Unsolved

This post is more than 5 years old

73 Posts

3159

August 8th, 2008 14:00

HIjackthis File - Remote Hacking of emails/passwords...keyloggers?

I have a Dell Inspiron 1720, Windows Vista Home premium, Service Pack 1, 4GB ram, T5750, 32 bit operating system.  I have AVG antivirus, Zone Alarm Firewall, Spybot, Adware and Roboform.  I ran trend micro and there was nothing significant.  But when i ran bitdefender it caused my computer to crash..it said something about DUMP?  Not sure, so I had to restart and its working fine now. 

 

I dont know much about computers so please bear with me.  My emails have been hacked into....Its been going on for a long time.  I have changed my passwords numerous times.  Recently I downloaded roboform to prevent keyloggers? This is a brand new computer and it froze like someone took over my computer and I couldnt get the task manager opened so the only way was to hold the power button down and shut it down.  This happened NUMEROUS times with my OLD laptop but i figured it was old.  But this laptop is only a week old, so I know its someone that I know who is trying to hack into my computer and emails.  So please if you can help, I would appreciate it. This is my hijackthis log:

 

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:36:28 AM, on 8/8/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Spybot\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Palm\Hotsync.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Spybot\SPYBOT~1\SDHelper.dll
O2 - BHO: RoboForm - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [HotSync] "C:\Program Files\PalmSource\Desktop\HotSync.exe" -AllUsers
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Spybot\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [RoboForm] "C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Palm\Hotsync.exe
O8 - Extra context menu item: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O8 - Extra context menu item: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Spybot\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Spybot\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Adware\aawservice.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Spybot\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10443 bytes

10.4K Posts

August 11th, 2008 12:00

jlu

1. Go HERE and download File Lister.
  • Save it to your Desktop
    Rt Click ->> Extract all ->> And extract it to your Desktop
    Additional help on extracting zip files can be found HERE
    Open the File Lister Folder.
    Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
    As the program runs, it will appear that nothing is happening.
    When the program is fnished it will produce a log for you C:\Files.txt






Copy and paste the contents of that log in your reply.







Microsoft MVP Consumer-Security

 


"The world is what you make of it"




73 Posts

August 11th, 2008 21:00

its not allowing me to past the rest of the msg..this is what it says:

 

The message body contains the following prohibited content: B F E & n b s p You must remove this content before submitting your post.

