Unsolved
This post is more than 5 years old
7 Posts
0
6046
February 6th, 2009 08:00
Google redirect virus removal; antispyware update blocked
In the last week I believe I have been infected with what appears to be one of the viruses that redirects google searches (both on IE and Firefox). Also, windows update, defender and adaware updates have quit working although my McAfee is still updating. I believe the machine was infected through an autorun virus on a usb memory stick. I have tried some of the analysis tools such as Maywarebytes Antimalware which found some registry issues which were cleaned up. It seemed to work OK for a short period of time but then the virus reappeared. I have downloaded Hijackthis and captured the analysis log. Unfortunately, I am at about the end of my confidence level at modifying the register to rid the machine ot his. Anyone there that can help?
Here is the log:
____________________________________________________________________
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:44:59 PM, on 05/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files\BellCanada\McciTrayApp.exe
C:\Program Files\Password Keychain\Passkeychain.exe
C:\Program Files\Samsung\FrameManager\FrameManager.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [BellCanada_McciTrayApp] C:\Program Files\BellCanada\McciTrayApp.exe
O4 - HKLM\..\Run: [Password Keychain] C:\Program Files\Password Keychain\Passkeychain.exe /H
O4 - HKLM\..\Run: [FrameManager] C:\Program Files\Samsung\FrameManager\FrameManager.exe
O4 - HKLM\..\Run: [zzzHPSETUP] E:\Setup.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/44.10/uploader2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FrameManager Service - Samsung India Software Center - C:\Program Files\Samsung\FrameManager\sam_service.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
--
End of file - 12289 bytes


bamajim
10.4K Posts
0
February 6th, 2009 09:00
Not much showing up in your log
1. Go HERE and download File Lister.
Rt Click ->> Extract all ->> And extract it to your Desktop
Additional help on extracting zip files can be found HERE
Open the File Lister Folder.
Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
As the program runs, it will appear that nothing is happening.
When the program is fnished it will produce a log for you C:\Files.txt
Copy and paste the contents of that log in your reply.
The_Chief
7 Posts
0
February 7th, 2009 05:00
I was unable to get the File Lister to produce the log file (waited 10 minutes). It extraced OK.
I checked the process running and found wscript.exe consuming about 50% of the processor resources. Is this a symptom of the virus???
bamajim
10.4K Posts
0
February 10th, 2009 06:00
Sorry for the late reply, I have been under the weather.
1. Reboot into Safe Mode and see if you can get FileLister to run in Safe Mode. If you are unabletto do so, then proceed to step 2.
2. Go HERE and Download System Repair Engineer by smallfrogs
Select local download
Rt Click sreng2.zip->>Extract all->>Extract it to your desktop
Open the sreng folder
Double click SREngPS.exe->>Click Run
At the main Window, in the left Pane,Select Smart Scan
At the next window make sure all of the boxes are checked and Select Scan
When the scan is complete Select Save reports
Save it to your desktop and Close the tool
Double Click SREngLog.txt copy and paste that log as a reply to this thread
Do not run any other options with this tool unless instructed to do so.
The_Chief
7 Posts
0
February 12th, 2009 05:00
I was able to run file lister under safe mode. Here is the log:
+++++++++++++++++++++++++++++++++
+ File Lister Version 1.0.5
+
+ By bamajim / bamajim.com
+++++++++++++++++++++++++++++++++
Report ran on --->>> 12/02/2009 8:20:30 AM
====== Running Processes ======
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\System32\WScript.exe
C:\Windows\system32\wbem\wmiprvse.exe
====== BHO's under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects ======
BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: (NO NAME) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
BHO: (NO NAME) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
BHO: (NO NAME) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
====== Values under HKLM\~\Run ======
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,57,69,\
6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,4d,53,41,53,43,75,69,2e,65,78,\
65,20,2d,68,69,64,65,00
"ECenter"="C:\\Dell\\E-Center\\EULALauncher.exe"
"Apoint"="C:\\Program Files\\DellTPad\\Apoint.exe"
"SysTrayApp"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,49,44,54,5c,\
57,44,4d,5c,73,74,74,72,61,79,2e,65,78,65,00
"StartCCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\Core-Static\\CLIStart.exe\""
"IAAnotif"="\"C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\Iaanotif.exe\""
"Broadcom Wireless Manager UI"="C:\\Windows\\system32\\WLTRAY.exe"
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"dscactivate"="\"C:\\Program Files\\Dell Support Center\\gs_agent\\custom\\dsca.exe\""
"Dell Webcam Central"="\"C:\\Program Files\\Dell Webcam\\Dell Webcam Central\\WebcamDell.exe\" /mode2"
"PCMService"="\"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe\""
"Dell DataSafe Online"="\"C:\\Program Files\\Dell DataSafe Online\\DataSafeOnline.exe\" /m"
"Adobe Reader Speed Launcher"="\"c:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\""
"WD Button Manager"="WDBtnMgr.exe"
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"
"ShStatEXE"="\"C:\\Program Files\\McAfee\\VirusScan Enterprise\\SHSTAT.EXE\" /STANDALONE"
"McAfeeUpdaterUI"="\"C:\\Program Files\\McAfee\\Common Framework\\UdaterUI.exe\" /StartedFromRunKey"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Elements 6.0\\apdproxy.exe\""
"NBKeyScan"="\"C:\\Program Files\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"
"BellCanada_McciTrayApp"="C:\\Program Files\\BellCanada\\McciTrayApp.exe"
"Password Keychain"="C:\\Program Files\\Password Keychain\\Passkeychain.exe /H"
"FrameManager"="C:\\Program Files\\Samsung\\FrameManager\\FrameManager.exe"
"zzzHPSETUP"="E:\\Setup.exe"
"Ad-Watch"="C:\\Program Files\\Lavasoft\\Ad-Aware\\AAWTray.exe"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
@=""
====== Values under HKCU\~\Run ======
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"
"DAEMON Tools Lite"="\"C:\\Program Files\\DAEMON Tools Lite\\daemon.exe\" -autorun"
