Unsolved

This post is more than 5 years old

19 Posts

1577

November 12th, 2007 19:00

Pop-up windows when searching internet

While I search the Internet I constantly am getting windows that pop up over mine with different ads.  It's very annoying Can someone please help?
 
 
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 4:22:08 PM, on 11/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Netscape Internet Service\Netscape High Speed Internet\app\TangoService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\mrofinu77.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\NETSCA~2\NETSCA~1\app\TangoManager.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Ashley\Local Settings\Temporary Internet Files\Content.IE5\8V5MDXJ5\HiJackThis_v2[1].exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.ca/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://v4.windowsupdate.microsoft.com/
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {00C0D9A5-EB06-4EF8-A10B-7ADA34F72D0A} - C:\WINDOWS\system32\jkhfc.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: {071acbd4-47b9-a0e8-db04-379900821df1} - {1fd12800-9973-40bd-8e0a-9b744dbca170} - C:\WINDOWS\system32\kekhsydr.dll
O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\system32\yayaayx.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194577771500
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194831219281
O17 - HKLM\System\CCS\Services\Tcpip\..\{E3F0368A-02DB-4BEE-8088-A87BCFC03C5E}: NameServer = 205.188.146.145
O20 - Winlogon Notify: yayaayx - C:\WINDOWS\SYSTEM32\yayaayx.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\Netscape Internet Service\Netscape High Speed Internet\app\TangoService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
--
End of file - 11505 bytes

19 Posts

November 13th, 2007 02:00

ComboFix 07-11-08.1 - Ashley 2007-11-12 23:05:40.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.128 [GMT -5:00]
Running from: C:\Documents and Settings\Ashley\Desktop\ComboFix.exe
 * Created a new restore point
.
 Unable to gain System Privileges
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\cfhkj.bak1
C:\WINDOWS\system32\cfhkj.ini
C:\WINDOWS\system32\cfhkj.ini2
C:\WINDOWS\system32\cfhkj.tmp
C:\WINDOWS\system32\jkhfc.dll
C:\WINDOWS\system32\pac.txt
.
(((((((((((((((((((((((((   Files Created from 2007-10-13 to 2007-11-13  )))))))))))))))))))))))))))))))
.
2007-11-12 23:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 21:10   d-------- C:\VundoFix Backups
2007-11-12 18:56   d-------- C:\Program Files\Trend Micro
2007-11-12 17:56 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-11-12 14:38   d-------- C:\Documents and Settings\Ashley\Application Data\WholeSecurity
2007-11-12 14:08   d-------- C:\Program Files\Printer's Apprentice 7.5
2007-11-12 14:08 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2007-11-12 12:25 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2007-11-12 12:24   d-------- C:\Program Files\TuneUp Utilities 2007
2007-11-12 12:24   d-------- C:\Documents and Settings\Ashley\Application Data\TuneUp Software
2007-11-12 12:24   d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-11-12 12:23   d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-12 10:12 81,472 --a------ C:\WINDOWS\system32\kekhsydr.dll
2007-11-11 21:43 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-11-11 21:43 5,504 --a------ C:\WINDOWS\system32\dllcache\mstee.sys
2007-11-11 21:41 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-11-11 21:41 53,760 --a------ C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2007-11-11 21:40 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-11-11 21:40 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-11-11 21:39 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-11 21:37 290,816 --a------ C:\WINDOWS\Uninstall.exe
2007-11-11 21:37 75,648 --a------ C:\WINDOWS\system32\drivers\CamAv.sys
2007-11-11 21:37 57,344 --a------ C:\WINDOWS\HAJEInstall.dll
2007-11-11 21:35 700,416 --a------ C:\WINDOWS\system32\mcs_cor1.dll
2007-11-11 21:35 245,760 --a------ C:\WINDOWS\system32\mcs_cor2.dll
2007-11-11 21:35 147,456 --a------ C:\WINDOWS\system32\mcs_vfw.dll
2007-11-11 21:01 35,840 --a------ C:\WINDOWS\mrofinu77.exe
2007-11-11 21:00 36,352 --a------ C:\WINDOWS\system32\yayaayx.dll
2007-11-11 17:25   d-------- C:\Program Files\AnswerWorks 4.0
2007-11-11 17:20   d-------- C:\Program Files\AutoCAD 2006
2007-11-11 17:20   d-------- C:\Documents and Settings\Ashley\Application Data\Autodesk