73 Posts

August 11th, 2008 21:00


====== Running Processes ======

System Idle Process   [0]  
System   [4]  
smss.exe   [444]   \SystemRoot\System32\smss.exe
csrss.exe   [584]   C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
wininit.exe   [628]   wininit.exe
csrss.exe   [640]   C:\Windows\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,12288,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
services.exe   [688]   C:\Windows\system32\services.exe
lsass.exe   [780]   C:\Windows\system32\lsass.exe
winlogon.exe   [788]   winlogon.exe
lsm.exe   [800]   C:\Windows\system32\lsm.exe
svchost.exe   [948]   C:\Windows\system32\svchost.exe -k DcomLaunch
svchost.exe   [1008]   C:\Windows\system32\svchost.exe -k rpcss
svchost.exe   [1048]   C:\Windows\System32\svchost.exe -k secsvcs
svchost.exe   [1136]   C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
svchost.exe   [1188]   C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
svchost.exe   [1212]   C:\Windows\system32\svchost.exe -k netsvcs
audiodg.exe   [1300]  
SLsvc.exe   [1348]   C:\Windows\system32\SLsvc.exe
svchost.exe   [1380]   C:\Windows\system32\svchost.exe -k LocalService
svchost.exe   [1536]   C:\Windows\system32\svchost.exe -k NetworkService
vsmon.exe   [1628]   C:\Windows\System32\ZoneLabs\vsmon.exe -service
wlanext.exe   [1792]   C:\Windows\system32\WLANExt.exe 4127488
aawservice.exe   [1936]   C:\Adware\aawservice.exe
dwm.exe   [12]   "C:\Windows\system32\Dwm.exe"
explorer.exe   [740]   C:\Windows\Explorer.EXE
spoolsv.exe   [1592]   C:\Windows\System32\spoolsv.exe
svchost.exe   [732]   C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe   [1692]   taskeng.exe {5B568475-1328-477E-A31C-003CF0FDC432}
MSASCui.exe   [2140]   "C:\Program Files\Windows Defender\MSASCui.exe" -hide
Apoint.exe   [2160]   "C:\Program Files\DellTPad\Apoint.exe"
taskeng.exe   [2176]   taskeng.exe {D10F63F7-7E35-47AB-85BF-A390ECE1ECD4}
OEM02Mon.exe   [2208]   "C:\Windows\OEM02Mon.exe"
sttray.exe   [2264]   "C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe"
hkcmd.exe   [2300]   "C:\Windows\System32\hkcmd.exe"
igfxsrvc.exe   [2328]   C:\Windows\system32\igfxsrvc.exe -Embedding
igfxpers.exe   [2340]   "C:\Windows\System32\igfxpers.exe"
DellWMgr.exe   [2352]   "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s
PCMService.exe   [2384]   "C:\Program Files\Dell\MediaDirect\PCMService.exe"
avgtray.exe   [2392]   "C:\Program Files\AVG\AVG8\avgtray.exe"
zlclient.exe   [2400]   "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
sprtcmd.exe   [2408]   "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
ehtray.exe   [2416]   "C:\Windows\ehome\ehtray.exe"
wmpnscfg.exe   [2440]   "C:\Program Files\Windows Media Player\wmpnscfg.exe"
TeaTimer.exe   [2472]   "C:\Spybot\Spybot - Search & Destroy\TeaTimer.exe"
robotaskbaricon.exe   [2484]   "C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe"
BTTray.exe   [2496]   "C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
DLG.exe   [2504]   "C:\Program Files\Digital Line Detect\DLG.exe"
Hotsync.exe   [2512]   "C:\Program Files\Palm\Hotsync.exe"
ApMsgFwd.exe   [2548]   "C:\Program Files\DellTPad\ApMsgFwd.exe" -s{05FA8492-C047-4207-BE65-780D8591C113}
ehmsas.exe   [2604]   C:\Windows\ehome\ehmsas.exe -Embedding
ApntEx.exe   [2704]   "Apntex.exe"
hidfind.exe   [2744]   "C:\Program Files\DellTPad\HidFind.exe"
AEstSrv.exe   [2808]   C:\Windows\system32\aestsrv.exe
avgwdsvc.exe   [2820]   C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
svchost.exe   [2832]   C:\Windows\system32\svchost.exe -k bthsvcs
EvtEng.exe   [2884]   "C:\Program Files\Intel\Wireless\Bin\EvtEng.exe"
MDM.EXE   [2972]   "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
svchost.exe   [3072]   C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
RegSrvc.exe   [3168]   "C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe"
sprtsvc.exe   [3284]   "C:\Program Files\Dell Support Center\bin\sprtsvc.exe" /service /p dellsupportcenter
stacsv.exe   [3336]   C:\Windows\system32\STacSV.exe
svchost.exe   [3852]   C:\Windows\system32\svchost.exe -k imgsvc
svchost.exe   [3904]   C:\Windows\System32\svchost.exe -k WerSvcGroup
SearchIndexer.exe   [3936]   C:\Windows\system32\SearchIndexer.exe /Embedding
XAudio.exe   [4088]   C:\Windows\system32\DRIVERS\xaudio.exe
SDWinSec.exe   [1740]   "C:\Spybot\Spybot - Search & Destroy\SDWinSec.exe"
avgrsx.exe   [3700]   avgrsx.exe
BTStackServer.exe   [3836]   "c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
wmpnetwk.exe   [3488]   "C:\Program Files\Windows Media Player\wmpnetwk.exe"
firefox.exe   [4756]   "C:\Program Files\Mozilla Firefox\firefox.exe"
SearchProtocolHost.exe   [1424]   "C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe23_ Global\UsGthrCtrlFltPipeMssGthrPipe23 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
SearchFilterHost.exe   [5980]   "C:\Windows\system32\SearchFilterHost.exe" 0 620 624 632 65536 628
wscript.exe   [592]   "C:\Windows\System32\WScript.exe" "C:\Users\JLukaMD\Desktop\FileLister.vbe"
WmiPrvSE.exe   [5548]   C:\Windows\system32\wbem\wmiprvse.exe
WmiPrvSE.exe   [4960]   C:\Windows\system32\wbem\wmiprvse.exe

====== Uninstall List From Registry ======

Panda ActiveScan 2.0
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Advanced Audio FX Engine
Advanced Video FX Engine
AVG Free 8.0
Conexant HDA D330 MDC V.92 Modem
Laptop Integrated Webcam Driver (1.04.01.1011) 
Dell Webcam Center
Dell Webcam Manager
DynaMed (Palm) v 11.27.0 by Skyscape
GoToAssist 8.0.0.514
HijackThis 2.0.2
LimeWire PRO 4.12.3
MedAlert (Palm) v 10.0.11 by Skyscape
Mozilla Firefox (3.0.1)
Intel(R) PROSet/Wireless Software
smARTupdate
WinRAR archiver
ZoneAlarm
Roxio Creator Data
Roxio Creator DE
Microsoft Works
Live! Cam Avatar v1.0
Roxio Creator Tools
Roxio Update Manager
Java(TM) 6 Update 5
NetWaiting
QuickSet
Dell DataSafe Online
Browser Address Error Redirector
mWMI
Live! Cam Avatar Creator
Roxio Express Labeler 3
EDocs
Microsoft Visual C++ 2005 Redistributable
Roxio Creator Audio
Dell Getting Started Guide
Product Documentation Launcher
mPfMgr

mHelp
Microsoft Office Professional Edition 2003
Compatibility Pack for the 2007 Office system
Microsoft Office PowerPoint Viewer 2007 (English)
OutlookAddinSetup
MediaDirect
Dell Touchpad
WIDCOMM Bluetooth Software 6.0.1.3100
Adobe Reader 8.1.0
GoodSync
Spybot - Search & Destroy
Roxio Creator Copy
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
Broadcom Management Programs
Music, Photos & Videos Launcher
Ad-Aware
Dell Support Center
Digital Line Detect
Roxio Creator DE
mMHouse
mCore
Modem Diagnostic Tool
Palm Desktop by ACCESS