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Nero\\Lib\\NMIndexStoreSvr.exe\" ASO-616B5711-6DAE-4795-A05F-39A1E5104020"
====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======
25/01/2009 4:52:37 PM 0 C:\My_Outlook_Files
02/02/2009 3:58:19 PM 1460832256 C:\Temp
30/01/2009 10:46:39 AM 2144 32 C:\aaw7boot.log
12/02/2009 8:20:31 AM 0 32 C:\Files.txt
25/01/2009 4:52:40 PM 0 32 C:\temp.000
04/01/2009 8:57:14 PM 0 C:\Windows\Roaming
04/01/2009 8:57:14 PM 0 C:\Windows\Roaming\Motive
25/01/2009 4:52:37 PM 71 32 C:\Windows\34h929a.o2m
23/01/2009 1:09:05 PM 0 32 C:\Windows\Irremote.ini
22/01/2009 1:55:34 PM 306688 32 C:\Windows\IsUninst.exe
25/01/2009 4:52:37 PM 0 32 C:\Windows\j38fnbs1.tmp
12/01/2009 9:26:17 AM 74 32 C:\Windows\MPLAYER.INI
12/02/2009 8:19:27 AM 187808 32 C:\Windows\ntbtlog.txt
05/02/2009 5:16:59 PM 336 32 C:\Windows\PFRO.log
28/12/2008 3:42:28 PM 188 32 C:\Windows\QUICKEN.INI
10/02/2009 11:07:17 AM 714 32 C:\Windows\setupact.log
10/02/2009 11:07:17 AM 0 32 C:\Windows\setuperr.log
12/12/2008 8:32:10 AM 972072 32 C:\Windows\UNNeroMediaHome.exe
28/01/2009 10:57:36 AM 73867 C:\Windows\System32\DRVSTORE
28/01/2009 10:57:36 AM 73867 C:\Windows\System32\DRVSTORE\lbd_D996E5CC178082520D5C11260A28955C8455FD4A
28/12/2008 3:43:16 PM 1843200 32 C:\Windows\System32\acXMLParser.dll
28/12/2008 3:43:15 PM 3518464 32 C:\Windows\System32\cdintf300.dll
05/01/2009 5:33:03 PM 3751995 32 C:\Windows\System32\GPhotos.scr
22/01/2009 1:55:12 PM 40960 32 C:\Windows\System32\hpg4400.dll
22/01/2009 1:55:12 PM 225280 32 C:\Windows\System32\hpgtpusd.dll
22/01/2009 1:55:12 PM 253952 32 C:\Windows\System32\hpgtulbz.dll
22/01/2009 1:55:12 PM 106496 32 C:\Windows\System32\hpguapi.dll
22/01/2009 1:55:12 PM 249856 32 C:\Windows\System32\hpgud32.dll
22/01/2009 1:55:12 PM 118784 32 C:\Windows\System32\hpsjvset.dll
28/01/2009 2:43:54 PM 15688 32 C:\Windows\System32\lsdelete.exe
18/12/2008 3:00:24 AM 3578880 32 C:\Windows\System32\mshtml.dll
23/01/2009 1:09:49 PM 773120 32 C:\Windows\System32\NEROINSTAEC43759.DB
06/02/2009 5:04:27 PM 2767 32 C:\Windows\System32\R.txt
22/01/2009 1:55:12 PM 385024 32 C:\Windows\System32\rts8891u.dll
09/01/2009 9:07:10 AM 18744 32 C:\Windows\System32\sam_minidisplay.dll
23/01/2009 1:09:48 PM 1414440 32 C:\Windows\System32\ShellManager310E2D762.dll
22/01/2009 1:51:53 PM 1409 32 C:\Windows\System32\tmp07535.FOT
22/01/2009 1:51:53 PM 1409 32 C:\Windows\System32\tmp35735.FOT
22/01/2009 1:51:53 PM 1409 32 C:\Windows\System32\tmp4C435.FOT
22/01/2009 1:51:53 PM 1409 32 C:\Windows\System32\tmp67435.FOT
22/01/2009 1:51:53 PM 1409 32 C:\Windows\System32\tmp7B635.FOT
22/01/2009 1:51:53 PM 1409 32 C:\Windows\System32\tmpDE535.FOT
====== Files under "\Administrator\Startup" Last 60 Days======
====== Files under "\All Users\Startup" Last 60 Days======
====== Folders under "\Program Files" Last 60 Days======
04/01/2009 8:58:19 PM 7386464 C:\Program Files\BellCanada
04/01/2009 8:59:00 PM 3620870 C:\Program Files\BellCanada\OCB
04/01/2009 8:59:01 PM 1915886 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53
04/01/2009 8:59:06 PM 38384 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\AlertTemplates
04/01/2009 8:59:06 PM 34780 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\AlertWebFlow
04/01/2009 8:59:06 PM 482353 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant
04/01/2009 8:59:08 PM 1476 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\css
04/01/2009 8:59:07 PM 150277 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\images
04/01/2009 8:59:07 PM 49950 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\images\CPE
04/01/2009 8:59:08 PM 56275 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\LAN
04/01/2009 8:59:08 PM 101498 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\text
04/01/2009 8:59:08 PM 102890 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\wireless
04/01/2009 8:59:06 PM 18756 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\css
04/01/2009 8:59:06 PM 202206 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\Escalator
04/01/2009 8:59:06 PM 202206 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\Escalator\DSL
04/01/2009 8:59:09 PM 23971 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\images
04/01/2009 8:59:06 PM 24325 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\IVRWebFlow
04/01/2009 8:59:01 PM 63122 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ProfileDefinitions
04/01/2009 8:59:02 PM 6762 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\Registration
04/01/2009 8:59:02 PM 893682 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts
04/01/2009 8:59:03 PM 104944 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\en_US
04/01/2009 8:59:05 PM 66198 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\fr_CA
04/01/2009 8:59:03 PM 231820 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\modems
04/01/2009 8:59:03 PM 179666 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\modems\EfficientBC
04/01/2009 8:59:02 PM 75809 C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\SDM
04/01/2009 8:59:00 PM 1704984 C:\Program Files\BellCanada\OCB\McciScripts
04/01/2009 8:59:01 PM 787002 C:\Program Files\BellCanada\OCB\McciScripts\McciInstrumentation
04/01/2009 8:59:01 PM 109262 C:\Program Files\BellCanada\OCB\McciScripts\McciInstrumentation\McciFirewall
04/01/2009 8:59:00 PM 117778 C:\Program Files\BellCanada\OCB\McciScripts\McciNet
04/01/2009 8:59:00 PM 536147 C:\Program Files\BellCanada\OCB\McciScripts\McciProfiler
04/01/2009 8:59:00 PM 168156 C:\Program Files\BellCanada\OCB\McciScripts\McciSys
04/01/2009 8:59:00 PM 95901 C:\Program Files\BellCanada\OCB\McciScripts\McciUtility
05/02/2009 5:03:46 PM 2332882 C:\Program Files\CCleaner
05/02/2009 5:03:46 PM 766976 C:\Program Files\CCleaner\Lang
12/01/2009 9:25:25 AM 54803776 C:\Program Files\Family Tree Maker 2005
12/01/2009 9:25:25 AM 510102 C:\Program Files\Family Tree Maker 2005\ASPI
12/01/2009 9:25:33 AM 8512542 C:\Program Files\Family Tree Maker 2005\Clickart
12/01/2009 9:25:33 AM 81474 C:\Program Files\Family Tree Maker 2005\Clickart\Chanuka
12/01/2009 9:25:34 AM 1337740 C:\Program Files\Family Tree Maker 2005\Clickart\Christms
12/01/2009 9:25:35 AM 489330 C:\Program Files\Family Tree Maker 2005\Clickart\Easter
12/01/2009 9:25:33 AM 538718 C:\Program Files\Family Tree Maker 2005\Clickart\History
12/01/2009 9:25:35 AM 1281202 C:\Program Files\Family Tree Maker 2005\Clickart\Misc