2007-11-11 17:20   d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2007-11-11 17:18   d-------- C:\Program Files\Common Files\Autodesk Shared
2007-11-11 17:18   d-------- C:\Program Files\Autodesk
2007-11-11 02:53   d-------- C:\Documents and Settings\All Users\Application Data\Musicnotes
2007-11-11 01:31   d-------- C:\Program Files\MusicLab
2007-11-09 23:45   d-------- C:\Documents and Settings\Ashley\Application Data\AdobeUM
2007-11-09 23:44   d-------- C:\Program Files\Common Files\Adobe
2007-11-09 20:18   d-------- C:\Program Files\Guitar Pro 5
2007-11-09 19:31   d-------- C:\Program Files\Windows Media Connect 2
2007-11-09 19:30   d-------- C:\WINDOWS\system32\LogFiles
2007-11-09 19:30   d-------- C:\WINDOWS\system32\drivers\UMDF
2007-11-09 16:00   d-------- C:\Program Files\WWW File Share Pro
2007-11-09 15:52   d-------- C:\Program Files\Google
2007-11-09 15:52   d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-09 03:36 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-11-09 02:55   d-------- C:\Temp\abW9
2007-11-09 02:55   d-------- C:\Temp
2007-11-09 02:35   d-------- C:\WINDOWS\Sun
2007-11-09 01:57   d-------- C:\Documents and Settings\Ashley\Application Data\BitTorrent
2007-11-09 01:00   d-------- C:\Documents and Settings\Ashley\Application Data\Sony
2007-11-09 01:00   d-------- C:\Documents and Settings\Ashley\Application Data\Publish Providers
2007-11-09 00:52   d-------- C:\Program Files\Vstplugins
2007-11-09 00:52   d-------- C:\Program Files\Sony
2007-11-09 00:52   d-------- C:\Documents and Settings\All Users\Application Data\Sony
2007-11-09 00:07   d-------- C:\Program Files\Sony Setup
2007-11-09 00:07   d-------- C:\Documents and Settings\Ashley\Application Data\Sony Setup
2007-11-08 23:53   d-------- C:\Documents and Settings\Jay\Application Data\You've Got Pictures Screensaver
2007-11-08 23:53   d-------- C:\Documents and Settings\Jay\Application Data\Jasc Software Inc
2007-11-08 23:53   d-------- C:\Documents and Settings\Jay\Application Data\Gtek
2007-11-08 22:46   d-------- C:\Program Files\MSXML 4.0
2007-11-08 22:35 582,656 --a------ C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-11-08 22:12 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-11-08 22:10 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-11-08 22:02   d--hs---- C:\Documents and Settings\Ashley\UserData
2007-11-08 21:50   d--h----- C:\WINDOWS\PIF
2007-11-08 21:40   d-------- C:\Program Files\Norton Internet Security
2007-11-08 21:39 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-08 21:39 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-08 21:38   d-------- C:\Program Files\Symantec
2007-11-08 21:38   d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-08 21:37   d-------- C:\Program Files\Common Files\Symantec Shared
2007-11-08 21:30   d-------- C:\Program Files\Netscape High Speed
2007-11-08 21:29   d-------- C:\Program Files\Netscape Internet Service
2007-11-08 21:29   d-------- C:\Program Files\Actiontec
2007-11-08 21:29 86,016 --a------ C:\WINDOWS\aeirem.exe
2007-11-08 21:29 50,236 --a------ C:\WINDOWS\system32\drivers\VVBUSUSB.SYS
2007-11-08 21:29 45,056 --a------ C:\WINDOWS\aeirmpca.exe
2007-11-08 21:29 40,832 --a------ C:\WINDOWS\system32\drivers\enetnt.sys
2007-11-08 21:29 34,560 --a------ C:\WINDOWS\system32\drivers\VVBETH.SYS
2007-11-08 21:13   d-------- C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2007-11-08 05:59   d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2007-11-08 05:59   d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Jasc Software Inc
2007-11-08 05:59   d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Gtek
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\You've Got Pictures Screensaver
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\McAfee.com Personal Firewall
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\Jasc Software Inc
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\Gtek
2007-10-30 20:55 625,032 --a------ C:\WINDOWS\system32\SymNeti.dll
2007-10-30 20:55 242,056 --a------ C:\WINDOWS\system32\SymRedir.dll
2007-10-30 20:55 191,536 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-30 20:55 145,968 --a------ C:\WINDOWS\system32\drivers\symfw.sys
2007-10-30 20:55 39,856 --a------ C:\WINDOWS\system32\drivers\symids.sys
2007-10-30 20:55 37,936 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
2007-10-30 20:55 35,120 --a------ C:\WINDOWS\system32\drivers\symndis.sys
2007-10-30 20:55 27,696 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-30 20:55 12,848 --a------ C:\WINDOWS\system32\drivers\symdns.sys