======== Other Info ========

TOTAL PHYSICAL RAM: 3747 MB

73 Posts

August 11th, 2008 21:00

KtmRm for Distributed Transaction Coordinator (KtmRm) C:\Windows\System32\svchost.exe -k NetworkService  - Auto

 Link-Layer Topology Discovery Mapper (lltdsvc) C:\Windows\System32\svchost.exe -k LocalService  - Manual

 Windows Media Center Extender Service (Mcx2Svc) C:\Windows\system32\svchost.exe -k LocalService  - Disabled

 Multimedia Class Scheduler (MMCSS) C:\Windows\system32\svchost.exe -k netsvcs  - Auto

 Windows Firewall (MpsSvc) C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork  - Auto

 Microsoft iSCSI Initiator Service (MSiSCSI) C:\Windows\system32\svchost.exe -k netsvcs  - Manual

 Network List Service (netprofm) C:\Windows\System32\svchost.exe -k LocalService  - Auto

 Network Location Awareness (NlaSvc) C:\Windows\System32\svchost.exe -k NetworkService  - Auto

 Peer Networking Identity Manager (p2pimsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Manual

 Peer Networking Grouping (p2psvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Manual

 Program Compatibility Assistant Service (PcaSvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto

 PNRP Machine Name Publication Service (PNRPAutoReg) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Manual

 Peer Name Resolution Protocol (PNRPsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Manual

 User Profile Service (ProfSvc) C:\Windows\system32\svchost.exe -k netsvcs  - Auto

 Quality Windows Audio Video Experience (QWAVE) C:\Windows\system32\svchost.exe -k LocalService  - Manual

 Intel(R) PROSet/Wireless Registry Service (RegSrvc) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe  - Auto

 SBSD Security Center Service (SBSDWSCService) C:\Spybot\Spybot - Search & Destroy\SDWinSec.exe  - Auto

 Smart Card Removal Policy (SCPolicySvc) C:\Windows\system32\svchost.exe -k netsvcs  - Manual

 Windows Backup (SDRSVC) C:\Windows\system32\svchost.exe -k SDRSVC  - Manual

 Terminal Services Configuration (SessionEnv) C:\Windows\System32\svchost.exe -k netsvcs  - Manual

 Software Licensing (slsvc) C:\Windows\system32\SLsvc.exe  - Auto

 SL UI Notification Service (SLUINotify) C:\Windows\system32\svchost.exe -k LocalService  - Manual

 SNMP Trap (SNMPTRAP) C:\Windows\System32\snmptrap.exe  - Manual

 SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter  - Auto

 SigmaTel Audio Service (STacSV) C:\Windows\system32\STacSV.exe  - Auto

 stllssvr (stllssvr) "C:\Program Files\Common Files\SureThing Shared\stllssvr.exe"  - Manual

 Superfetch (SysMain) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto

 Tablet PC Input Service (TabletInputService) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted  - Auto

 TPM Base Services (TBS) C:\Windows\System32\svchost.exe -k LocalService  - Auto

 Thread Ordering Server (THREADORDER) C:\Windows\system32\svchost.exe -k LocalService  - Manual

 Windows Modules Installer (TrustedInstaller) C:\Windows\servicing\TrustedInstaller.exe  - Manual

 Interactive Services Detection (UI0Detect) C:\Windows\system32\UI0Detect.exe  - Manual

 Desktop Window Manager Session Manager (UxSms) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted  - Auto

 Windows Connect Now - Config Registrar (wcncsvc) C:\Windows\System32\svchost.exe -k LocalService  - Manual

 Windows Color System (WcsPlugInService) C:\Windows\system32\svchost.exe -k wcssvc  - Manual

 Diagnostic Service Host (WdiServiceHost) C:\Windows\System32\svchost.exe -k wdisvc  - Manual

 Diagnostic System Host (WdiSystemHost) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted  - Manual

 Windows Event Collector (Wecsvc) C:\Windows\system32\svchost.exe -k NetworkService  - Manual

 Problem Reports and Solutions Control Panel Support (wercplsupport) C:\Windows\System32\svchost.exe -k netsvcs  - Manual

 Windows Error Reporting Service (WerSvc) C:\Windows\System32\svchost.exe -k WerSvcGroup  - Auto

 Windows Defender (WinDefend) C:\Windows\System32\svchost.exe -k secsvcs  - Auto

 WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc) C:\Windows\system32\svchost.exe -k LocalService  - Manual

 Windows Remote Management (WS-Management) (WinRM) C:\Windows\System32\svchost.exe -k NetworkService  - Manual