12/01/2009 9:25:36 AM 3566254 C:\Program Files\Family Tree Maker 2005\Clickart\National
12/01/2009 9:25:37 AM 2231692 C:\Program Files\Family Tree Maker 2005\Clickart\National\Flags
12/01/2009 9:25:40 AM 874988 C:\Program Files\Family Tree Maker 2005\Clickart\Nature
12/01/2009 9:25:40 AM 78384 C:\Program Files\Family Tree Maker 2005\Clickart\Nature\Flowers
12/01/2009 9:25:40 AM 383860 C:\Program Files\Family Tree Maker 2005\Clickart\Nature\Misc
12/01/2009 9:25:41 AM 412744 C:\Program Files\Family Tree Maker 2005\Clickart\Nature\Trees
12/01/2009 9:25:41 AM 342836 C:\Program Files\Family Tree Maker 2005\Clickart\Religion
12/01/2009 9:25:41 AM 210212 C:\Program Files\Family Tree Maker 2005\Clickart\Religion\Chrstian
12/01/2009 9:25:41 AM 128464 C:\Program Files\Family Tree Maker 2005\Clickart\Religion\Judaism
12/01/2009 9:25:32 AM 2915206 C:\Program Files\Family Tree Maker 2005\Dirfiles
12/01/2009 9:25:32 AM 123127 C:\Program Files\Family Tree Maker 2005\Events
12/01/2009 9:25:33 AM 12150 C:\Program Files\Family Tree Maker 2005\Html
12/01/2009 9:25:33 AM 7322 C:\Program Files\Family Tree Maker 2005\Html\Images
12/01/2009 9:25:54 AM 1948479 C:\Program Files\Family Tree Maker 2005\Manuals
12/01/2009 9:25:32 AM 16999424 C:\Program Files\Family Tree Maker 2005\Maps
12/01/2009 9:25:31 AM 665305 C:\Program Files\Family Tree Maker 2005\Spell
12/01/2009 9:25:32 AM 870821 C:\Program Files\Family Tree Maker 2005\Template
22/01/2009 1:53:48 PM 0 C:\Program Files\Hewlett-Packard
22/01/2009 1:53:48 PM 0 C:\Program Files\Hewlett-Packard\Precisionscan Pro 3.1
28/01/2009 10:57:19 AM 46747814 C:\Program Files\Lavasoft
28/01/2009 10:57:19 AM 46747814 C:\Program Files\Lavasoft\Ad-Aware
28/01/2009 10:57:19 AM 1345790 C:\Program Files\Lavasoft\Ad-Aware\drivers
28/01/2009 10:57:19 AM 466387 C:\Program Files\Lavasoft\Ad-Aware\drivers\32
28/01/2009 10:57:19 AM 879403 C:\Program Files\Lavasoft\Ad-Aware\drivers\64
28/01/2009 10:57:19 AM 28207815 C:\Program Files\Lavasoft\Ad-Aware\Resources
28/01/2009 10:57:19 AM 6106987 C:\Program Files\Lavasoft\Ad-Aware\Toolbox
28/01/2009 10:57:19 AM 674478 C:\Program Files\Lavasoft\Ad-Aware\Toolbox\AutoStart Manager
28/01/2009 10:57:19 AM 103801 C:\Program Files\Lavasoft\Ad-Aware\Toolbox\AutoStart Manager\Skins
28/01/2009 10:57:19 AM 103801 C:\Program Files\Lavasoft\Ad-Aware\Toolbox\AutoStart Manager\Skins\grey
28/01/2009 10:57:19 AM 27993 C:\Program Files\Lavasoft\Ad-Aware\Toolbox\AutoStart Manager\translations
28/01/2009 10:57:19 AM 5432509 C:\Program Files\Lavasoft\Ad-Aware\Toolbox\LT
28/01/2009 10:57:19 AM 784843 C:\Program Files\Lavasoft\Ad-Aware\Toolbox\LT\Lang
04/02/2009 9:12:41 AM 4107152 C:\Program Files\Malwarebytes' Anti-Malware
04/02/2009 9:12:41 AM 372752 C:\Program Files\Malwarebytes' Anti-Malware\Languages
02/02/2009 10:25:26 AM 23928733 C:\Program Files\Mozilla Firefox
02/02/2009 10:25:26 AM 6088054 C:\Program Files\Mozilla Firefox\chrome
02/02/2009 10:25:26 AM 2113661 C:\Program Files\Mozilla Firefox\components
02/02/2009 10:25:26 AM 53332 C:\Program Files\Mozilla Firefox\defaults
02/02/2009 10:25:27 AM 7383 C:\Program Files\Mozilla Firefox\defaults\autoconfig
02/02/2009 10:25:27 AM 36560 C:\Program Files\Mozilla Firefox\defaults\pref
02/02/2009 10:25:28 AM 9389 C:\Program Files\Mozilla Firefox\defaults\profile
02/02/2009 10:25:28 AM 1741 C:\Program Files\Mozilla Firefox\defaults\profile\chrome
02/02/2009 10:25:26 AM 1390 C:\Program Files\Mozilla Firefox\extensions
02/02/2009 10:25:27 AM 1390 C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
02/02/2009 10:25:26 AM 76331 C:\Program Files\Mozilla Firefox\greprefs
02/02/2009 10:25:26 AM 188678 C:\Program Files\Mozilla Firefox\modules
02/02/2009 10:25:26 AM 65528 C:\Program Files\Mozilla Firefox\plugins
02/02/2009 10:25:26 AM 369036 C:\Program Files\Mozilla Firefox\res
02/02/2009 10:25:26 AM 72215 C:\Program Files\Mozilla Firefox\res\dtd
02/02/2009 10:25:26 AM 80646 C:\Program Files\Mozilla Firefox\res\entityTables
02/02/2009 10:25:26 AM 79512 C:\Program Files\Mozilla Firefox\res\fonts
02/02/2009 10:25:26 AM 619 C:\Program Files\Mozilla Firefox\res\html
02/02/2009 10:25:27 AM 10686 C:\Program Files\Mozilla Firefox\searchplugins
02/02/2009 10:25:26 AM 516550 C:\Program Files\Mozilla Firefox\uninstall
25/01/2009 4:45:57 PM 3131966 C:\Program Files\O2M
25/01/2009 4:45:58 PM 130313 C:\Program Files\O2M\clicklib
25/01/2009 4:45:57 PM 168929 C:\Program Files\O2M\help
05/01/2009 11:59:25 AM 1536000 C:\Program Files\Password Keeper 3
05/01/2009 2:26:08 PM 1642845 C:\Program Files\Password Keychain
05/01/2009 2:26:11 PM 0 C:\Program Files\Password Keychain\Backups
28/12/2008 3:42:32 PM 72589807 C:\Program Files\Quicken
28/12/2008 3:42:42 PM 4689310 C:\Program Files\Quicken\AnswerWorks
28/12/2008 3:42:52 PM 993 C:\Program Files\Quicken\certs
28/12/2008 3:42:40 PM 5486632 C:\Program Files\Quicken\Convert03
28/12/2008 3:43:04 PM 79136 C:\Program Files\Quicken\inet
28/12/2008 3:43:04 PM 79136 C:\Program Files\Quicken\inet\common
28/12/2008 3:43:04 PM 79136 C:\Program Files\Quicken\inet\common\system
28/12/2008 3:42:42 PM 7270849 C:\Program Files\Quicken\PDFDrv
28/12/2008 3:42:32 PM 57408 C:\Program Files\Quicken\Qsapi
28/12/2008 3:42:32 PM 691968 C:\Program Files\Quicken\Snap
28/12/2008 3:43:03 PM 3132000 C:\Program Files\Quicken\Sounds
09/01/2009 9:06:56 AM 13364301 C:\Program Files\Samsung
09/01/2009 9:06:56 AM 13364301 C:\Program Files\Samsung\FrameManager
05/02/2009 4:44:39 PM 408579 C:\Program Files\Trend Micro
05/02/2009 4:44:39 PM 408579 C:\Program Files\Trend Micro\HijackThis
====== Files under "\System32\Drivers" Last 60 Days======
28/01/2009 10:57:36 AM 64160 32 C:\Windows\System32\drivers\Lbd.sys
04/02/2009 9:12:44 AM 15504 32 C:\Windows\System32\drivers\mbam.sys
04/02/2009 9:12:42 AM 38496 32 C:\Windows\System32\drivers\mbamswissarmy.sys
04/01/2009 11:14:12 PM 0 34 C:\Windows\System32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
04/01/2009 11:14:12 PM 0 34 C:\Windows\System32\drivers\Msft_Kernel_motccgp_01005.Wdf
04/01/2009 11:14:17 PM 0 34 C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
04/01/2009 11:14:20 PM 0 34 C:\Windows\System32\drivers\Msft_Kernel_motport_01005.Wdf
09/01/2009 9:07:10 AM 18616 32 C:\Windows\System32\drivers\sam_miniport.sys
09/01/2009 9:11:45 AM 17336 32 C:\Windows\System32\drivers\sam_miniusb.sys
13/01/2009 4:04:50 PM 288768 32 C:\Windows\System32\drivers\srv.sys