19 Posts

November 13th, 2007 02:00

Here is part of the combofix log.
 
ComboFix 07-11-08.1 - Ashley 2007-11-12 23:05:40.1 - NTFSx86
Microsoft Windows XP Home Edition  5.1.2600.2.1252.1.1033.18.128 [GMT -5:00]
Running from: C:\Documents and Settings\Ashley\Desktop\ComboFix.exe
 * Created a new restore point
.
 Unable to gain System Privileges
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\cfhkj.bak1
C:\WINDOWS\system32\cfhkj.ini
C:\WINDOWS\system32\cfhkj.ini2
C:\WINDOWS\system32\cfhkj.tmp
C:\WINDOWS\system32\jkhfc.dll
C:\WINDOWS\system32\pac.txt
.
(((((((((((((((((((((((((   Files Created from 2007-10-13 to 2007-11-13  )))))))))))))))))))))))))))))))
.
2007-11-12 23:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 21:10   d-------- C:\VundoFix Backups
2007-11-12 18:56   d-------- C:\Program Files\Trend Micro
2007-11-12 17:56 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-11-12 14:38   d-------- C:\Documents and Settings\Ashley\Application Data\WholeSecurity
2007-11-12 14:08   d-------- C:\Program Files\Printer's Apprentice 7.5
2007-11-12 14:08 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2007-11-12 12:25 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2007-11-12 12:24   d-------- C:\Program Files\TuneUp Utilities 2007
2007-11-12 12:24   d-------- C:\Documents and Settings\Ashley\Application Data\TuneUp Software
2007-11-12 12:24   d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-11-12 12:23   d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-12 10:12 81,472 --a------ C:\WINDOWS\system32\kekhsydr.dll
2007-11-11 21:43 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-11-11 21:43 5,504 --a------ C:\WINDOWS\system32\dllcache\mstee.sys
2007-11-11 21:41 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-11-11 21:41 53,760 --a------ C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2007-11-11 21:40 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-11-11 21:40 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-11-11 21:39 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-11 21:37 290,816 --a------ C:\WINDOWS\Uninstall.exe
2007-11-11 21:37 75,648 --a------ C:\WINDOWS\system32\drivers\CamAv.sys
2007-11-11 21:37 57,344 --a------ C:\WINDOWS\HAJEInstall.dll
2007-11-11 21:35 700,416 --a------ C:\WINDOWS\system32\mcs_cor1.dll
2007-11-11 21:35 245,760 --a------ C:\WINDOWS\system32\mcs_cor2.dll
2007-11-11 21:35 147,456 --a------ C:\WINDOWS\system32\mcs_vfw.dll
2007-11-11 21:01 35,840 --a------ C:\WINDOWS\mrofinu77.exe
2007-11-11 21:00 36,352 --a------ C:\WINDOWS\system32\yayaayx.dll
2007-11-11 17:25   d-------- C:\Program Files\AnswerWorks 4.0
2007-11-11 17:20   d-------- C:\Program Files\AutoCAD 2006
2007-11-11 17:20   d-------- C:\Documents and Settings\Ashley\Application Data\Autodesk
2007-11-11 17:20   d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2007-11-11 17:18   d-------- C:\Program Files\Common Files\Autodesk Shared
2007-11-11 17:18   d-------- C:\Program Files\Autodesk
2007-11-11 02:53   d-------- C:\Documents and Settings\All Users\Application Data\Musicnotes
2007-11-11 01:31   d-------- C:\Program Files\MusicLab
2007-11-09 23:45   d-------- C:\Documents and Settings\Ashley\Application Data\AdobeUM
2007-11-09 23:44   d-------- C:\Program Files\Common Files\Adobe
2007-11-09 20:18   d-------- C:\Program Files\Guitar Pro 5
2007-11-09 19:31   d-------- C:\Program Files\Windows Media Connect 2
2007-11-09 19:30   d-------- C:\WINDOWS\system32\LogFiles
2007-11-09 19:30   d-------- C:\WINDOWS\system32\drivers\UMDF
2007-11-09 16:00   d-------- C:\Program Files\WWW File Share Pro
2007-11-09 15:52   d-------- C:\Program Files\Google
2007-11-09 15:52   d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-09 03:36 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-11-09 02:55   d-------- C:\Temp\abW9
2007-11-09 02:55   d-------- C:\Temp
2007-11-09 02:35   d-------- C:\WINDOWS\Sun
2007-11-09 01:57   d-------- C:\Documents and Settings\Ashley\Application Data\BitTorrent
2007-11-09 01:00   d-------- C:\Documents and Settings\Ashley\Application Data\Sony
2007-11-09 01:00   d-------- C:\Documents and Settings\Ashley\Application Data\Publish Providers
2007-11-09 00:52   d-------- C:\Program Files\Vstplugins
2007-11-09 00:52   d-------- C:\Program Files\Sony
2007-11-09 00:52   d-------- C:\Documents and Settings\All Users\Application Data\Sony
2007-11-09 00:07   d-------- C:\Program Files\Sony Setup
2007-11-09 00:07   d-------- C:\Documents and Settings\Ashley\Application Data\Sony Setup
2007-11-08 23:53   d-------- C:\Documents and Settings\Jay\Application Data\You've Got Pictures Screensaver
2007-11-08 23:53   d-------- C:\Documents and Settings\Jay\Application Data\Jasc Software Inc
2007-11-08 23:53   d-------- C:\Documents and Settings\Jay\Application Data\Gtek
2007-11-08 22:46   d-------- C:\Program Files\MSXML 4.0
2007-11-08 22:35 582,656 --a------ C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-11-08 22:12 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-11-08 22:10 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-11-08 22:02   d--hs---- C:\Documents and Settings\Ashley\UserData
2007-11-08 21:50   d--h----- C:\WINDOWS\PIF
2007-11-08 21:40   d-------- C:\Program Files\Norton Internet Security
2007-11-08 21:39 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-08 21:39 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-08 21:38   d-------- C:\Program Files\Symantec
2007-11-08 21:38   d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-08 21:37   d-------- C:\Program Files\Common Files\Symantec Shared
2007-11-08 21:30   d-------- C:\Program Files\Netscape High Speed
2007-11-08 21:29   d-------- C:\Program Files\Netscape Internet Service
2007-11-08 21:29   d-------- C:\Program Files\Actiontec
2007-11-08 21:29 86,016 --a------ C:\WINDOWS\aeirem.exe
2007-11-08 21:29 50,236 --a------ C:\WINDOWS\system32\drivers\VVBUSUSB.SYS
2007-11-08 21:29 45,056 --a------ C:\WINDOWS\aeirmpca.exe
2007-11-08 21:29 40,832 --a------ C:\WINDOWS\system32\drivers\enetnt.sys
2007-11-08 21:29 34,560 --a------ C:\WINDOWS\system32\drivers\VVBETH.SYS
2007-11-08 21:13   d-------- C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2007-11-08 05:59   d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2007-11-08 05:59   d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Jasc Software Inc
2007-11-08 05:59   d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Gtek
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\You've Got Pictures Screensaver
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\McAfee.com Personal Firewall
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\Jasc Software Inc
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\Gtek
2007-10-30 20:55 625,032 --a------ C:\WINDOWS\system32\SymNeti.dll
2007-10-30 20:55 242,056 --a------ C:\WINDOWS\system32\SymRedir.dll
2007-10-30 20:55 191,536 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-30 20:55 145,968 --a------ C:\WINDOWS\system32\drivers\symfw.sys
2007-10-30 20:55 39,856 --a------ C:\WINDOWS\system32\drivers\symids.sys
2007-10-30 20:55 37,936 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
2007-10-30 20:55 35,120 --a------ C:\WINDOWS\system32\drivers\symndis.sys
2007-10-30 20:55 27,696 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-30 20:55 12,848 --a------ C:\WINDOWS\system32\drivers\symdns.sys