 WLAN AutoConfig (Wlansvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto

 Parental Controls (WPCSvc) C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted  - Manual

 Portable Device Enumerator Service (WPDBusEnum) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto

 Windows Search (WSearch) C:\Windows\system32\SearchIndexer.exe /Embedding  - Auto

 XAudioService (XAudioService) C:\Windows\system32\DRIVERS\xaudio.exe  - Auto

73 Posts

August 11th, 2008 21:00



====== Files under "\Administrator\Startup" Last 30 Days======



====== Files under "\All Users\Startup" Last 30 Days======



====== Folders under "\Program Files" Last 30 Days======

8/7/2008 12:14:37 AM    24687645    C:\Program Files\Mozilla Firefox
8/7/2008 12:14:37 AM    6070205    C:\Program Files\Mozilla Firefox\chrome
8/7/2008 12:14:37 AM    2330882    C:\Program Files\Mozilla Firefox\components
8/7/2008 12:14:37 AM    53894    C:\Program Files\Mozilla Firefox\defaults
8/7/2008 12:14:39 AM    7383    C:\Program Files\Mozilla Firefox\defaults\autoconfig
8/7/2008 12:14:39 AM    36775    C:\Program Files\Mozilla Firefox\defaults\pref
8/7/2008 12:14:41 AM    9736    C:\Program Files\Mozilla Firefox\defaults\profile
8/7/2008 12:14:41 AM    1741    C:\Program Files\Mozilla Firefox\defaults\profile\chrome
8/7/2008 12:14:41 AM    612845    C:\Program Files\Mozilla Firefox\dictionaries
8/7/2008 12:14:37 AM    1390    C:\Program Files\Mozilla Firefox\extensions
8/7/2008 12:14:39 AM    1390    C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
8/7/2008 12:14:37 AM    76011    C:\Program Files\Mozilla Firefox\greprefs
8/7/2008 12:14:37 AM    185990    C:\Program Files\Mozilla Firefox\modules
8/7/2008 12:14:37 AM    65536    C:\Program Files\Mozilla Firefox\plugins
8/7/2008 12:14:37 AM    368828    C:\Program Files\Mozilla Firefox\res
8/7/2008 12:14:38 AM    72215    C:\Program Files\Mozilla Firefox\res\dtd
8/7/2008 12:14:38 AM    80646    C:\Program Files\Mozilla Firefox\res\entityTables
8/7/2008 12:14:38 AM    79512    C:\Program Files\Mozilla Firefox\res\fonts
8/7/2008 12:14:38 AM    619    C:\Program Files\Mozilla Firefox\res\html
8/7/2008 12:14:41 AM    11439    C:\Program Files\Mozilla Firefox\searchplugins
8/7/2008 12:14:37 AM    514364    C:\Program Files\Mozilla Firefox\uninstall
7/14/2008 10:41:15 PM    0    C:\Program Files\MSXML 4.0
7/18/2008 10:20:35 PM    6358    C:\Program Files\Musicmatch
7/18/2008 10:20:35 PM    6358    C:\Program Files\Musicmatch\Musicmatch Jukebox
8/11/2008 8:03:44 AM    73994032    C:\Program Files\Panda Security
8/11/2008 8:03:44 AM    73994032    C:\Program Files\Panda Security\ActiveScan 2.0
8/11/2008 8:04:26 AM    2104716    C:\Program Files\Panda Security\ActiveScan 2.0\psqstore
8/6/2008 12:04:26 AM    13826030    C:\Program Files\Siber Systems
8/6/2008 12:04:26 AM    10897200    C:\Program Files\Siber Systems\AI RoboForm
8/7/2008 1:14:54 AM    1097736    C:\Program Files\Siber Systems\AI RoboForm\Firefox
8/7/2008 1:14:54 AM    23792    C:\Program Files\Siber Systems\AI RoboForm\Firefox\chrome
8/7/2008 1:14:54 AM    1072410    C:\Program Files\Siber Systems\AI RoboForm\Firefox\components
8/7/2008 11:53:29 AM    2928830    C:\Program Files\Siber Systems\GoodSync
8/8/2008 11:34:56 AM    417178    C:\Program Files\Trend Micro
8/8/2008 11:34:56 AM    406733    C:\Program Files\Trend Micro\HijackThis
7/11/2008 8:37:26 PM    2686615    C:\Program Files\WinRAR
7/11/2008 8:37:27 PM    599040    C:\Program Files\WinRAR\Formats
7/13/2008 12:52:21 AM    8741794    C:\Program Files\Zone Labs
7/13/2008 12:52:21 AM    8741794    C:\Program Files\Zone Labs\ZoneAlarm
7/13/2008 7:39:52 AM    1009252    C:\Program Files\Zone Labs\ZoneAlarm\Help
7/13/2008 7:39:49 AM    14551    C:\Program Files\Zone Labs\ZoneAlarm\images
7/13/2008 7:39:34 AM    2174408    C:\Program Files\Zone Labs\ZoneAlarm\repair

