Unsolved

This post is more than 5 years old

7 Posts

6046

February 6th, 2009 08:00

Google redirect virus removal; antispyware update blocked

In the last week I believe I have been infected with what appears to be one of the viruses that redirects google searches (both on IE and Firefox). Also, windows update, defender and adaware updates have quit working although my McAfee is still updating. I believe the machine was infected through an autorun virus on a usb memory stick. I have tried some of the analysis tools such as Maywarebytes Antimalware which found some registry issues which were cleaned up. It seemed to work OK for a short period of time but then the virus reappeared. I have downloaded Hijackthis and captured the analysis log. Unfortunately, I am at about the end of my confidence level at modifying the register to rid the machine ot his. Anyone there that can help?

Here is the log:

____________________________________________________________________

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:44:59 PM, on 05/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files\BellCanada\McciTrayApp.exe
C:\Program Files\Password Keychain\Passkeychain.exe
C:\Program Files\Samsung\FrameManager\FrameManager.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [BellCanada_McciTrayApp] C:\Program Files\BellCanada\McciTrayApp.exe
O4 - HKLM\..\Run: [Password Keychain] C:\Program Files\Password Keychain\Passkeychain.exe /H
O4 - HKLM\..\Run: [FrameManager] C:\Program Files\Samsung\FrameManager\FrameManager.exe
O4 - HKLM\..\Run: [zzzHPSETUP] E:\Setup.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/44.10/uploader2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FrameManager Service - Samsung India Software Center - C:\Program Files\Samsung\FrameManager\sam_service.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

--
End of file - 12289 bytes

10.4K Posts

February 6th, 2009 09:00


The_Chief

Not much showing up in your log

1. Go HERE and download File Lister.
  • Save it to your Desktop
    Rt Click ->> Extract all ->> And extract it to your Desktop
    Additional help on extracting zip files can be found HERE
    Open the File Lister Folder.
    Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
    As the program runs, it will appear that nothing is happening.
    When the program is fnished it will produce a log for you C:\Files.txt

Copy and paste the contents of that log in your reply.

7 Posts

February 7th, 2009 05:00

I was unable to get the File Lister to produce the log file (waited 10 minutes). It extraced OK.

I checked the process running and found wscript.exe consuming about 50% of the processor resources. Is this a symptom of the virus???

10.4K Posts

February 10th, 2009 06:00


The_Chief

Sorry for the late reply, I have been under the weather.

1. Reboot into Safe Mode and see if you can get FileLister to run in Safe Mode. If you are unabletto do so, then proceed to step 2.


2. Go HERE and Download System Repair Engineer by smallfrogs
Select local download
  • Save it to your Desktop
    Rt Click sreng2.zip->>Extract all->>Extract it to your desktop
    Open the sreng folder
    Double click SREngPS.exe->>Click Run
    At the main Window, in the left Pane,Select Smart Scan
    At the next window make sure all of the boxes are checked and Select Scan
    When the scan is complete Select Save reports
    Save it to your desktop and Close the tool
    Double Click SREngLog.txt copy and paste that log as a reply to this thread


Do not run any other options with this tool unless instructed to do so.

7 Posts

February 12th, 2009 05:00

I was able to run file lister under safe mode. Here is the log:


+++++++++++++++++++++++++++++++++
+ File Lister  Version 1.0.5
+
+  By bamajim / bamajim.com
+++++++++++++++++++++++++++++++++

Report ran on --->>>  12/02/2009 8:20:30 AM


====== Running Processes ======

C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\System32\WScript.exe
C:\Windows\system32\wbem\wmiprvse.exe

====== BHO's under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects ======

BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

BHO: (NO NAME) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll

BHO: (NO NAME) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

BHO: (NO NAME) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll

BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll

BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll

====== Values under HKLM\~\Run ======

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,57,69,\
  6e,64,6f,77,73,20,44,65,66,65,6e,64,65,72,5c,4d,53,41,53,43,75,69,2e,65,78,\
  65,20,2d,68,69,64,65,00
"ECenter"="C:\\Dell\\E-Center\\EULALauncher.exe"
"Apoint"="C:\\Program Files\\DellTPad\\Apoint.exe"
"SysTrayApp"=hex(2):25,50,72,6f,67,72,61,6d,46,69,6c,65,73,25,5c,49,44,54,5c,\
  57,44,4d,5c,73,74,74,72,61,79,2e,65,78,65,00
"StartCCC"="\"C:\\Program Files\\ATI Technologies\\ATI.ACE\\Core-Static\\CLIStart.exe\""
"IAAnotif"="\"C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\Iaanotif.exe\""
"Broadcom Wireless Manager UI"="C:\\Windows\\system32\\WLTRAY.exe"
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"dscactivate"="\"C:\\Program Files\\Dell Support Center\\gs_agent\\custom\\dsca.exe\""
"Dell Webcam Central"="\"C:\\Program Files\\Dell Webcam\\Dell Webcam Central\\WebcamDell.exe\" /mode2"
"PCMService"="\"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe\""
"Dell DataSafe Online"="\"C:\\Program Files\\Dell DataSafe Online\\DataSafeOnline.exe\" /m"
"Adobe Reader Speed Launcher"="\"c:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\""
"WD Button Manager"="WDBtnMgr.exe"
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"
"ShStatEXE"="\"C:\\Program Files\\McAfee\\VirusScan Enterprise\\SHSTAT.EXE\" /STANDALONE"
"McAfeeUpdaterUI"="\"C:\\Program Files\\McAfee\\Common Framework\\UdaterUI.exe\" /StartedFromRunKey"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Elements 6.0\\apdproxy.exe\""
"NBKeyScan"="\"C:\\Program Files\\Nero\\Nero8\\Nero BackItUp\\NBKeyScan.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\QTTask.exe\" -atboottime"
"BellCanada_McciTrayApp"="C:\\Program Files\\BellCanada\\McciTrayApp.exe"
"Password Keychain"="C:\\Program Files\\Password Keychain\\Passkeychain.exe /H"
"FrameManager"="C:\\Program Files\\Samsung\\FrameManager\\FrameManager.exe"
"zzzHPSETUP"="E:\\Setup.exe"
"Ad-Watch"="C:\\Program Files\\Lavasoft\\Ad-Aware\\AAWTray.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
@=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"
@=""


====== Values under HKCU\~\Run ======

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"
"DAEMON Tools Lite"="\"C:\\Program Files\\DAEMON Tools Lite\\daemon.exe\" -autorun"
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Program Files\\Common Files\\Nero\\Lib\\NMIndexStoreSvr.exe\" ASO-616B5711-6DAE-4795-A05F-39A1E5104020"


====== Folders and Files from "%\" and "%\Windows" Created Last 60 Days ======

25/01/2009 4:52:37 PM    0    C:\My_Outlook_Files
02/02/2009 3:58:19 PM    1460832256    C:\Temp
30/01/2009 10:46:39 AM    2144    32    C:\aaw7boot.log
12/02/2009 8:20:31 AM    0    32    C:\Files.txt
25/01/2009 4:52:40 PM    0    32    C:\temp.000
04/01/2009 8:57:14 PM    0    C:\Windows\Roaming
04/01/2009 8:57:14 PM    0    C:\Windows\Roaming\Motive
25/01/2009 4:52:37 PM    71    32    C:\Windows\34h929a.o2m
23/01/2009 1:09:05 PM    0    32    C:\Windows\Irremote.ini
22/01/2009 1:55:34 PM    306688    32    C:\Windows\IsUninst.exe
25/01/2009 4:52:37 PM    0    32    C:\Windows\j38fnbs1.tmp
12/01/2009 9:26:17 AM    74    32    C:\Windows\MPLAYER.INI
12/02/2009 8:19:27 AM    187808    32    C:\Windows\ntbtlog.txt
05/02/2009 5:16:59 PM    336    32    C:\Windows\PFRO.log
28/12/2008 3:42:28 PM    188    32    C:\Windows\QUICKEN.INI
10/02/2009 11:07:17 AM    714    32    C:\Windows\setupact.log
10/02/2009 11:07:17 AM    0    32    C:\Windows\setuperr.log
12/12/2008 8:32:10 AM    972072    32    C:\Windows\UNNeroMediaHome.exe
28/01/2009 10:57:36 AM    73867    C:\Windows\System32\DRVSTORE
28/01/2009 10:57:36 AM    73867    C:\Windows\System32\DRVSTORE\lbd_D996E5CC178082520D5C11260A28955C8455FD4A
28/12/2008 3:43:16 PM    1843200    32    C:\Windows\System32\acXMLParser.dll
28/12/2008 3:43:15 PM    3518464    32    C:\Windows\System32\cdintf300.dll
05/01/2009 5:33:03 PM    3751995    32    C:\Windows\System32\GPhotos.scr
22/01/2009 1:55:12 PM    40960    32    C:\Windows\System32\hpg4400.dll
22/01/2009 1:55:12 PM    225280    32    C:\Windows\System32\hpgtpusd.dll
22/01/2009 1:55:12 PM    253952    32    C:\Windows\System32\hpgtulbz.dll
22/01/2009 1:55:12 PM    106496    32    C:\Windows\System32\hpguapi.dll
22/01/2009 1:55:12 PM    249856    32    C:\Windows\System32\hpgud32.dll
22/01/2009 1:55:12 PM    118784    32    C:\Windows\System32\hpsjvset.dll
28/01/2009 2:43:54 PM    15688    32    C:\Windows\System32\lsdelete.exe
18/12/2008 3:00:24 AM    3578880    32    C:\Windows\System32\mshtml.dll
23/01/2009 1:09:49 PM    773120    32    C:\Windows\System32\NEROINSTAEC43759.DB
06/02/2009 5:04:27 PM    2767    32    C:\Windows\System32\R.txt
22/01/2009 1:55:12 PM    385024    32    C:\Windows\System32\rts8891u.dll
09/01/2009 9:07:10 AM    18744    32    C:\Windows\System32\sam_minidisplay.dll
23/01/2009 1:09:48 PM    1414440    32    C:\Windows\System32\ShellManager310E2D762.dll
22/01/2009 1:51:53 PM    1409    32    C:\Windows\System32\tmp07535.FOT
22/01/2009 1:51:53 PM    1409    32    C:\Windows\System32\tmp35735.FOT
22/01/2009 1:51:53 PM    1409    32    C:\Windows\System32\tmp4C435.FOT
22/01/2009 1:51:53 PM    1409    32    C:\Windows\System32\tmp67435.FOT
22/01/2009 1:51:53 PM    1409    32    C:\Windows\System32\tmp7B635.FOT
22/01/2009 1:51:53 PM    1409    32    C:\Windows\System32\tmpDE535.FOT