4 Apprentice

 • 

20.5K Posts

November 13th, 2007 04:00

I will review your logs and write some script, but it's after 1:00 AM here, so I'll post in about 8-10 hours.

4 Apprentice

 • 

20.5K Posts

November 13th, 2007 14:00

Please launch HijackThis and place a checkmark next to these:

O2 - BHO: {071acbd4-47b9-a0e8-db04-379900821df1} - {1fd12800-9973-40bd-8e0a-9b744dbca170} - C:\WINDOWS\system32\kekhsydr.dll
O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\system32\yayaayx.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O20 - Winlogon Notify: yayaayx - C:\WINDOWS\SYSTEM32\yayaayx.dll


Close all windows except HijackThis and click "Fix checked". Close HijackThis.

Open Notepad and copy/paste the following text between the dotted lines into it. Do not copy the dotted lines.
** Make sure you copy/paste ALL the text at once.
-----------------------------------------------------------------------------------------------

File::
C:\WINDOWS\mrofinu77.exe
C:\WINDOWS\SYSTEM32\yayaayx.dll
C:\WINDOWS\system32\kekhsydr.dll
C:\WINDOWS\mrofinu77.exe


Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1fd12800-9973-40bd-8e0a-9b744dbca170}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayaayx]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00



--------------------------------------------------------------------------------------------------------

Save this as CFScript.txt

Photo Sharing and Video Hosting at Photobucket

Referring to the picture above, drag CFScript into ComboFix.exe
You will be prompted to run Combofix again. Follow the same instructions you did before for running ComboFix.
CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.

When finished, a log is produced here: C:\ComboFix.txt

Please download
ATF Cleaner by Atribune.
This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
    Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please
    click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please
    click No at the prompt.
Click Exit on the Main menu to close the program.For Technical Support, double-click the e-mail address located
at the bottom of each menu.



Please provide the contents of the new ComboFix log in your next reply along with a new HijackThis log, and let me know how things are running.

19 Posts

November 13th, 2007 22:00

2007-08-14 00:54 413,696 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
2007-08-14 00:54 33,792 ----a-w C:\WINDOWS\system32\dllcache\custsat.dll
2007-08-14 00:54 191,488 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-08-14 00:54 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2007-08-14 00:54 156,160 ------w C:\WINDOWS\system32\dllcache\msls31.dll
2007-08-14 00:45 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2007-08-14 00:45 78,336 ------w C:\WINDOWS\system32\dllcache\ieencode.dll
2007-08-14 00:44 69,120 ------w C:\WINDOWS\system32\dllcache\iedw.exe
2007-08-14 00:44 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-14 00:44 40,960 ------w C:\WINDOWS\system32\dllcache\licmgr10.dll
2007-08-14 00:42 17,408 ------w C:\WINDOWS\system32\dllcache\corpol.dll
2007-08-14 00:39 92,672 ------w C:\WINDOWS\system32\dllcache\inseng.dll
2007-08-14 00:39 71,680 ----a-w C:\WINDOWS\system32\admparse.dll
2007-08-14 00:39 71,680 ------w C:\WINDOWS\system32\dllcache\admparse.dll
2007-08-14 00:39 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2007-08-14 00:39 55,296 ------w C:\WINDOWS\system32\dllcache\iesetup.dll
2007-08-14 00:38 491,520 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-08-14 00:36 44,544 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-08-14 00:36 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2007-08-14 00:36 36,352 ------w C:\WINDOWS\system32\dllcache\imgutil.dll
2007-08-14 00:35 346,624 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-08-14 00:32 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2007-08-14 00:32 45,568 ------w C:\WINDOWS\system32\dllcache\mshta.exe
2007-08-14 00:18 60,416 ------w C:\WINDOWS\system32\dllcache\hmmapi.dll
2007-08-14 00:01 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2007-08-14 00:01 48,128 ------w C:\WINDOWS\system32\dllcache\mshtmler.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}]
2007-11-11 21:00 36352 --a------ C:\WINDOWS\system32\yayaayx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ed93c9f5-65af-4542-832f-6494e794ba9d}]
2007-11-13 18:31 80448 --a------ C:\WINDOWS\system32\dqqhxabg.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-19 23:09]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-19 23:06]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-19 23:10]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-13 10:23]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 00:35]
"PRONoMgrWired"="C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe" [2004-12-09 13:58]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2005-03-04 11:26]
"Dell Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY" []
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-10-19 22:36]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-19 22:36]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 01:05]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 01:02]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 00:59]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2007-01-14 02:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 19:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2005-05-15 02:04]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 05:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-12 17:34]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AOL 9.0 Tray Icon.lnk - C:\Program Files\AOL 9.0\aoltray.exe [2005-10-19 22:36:03]
AutoCAD Startup Accelerator.lnk - C:\Program Files\Common Files\Autodesk Shared\acstart16.exe [2005-03-05 08:18:22]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2005-10-19 22:35:17]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}"= C:\WINDOWS\system32\yayaayx.dll [2007-11-11 21:00 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayaayx]
yayaayx.dll 2007-11-11 21:00 36352 C:\WINDOWS\system32\yayaayx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\\WINDOWS\\system32\\jkkjh
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 ENETNT5;Efficient Networks, tango Access PPPoE WAN Miniport;C:\WINDOWS\system32\DRIVERS\enetnt.sys
S3 CamAv;SAMSUNG Video Capture;C:\WINDOWS\system32\Drivers\CamAv.sys
S3 ENDETECT;ENDETECT;\??\C:\PROGRA~1\NETSCA~2\NETSCA~1\app\ENDETECT.SYS
S3 NTSTPL1;NTSTPL1;\??\C:\PROGRA~1\NETSCA~2\NETSCA~1\app\NTSTPL1.SYS
S3 RAWESR;RAWESR;\??\C:\PROGRA~1\NETSCA~2\NETSCA~1\app\RAWESR.SYS
S3 TAPBIND;TAPBIND;\??\C:\PROGRA~1\NETSCA~2\NETSCA~1\app\TAPBIND1.SYS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
UxTuneUp
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2007-11-12 17:26:06 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-13 01:55:59 C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - Ashley.job"
- C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-13 19:24:28
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-13 19:27:40 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-12 23:26
.
 --- E O F ---