====== Files under "\System32\Drivers" Last 30 Days======

7/12/2008 12:01:16 PM    0    34    C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
8/11/2008 8:04:24 AM    28544    32    C:\Windows\System32\drivers\pavboot.sys
7/13/2008 7:39:13 AM    352615    34    C:\Windows\System32\drivers\vsconfig.xml
7/13/2008 7:39:13 AM    279440    0    C:\Windows\System32\drivers\vsdatant.sys
7/12/2008 11:40:58 PM    279440    32    C:\Windows\System32\drivers\~GLH0014.TMP
7/13/2008 7:39:33 AM    279440    32    C:\Windows\System32\drivers\~GLH0015.TMP

====== Files under "\User\Local Settings\Temp" Last 30 Days======



====== Files and Folders under "All Users\Application Data" Last 30 Days======



 ====== Possible Rootkit Scan (Note: Items listed here are not necessarily bad)======

73 Posts

August 11th, 2008 21:00

thank you for replying.  I dont know if this matters but I think the person that is doing this is an IT software consultant.  I cant prove it.  This is the file listerlog, it wont allow me to paste over 20,000 characters so I will have to break it up. let me know what to do next.




+++++++++++++++++++++++++++++++++
+
+ File Lister
+
+ Version 1.0.4
+
+  By bamajim / bamajim.com
+
+++++++++++++++++++++++++++++++++


Report ran on --->>>  8/11/2008 6:25:58 PM

====== Values under HKLM\~\Run ======

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,57,69,\
  6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,4d,53,41,53,43,75,69,2e,65,78,\
  65,20,2d,68,69,64,65,00
"Apoint"="C:\\Program Files\\DellTPad\\Apoint.exe"
"OEM02Mon.exe"="C:\\Windows\\OEM02Mon.exe"
"SigmatelSysTrayApp"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,53,69,\
  67,6d,61,54,65,6c,5c,43,2d,4d,61,6a,6f,72,20,41,75,64,69,6f,5c,57,44,4d,5c,\
  73,74,74,72,61,79,2e,65,78,65,00
"IgfxTray"="C:\\Windows\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\Windows\\system32\\hkcmd.exe"
"Persistence"="C:\\Windows\\system32\\igfxpers.exe"
"DELL Webcam Manager"="\"C:\\Program Files\\Dell\\Dell Webcam Manager\\DellWMgr.exe\" /s"
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"PCMService"="\"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe\""
"HotSync"="\"C:\\Program Files\\PalmSource\\Desktop\\HotSync.exe\" -AllUsers"
"AVG8_TRAY"="C:\\PROGRA~1\\AVG\\AVG8\\avgtray.exe"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
@=""


====== Values under HKCU\~\Run ======

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\\Windows\\ehome\\ehTray.exe"
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
"SpybotSD TeaTimer"="C:\\Spybot\\Spybot - Search & Destroy\\TeaTimer.exe"
"RoboForm"="\"C:\\Program Files\\Siber Systems\\AI RoboForm\\RoboTaskBarIcon.exe\""