====== Files under "\Administrator\Startup" Last 60 Days======



====== Files under "\All Users\Startup" Last 60 Days======


====== Folders under "\Program Files" Last 60 Days======

04/01/2009 8:58:19 PM    7386464    C:\Program Files\BellCanada
04/01/2009 8:59:00 PM    3620870    C:\Program Files\BellCanada\OCB
04/01/2009 8:59:01 PM    1915886    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53
04/01/2009 8:59:06 PM    38384    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\AlertTemplates
04/01/2009 8:59:06 PM    34780    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\AlertWebFlow
04/01/2009 8:59:06 PM    482353    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant
04/01/2009 8:59:08 PM    1476    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\css
04/01/2009 8:59:07 PM    150277    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\images
04/01/2009 8:59:07 PM    49950    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\images\CPE
04/01/2009 8:59:08 PM    56275    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\LAN
04/01/2009 8:59:08 PM    101498    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\text
04/01/2009 8:59:08 PM    102890    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ConnectivityAssistant\wireless
04/01/2009 8:59:06 PM    18756    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\css
04/01/2009 8:59:06 PM    202206    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\Escalator
04/01/2009 8:59:06 PM    202206    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\Escalator\DSL
04/01/2009 8:59:09 PM    23971    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\images
04/01/2009 8:59:06 PM    24325    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\IVRWebFlow
04/01/2009 8:59:01 PM    63122    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\ProfileDefinitions
04/01/2009 8:59:02 PM    6762    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\Registration
04/01/2009 8:59:02 PM    893682    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts
04/01/2009 8:59:03 PM    104944    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\en_US
04/01/2009 8:59:05 PM    66198    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\fr_CA
04/01/2009 8:59:03 PM    231820    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\modems
04/01/2009 8:59:03 PM    179666    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\modems\EfficientBC
04/01/2009 8:59:02 PM    75809    C:\Program Files\BellCanada\OCB\91cc9e48-9c93-4b41-8ad1-7243c92d0f53\scripts\SDM
04/01/2009 8:59:00 PM    1704984    C:\Program Files\BellCanada\OCB\McciScripts
04/01/2009 8:59:01 PM    787002    C:\Program Files\BellCanada\OCB\McciScripts\McciInstrumentation
04/01/2009 8:59:01 PM    109262    C:\Program Files\BellCanada\OCB\McciScripts\McciInstrumentation\McciFirewall
04/01/2009 8:59:00 PM    117778    C:\Program Files\BellCanada\OCB\McciScripts\McciNet
04/01/2009 8:59:00 PM    536147    C:\Program Files\BellCanada\OCB\McciScripts\McciProfiler
04/01/2009 8:59:00 PM    168156    C:\Program Files\BellCanada\OCB\McciScripts\McciSys
04/01/2009 8:59:00 PM    95901    C:\Program Files\BellCanada\OCB\McciScripts\McciUtility
05/02/2009 5:03:46 PM    2332882    C:\Program Files\CCleaner
05/02/2009 5:03:46 PM    766976    C:\Program Files\CCleaner\Lang
12/01/2009 9:25:25 AM    54803776    C:\Program Files\Family Tree Maker 2005
12/01/2009 9:25:25 AM    510102    C:\Program Files\Family Tree Maker 2005\ASPI
12/01/2009 9:25:33 AM    8512542    C:\Program Files\Family Tree Maker 2005\Clickart
12/01/2009 9:25:33 AM    81474    C:\Program Files\Family Tree Maker 2005\Clickart\Chanuka
12/01/2009 9:25:34 AM    1337740    C:\Program Files\Family Tree Maker 2005\Clickart\Christms
12/01/2009 9:25:35 AM    489330    C:\Program Files\Family Tree Maker 2005\Clickart\Easter
12/01/2009 9:25:33 AM    538718    C:\Program Files\Family Tree Maker 2005\Clickart\History
12/01/2009 9:25:35 AM    1281202    C:\Program Files\Family Tree Maker 2005\Clickart\Misc
12/01/2009 9:25:36 AM    3566254    C:\Program Files\Family Tree Maker 2005\Clickart\National
12/01/2009 9:25:37 AM    2231692    C:\Program Files\Family Tree Maker 2005\Clickart\National\Flags
12/01/2009 9:25:40 AM    874988    C:\Program Files\Family Tree Maker 2005\Clickart\Nature
12/01/2009 9:25:40 AM    78384    C:\Program Files\Family Tree Maker 2005\Clickart\Nature\Flowers
12/01/2009 9:25:40 AM    383860    C:\Program Files\Family Tree Maker 2005\Clickart\Nature\Misc
12/01/2009 9:25:41 AM    412744    C:\Program Files\Family Tree Maker 2005\Clickart\Nature\Trees
12/01/2009 9:25:41 AM    342836    C:\Program Files\Family Tree Maker 2005\Clickart\Religion
12/01/2009 9:25:41 AM    210212    C:\Program Files\Family Tree Maker 2005\Clickart\Religion\Chrstian
12/01/2009 9:25:41 AM    128464    C:\Program Files\Family Tree Maker 2005\Clickart\Religion\Judaism
12/01/2009 9:25:32 AM    2915206    C:\Program Files\Family Tree Maker 2005\Dirfiles