19 Posts

November 13th, 2007 22:00

The items below were not in my hijack this log for me to put checks next to. Below those is my combo fix log and new hijack this log.
 
 
 
O2 - BHO: {071acbd4-47b9-a0e8-db04-379900821df1} - {1fd12800-9973-40bd-8e0a-9b744dbca170} - C:\WINDOWS\system32\kekhsydr.dll
O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\system32\yayaayx.dll
O20 - Winlogon Notify: yayaayx - C:\WINDOWS\SYSTEM32\yayaayx.dll

ComboFix 07-11-08.1 - Ashley 2007-11-13 18:55:28.2 - NTFSx86
Running from: C:\Documents and Settings\Ashley\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Ashley\Desktop\CFScript.txt
 * Created a new restore point
FILE
File::C:\WINDOWS\mrofinu77.exeC:\WINDOWS\SYSTEM32\yayaayx.dllC:\WINDOWS\system32\kekhsydr.dllC:\WINDOWS\mrofinu77.exeRegistry::[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1fd12800-9973-40bd-8e0a-9b744dbca170}][-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]"{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}"=-[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayaayx][HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\hjkkj.ini
C:\WINDOWS\system32\hjkkj.ini2
C:\WINDOWS\system32\jkkjh.dll
.
(((((((((((((((((((((((((   Files Created from 2007-10-14 to 2007-11-14  )))))))))))))))))))))))))))))))
.
2007-11-13 18:31 80,448 --a------ C:\WINDOWS\system32\dqqhxabg.dll
2007-11-13 18:17 80,448 --a------ C:\WINDOWS\system32\javsuttw.dll
2007-11-12 23:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-12 21:10   d-------- C:\VundoFix Backups
2007-11-12 18:56   d-------- C:\Program Files\Trend Micro
2007-11-12 17:56 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-11-12 14:38   d-------- C:\Documents and Settings\Ashley\Application Data\WholeSecurity
2007-11-12 14:08   d-------- C:\Program Files\Printer's Apprentice 7.5
2007-11-12 14:08 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2007-11-12 12:25 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2007-11-12 12:24   d-------- C:\Program Files\TuneUp Utilities 2007
2007-11-12 12:24   d-------- C:\Documents and Settings\Ashley\Application Data\TuneUp Software
2007-11-12 12:24   d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-11-12 12:23   d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-12 10:12 81,472 --a------ C:\WINDOWS\system32\kekhsydr.dll
2007-11-11 21:43 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-11-11 21:43 5,504 --a------ C:\WINDOWS\system32\dllcache\mstee.sys
2007-11-11 21:41 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-11-11 21:41 53,760 --a------ C:\WINDOWS\system32\dllcache\vfwwdm32.dll
2007-11-11 21:40 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2007-11-11 21:40 31,616 --a------ C:\WINDOWS\system32\dllcache\usbccgp.sys
2007-11-11 21:39 26,496 --a------ C:\WINDOWS\system32\dllcache\usbstor.sys
2007-11-11 21:37 290,816 --a------ C:\WINDOWS\Uninstall.exe
2007-11-11 21:37 75,648 --a------ C:\WINDOWS\system32\drivers\CamAv.sys
2007-11-11 21:37 57,344 --a------ C:\WINDOWS\HAJEInstall.dll
2007-11-11 21:35 700,416 --a------ C:\WINDOWS\system32\mcs_cor1.dll
2007-11-11 21:35 245,760 --a------ C:\WINDOWS\system32\mcs_cor2.dll
2007-11-11 21:35 147,456 --a------ C:\WINDOWS\system32\mcs_vfw.dll
2007-11-11 21:01 35,840 --a------ C:\WINDOWS\mrofinu77.exe
2007-11-11 21:00 36,352 --a------ C:\WINDOWS\system32\yayaayx.dll
2007-11-11 17:25   d-------- C:\Program Files\AnswerWorks 4.0
2007-11-11 17:20   d-------- C:\Program Files\AutoCAD 2006
2007-11-11 17:20   d-------- C:\Documents and Settings\Ashley\Application Data\Autodesk
2007-11-11 17:20   d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2007-11-11 17:18   d-------- C:\Program Files\Common Files\Autodesk Shared
2007-11-11 17:18   d-------- C:\Program Files\Autodesk
2007-11-11 02:53   d-------- C:\Documents and Settings\All Users\Application Data\Musicnotes
2007-11-11 01:31   d-------- C:\Program Files\MusicLab
2007-11-09 23:45   d-------- C:\Documents and Settings\Ashley\Application Data\AdobeUM
2007-11-09 23:44   d-------- C:\Program Files\Common Files\Adobe
2007-11-09 20:18   d-------- C:\Program Files\Guitar Pro 5
2007-11-09 19:31   d-------- C:\Program Files\Windows Media Connect 2
2007-11-09 19:30   d-------- C:\WINDOWS\system32\LogFiles
2007-11-09 19:30   d-------- C:\WINDOWS\system32\drivers\UMDF
2007-11-09 16:00   d-------- C:\Program Files\WWW File Share Pro
2007-11-09 15:52   d-------- C:\Program Files\Google
2007-11-09 15:52   d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-11-09 03:36 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-11-09 02:55   d-------- C:\Temp\abW9
2007-11-09 02:55   d-------- C:\Temp