====== Files Deleted under "%Temp%" ======
C:\Users\Chris\AppData\Local\Temp\alm.log
C:\Users\Chris\AppData\Local\Temp\amt.log
C:\Users\Chris\AppData\Local\Temp\Chris.bmp
C:\Users\Chris\AppData\Local\Temp\HostsXpert.zip
C:\Users\Chris\AppData\Local\Temp\jinstall.cfg
C:\Users\Chris\AppData\Local\Temp\jre-6u11-windows-i586-p-iftw_196cf524.exe
C:\Users\Chris\AppData\Local\Temp\jusched.log
C:\Users\Chris\AppData\Local\Temp\MSI66279.LOG
C:\Users\Chris\AppData\Local\Temp\MSIc10d0.LOG
C:\Users\Chris\AppData\Local\Temp\MSIf78b7.LOG
C:\Users\Chris\AppData\Local\Temp\pse-conversion-log_My Catalog.txt
C:\Users\Chris\AppData\Local\Temp\swtag.log
C:\Users\Chris\AppData\Local\Temp\TWAIN.LOG
C:\Users\Chris\AppData\Local\Temp\Twain001.Mtx
C:\Users\Chris\AppData\Local\Temp\Twunk001.MTX
C:\Users\Chris\AppData\Local\Temp\Twunk002.MTX
C:\Users\Chris\AppData\Local\Temp\wmplog00.sqm
C:\Users\Chris\AppData\Local\Temp\~DF2E0D.tmp
C:\Users\Chris\AppData\Local\Temp\~DF4A41.tmp
C:\Users\Chris\AppData\Local\Temp\~DF97FA.tmp
C:\Users\Chris\AppData\Local\Temp\~DF99D3.tmp
C:\Users\Chris\AppData\Local\Temp\~DFB574.tmp
C:\Users\Chris\AppData\Local\Temp\~DFDA82.tmp
23 Files deleted
====== Files and Folders under "All Users\Application Data" Last 60 Days======
====== Possible Rootkit Scan (Note: Items listed here are not necessarily bad)======
====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======
HKLM\Software\microsoft\shared tools\msconfig\startupreg\
====== Services ( Services that are Whitelisted are not shown) ======
Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe - Auto
Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe - Auto
Application Experience (AeLookupSvc) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Andrea ST Filters Service (AESTFilters) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe - Auto
Application Layer Gateway Service (ALG) C:\Windows\System32\alg.exe - Manual
Application Information (Appinfo) C:\Windows\system32\svchost.exe -k netsvcs - Manual
Ati External Event Utility (Ati External Event Utility) C:\Windows\system32\Ati2evxx.exe - Auto
Windows Audio Endpoint Builder (AudioEndpointBuilder) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Windows Audio (Audiosrv) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Auto
Base Filtering Engine (***) C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - Auto
Background Intelligent Transfer Service (BITS) C:\Windows\System32\svchost.exe -k netsvcs - Auto
Computer Browser (Browser) C:\Windows\System32\svchost.exe -k netsvcs - Auto
Certificate Propagation (CertPropSvc) C:\Windows\system32\svchost.exe -k netsvcs - Manual
Microsoft .NET Framework NGEN v2.0.50727_X86 (clr_optimization_v2.0.50727_32) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe - Manual
COM+ System Application (COMSysApp) C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} - Manual
Cryptographic Services (CryptSvc) C:\Windows\system32\svchost.exe -k NetworkService - Auto
DCOM Server Process Launcher (DcomLaunch) C:\Windows\system32\svchost.exe -k DcomLaunch - Auto
DFS Replication (DFSR) C:\Windows\system32\DFSR.exe - Manual
DHCP Client (Dhcp) C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted - Auto
DNS Client (Dnscache) C:\Windows\system32\svchost.exe -k NetworkService - Auto
Dock Login Service (DockLoginService) C:\Program Files\Dell\DellDock\DockLogin.exe - Auto
Wired AutoConfig (dot3svc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Manual
Diagnostic Policy Service (DPS) C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork - Auto
Extensible Authentication Protocol (EapHost) C:\Windows\System32\svchost.exe -k netsvcs - Manual
Windows Media Center Receiver Service (ehRecvr) C:\Windows\ehome\ehRecvr.exe - Manual
Windows Media Center Scheduler Service (ehSched) C:\Windows\ehome\ehsched.exe - Manual
Windows Media Center Service Launcher (ehstart) C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - Auto
ReadyBoost (EMDMgmt) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Windows Event Log (Eventlog) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Auto
COM+ Event System (EventSystem) C:\Windows\system32\svchost.exe -k LocalService - Auto
Function Discovery Provider Host (fdPHost) C:\Windows\system32\svchost.exe -k LocalService - Manual
Function Discovery Resource Publication (FDResPub) C:\Windows\system32\svchost.exe -k LocalService - Auto
FLEXnet Licensing Service (FLEXnet Licensing Service) "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe" - Manual
Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe - Manual
FrameManager Service (FrameManager Service) C:\Program Files\Samsung\FrameManager\sam_service.exe - Auto
Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" - Manual
GoToAssist (GoToAssist) "C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe" Start=service - Manual
Group Policy Client (gpsvc) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Google Updater Service (gusvc) "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" - Auto
Human Interface Device Access (hidserv) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Health Key and Certificate Management (hkmsvc) C:\Windows\System32\svchost.exe -k netsvcs - Manual
Intel(R) Matrix Storage Event Monitor (IAANTMON) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe - Auto
Windows CardSpace (idsvc) "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe" - Manual
IKE and AuthIP IPsec Keying Modules (IKEEXT) C:\Windows\system32\svchost.exe -k netsvcs - Auto
PnP-X IP Bus Enumerator (IPBusEnum) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Manual
IP Helper (iphlpsvc) C:\Windows\System32\svchost.exe -k NetSvcs - Auto
CNG Key Isolation (KeyIso) C:\Windows\system32\lsass.exe - Manual
KtmRm for Distributed Transaction Coordinator (KtmRm) C:\Windows\System32\svchost.exe -k NetworkService - Auto
Server (LanmanServer) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Workstation (LanmanWorkstation) C:\Windows\System32\svchost.exe -k LocalService - Auto
Lavasoft Ad-Aware Service (Lavasoft Ad-Aware Service) "C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe" - Auto
Link-Layer Topology Discovery Mapper (lltdsvc) C:\Windows\System32\svchost.exe -k LocalService - Manual
TCP/IP NetBIOS Helper (lmhosts) C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted - Auto
McAfee Framework Service (McAfeeFramework) "C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart - Auto