====== Folders and Files from "%\" and "%\Windows" Created Last 30 Days ======

8/6/2008 12:41:00 AM    19618003    C:\Adware
8/6/2008 1:00:05 AM    2146934    C:\Adware\Help
8/6/2008 1:00:05 AM    709483    C:\Adware\Lang
8/6/2008 1:00:06 AM    3498834    C:\Adware\Skin
8/11/2008 8:21:58 AM    686630    C:\deckers
8/7/2008 12:13:35 AM    7499056    C:\firefox
8/11/2008 8:07:33 AM    322518    C:\IESpyad
8/11/2008 1:49:36 AM    53248    C:\JD2
8/11/2008 1:38:03 AM    15537    C:\JP2
7/18/2008 10:10:09 PM    0    C:\Music Match
7/11/2008 8:39:10 PM    50339065    C:\Palm Medical
7/11/2008 9:17:00 PM    0    C:\Palm Medical\Palm
7/11/2008 9:17:00 PM    0    C:\Palm Medical\Palm\Palm_User_Files
8/11/2008 8:03:19 AM    175648    C:\Panda
8/5/2008 11:48:26 PM    10814410    C:\Roboform
8/7/2008 12:09:05 PM    741    C:\Roboform\Documents
8/7/2008 12:09:05 PM    0    C:\Roboform\Documents\CruzerSyncData
8/7/2008 12:09:05 PM    0    C:\Roboform\Documents\Downloads
8/7/2008 12:09:05 PM    0    C:\Roboform\Documents\Music
8/7/2008 12:09:05 PM    741    C:\Roboform\Documents\My RoboForm Data
8/7/2008 12:09:05 PM    741    C:\Roboform\Documents\My RoboForm Data\Default Profile
8/7/2008 12:09:06 PM    0    C:\Roboform\Documents\Pictures
8/7/2008 12:09:06 PM    0    C:\Roboform\Documents\Videos
8/7/2008 12:07:24 PM    4175    C:\Roboform\_gsdata_
7/16/2008 9:35:16 PM    55687766    C:\Skyscape
7/16/2008 9:35:16 PM    53801242    C:\Skyscape\DynaMed
7/16/2008 9:35:16 PM    53801242    C:\Skyscape\DynaMed\11.27.0
7/16/2008 9:35:17 PM    53184722    C:\Skyscape\DynaMed\11.27.0\Palm Install Files
7/16/2008 11:52:34 PM    1886524    C:\Skyscape\smARTalerts
7/16/2008 11:52:34 PM    1826830    C:\Skyscape\smARTalerts\Palm Install Files
8/6/2008 12:59:17 AM    66176242    C:\Spybot
8/6/2008 1:03:57 AM    51092722    C:\Spybot\Spybot - Search & Destroy
8/6/2008 1:03:59 AM    55992    C:\Spybot\Spybot - Search & Destroy\Dummies
8/6/2008 1:04:02 AM    573029    C:\Spybot\Spybot - Search & Destroy\Help
8/6/2008 1:03:59 AM    13612954    C:\Spybot\Spybot - Search & Destroy\Includes
8/6/2008 1:04:01 AM    4261934    C:\Spybot\Spybot - Search & Destroy\Languages
8/6/2008 1:03:59 AM    2424432    C:\Spybot\Spybot - Search & Destroy\Plugins
8/6/2008 1:04:02 AM    49349    C:\Spybot\Spybot - Search & Destroy\Skins
8/6/2008 1:04:02 AM    3932925    C:\Spybot\Spybot - Search & Destroy\Updates
8/11/2008 8:07:07 AM    2869536    C:\SpywareBlaster
7/12/2008 5:07:11 PM    6793206    C:\WidescreenWallpaper
8/11/2008 6:25:58 PM    4974    32    C:\Files.txt
8/6/2008 10:54:19 PM    22874365    C:\Windows\BDOSCAN8
8/6/2008 10:54:54 PM    21583086    C:\Windows\BDOSCAN8\plugins
7/12/2008 11:36:58 PM    11679711    C:\Windows\Internet Logs
7/14/2008 10:34:06 PM    417528    C:\Windows\Minidump
7/18/2008 7:27:18 PM    2941    C:\Windows\pss
7/16/2008 9:35:17 PM    471552    C:\Windows\Skyscape
7/16/2008 9:35:17 PM    471552    C:\Windows\Skyscape\DynaMed_Palm
7/16/2008 9:35:17 PM    471552    C:\Windows\Skyscape\DynaMed_Palm\11.27.0
7/20/2008 5:21:58 PM    0    C:\Windows\Sun
7/20/2008 5:21:58 PM    0    C:\Windows\Sun\Java
7/20/2008 5:21:58 PM    0    C:\Windows\Sun\Java\Deployment
7/11/2008 8:46:03 PM    118849    32    C:\Windows\ctpu.exe
7/16/2008 9:35:30 PM    724992    32    C:\Windows\iun6002.exe
7/14/2008 10:33:27 PM    461864415    32    C:\Windows\MEMORY.DMP
7/14/2008 10:41:07 PM    262518    32    C:\Windows\msxml4-KB936181-enu.LOG
7/18/2008 11:31:57 PM    261010    32    C:\Windows\msxml4-KB941833-enu.LOG
8/7/2008 12:28:08 AM    0    32    C:\Windows\nsreg.dat
7/11/2008 8:44:47 PM    57344    32    C:\Windows\ResENU.dll
7/13/2008 7:39:13 AM    29273220    C:\Windows\System32\ZoneLabs
7/13/2008 7:39:36 AM    2391824    C:\Windows\System32\ZoneLabs\lib
7/13/2008 7:39:36 AM    437680    C:\Windows\System32\ZoneLabs\lib\pyd
7/13/2008 7:39:37 AM    60640    C:\Windows\System32\ZoneLabs\plugins
7/13/2008 7:39:37 AM    30290    C:\Windows\System32\ZoneLabs\plugins\rpc_server
7/13/2008 7:39:37 AM    30350    C:\Windows\System32\ZoneLabs\plugins\vsmon_plugin
7/13/2008 7:39:51 AM    6364    C:\Windows\System32\ZoneLabs\Updates
8/4/2008 11:36:17 PM    1671680    32    C:\Windows\System32\chsbrkr.dll
8/4/2008 11:36:17 PM    6103040    32    C:\Windows\System32\chtbrkr.dll
8/5/2008 9:57:19 PM    10752    32    C:\Windows\System32\gcmd5query.dll
8/4/2008 11:36:18 PM    143872    32    C:\Windows\System32\korwbrkr.dll
8/4/2008 11:36:17 PM    11967524    32    C:\Windows\System32\korwbrkr.lex
8/4/2008 11:36:17 PM    40448    32    C:\Windows\System32\mimefilt.dll
8/4/2008 11:36:19 PM    34816    32    C:\Windows\System32\msscb.dll
8/4/2008 11:36:17 PM    60416    32    C:\Windows\System32\msscntrs.dll
8/4/2008 11:36:19 PM    11776    32    C:\Windows\System32\msshooks.dll
8/4/2008 11:36:18 PM    231936    32    C:\Windows\System32\msshsq.dll
8/4/2008 11:36:18 PM    87552    32    C:\Windows\System32\mssitlb.dll
8/4/2008 11:36:16 PM    350208    32    C:\Windows\System32\mssph.dll
8/4/2008 11:36:16 PM    203776    32    C:\Windows\System32\mssphtb.dll
8/4/2008 11:36:18 PM    32768    32    C:\Windows\System32\mssprxy.dll
8/4/2008 11:36:16 PM    1418240    32    C:\Windows\System32\mssrch.dll
8/4/2008 11:36:18 PM    44032    32    C:\Windows\System32\msstrc.dll
8/4/2008 11:36:16 PM    670208    32    C:\Windows\System32\mssvp.dll
8/4/2008 11:36:17 PM    136704    32    C:\Windows\System32\nlhtml.dll
8/4/2008 11:36:17 PM    194560    32    C:\Windows\System32\offfilt.dll
8/4/2008 11:36:18 PM    71680    32    C:\Windows\System32\propdefs.dll
8/4/2008 11:36:18 PM    754176    32    C:\Windows\System32\propsys.dll
8/4/2008 11:36:17 PM    38400    32    C:\Windows\System32\rtffilt.dll
8/4/2008 11:36:18 PM    87552    32    C:\Windows\System32\SearchFilterHost.exe
8/4/2008 11:36:17 PM    439808    32    C:\Windows\System32\SearchIndexer.exe
8/4/2008 11:36:17 PM    184832    32    C:\Windows\System32\SearchProtocolHost.exe
8/4/2008 11:36:18 PM    301568    32    C:\Windows\System32\srchadmin.dll
8/4/2008 11:36:19 PM    106605    32    C:\Windows\System32\StructuredQuerySchema.bin
8/4/2008 11:36:19 PM    18904    32    C:\Windows\System32\StructuredQuerySchemaTrivial.bin
8/4/2008 11:36:18 PM    313344    32    C:\Windows\System32\thawbrkr.dll
8/4/2008 11:36:16 PM    1582592    32    C:\Windows\System32\tquery.dll
7/13/2008 7:39:33 AM    95720    32    C:\Windows\System32\vsdata.dll
7/13/2008 7:38:34 AM    165352    32    C:\Windows\System32\vsinit.dll
7/13/2008 7:39:34 AM    103912    32    C:\Windows\System32\vsmonapi.dll
7/13/2008 7:39:34 AM    275944    32    C:\Windows\System32\vspubapi.dll
7/13/2008 7:39:48 AM    71144    32    C:\Windows\System32\vsregexp.dll
7/13/2008 7:38:34 AM    493032    32    C:\Windows\System32\vsutil.dll
7/13/2008 7:39:37 AM    46568    32    C:\Windows\System32\vswmi.dll
7/13/2008 7:39:35 AM    99816    32    C:\Windows\System32\vsxml.dll
8/4/2008 11:36:17 PM    29184    32    C:\Windows\System32\wsepno.dll
8/4/2008 11:36:17 PM    56320    32    C:\Windows\System32\xmlfilter.dll
7/13/2008 7:39:40 AM    83432    32    C:\Windows\System32\zlcomm.dll
7/13/2008 7:39:40 AM    71144    32    C:\Windows\System32\zlcommdb.dll
7/13/2008 7:39:35 AM    1086952    32    C:\Windows\System32\zpeng24.dll