12/01/2009 9:25:32 AM    123127    C:\Program Files\Family Tree Maker 2005\Events
12/01/2009 9:25:33 AM    12150    C:\Program Files\Family Tree Maker 2005\Html
12/01/2009 9:25:33 AM    7322    C:\Program Files\Family Tree Maker 2005\Html\Images
12/01/2009 9:25:54 AM    1948479    C:\Program Files\Family Tree Maker 2005\Manuals
12/01/2009 9:25:32 AM    16999424    C:\Program Files\Family Tree Maker 2005\Maps
12/01/2009 9:25:31 AM    665305    C:\Program Files\Family Tree Maker 2005\Spell
12/01/2009 9:25:32 AM    870821    C:\Program Files\Family Tree Maker 2005\Template
22/01/2009 1:53:48 PM    0    C:\Program Files\Hewlett-Packard
22/01/2009 1:53:48 PM    0    C:\Program Files\Hewlett-Packard\Precisionscan Pro 3.1
28/01/2009 10:57:19 AM    46747814    C:\Program Files\Lavasoft
28/01/2009 10:57:19 AM    46747814    C:\Program Files\Lavasoft\Ad-Aware
28/01/2009 10:57:19 AM    1345790    C:\Program Files\Lavasoft\Ad-Aware\drivers
28/01/2009 10:57:19 AM    466387    C:\Program Files\Lavasoft\Ad-Aware\drivers\32
28/01/2009 10:57:19 AM    879403    C:\Program Files\Lavasoft\Ad-Aware\drivers\64
28/01/2009 10:57:19 AM    28207815    C:\Program Files\Lavasoft\Ad-Aware\Resources
28/01/2009 10:57:19 AM    6106987    C:\Program Files\Lavasoft\Ad-Aware\Toolbox
28/01/2009 10:57:19 AM    674478    C:\Program Files\Lavasoft\Ad-Aware\Toolbox\AutoStart Manager
28/01/2009 10:57:19 AM    103801    C:\Program Files\Lavasoft\Ad-Aware\Toolbox\AutoStart Manager\Skins
28/01/2009 10:57:19 AM    103801    C:\Program Files\Lavasoft\Ad-Aware\Toolbox\AutoStart Manager\Skins\grey
28/01/2009 10:57:19 AM    27993    C:\Program Files\Lavasoft\Ad-Aware\Toolbox\AutoStart Manager\translations
28/01/2009 10:57:19 AM    5432509    C:\Program Files\Lavasoft\Ad-Aware\Toolbox\LT
28/01/2009 10:57:19 AM    784843    C:\Program Files\Lavasoft\Ad-Aware\Toolbox\LT\Lang
04/02/2009 9:12:41 AM    4107152    C:\Program Files\Malwarebytes' Anti-Malware
04/02/2009 9:12:41 AM    372752    C:\Program Files\Malwarebytes' Anti-Malware\Languages
02/02/2009 10:25:26 AM    23928733    C:\Program Files\Mozilla Firefox
02/02/2009 10:25:26 AM    6088054    C:\Program Files\Mozilla Firefox\chrome
02/02/2009 10:25:26 AM    2113661    C:\Program Files\Mozilla Firefox\components
02/02/2009 10:25:26 AM    53332    C:\Program Files\Mozilla Firefox\defaults
02/02/2009 10:25:27 AM    7383    C:\Program Files\Mozilla Firefox\defaults\autoconfig
02/02/2009 10:25:27 AM    36560    C:\Program Files\Mozilla Firefox\defaults\pref
02/02/2009 10:25:28 AM    9389    C:\Program Files\Mozilla Firefox\defaults\profile
02/02/2009 10:25:28 AM    1741    C:\Program Files\Mozilla Firefox\defaults\profile\chrome
02/02/2009 10:25:26 AM    1390    C:\Program Files\Mozilla Firefox\extensions
02/02/2009 10:25:27 AM    1390    C:\Program Files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
02/02/2009 10:25:26 AM    76331    C:\Program Files\Mozilla Firefox\greprefs
02/02/2009 10:25:26 AM    188678    C:\Program Files\Mozilla Firefox\modules
02/02/2009 10:25:26 AM    65528    C:\Program Files\Mozilla Firefox\plugins
02/02/2009 10:25:26 AM    369036    C:\Program Files\Mozilla Firefox\res
02/02/2009 10:25:26 AM    72215    C:\Program Files\Mozilla Firefox\res\dtd
02/02/2009 10:25:26 AM    80646    C:\Program Files\Mozilla Firefox\res\entityTables
02/02/2009 10:25:26 AM    79512    C:\Program Files\Mozilla Firefox\res\fonts
02/02/2009 10:25:26 AM    619    C:\Program Files\Mozilla Firefox\res\html
02/02/2009 10:25:27 AM    10686    C:\Program Files\Mozilla Firefox\searchplugins
02/02/2009 10:25:26 AM    516550    C:\Program Files\Mozilla Firefox\uninstall
25/01/2009 4:45:57 PM    3131966    C:\Program Files\O2M
25/01/2009 4:45:58 PM    130313    C:\Program Files\O2M\clicklib
25/01/2009 4:45:57 PM    168929    C:\Program Files\O2M\help
05/01/2009 11:59:25 AM    1536000    C:\Program Files\Password Keeper 3
05/01/2009 2:26:08 PM    1642845    C:\Program Files\Password Keychain
05/01/2009 2:26:11 PM    0    C:\Program Files\Password Keychain\Backups
28/12/2008 3:42:32 PM    72589807    C:\Program Files\Quicken
28/12/2008 3:42:42 PM    4689310    C:\Program Files\Quicken\AnswerWorks
28/12/2008 3:42:52 PM    993    C:\Program Files\Quicken\certs
28/12/2008 3:42:40 PM    5486632    C:\Program Files\Quicken\Convert03
28/12/2008 3:43:04 PM    79136    C:\Program Files\Quicken\inet
28/12/2008 3:43:04 PM    79136    C:\Program Files\Quicken\inet\common
28/12/2008 3:43:04 PM    79136    C:\Program Files\Quicken\inet\common\system
28/12/2008 3:42:42 PM    7270849    C:\Program Files\Quicken\PDFDrv
28/12/2008 3:42:32 PM    57408    C:\Program Files\Quicken\Qsapi
28/12/2008 3:42:32 PM    691968    C:\Program Files\Quicken\Snap
28/12/2008 3:43:03 PM    3132000    C:\Program Files\Quicken\Sounds
09/01/2009 9:06:56 AM    13364301    C:\Program Files\Samsung
09/01/2009 9:06:56 AM    13364301    C:\Program Files\Samsung\FrameManager
05/02/2009 4:44:39 PM    408579    C:\Program Files\Trend Micro
05/02/2009 4:44:39 PM    408579    C:\Program Files\Trend Micro\HijackThis