McciCMService (McciCMService) "C:\Program Files\Common Files\Motive\McciCMService.exe" - Auto
McAfee McShield (McShield) "C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe" - Auto
McAfee Task Manager (McTaskManager) "C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe" - Auto
Windows Media Center Extender Service (Mcx2Svc) C:\Windows\system32\svchost.exe -k LocalService - Disabled
Multimedia Class Scheduler (MMCSS) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Windows Firewall (MpsSvc) C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork - Auto
Distributed Transaction Coordinator (MSDTC) C:\Windows\System32\msdtc.exe - Manual
Microsoft iSCSI Initiator Service (MSiSCSI) C:\Windows\system32\svchost.exe -k netsvcs - Manual
Windows Installer (msiserver) C:\Windows\system32\msiexec /V - Manual
Network Access Protection Agent (napagent) C:\Windows\System32\svchost.exe -k NetworkService - Manual
Nero BackItUp Scheduler 3 (Nero BackItUp Scheduler 3) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe - Auto
Netlogon (Netlogon) C:\Windows\system32\lsass.exe - Manual
Network Connections (Netman) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - Manual
Network List Service (netprofm) C:\Windows\System32\svchost.exe -k LocalService - Auto
Net.Tcp Port Sharing Service (NetTcpPortSharing) "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe" - Disabled
Network Location Awareness (NlaSvc) C:\Windows\System32\svchost.exe -k NetworkService - Auto
NMIndexingService (NMIndexingService) "C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe" - Manual
Network Store Interface Service (nsi) C:\Windows\system32\svchost.exe -k LocalService - Auto
Office Source Engine (ose) "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" - Manual
Peer Networking Identity Manager (p2pimsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Manual
Peer Networking Grouping (p2psvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Manual
Program Compatibility Assistant Service (PcaSvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Performance Logs & Alerts (pla) C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork - Manual
PLFlash DeviceIoControl Service (PLFlash DeviceIoControl Service) C:\Windows\system32\IoctlSvc.exe - Auto
Plug and Play (PlugPlay) C:\Windows\system32\svchost.exe -k DcomLaunch - Auto
PNRP Machine Name Publication Service (PNRPAutoReg) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Manual
Peer Name Resolution Protocol (PNRPsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Manual
IPsec Policy Agent (PolicyAgent) C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted - Auto
User Profile Service (ProfSvc) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Protected Storage (ProtectedStorage) C:\Windows\system32\lsass.exe - Manual
Quality Windows Audio Video Experience (QWAVE) C:\Windows\system32\svchost.exe -k LocalService - Manual
Remote Access Auto Connection Manager (RasAuto) C:\Windows\system32\svchost.exe -k netsvcs - Manual
Remote Access Connection Manager (RasMan) C:\Windows\system32\svchost.exe -k netsvcs - Manual
Routing and Remote Access (RemoteAccess) C:\Windows\system32\svchost.exe -k netsvcs - Disabled
Remote Registry (RemoteRegistry) C:\Windows\system32\svchost.exe -k regsvc - Manual
Remote Procedure Call (RPC) Locator (RpcLocator) C:\Windows\system32\locator.exe - Manual
Remote Procedure Call (RPC) (RpcSs) C:\Windows\system32\svchost.exe -k rpcss - Auto
Security Accounts Manager (SamSs) C:\Windows\system32\lsass.exe - Auto
Smart Card (SCardSvr) C:\Windows\system32\svchost.exe -k LocalService - Manual
Task Scheduler (Schedule) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Smart Card Removal Policy (SCPolicySvc) C:\Windows\system32\svchost.exe -k netsvcs - Manual
Windows Backup (SDRSVC) C:\Windows\system32\svchost.exe -k SDRSVC - Manual
Secondary Logon (seclogon) C:\Windows\system32\svchost.exe -k netsvcs - Auto
System Event Notification Service (SENS) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Terminal Services Configuration (SessionEnv) C:\Windows\System32\svchost.exe -k netsvcs - Manual
Internet Connection Sharing (ICS) (SharedAccess) C:\Windows\System32\svchost.exe -k netsvcs - Disabled
Shell Hardware Detection (ShellHWDetection) C:\Windows\System32\svchost.exe -k netsvcs - Auto
Software Licensing (slsvc) C:\Windows\system32\SLsvc.exe - Auto
SL UI Notification Service (SLUINotify) C:\Windows\system32\svchost.exe -k LocalService - Manual
SNMP Trap (SNMPTRAP) C:\Windows\System32\snmptrap.exe - Manual
Print Spooler (Spooler) C:\Windows\System32\spoolsv.exe - Auto
SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter - Auto
SSDP Discovery (SSDPSRV) C:\Windows\system32\svchost.exe -k LocalService - Manual
Secure Socket Tunneling Protocol Service (SstpSvc) C:\Windows\system32\svchost.exe -k LocalService - Manual
Audio Service (STacSV) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe - Auto
Windows Image Acquisition (WIA) (stisvc) C:\Windows\system32\svchost.exe -k imgsvc - Auto
stllssvr (stllssvr) "C:\Program Files\Common Files\SureThing Shared\stllssvr.exe" - Manual
Microsoft Software Shadow Copy Provider (swprv) C:\Windows\System32\svchost.exe -k swprv - Manual
Superfetch (SysMain) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Tablet PC Input Service (TabletInputService) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Telephony (TapiSrv) C:\Windows\System32\svchost.exe -k NetworkService - Manual
TPM Base Services (TBS) C:\Windows\System32\svchost.exe -k LocalService - Auto
Terminal Services (TermService) C:\Windows\System32\svchost.exe -k NetworkService - Auto
Themes (Themes) C:\Windows\System32\svchost.exe -k netsvcs - Auto
Thread Ordering Server (THREADORDER) C:\Windows\system32\svchost.exe -k LocalService - Manual
Distributed Link Tracking Client (TrkWks) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Windows Modules Installer (TrustedInstaller) C:\Windows\servicing\TrustedInstaller.exe - Manual
Interactive Services Detection (UI0Detect) C:\Windows\system32\UI0Detect.exe - Manual
UPnP Device Host (upnphost) C:\Windows\system32\svchost.exe -k LocalService - Auto
Desktop Window Manager Session Manager (UxSms) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Virtual Disk (vds) C:\Windows\System32\vds.exe - Manual
Volume Shadow Copy (VSS) C:\Windows\system32\vssvc.exe - Manual
