MsiExec.exe /X{047815FB-4E38-42D5-95CB-8A131DDD8668}Microsoft Windows Theme Ontario --> MsiExec.exe /X{9757283E-3FCA-4F3D-9257-928859318E55}Microsoft Works --> MsiExec.exe /I{416D80BA-6F6D-4672-B7CF-F54DA2F80B44}Mozilla Firefox (1.5.0.12) --> C:\PROGRA~1\MOZILL~1\uninstall\uninstall.exe /ua "1.5.0.12 (en-US)"Mozilla Firefox (2.0.0.7) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exemuvee autoProducer 4.5 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{286F29AF-0BE2-4D5F-AB17-B7631A810553}\setup.exe" -l0x9 Nero 7 Essentials --> MsiExec.exe /I{37BA50EE-C851-4394-93DD-A0A611891033}NILE THEME --> MsiExec.exe /X{B19C841C-D60A-462F-AB86-4FDD51A77FA3}Norton Internet Security --> MsiExec.exe /I{AADFE0B9-F905-4d5f-A144-0ADB2EFA747B}Norton Internet Security --> MsiExec.exe /I{FFB4DD53-28B7-4981-BFF0-9BD801F61095}Norton Protection Center --> MsiExec.exe /I{82A5BF38-8461-4A5C-B2C9-24F5256D92A6}OpenMG Limited Patch 4.4-06-13-19-01 --> C:\Program Files\Common Files\Sony Shared\OpenMG\HotFixes\HotFix4.4-06-13-19-01\HotFixSetup\setup.exe /uOpenMG Secure Module 4.4.00 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{CFB17307-B244-4EAD-AE8E-CDAF440477C2} UNINSTALLPDF Settings --> MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}PowerISO --> "C:\Program Files\PowerISO\uninstall.exe"PowerPlayer II --> "C:\Program Files\Winamp\uninst_pwrplay.exe"PowerQuest PartitionMagic 8.0 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{6BE2A4A4-99FB-48ED-AE1E-4E850389F804} RealPlayer --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0Rhapsody Player Engine --> MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}Security Update for Excel 2007 (KB936509) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A00724F5-82C4-4924-B707-0E5A84B52471}Security Update for Office 2007 (KB934062) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {305D509B-F194-4638-9F0F-D9E4C05F9D33}Security Update for Office 2007 (KB936514) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C7A78F7F-EF32-4477-BAD7-3439EA7571BF}Security Update for Publisher 2007 (KB936646) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {A32E4BAF-6477-45FA-B8AB-E743FA8D63FF}Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"Security Update for the 2007 Microsoft Office System (KB936960) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {5E5BD655-7AA9-47F9-BB6D-A1D8CE29AC86}SmartAudio --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\100\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AEF7A12C-CD9B-4773-8AD1-6916138CA7EA}\setup.exe" -l0x9 -removeonly -SSonic Audio Module --> MsiExec.exe /I{AB708C9B-97C8-4AC9-899B-DBF226AC9382}Sonic Copy Module --> MsiExec.exe /I{B12665F4-4E93-4AB4-B7FC-37053B524629}Sonic Data Module --> MsiExec.exe /I{075473F5-846A-448B-BCB3-104AA1760205}Sonic Express Labeler --> MsiExec.exe /I{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}Sonic MyDVD Plus --> MsiExec.exe /I{21657574-BD54-48A2-9450-EB03B2C7FC29}Sonic Update Manager --> MsiExec.exe /I{30465B6C-B53F-49A1-9EBA-A3F187AD502E}SonicStage 3.4 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\101\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A0EB195B-5876-48E6-879D-33D4B2102610}\setup.exe" -l0x9 UNINSTALL -removeonlySymantec KB-DocID:2003093015493306 --> MsiExec.exe /I{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}Synaptics Pointing Device Driver --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstallThe KMPlayer (remove only) --> "C:\Program Files\The KMPlayer\uninstall.exe"TheSage --> "C:\Program Files\TheSage\uninstall.exe"Update for Office 2007 (KB932080) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {EDC9CA29-6BC1-471C-828C-7A36109005D7}Update for Office 2007 (KB934391) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {B3091818-7C56-4C45-BE7D-CA23027A5EA5}Update for Office 2007 (KB934393) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {92FBAD46-E7F6-49FA-89B5-C39FC5BFAD15}Update for Outlook 2007 (KB937608) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {CBB2454D-193F-4523-8A31-FEB343B7C30E}Update for Outlook 2007 Junk Email Filter (kb937833) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {ACB40B61-03E6-4F6F-AA5E-7B02A89E8AD3}Update for Word 2007 (KB934173) --> msiexec /package {90120000-0030-0000-0000-0000000FF1CE} /uninstall {C6A89125-5473-45E3-B413-ED8186437475}Update Manager --> MsiExec.exe /I{F428D0FB-765D-40EB-BDD8-A1E7F5C597FA}VBA --> MsiExec.exe /I{C94E45B0-6AA6-4FB9-9AAE-22085F631880}VideoLAN VLC media player 0.8.6c --> C:\Program Files\VideoLAN\VLC\uninstall.exeWinamp (remove only) --> "C:\Program Files\Winamp\UninstWA.exe"Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exeWinZip --> "C:\Program Files\WinZip\WINZIP32.EXE" /uninstall-- Application Event Log -------------------------------------------------------Event Record #/Type3773 / ErrorEvent Submitted/Written: 10/09/2007 08:51:54 PMEvent ID/Source: 1000 / Application ErrorEvent Description:Faulting application sed.cfexe, version 0.0.0.0, faulting module sed.cfexe, version 0.0.0.0, fault address 0x000106ac.Processing media-specific event for [sed.cfexe!ws!]Event Record #/Type3768 / ErrorEvent Submitted/Written: 10/09/2007 08:48:33 PMEvent ID/Source: 101 / Automatic LiveUpdate SchedulerEvent Description:Information Level: errorThis service is not authorized to start.Event Record #/Type3764 / ErrorEvent Submitted/Written: 10/09/2007 08:42:40 PMEvent ID/Source: 1000 / Application ErrorEvent Description:Faulting application sed.cfexe, version 0.0.0.0, faulting module sed.cfexe, version 0.0.0.0, fault address 0x000106ac.Processing media-specific event for [sed.cfexe!ws!]Event Record #/Type3762 / ErrorEvent Submitted/Written: 10/09/2007 08:21:46 PMEvent ID/Source: 1000 / Application ErrorEvent Description:Faulting application cricket07.exe, version 0.0.0.0, faulting module cricket07.exe, version 0.0.0.0, fault address 0x00252d32.Processing media-specific event for [cricket07.exe!ws!]Event Record #/Type3761 / ErrorEvent Submitted/Written: 10/09/2007 06:42:08 PMEvent ID/Source: 1000 / Application ErrorEvent Description:Faulting application vlc.exe, version 0.8.6.0, faulting module libwxwidgets_plugin.dll, version 0.0.0.0, fault address 0x00167c6c.Processing media-specific event for [vlc.exe!ws!]