====== Files under "\System32\Drivers" Last 60 Days======

28/01/2009 10:57:36 AM    64160    32    C:\Windows\System32\drivers\Lbd.sys
04/02/2009 9:12:44 AM    15504    32    C:\Windows\System32\drivers\mbam.sys
04/02/2009 9:12:42 AM    38496    32    C:\Windows\System32\drivers\mbamswissarmy.sys
04/01/2009 11:14:12 PM    0    34    C:\Windows\System32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
04/01/2009 11:14:12 PM    0    34    C:\Windows\System32\drivers\Msft_Kernel_motccgp_01005.Wdf
04/01/2009 11:14:17 PM    0    34    C:\Windows\System32\drivers\Msft_Kernel_motmodem_01005.Wdf
04/01/2009 11:14:20 PM    0    34    C:\Windows\System32\drivers\Msft_Kernel_motport_01005.Wdf
09/01/2009 9:07:10 AM    18616    32    C:\Windows\System32\drivers\sam_miniport.sys
09/01/2009 9:11:45 AM    17336    32    C:\Windows\System32\drivers\sam_miniusb.sys
13/01/2009 4:04:50 PM    288768    32    C:\Windows\System32\drivers\srv.sys

====== Files Deleted under "%Temp%" ======

C:\Users\Chris\AppData\Local\Temp\alm.log
C:\Users\Chris\AppData\Local\Temp\amt.log
C:\Users\Chris\AppData\Local\Temp\Chris.bmp
C:\Users\Chris\AppData\Local\Temp\HostsXpert.zip
C:\Users\Chris\AppData\Local\Temp\jinstall.cfg
C:\Users\Chris\AppData\Local\Temp\jre-6u11-windows-i586-p-iftw_196cf524.exe
C:\Users\Chris\AppData\Local\Temp\jusched.log
C:\Users\Chris\AppData\Local\Temp\MSI66279.LOG
C:\Users\Chris\AppData\Local\Temp\MSIc10d0.LOG
C:\Users\Chris\AppData\Local\Temp\MSIf78b7.LOG
C:\Users\Chris\AppData\Local\Temp\pse-conversion-log_My Catalog.txt
C:\Users\Chris\AppData\Local\Temp\swtag.log
C:\Users\Chris\AppData\Local\Temp\TWAIN.LOG
C:\Users\Chris\AppData\Local\Temp\Twain001.Mtx
C:\Users\Chris\AppData\Local\Temp\Twunk001.MTX
C:\Users\Chris\AppData\Local\Temp\Twunk002.MTX
C:\Users\Chris\AppData\Local\Temp\wmplog00.sqm
C:\Users\Chris\AppData\Local\Temp\~DF2E0D.tmp
C:\Users\Chris\AppData\Local\Temp\~DF4A41.tmp
C:\Users\Chris\AppData\Local\Temp\~DF97FA.tmp
C:\Users\Chris\AppData\Local\Temp\~DF99D3.tmp
C:\Users\Chris\AppData\Local\Temp\~DFB574.tmp
C:\Users\Chris\AppData\Local\Temp\~DFDA82.tmp

23 Files deleted

====== Files and Folders under "All Users\Application Data" Last 60 Days======



 ====== Possible Rootkit Scan (Note: Items listed here are not necessarily bad)======