19 Posts

November 13th, 2007 22:00

2007-11-09 02:35   d-------- C:\WINDOWS\Sun
2007-11-09 01:57   d-------- C:\Documents and Settings\Ashley\Application Data\BitTorrent
2007-11-09 01:00   d-------- C:\Documents and Settings\Ashley\Application Data\Sony
2007-11-09 01:00   d-------- C:\Documents and Settings\Ashley\Application Data\Publish Providers
2007-11-09 00:52   d-------- C:\Program Files\Vstplugins
2007-11-09 00:52   d-------- C:\Program Files\Sony
2007-11-09 00:52   d-------- C:\Documents and Settings\All Users\Application Data\Sony
2007-11-09 00:07   d-------- C:\Program Files\Sony Setup
2007-11-09 00:07   d-------- C:\Documents and Settings\Ashley\Application Data\Sony Setup
2007-11-08 23:53   d-------- C:\Documents and Settings\Jay\Application Data\You've Got Pictures Screensaver
2007-11-08 23:53   d-------- C:\Documents and Settings\Jay\Application Data\Jasc Software Inc
2007-11-08 23:53   d--h----- C:\Documents and Settings\Jay\Application Data\Gtek
2007-11-08 22:46   d-------- C:\Program Files\MSXML 4.0
2007-11-08 22:35 582,656 --a------ C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-11-08 22:12 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-11-08 22:10 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2007-11-08 22:02   d--hs---- C:\Documents and Settings\Ashley\UserData
2007-11-08 21:50   d--h----- C:\WINDOWS\PIF
2007-11-08 21:40   d-------- C:\Program Files\Norton Internet Security
2007-11-08 21:39 123,952 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-08 21:39 60,800 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-11-08 21:38   d-------- C:\Program Files\Symantec
2007-11-08 21:38   d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2007-11-08 21:37   d-------- C:\Program Files\Common Files\Symantec Shared
2007-11-08 21:30   d-------- C:\Program Files\Netscape High Speed
2007-11-08 21:29   d-------- C:\Program Files\Netscape Internet Service
2007-11-08 21:29   d-------- C:\Program Files\Actiontec
2007-11-08 21:29 86,016 --a------ C:\WINDOWS\aeirem.exe
2007-11-08 21:29 50,236 --a------ C:\WINDOWS\system32\drivers\VVBUSUSB.SYS
2007-11-08 21:29 45,056 --a------ C:\WINDOWS\aeirmpca.exe
2007-11-08 21:29 40,832 --a------ C:\WINDOWS\system32\drivers\enetnt.sys
2007-11-08 21:29 34,560 --a------ C:\WINDOWS\system32\drivers\VVBETH.SYS
2007-11-08 21:13   d-------- C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\You've Got Pictures Screensaver
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\McAfee.com Personal Firewall
2007-11-08 05:59   d-------- C:\Documents and Settings\Ashley\Application Data\Jasc Software Inc
2007-11-08 05:59   d--h----- C:\Documents and Settings\Ashley\Application Data\Gtek
2007-10-30 20:55 625,032 --a------ C:\WINDOWS\system32\SymNeti.dll
2007-10-30 20:55 242,056 --a------ C:\WINDOWS\system32\SymRedir.dll
2007-10-30 20:55 191,536 --a------ C:\WINDOWS\system32\drivers\symtdi.sys
2007-10-30 20:55 145,968 --a------ C:\WINDOWS\system32\drivers\symfw.sys
2007-10-30 20:55 39,856 --a------ C:\WINDOWS\system32\drivers\symids.sys
2007-10-30 20:55 37,936 --a------ C:\WINDOWS\system32\drivers\symndisv.sys
2007-10-30 20:55 35,120 --a------ C:\WINDOWS\system32\drivers\symndis.sys
2007-10-30 20:55 27,696 --a------ C:\WINDOWS\system32\drivers\symredrv.sys
2007-10-30 20:55 12,848 --a------ C:\WINDOWS\system32\drivers\symdns.sys
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-09 02:57 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-09 02:57 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-09 02:56 --------- d-----w C:\Program Files\Dell Support
2007-11-09 02:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-09 02:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-31 01:24 12,963 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2007-10-31 01:24 1,358 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2007-09-18 20:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspx.cat
2007-09-18 20:44 10,662 ----a-w C:\WINDOWS\system32\drivers\srtspl.cat
2007-09-18 20:44 10,658 ----a-w C:\WINDOWS\system32\drivers\srtsp.cat
2007-09-18 20:44 1,430 ----a-w C:\WINDOWS\system32\drivers\srtspl.inf
2007-09-18 20:44 1,421 ----a-w C:\WINDOWS\system32\drivers\srtspx.inf
2007-09-18 20:44 1,415 ----a-w C:\WINDOWS\system32\drivers\srtsp.inf
2007-09-18 20:43 43,696 ----a-w C:\WINDOWS\system32\drivers\srtspx.sys
2007-09-18 20:43 317,616 ----a-w C:\WINDOWS\system32\drivers\srtspl.sys
2007-09-18 20:43 278,576 ----a-w C:\WINDOWS\system32\drivers\srtsp.sys
2007-08-22 12:55 474,112 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-08-22 12:55 151,040 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-08-22 12:55 1,498,112 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-08-22 12:55 1,054,208 ------w C:\WINDOWS\system32\dllcache\danim.dll
2007-08-22 12:55 1,022,976 ------w C:\WINDOWS\system32\dllcache\browseui.dll
2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-21 06:15 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-08-20 21:34 3,584,512 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-08-20 10:04 824,832 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2007-08-20 10:04 671,232 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll
2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-08-20 10:04 477,696 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-08-20 10:04 44,544 ------w C:\WINDOWS\system32\dllcache\iernonce.dll
2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll
2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-08-20 10:04 27,648 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll
2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2007-08-20 10:04 230,400 ------w C:\WINDOWS\system32\dllcache\ieaksie.dll
2007-08-20 10:04 214,528 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-08-20 10:04 193,024 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2007-08-20 10:04 153,088 ------w C:\WINDOWS\system32\dllcache\ieakeng.dll
2007-08-20 10:04 132,608 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll
2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll
2007-08-20 10:04 1,152,000 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-08-17 07:34 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2007-08-14 00:54 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll

19 Posts

November 13th, 2007 22:00

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:40:35 PM, on 11/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Netscape Internet Service\Netscape High Speed Internet\app\TangoService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\NETSCA~2\NETSCA~1\app\TangoManager.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://v4.windowsupdate.microsoft.com/
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {4CB8F4B4-5F66-4D9E-BC3B-184596A58824} - C:\WINDOWS\system32\yayaayx.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: {d9ab497e-4946-f238-2454-fa565f9c39de} - {ed93c9f5-65af-4542-832f-6494e794ba9d} - C:\WINDOWS\system32\dqqhxabg.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194577771500
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194831219281
O17 - HKLM\System\CCS\Services\Tcpip\..\{E3F0368A-02DB-4BEE-8088-A87BCFC03C5E}: NameServer = 205.188.146.145
O20 - Winlogon Notify: yayaayx - C:\WINDOWS\SYSTEM32\yayaayx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\Netscape Internet Service\Netscape High Speed Internet\app\TangoService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
--
End of file - 10683 bytes

19 Posts

November 13th, 2007 23:00

When I copy and paste those files into killbox and do everything you told me to.  when I cick on the button to erase them I get a message saying:"PendingFileRenameOperationsRegistryDatabase has been rmoved by External Process!"
I have not continued with any of the other instruction as I was no sure if that wouuld do more harm.  My system did not automatically shut down either.  I have not shut it down manually either.  I will wait to hear back from you before doing anything else.

4 Apprentice

 • 

20.5K Posts

November 13th, 2007 23:00

Download KILLBOX, extract it to your desktop.
If not available, here is an alternate link for the download:
KILLBOX



Note: In the event you already have Killbox, this is a new version that I need you to download
Save it to your Desktop. Do not run it yet.


Please run Notepad and paste the following text between the dotted lines into a new file (Do not copy the dotted lines.):
------------------------------------------------------------------------------------------------------------------------
REGEDIT4

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}]

[-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ed93c9f5-65af-4542-832f-6494e794ba9d}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{4CB8F4B4-5F66-4D9E-BC3B-184596A58824}"=-

[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayaayx]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

-------------------------------------------------------------------------------------------------------------------------

Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files". Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.


Please double-click Killbox.exe to run it.
Select: Delete on Reboot
Photobucket - Video and Image Hosting

Click on the All Files button.
Photobucket - Video and Image Hosting

Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):


C:\WINDOWS\system32\yayaayx.dll
C:\WINDOWS\system32\dqqhxabg.dll


Return to Killbox, go to the File menu, and choose Paste from Clipboard.

Click the red-and-white Delete File button.
Click Yes at the Delete on Reboot prompt.
Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message.).

If your computer does not restart automatically, please restart it manually into normal mode.