73 Posts

August 11th, 2008 21:00

im sorry one section is missing cause its not allowing me to paste into the box because of the above msg. I added some more below, its out of order.  There is still a section missing do you want me to email the file?
Message Edited by jlu on 08-11-2008 06:02 PM

73 Posts

August 11th, 2008 21:00



====== Files and Folders under "All Users\Application Data" Last 30 Days======



 ====== Possible Rootkit Scan (Note: Items listed here are not necessarily bad)======


====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======

====== BHO's under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects ======

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
WormRadar.com IESiteBlocker.NavFilter

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{724d43a9-0d85-11d4-9908-00400523e39a}
RoboForm

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}
Browser Address Error Redirector

73 Posts

August 12th, 2008 01:00

ever since I downloaded this program my AVG is not working it keeps saying to restart the computer which I have 3 times already. none of the components are active and it keeps saying the database is outdated!

10.4K Posts

August 12th, 2008 12:00

jlu

File Lister would have no affect on AVG. It doesn't remove anything, it only lists files and drivers.

The good news is I don't see any signs of a keylogger program. If your email account has been compromised, it hasn't gotten into your PC.

It does look like you have downloaded and installed quite a few programs in an effort to protect your PC. But you may have too many.

I have a couple of questions:

Does your version of Zone Alarm have the Anti Virus in it? OR is it only the Firewall?

Does your version of Ad Aware have the Anti Virus in it?