-- Security Event Log ----------------------------------------------------------No Errors/Warnings found.-- System Event Log ------------------------------------------------------------Event Record #/Type6968 / ErrorEvent Submitted/Written: 10/09/2007 08:49:15 PMEvent ID/Source: 7000 / Service Control ManagerEvent Description:The Norton Protection Center Service service failed to start due to the following error: %%2Event Record #/Type6967 / ErrorEvent Submitted/Written: 10/09/2007 08:49:15 PMEvent ID/Source: 7000 / Service Control ManagerEvent Description:The Automatic LiveUpdate Scheduler service failed to start due to the following error: %%1053Event Record #/Type6966 / ErrorEvent Submitted/Written: 10/09/2007 08:49:15 PMEvent ID/Source: 7009 / Service Control ManagerEvent Description:Timeout (30000 milliseconds) waiting for the Automatic LiveUpdate Scheduler service to connect.Event Record #/Type6953 / ErrorEvent Submitted/Written: 10/09/2007 08:22:19 PMEvent ID/Source: 29 / W32TimeEvent Description:The time provider NtpClient is configured to acquire time from one or moretime sources, however none of the sources are currently accessible. No attempt to contact a source will be made for 14 minutes.NtpClient has no source of accurate time.Event Record #/Type6952 / ErrorEvent Submitted/Written: 10/09/2007 08:22:19 PMEvent ID/Source: 17 / W32TimeEvent Description:Time Provider NtpClient: An error occurred during DNS lookup of the manuallyconfigured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15minutes.The error was: A socket operation was attempted to an unreachable host. (0x80072751)-- End of Deckard's System Scanner: finished at 2007-10-09 21:06:28 ------------Thanks A Million For Helping!!! Link to post Share on other sites
Andro1d Posted October 10, 2007 Report Share Posted October 10, 2007 Hey,Step 1Jotti File Submission:Please go to Jotti's malware scanCopy and paste the following file path into the "File to upload & scan"box on the top of the page:C:\WINDOWS\system32\7881C6E694.sysClick on the submit buttonPlease also submit this fileC:\WINDOWS\system32\6A779F9613.sysPlease post the results of the scan in your next reply.If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/ Step 2Open notepad and copy/paste the text in the quotebox below into it:DirLook::C:\.Trash-guestC:\MicrosoftFileLook::C:\WINDOWS\system32\7881C6E694.sysC:\WINDOWS\system32\6A779F9613.sysSave this as CFScript.txtThen drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThislog.Step 3I do not recommend that you have more than one anti virus product installed and running on your computer at a time. The reason for this is that if both products have their automatic (Real-Time) protection switched on, then those products which do not encrypt the virus strings within them can cause other anti virus products to cause "false alarms". It can also lead to a clash as both products fight for access to files which are opened again this is the resident/automatic protection. In general terms, the two programs may conflict and cause:1) False Alarms: When the anti virus software tells you that your PC has a virus when it actually doesn't. 2) System Performance Problems: Your system may lock up due to both products attempting to access the same file at the same time.Therefore please go to Add or Remove in the control panel and remove either Norton or Kaspersky.Step 4Lets run an F-Secure online scan for Viruses, Spyware and RootKits:Go to http://support.f-secure.com/enu/home/ols.shtmlScroll to the bottom of the page and click the Start scanning button. A window will pop up.Allow the Active X control to be installed on your computer, then click the Accept buttonClick Full System Scan and allow the components to download and the scan to complete.If malware is found, check Submit samples to F-Secure then select Automatic cleaningWhen cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this postIf Automatic cleaning with Submit samples hangs, click Cancel, then New ScanWhen the cleaning option is presented, Uncheck Submit samples to F-SecureClick Automatic cleaningWhen cleaning has finitished, click Show report (this will open an Internet Explorer window containing the report)Highlight and Copy (CTRL + C) the complete report, and Paste (CTRL + V) in a new reply to this postNotes: This scan will only work with Internet ExplorerYou must have administrator rights to run this scanThis scan can take several hours, so please be patient Link to post Share on other sites
rohangpatil Posted October 10, 2007 Author Report Share Posted October 10, 2007 Kaspersky has by default uninstalled the the previous antivirus program. i dunno why the log shows both Symantec and Kaspersky running.. Norton not listed in Add Remove Programs. Link to post Share on other sites
Andro1d Posted October 11, 2007 Report Share Posted October 11, 2007 So I am guessing you want Norton removed? Link to post Share on other sites
Recommended Posts