====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======

HKLM\Software\microsoft\shared tools\msconfig\startupreg\


====== Services ( Services that are Whitelisted are not shown) ======

 Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe  - Auto
 Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe  - Auto
 Application Experience (AeLookupSvc) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 Andrea ST Filters Service (AESTFilters) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe  - Auto
 Application Layer Gateway Service (ALG) C:\Windows\System32\alg.exe  - Manual
 Application Information (Appinfo) C:\Windows\system32\svchost.exe -k netsvcs  - Manual
 Ati External Event Utility (Ati External Event Utility) C:\Windows\system32\Ati2evxx.exe  - Auto
 Windows Audio Endpoint Builder (AudioEndpointBuilder) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Windows Audio (Audiosrv) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Auto
 Base Filtering Engine (***) C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork  - Auto
 Background Intelligent Transfer Service (BITS) C:\Windows\System32\svchost.exe -k netsvcs  - Auto
 Computer Browser (Browser) C:\Windows\System32\svchost.exe -k netsvcs  - Auto
 Certificate Propagation (CertPropSvc) C:\Windows\system32\svchost.exe -k netsvcs  - Manual
 Microsoft .NET Framework NGEN v2.0.50727_X86 (clr_optimization_v2.0.50727_32) C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe  - Manual
 COM+ System Application (COMSysApp) C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}  - Manual
 Cryptographic Services (CryptSvc) C:\Windows\system32\svchost.exe -k NetworkService  - Auto
 DCOM Server Process Launcher (DcomLaunch) C:\Windows\system32\svchost.exe -k DcomLaunch  - Auto
 DFS Replication (DFSR) C:\Windows\system32\DFSR.exe  - Manual
 DHCP Client (Dhcp) C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted  - Auto
 DNS Client (Dnscache) C:\Windows\system32\svchost.exe -k NetworkService  - Auto
 Dock Login Service (DockLoginService) C:\Program Files\Dell\DellDock\DockLogin.exe  - Auto
 Wired AutoConfig (dot3svc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Manual
 Diagnostic Policy Service (DPS) C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork  - Auto
 Extensible Authentication Protocol (EapHost) C:\Windows\System32\svchost.exe -k netsvcs  - Manual
 Windows Media Center Receiver Service (ehRecvr) C:\Windows\ehome\ehRecvr.exe  - Manual
 Windows Media Center Scheduler Service (ehSched) C:\Windows\ehome\ehsched.exe  - Manual
 Windows Media Center Service Launcher (ehstart) C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork  - Auto
 ReadyBoost (EMDMgmt) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Windows Event Log (Eventlog) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Auto
 COM+ Event System (EventSystem) C:\Windows\system32\svchost.exe -k LocalService  - Auto
 Function Discovery Provider Host (fdPHost) C:\Windows\system32\svchost.exe -k LocalService  - Manual
 Function Discovery Resource Publication (FDResPub) C:\Windows\system32\svchost.exe -k LocalService  - Auto
 FLEXnet Licensing Service (FLEXnet Licensing Service) "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"  - Manual
 Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe  - Manual
 FrameManager Service (FrameManager Service) C:\Program Files\Samsung\FrameManager\sam_service.exe  - Auto
 Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe"  - Manual
 GoToAssist (GoToAssist) "C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe" Start=service  - Manual
 Group Policy Client (gpsvc) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 Google Updater Service (gusvc) "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"  - Auto
 Human Interface Device Access (hidserv) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Health Key and Certificate Management (hkmsvc) C:\Windows\System32\svchost.exe -k netsvcs  - Manual
 Intel(R) Matrix Storage Event Monitor (IAANTMON) C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe  - Auto
 Windows CardSpace (idsvc) "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"  - Manual
 IKE and AuthIP IPsec Keying Modules (IKEEXT) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 PnP-X IP Bus Enumerator (IPBusEnum) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Manual