Windows Time (W32Time) C:\Windows\system32\svchost.exe -k LocalService - Auto
Windows Connect Now - Config Registrar (wcncsvc) C:\Windows\System32\svchost.exe -k LocalService - Manual
Windows Color System (WcsPlugInService) C:\Windows\system32\svchost.exe -k wcssvc - Manual
Diagnostic Service Host (WdiServiceHost) C:\Windows\System32\svchost.exe -k wdisvc - Manual
Diagnostic System Host (WdiSystemHost) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted - Manual
WebClient (WebClient) C:\Windows\system32\svchost.exe -k LocalService - Auto
Windows Event Collector (Wecsvc) C:\Windows\system32\svchost.exe -k NetworkService - Manual
Problem Reports and Solutions Control Panel Support (wercplsupport) C:\Windows\System32\svchost.exe -k netsvcs - Manual
Windows Error Reporting Service (WerSvc) C:\Windows\System32\svchost.exe -k WerSvcGroup - Auto
Windows Defender (WinDefend) C:\Windows\System32\svchost.exe -k secsvcs - Auto
WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc) C:\Windows\system32\svchost.exe -k LocalService - Manual
Windows Management Instrumentation (Winmgmt) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Windows Remote Management (WS-Management) (WinRM) C:\Windows\System32\svchost.exe -k NetworkService - Manual
WLAN AutoConfig (Wlansvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Dell Wireless WLAN Tray Service (wltrysvc) C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe - Auto
WMI Performance Adapter (wmiApSrv) C:\Windows\system32\wbem\WmiApSrv.exe - Manual
Windows Media Player Network Sharing Service (WMPNetworkSvc) "C:\Program Files\Windows Media Player\wmpnetwk.exe" - Manual
Parental Controls (WPCSvc) C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted - Manual
Portable Device Enumerator Service (WPDBusEnum) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
Security Center (wscsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted - Auto
Windows Search (WSearch) C:\Windows\system32\SearchIndexer.exe /Embedding - Auto
Windows Update (wuauserv) C:\Windows\system32\svchost.exe -k netsvcs - Auto
Windows Driver Foundation - User-mode Driver Framework (wudfsvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted - Auto
====== Uninstall List From Registry ======
Ad-Aware
Adobe AIR
Adobe Flash Player ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements 6.0
Adobe Photoshop Elements 7.0
Advanced Audio FX Engine
BitLord 1.1
Dell Wireless WLAN Card Utility
CCleaner (remove only)
Acrobat.com
Integrated Webcam Driver (1.02.02.0603)
Dell Video Chat (remove only)
Dell Webcam Central
Google Desktop
Google Updater
GoToAssist 8.0.0.514
HijackThis 2.0.2
Internet Check-Up
Malwarebytes' Anti-Malware
Mozilla Firefox (3.0.6)
O2M 2.0 (Outlook 2002/2003/XP)
OneGlobalConnect
Password Keychain 1.0
Picasa 3
Unity Web Player
ATI Catalyst Control Center
Catalyst Control Center Core Implementation
Roxio Creator Data
Roxio Creator DE
WD Diagnostics
Catalyst Control Center Localization Chinese Standard
Dell DataSafe Online
Microsoft Works
AutoUpdate
Nero 8
Google Earth
Roxio Creator Tools
Google Toolbar for Internet Explorer
Citrix Presentation Server Client - Web Only
FrameManager
OpenOffice.org 2.4
Roxio Update Manager
Java(TM) 6 Update 4
Java(TM) 6 Update 5
Java(TM) 6 Update 7
CCC Help Italian
Catalyst Control Center Localization Chinese Traditional
McAfee VirusScan Enterprise
Catalyst Control Center Localization Norwegian
Catalyst Control Center Graphics Full New
Catalyst Control Center Localization Italian
Catalyst Control Center - Branding
Catalyst Control Center Localization Dutch
neroxml
Browser Address Error Redirector
Live! Cam Avatar Creator
Roxio Express Labeler 3
Cisco PEAP Module
CCC Help Chinese Standard
ccc-core-static
Catalyst Control Center Localization Swedish
Apple Software Update
EDocs
CCC Help German
Cisco EAP-FAST Module
CCC Help Norwegian
Aventail Access Manager
Microsoft Visual C++ 2005 Redistributable
Catalyst Control Center Localization Finnish
Roxio Creator Audio
Catalyst Control Center Localization German
Acrobat.com
Skins
CCC Help Russian
DivX Codec
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center Localization Danish
Dell Getting Started Guide
CCC Help English
Motorola Driver Installation 3.4.0
Catalyst Control Center Localization Portuguese
Cisco LEAP Module
MSXML 4.0 SP2 (KB954430)
DivX Player
QuickTime
Microsoft Office Professional Edition 2003
Compatibility Pack for the 2007 Office system
Catalyst Control Center Localization French
Intel(R) Matrix Storage Manager
Microsoft Office PowerPoint Viewer 2007 (English)
CCC Help French
Catalyst Control Center Graphics Previews Common
CCC Help Danish
Aventail Web Proxy Agent
MediaDirect
Dell Touchpad
Adobe AIR
OneGlobalConnect
Family Tree Maker 2005
CCC Help Japanese
CCC Help Portuguese
Adobe Reader 9
Spelling Dictionaries Support For Adobe Reader 9
DivX Converter
Roxio Creator Copy
DivX Web Player
Motorola Phone Tools
Catalyst Control Center Localization Spanish
MSXML 4.0 SP2 (KB936181)
QuickSet
CCC Help Finnish
MSXML 4.0 SP2 (KB941833)
Adobe Photoshop Elements 7.0
Catalyst Control Center Localization Japanese
ccc-utility
CCC Help Dutch
CCC Help Spanish
Catalyst Control Center Localization Russian
AnswerWorks 5.0 English Runtime
Catalyst Control Center Graphics Full Existing
Ad-Aware
CCC Help Chinese Traditional
Dell Support Center (Support Software)
Quicken 2008
CCC Help Swedish
Catalyst Control Center Graphics Light
Roxio Creator DE
Catalyst Control Center Localization Korean
CCC Help Korean
FrameManager
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Motorola Phone Tools
Adobe Photoshop Elements 6.0
Dell Dock
ITECIR Driver
WD Firewire HID Driver
======== Other Info ========
TOTAL PHYSICAL RAM: 3218 MB
bamajim
10.4K Posts
0
February 12th, 2009 07:00
1. Please download HostsXpert 4.0 - Hosts File Manager
2. Reboot and see if that resolves your issue
3. Do you use a router?
The_Chief
7 Posts
0
February 12th, 2009 11:00
I did the "restore original hosts" routine and the issue still remains - google searches get redirected and am unable to update Windows and Adaware.
I am using a router.
Any more suggestions???
Thanks....
bamajim
10.4K Posts
0
February 12th, 2009 13:00
Some Malware as set redirect triggers in routers by way of DNS manipulation. The only way to fix this is to do a hard reset on the router.
On most routers the reset button is on the back, but the location could be different depending on the model.