Microsoft MVP Consumer-Security

 


"The world is what you make of it"




73 Posts

August 12th, 2008 20:00

After shutting down my computer llike 5 times, Avg is working now...=)  I have no idea why it did that.  My Zone Alarm and Adware has no antivirus...their both the free version.  So there is nothing on my hijackthis log or file lister?  Someone has access to my computer and info and I have no idea how they are doing it.  Noone uses my laptop.

 

-what program can I use to clean my temp files and folders?  On my old computer I used cleanup but I cant use that on my new computer because it doesnt work with Vista.

 

-Which programs do you think I should take off my computer?  I downloaded Iespyad and spywareblaster but havent installed it on my computer yet.  I dont think adware and spybot really helps.  In your opnion which ones should I keep?

 

-Roboform keeps the profile IDs and passwords for all my accunts under my documents.  Isnt it possible for a hacker to easily access that under my folders?

 

-When I ran both Panda activescan and bit defender my computer crashed and when I did it for Panda activescan this is what it said:

 

Problem signature:

  Problem Event Name:                        BlueScreen

  OS Version:                                          6.0.6001.2.1.0.768.3

  Locale ID:                                             1033

 

Additional information about the problem:

  BCCode:                                               c2

  BCP1:                                                    00000007

  BCP2:                                                    0000110B

  BCP3:                                                    00000000

  BCP4:                                                    CC7FF008

  OS Version:                                          6_0_6001

  Service Pack:                                       1_0

  Product:                                               768_1

 

Files that help describe the problem:

  C:\Windows\Minidump\Mini081108-01.dmp

  C:\Users\JL\AppData\Local\Temp\WER-39764-0.sysdata.xml

  C:\Users\JL\AppData\Local\Temp\WERD097.tmp.version.txt

 

Read our privacy statement:

  http://go.microsoft.com/fwlink/?linkid=50163&clcid=0x0409

Message Edited by jlu on 08-12-2008 04:38 PM
Message Edited by jlu on 08-12-2008 05:15 PM

10.4K Posts

August 13th, 2008 12:00

jlu

There is nothing on your PC that would allow others to access it. If your email has been compromised by a Bot, that is not the same thing as controlling your PC. And without a remote desktop installed a hacker cannot gain access to your My Documents folder.

With Vista IE7, there is no need for ZoneAlarm. And of late there has been quite a number of problems with that software.
I would remove it as well as Iespyad and spywareblaster. There have been reported probelems with IEspyad and Vista as well.

Uninstall all of those and see is that stops some of your crashing.

To clean temp files use this

Download CCleaner from here to clean temp files from your computer.


  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Read the license agreement and click I Agree.
  • Click next to use the default install location. Click Install then finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the "Windows" tab, under "Internet Explorer," uncheck "Cookies" if you do not want them deleted. (If deleted, you will likely need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
  • If you use either the Firefox or Mozilla browsers, the box to uncheck for "Cookies" is on the Applications tab, under Firefox/Mozilla.
  • Click on the "Options" icon at the left side of the window, then click on "Advanced." deselect "Only delete files in Windows Temp folders older than 48 hours."
  • Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.
  • Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.
  • After CCleaner has completed its process, click Exit.


















Microsoft MVP Consumer-Security

 


"The world is what you make of it"




73 Posts

August 13th, 2008 21:00

Thank you.  I DL Ccleaner.  I uninstalled Iespyad and spywareblaster.  Im going to leave ZA for now and see what happens.  How can you prevent your emails from being compromised by a BOT?  what is that exactly?  Is there a program I can use to protect my emails.  ALso is it possible for hackers to have access to all your favorites/bookmarks on IE or Mozilla? 

10.4K Posts

August 14th, 2008 12:00

jlu

If you continue to have problems then I would dump ZoneAlarm. The firewall in Vista is quite good.

A Bot is a computer or bank of computers that auto sends random email to random email addresses in the hopes that someone will open one of the emails to see what it is. Once that happens it contacts the Bot computer, copies or tries to copy your Email address book. It then continues to send junk mail to your address as well as everyone in your address book.
Trying to seek out the emailer responsable only makes matters worse. The best course of action is to ride out the storm, it will soon pass.
1. Most good AntiVirus companies programs scan email, if yours doesn't then get one that does.
2. Be careful what you open. If you do not recognize the sender, delete it. Don't let curiousity get the best of you.
3. Empty your Deleted Items folder in your email program. Most people think that hte email is gone once it's deleted from your inbox, that is not the case. It sends it to the deleted items folder. Empty that folder often
4. Never store or leave passwords in any email folder. Everybody forgets their passwords to certain sites on the Internet, so we contact those sites and request our password, and they send it by email. So we keep the email in case we forget it again or store it in an email folder. Never do that. Once you retreive the password, delete that email right then.
5. Clean out your temp and cookie files



I have never heard of a hacker gaining access to your favorites/bookmarks in IE. There would be no point.

Does this information answer your questions?



















Microsoft MVP Consumer-Security

 


"The world is what you make of it"




73 Posts

August 14th, 2008 13:00

yes thank you for all your help!
No Events found!

Top