 IP Helper (iphlpsvc) C:\Windows\System32\svchost.exe -k NetSvcs  - Auto
 CNG Key Isolation (KeyIso) C:\Windows\system32\lsass.exe  - Manual
 KtmRm for Distributed Transaction Coordinator (KtmRm) C:\Windows\System32\svchost.exe -k NetworkService  - Auto
 Server (LanmanServer) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 Workstation (LanmanWorkstation) C:\Windows\System32\svchost.exe -k LocalService  - Auto
 Lavasoft Ad-Aware Service (Lavasoft Ad-Aware Service) "C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe"  - Auto
 Link-Layer Topology Discovery Mapper (lltdsvc) C:\Windows\System32\svchost.exe -k LocalService  - Manual
 TCP/IP NetBIOS Helper (lmhosts) C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted  - Auto
 McAfee Framework Service (McAfeeFramework) "C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart  - Auto
 McciCMService (McciCMService) "C:\Program Files\Common Files\Motive\McciCMService.exe"  - Auto
 McAfee McShield (McShield) "C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe"  - Auto
 McAfee Task Manager (McTaskManager) "C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe"  - Auto
 Windows Media Center Extender Service (Mcx2Svc) C:\Windows\system32\svchost.exe -k LocalService  - Disabled
 Multimedia Class Scheduler (MMCSS) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 Windows Firewall (MpsSvc) C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork  - Auto
 Distributed Transaction Coordinator (MSDTC) C:\Windows\System32\msdtc.exe  - Manual
 Microsoft iSCSI Initiator Service (MSiSCSI) C:\Windows\system32\svchost.exe -k netsvcs  - Manual
 Windows Installer (msiserver) C:\Windows\system32\msiexec /V  - Manual
 Network Access Protection Agent (napagent) C:\Windows\System32\svchost.exe -k NetworkService  - Manual
 Nero BackItUp Scheduler 3 (Nero BackItUp Scheduler 3) C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe  - Auto
 Netlogon (Netlogon) C:\Windows\system32\lsass.exe  - Manual
 Network Connections (Netman) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted  - Manual
 Network List Service (netprofm) C:\Windows\System32\svchost.exe -k LocalService  - Auto
 Net.Tcp Port Sharing Service (NetTcpPortSharing) "C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"  - Disabled
 Network Location Awareness (NlaSvc) C:\Windows\System32\svchost.exe -k NetworkService  - Auto
 NMIndexingService (NMIndexingService) "C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe"  - Manual
 Network Store Interface Service (nsi) C:\Windows\system32\svchost.exe -k LocalService  - Auto
 Office Source Engine (ose) "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"  - Manual
 Peer Networking Identity Manager (p2pimsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Manual
 Peer Networking Grouping (p2psvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Manual
 Program Compatibility Assistant Service (PcaSvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Performance Logs & Alerts (pla) C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork  - Manual
 PLFlash DeviceIoControl Service (PLFlash DeviceIoControl Service) C:\Windows\system32\IoctlSvc.exe  - Auto
 Plug and Play (PlugPlay) C:\Windows\system32\svchost.exe -k DcomLaunch  - Auto
 PNRP Machine Name Publication Service (PNRPAutoReg) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Manual
 Peer Name Resolution Protocol (PNRPsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Manual
 IPsec Policy Agent (PolicyAgent) C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted  - Auto
 User Profile Service (ProfSvc) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 Protected Storage (ProtectedStorage) C:\Windows\system32\lsass.exe  - Manual
 Quality Windows Audio Video Experience (QWAVE) C:\Windows\system32\svchost.exe -k LocalService  - Manual
 Remote Access Auto Connection Manager (RasAuto) C:\Windows\system32\svchost.exe -k netsvcs  - Manual
 Remote Access Connection Manager (RasMan) C:\Windows\system32\svchost.exe -k netsvcs  - Manual
 Routing and Remote Access (RemoteAccess) C:\Windows\system32\svchost.exe -k netsvcs  - Disabled
 Remote Registry (RemoteRegistry) C:\Windows\system32\svchost.exe -k regsvc  - Manual
 Remote Procedure Call (RPC) Locator (RpcLocator) C:\Windows\system32\locator.exe  - Manual