So Disconnect from the interent and do a hard reset on the router.
Reboot and see if that resolves your redirection issue.
If not;
Please download Combofix and save to your desktop:
Close any open browsers.
Double click on combofix.exe and follow the prompts.
When it's finished it will produce a log.
Post the contents of the C:\ComboFix.txt into your next reply.
Note: Do not mouseclick combofix's window whilst it's running.
That may cause the program to freeze/hang.
The_Chief
7 Posts
0
February 12th, 2009 15:00
Router reset did not solve the issue.
Ran Combofix and here is the log:
ComboFix 09-02-12.03 - Chris 2009-02-12 17:26:04.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3069.1916 [GMT -5:00]
Running from: c:\users\Chris\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\INSTALL.LOG
c:\windows\system32\drivers\gaopdxtxofcydw.sys
c:\windows\system32\gaopdxncxqitpi.dll
c:\windows\system32\R.txt
D:\resycled
d:\resycled\ntldr.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gaopdxserv.sys
((((((((((((((((((((((((( Files Created from 2009-01-12 to 2009-02-12 )))))))))))))))))))))))))))))))
.
2009-02-12 08:40 . 2009-02-12 08:40 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-02-05 17:03 . 2009-02-05 17:03
2009-02-05 16:44 . 2009-02-05 16:44
2009-02-04 09:12 . 2009-02-04 09:12
2009-02-04 09:12 . 2009-02-04 09:12
2009-02-04 09:12 . 2009-02-04 09:12
2009-02-04 09:12 . 2009-02-04 09:12
2009-02-04 09:12 . 2009-01-14 16:11 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-04 09:12 . 2009-01-14 16:11 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-02-02 15:58 . 2009-02-02 15:59
2009-01-28 14:43 . 2009-01-18 16:35 15,688 --a------ c:\windows\System32\lsdelete.exe
2009-01-28 10:57 . 2009-01-28 10:57
2009-01-28 10:57 . 2009-01-28 10:57
2009-01-28 10:57 . 2009-01-28 10:57
2009-01-28 10:57 . 2009-01-28 10:57
2009-01-28 10:57 . 2009-01-28 10:57
2009-01-28 10:57 . 2009-01-28 10:57
2009-01-28 10:57 . 2009-01-18 16:30 64,160 --a------ c:\windows\System32\drivers\Lbd.sys
2009-01-25 16:52 . 2009-01-25 16:52
2009-01-25 16:52 . 2009-01-25 16:52 71 --a------ c:\windows\34h929a.o2m
2009-01-25 16:52 . 2009-01-25 16:52 0 --a------ c:\windows\j38fnbs1.tmp
2009-01-25 16:52 . 2009-01-25 16:52 0 --a------ C:\temp.000
2009-01-25 16:45 . 2009-01-25 16:52
2009-01-23 13:09 . 2008-06-24 13:45 1,414,440 --a------ c:\windows\System32\ShellManager310E2D762.dll
2009-01-23 13:09 . 2008-06-23 17:36 773,120 --a------ c:\windows\System32\NEROINSTAEC43759.DB
2009-01-23 13:09 . 2009-01-23 13:09 0 --a------ c:\windows\Irremote.ini
2009-01-22 14:02 . 2009-01-31 21:07 8,318,896 --a------ c:\users\Chris\AppData\Roaming\DataSafeDotNet.exe
2009-01-22 13:55 . 2001-07-03 18:08 385,024 --a------ c:\windows\System32\rts8891u.dll
2009-01-22 13:55 . 1998-10-29 16:45 306,688 --a------ c:\windows\IsUninst.exe
2009-01-22 13:55 . 2001-07-03 18:08 253,952 --a------ c:\windows\System32\hpgtulbz.dll
2009-01-22 13:55 . 2001-07-03 18:08 249,856 --a------ c:\windows\System32\hpgud32.dll
2009-01-22 13:55 . 2001-07-03 18:06 225,280 --a------ c:\windows\System32\hpgtpusd.dll
2009-01-22 13:55 . 2001-07-27 15:48 118,784 --a------ c:\windows\System32\hpsjvset.dll
2009-01-22 13:55 . 2001-07-03 18:08 106,496 --a------ c:\windows\System32\hpguapi.dll
2009-01-22 13:55 . 2001-07-03 18:08 40,960 --a------ c:\windows\System32\hpg4400.dll
2009-01-22 13:54 . 2009-01-22 13:54
2009-01-22 13:54 . 2009-01-22 13:54
2009-01-22 13:53 . 2009-01-22 14:22
2009-01-22 13:51 . 2009-01-22 13:51 1,409 --a------ c:\windows\System32\tmpDE535.FOT
2009-01-22 13:51 . 2009-01-22 13:51 1,409 --a------ c:\windows\System32\tmp7B635.FOT
2009-01-22 13:51 . 2009-01-22 13:51 1,409 --a------ c:\windows\System32\tmp67435.FOT
2009-01-22 13:51 . 2009-01-22 13:51 1,409 --a------ c:\windows\System32\tmp4C435.FOT
2009-01-22 13:51 . 2009-01-22 13:51 1,409 --a------ c:\windows\System32\tmp35735.FOT
2009-01-22 13:51 . 2009-01-22 13:51 1,409 --a------ c:\windows\System32\tmp07535.FOT
2009-01-21 10:29 . 2009-01-21 10:29
2009-01-21 10:29 . 2009-01-21 10:29
2009-01-13 16:04 . 2008-12-15 21:42 288,768 --a------ c:\windows\System32\drivers\srv.sys
2009-01-13 08:40 . 2009-01-13 08:40
2009-01-12 09:26 . 2009-01-12 09:26
2009-01-12 09:26 . 2009-01-12 09:34 74 --a------ c:\windows\MPLAYER.INI
2009-01-12 09:25 . 2009-01-12 09:34
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-12 22:12 --------- d-----w c:\users\Chris\AppData\Roaming\OpenOffice.org2
2009-02-12 19:03 --------- d-----w c:\programdata\Google Updater
2009-01-23 18:12 --------- d-----w c:\program files\Common Files\Nero
2009-01-23 18:10 --------- d-----w c:\programdata\Nero
2009-01-22 19:20 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-14 08:02 --------- d-----w c:\program files\Windows Mail
2009-01-11 00:57 --------- d-----w c:\program files\Google
2009-01-09 14:06 --------- d-----w c:\program files\Samsung
2009-01-05 22:33 3,751,995 ----a-w c:\windows\System32\GPhotos.scr
2009-01-05 19:26 --------- d-----w c:\program files\Password Keychain
2009-01-05 19:13 --------- d-----w c:\program files\Password Keeper 3
2009-01-05 16:59 --------- d-----w c:\users\Chris\AppData\Roaming\AG Software
2009-01-05 07:59 --------- d-----w c:\programdata\Motive
2009-01-05 04:14 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_motport_01005.Wdf
2009-01-05 04:14 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-01-05 04:14 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2009-01-05 04:14 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2009-01-05 02:01 --------- d-----w c:\program files\Common Files\Motive
2009-01-05 01:59 --------- d-----w c:\program files\BellCanada
2008-12-28 21:22 --------- d-----w c:\program files\Common Files\Adobe AIR
2008-12-28 21:07 --------- d-----w c:\program files\Quicken
2008-12-28 21:06 --------- d-----w c:\program files\Common Files\AnswerWorks 5.0
2008-12-28 20:43 --------- d-----w c:\users\Chris\AppData\Roaming\Intuit
2008-12-28 20:43 --------- d-----w c:\program files\Common Files\Palo Alto Software
2008-12-28 20:42 --------- d-----w c:\programdata\Intuit
2008-12-28 20:42 --------- d-----w c:\program files\Common Files\Intuit
2008-12-12 13:32 972,072 ----a-w c:\windows\UNNeroMediaHome.exe
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
2008-09-24 20:46 76 --sh--r c:\windows\CT4CET.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-24 68856]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-12-12 1840424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-06-30 196608]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-06-25 442467]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-24 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-02-19 438403]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-01-14 132392]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2008-07-24 993520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-10-16 111952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2007-10-25 136512]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-12-02 2221352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-28 413696]
"BellCanada_McciTrayApp"="c:\program files\BellCanada\McciTrayApp.exe" [2008-12-07 1471488]
"Password Keychain"="c:\program files\Password Keychain\Passkeychain.exe" [2003-07-16 1437696]