[Note: Killbox makes backups of all deleted files & folders in a folder called C:\!killbox ]
If Killbox tells you any files are missing don't worry but make a note and let us know in your next reply.

Run Disk Cleanup in each user's profile:
Click "Start > Programs > Accessories > System Tools > Disk Cleanup"
Please make sure the following are checked:
-- Downloaded Program Files
-- Temporary Internet Files
-- Recycle Bin
-- Temporary Files
Click "OK" and Disk Cleanup will delete those files for you.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u3 allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each of the Java versions.

  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.

Official JAVA Installation Instructions if needed.


Please post a fresh HijackThis log and let me know how things are running.

4 Apprentice

 • 

20.5K Posts

November 14th, 2007 00:00

That message means that the malware is protecting itself and will not let Killbox reboot. It means there's a nasty that's really deep into the system.
Therefore you must reboot manually in order to finish the Killbox cleaning process.

4 Apprentice

 • 

20.5K Posts

November 14th, 2007 02:00

Excellent! I don't see any active malware in your log.

If everything is running well let's clean up our tools.

Please download the OTMoveIt by OldTimer
  • Save it to your desktop.
  • Run the tool by clicking on the icon.
  • Click the Cleanup button.
  • The tools that we used as well as this one will be removed from your system.


OTMoveIt will not delete HijackThis in case you want to keep HJT so you can post a log in the future if you ever have another problem -- assuming the tool does not have a newer version at that time.

Just to be sure you have a good Restore Point, let's flush System Restore.
If everything is running well....
To flush the XP System Restore Points:
(Using XP, you must be logged in as Administrator to do this.)
Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn Off System Restore.

Reboot. Go back in and turn System Restore ON. A new Restore Point will be created.

Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.

You may have already taken some of these steps, and depending on your current security, you may not need to implement all of these:
1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp

2. Adjust your security settings for ActiveX:
Go to Internet Options/Security/Internet, press 'default level', then OK.
Now press "Custom Level."
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.

3. Consider installing the following free programs:
a. SpywareBlaster: (Not recommended for Vista)
http://www.javacoolsoftware.com/spywareblaster.html
Tutorial here: http://www.bleepingcomputer.com/forums/tutorial49.html
b. SpywareGuard:
http://www.javacoolsoftware.com/spywareguard.html
Tutorial here: http://www.bleepingcomputer.com/tutorials/tutorial50.html
Periodically check for updates in both programs.

4. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
Note: Zone Alarm Firewall (by Checkpoint) has a free version http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads

5. You might consider installing Mozilla / Firefox.
http://www.mozilla.org/

6. Do not use file sharing. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known
vulnerabilities.

7. Before using or purchasing any Spyware/Malware protection/removal program, always check the following Rogue/Suspect Spyware Lists.
http://www.spywarewarrior.com/rogue_anti-spyware.htm
http://www.malwarebytes.org/database.php

8. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/
** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.

9. If you use Adobe Reader it may need to be updated to be sure that you have a more secure version. If you are using a version prior to v. 6.05, you should update to 6.05, preferably version 8.1.0 or higher.
It would be best to remove prior versions before updating to a new version.
If you need additional assistance, the Adobe forums are here: http://www.adobe.com/support/forums/main.html

10. Make sure you are using the most updated version of Java.
The current version is Java Runtime Environment (JRE) 6u3

You can go here to download the latest version of Java Runtime Environment (JRE) 6.
Scroll down to where it says " Java Runtime Environment (JRE) 6u3 allows end-users to run Java applications".

Click the link to download the Windows (Offline Installation) package: Save it, do not run it. When the download is complete, close the browser.

Remove all prior versions using Add/Remove Programs, and delete the Java folder in Program Files.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.
Official JAVA Installation Instructions if needed.
Reboot.

11. Practice Safe Surfing with with TrendProtect by Trendmicro.
TrendProtect is a browser plugin that assigns a safety rating to domains listed in your search engine. TrendProtect also adds a new button to your browser's toolbar area. The icon and color of the button changes to indicate whether the page currently open is safe, unsafe, trusted, or unrated, or whether it contains unwanted content.

The following color codes are used by TrendProtect to indicate the safety of each site.

Red for Warning
Yellow for Use Caution
Green for Safe
Grey for Unknown


12. Here are some helpful articles:
"So how did I get infected in the first place?"
by TonyKlein
http://computercops.biz/postlite7736-.html

"I'm not pulling your leg, honest"
by Sandi Hardmeier
http://www.microsoft.com/windows/IE/community/columns/pulling.mspx

13. This is an excellent resource for users of all levels. General computer maintenance as well as internet security is covered.
Rootkits for Dummies
(Paperback)
by Larry Stevenson (Author), Nancy Altholz (Author)

Let us know if we have not resolved your problem. Otherwise, you are good to go.
Happy and Safe Surfing!

19 Posts

November 14th, 2007 02:00

Here is my new hijack this log.
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:56:51 PM, on 11/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Netscape Internet Service\Netscape High Speed Internet\app\TangoService.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\AOL 9.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ca.my.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://v4.windowsupdate.microsoft.com/
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\system32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: AOL 9.0 Tray Icon.lnk = C:\Program Files\AOL 9.0\aoltray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194577771500
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194831219281
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\Netscape Internet Service\Netscape High Speed Internet\app\TangoService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
--
End of file - 9125 bytes
No Events found!

Top