"FrameManager"="c:\program files\Samsung\FrameManager\FrameManager.exe" [2008-08-12 512000]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
"WD Button Manager"="WDBtnMgr.exe" [2008-10-03 c:\windows\System32\WDBtnMgr.exe]
c:\users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-07-15 1226024]
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-05-02 1211472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-09-24 15:49 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{44E6FE93-0704-4700-8C1A-129EAFDD6DF5}"= UDP:c:\program files\Dell Video Chat\DellVideoChat.exe:Dell Video Chat
"{2CB42DA0-2B61-4016-8A53-7C8E6FEB1246}"= TCP:c:\program files\Dell Video Chat\DellVideoChat.exe:Dell Video Chat
"{CD5F073A-D515-4C56-8429-30465F199AF4}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{743EEF1B-6698-49BF-88A5-8E57816516A2}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{DDE4710C-6907-4606-91F1-A7816EA928CF}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{551720D0-ADE6-444F-A0EF-054CAE10B843}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{BF74B9CB-53C1-45C1-88C3-270310356B48}"= UDP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{120C0C6D-EA48-43F3-8536-ABC2ADFE90A8}"= TCP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{848E9101-426F-4803-B3AF-1A62D071E4AC}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{FF1CB75E-B800-47F6-97CB-69039F8F2AB4}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{9AA98B98-EC4E-450B-9A29-DAA2C0F704D2}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{24C12CC9-389D-49FC-ADA5-EADBA0042779}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{70642695-B02C-4A5B-81AB-A658CF0F0FBE}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{51362A93-3F09-4B57-A007-DE5E5588E517}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{B62AACFF-9ECD-4A55-939F-A54F3C072C87}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{C5DFE0BD-FC9D-46CF-A3E8-758D898B8E2D}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{C7D55760-2565-407F-B9E8-9B11748F1798}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{3D1AF9E0-1597-46FB-9A0D-C486C756D3C3}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-01-28 64160]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-10 124832]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\AEstSrv.exe [2008-09-24 73728]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-05-02 161048]
R2 FrameManager Service;FrameManager Service;c:\program files\Samsung\FrameManager\sam_service.exe [2009-01-09 188416]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]
R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [2008-09-24 54784]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\k57nd60x.sys [2008-09-24 203264]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\System32\drivers\OA001Ufd.sys [2008-09-24 144672]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\System32\drivers\OA001Vid.sys [2008-09-24 277504]
R3 SODI;SODI;c:\windows\System32\drivers\sam_miniport.sys [2009-01-09 18616]
S3 miniusb;FrameManager Display Adapter;c:\windows\System32\drivers\sam_miniusb.sys [2009-01-09 17336]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\System32\drivers\motccgp.sys [2007-11-02 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\System32\drivers\motccgpfl.sys [2007-01-22 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\System32\drivers\motport.sys [2007-06-18 23680]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - g:\wd_windows_tools\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0a0509a-8f31-11dd-af68-00217084631c}]
\shell\AutoRun\command - g:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 16:34]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-zzzHPSETUP - E:\Setup.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\ql9jcgr1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
FF - prefs.js: keyword.URL - about:neterror?e=query&u=
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-12 17:42:53
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files:
**************************************************************************
.
Completion time: 2009-02-12 17:44:20
ComboFix-quarantined-files.txt 2009-02-12 22:44:17
Pre-Run: 120,265,695,232 bytes free
Post-Run: 120,232,005,632 bytes free
228 --- E O F --- 2009-01-27 05:58:20
bamajim
10.4K Posts
0
February 13th, 2009 06:00
The_Chief
Nice work
Rerun Hijackthis and post a fresh Hiajckthis log.
And in your reply tell me how your PC is running now
The_Chief
7 Posts
0
February 13th, 2009 13:00
I believe the observed issues have been repaired, namely the redirected google searches and the ability to update Windows and Adaware.
Here is the log from Hijackthis .....
Let me know if there appears to be any residual problems.
Thanks again
----------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:15:15 PM, on 13/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files\BellCanada\McciTrayApp.exe
C:\Program Files\Password Keychain\Passkeychain.exe
C:\Program Files\Samsung\FrameManager\FrameManager.exe
C:\Windows\system32\conime.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Google\Picasa3\PicasaPhotoViewer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [BellCanada_McciTrayApp] C:\Program Files\BellCanada\McciTrayApp.exe
O4 - HKLM\..\Run: [Password Keychain] C:\Program Files\Password Keychain\Passkeychain.exe /H
O4 - HKLM\..\Run: [FrameManager] C:\Program Files\Samsung\FrameManager\FrameManager.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [MRT] "C:\Windows\system32\MRT.exe" /R
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/44.10/uploader2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FrameManager Service - Samsung India Software Center - C:\Program Files\Samsung\FrameManager\sam_service.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
--
End of file - 11102 bytes
bamajim
10.4K Posts
0
February 16th, 2009 06:00
Thats good news.
Let's Remove Combofix
Select Start ->> Run ->> type in combofix /u (there is a space between x and /) Then O.K.
You may now remove/delete/uninstall the other tools we used to clean your PC
Now that your log is clean
There are some final notes:
Lets create a clean System Restore point
To create a Clean System Restore Point in Vista
The System restore Window will open. Select Open System Protection
Another window will open, Hilite The C:\ Drive in the window
Then Select Create. Yet another window will open type in todays date 05262008 (or what ever you would like to remind you of this Restore Point) in the Create a restore point window.
Then Select Create. Windows will then create a restore point.
Once done you will receive notification that a System Restore point has been Created.
Close all the open widows and you are done.
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
Updating Java:
Java Runtime Environment (JRE) 6.u11.
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
Click the " Download" button to the right.
Check the box that says: " Accept License Agreement".
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u11-windowsi586-p.exe to install the newest version.
Update your Anti Virus Software
Use and maintain a Firewall
Visit Microsoft's Windows Update Site Frequently for critical updates
Backup your Important Documents and Files on a regular basis
You may want to read this article" So how did I get infected in the first place" by Tony Klein
surf safe