 Remote Procedure Call (RPC) (RpcSs) C:\Windows\system32\svchost.exe -k rpcss  - Auto
 Security Accounts Manager (SamSs) C:\Windows\system32\lsass.exe  - Auto
 Smart Card (SCardSvr) C:\Windows\system32\svchost.exe -k LocalService  - Manual
 Task Scheduler (Schedule) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 Smart Card Removal Policy (SCPolicySvc) C:\Windows\system32\svchost.exe -k netsvcs  - Manual
 Windows Backup (SDRSVC) C:\Windows\system32\svchost.exe -k SDRSVC  - Manual
 Secondary Logon (seclogon) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 System Event Notification Service (SENS) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 Terminal Services Configuration (SessionEnv) C:\Windows\System32\svchost.exe -k netsvcs  - Manual
 Internet Connection Sharing (ICS) (SharedAccess) C:\Windows\System32\svchost.exe -k netsvcs  - Disabled
 Shell Hardware Detection (ShellHWDetection) C:\Windows\System32\svchost.exe -k netsvcs  - Auto
 Software Licensing (slsvc) C:\Windows\system32\SLsvc.exe  - Auto
 SL UI Notification Service (SLUINotify) C:\Windows\system32\svchost.exe -k LocalService  - Manual
 SNMP Trap (SNMPTRAP) C:\Windows\System32\snmptrap.exe  - Manual
 Print Spooler (Spooler) C:\Windows\System32\spoolsv.exe  - Auto
 SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter  - Auto
 SSDP Discovery (SSDPSRV) C:\Windows\system32\svchost.exe -k LocalService  - Manual
 Secure Socket Tunneling Protocol Service (SstpSvc) C:\Windows\system32\svchost.exe -k LocalService  - Manual
 Audio Service (STacSV) C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe  - Auto
 Windows Image Acquisition (WIA) (stisvc) C:\Windows\system32\svchost.exe -k imgsvc  - Auto
 stllssvr (stllssvr) "C:\Program Files\Common Files\SureThing Shared\stllssvr.exe"  - Manual
 Microsoft Software Shadow Copy Provider (swprv) C:\Windows\System32\svchost.exe -k swprv  - Manual
 Superfetch (SysMain) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Tablet PC Input Service (TabletInputService) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Telephony (TapiSrv) C:\Windows\System32\svchost.exe -k NetworkService  - Manual
 TPM Base Services (TBS) C:\Windows\System32\svchost.exe -k LocalService  - Auto
 Terminal Services (TermService) C:\Windows\System32\svchost.exe -k NetworkService  - Auto
 Themes (Themes) C:\Windows\System32\svchost.exe -k netsvcs  - Auto
 Thread Ordering Server (THREADORDER) C:\Windows\system32\svchost.exe -k LocalService  - Manual
 Distributed Link Tracking Client (TrkWks) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Windows Modules Installer (TrustedInstaller) C:\Windows\servicing\TrustedInstaller.exe  - Manual
 Interactive Services Detection (UI0Detect) C:\Windows\system32\UI0Detect.exe  - Manual
 UPnP Device Host (upnphost) C:\Windows\system32\svchost.exe -k LocalService  - Auto
 Desktop Window Manager Session Manager (UxSms) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Virtual Disk (vds) C:\Windows\System32\vds.exe  - Manual
 Volume Shadow Copy (VSS) C:\Windows\system32\vssvc.exe  - Manual
 Windows Time (W32Time) C:\Windows\system32\svchost.exe -k LocalService  - Auto
 Windows Connect Now - Config Registrar (wcncsvc) C:\Windows\System32\svchost.exe -k LocalService  - Manual
 Windows Color System (WcsPlugInService) C:\Windows\system32\svchost.exe -k wcssvc  - Manual
 Diagnostic Service Host (WdiServiceHost) C:\Windows\System32\svchost.exe -k wdisvc  - Manual
 Diagnostic System Host (WdiSystemHost) C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted  - Manual
 WebClient (WebClient) C:\Windows\system32\svchost.exe -k LocalService  - Auto
 Windows Event Collector (Wecsvc) C:\Windows\system32\svchost.exe -k NetworkService  - Manual
 Problem Reports and Solutions Control Panel Support (wercplsupport) C:\Windows\System32\svchost.exe -k netsvcs  - Manual
 Windows Error Reporting Service (WerSvc) C:\Windows\System32\svchost.exe -k WerSvcGroup  - Auto
 Windows Defender (WinDefend) C:\Windows\System32\svchost.exe -k secsvcs  - Auto
 WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc) C:\Windows\system32\svchost.exe -k LocalService  - Manual
 Windows Management Instrumentation (Winmgmt) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 Windows Remote Management (WS-Management) (WinRM) C:\Windows\System32\svchost.exe -k NetworkService  - Manual
 WLAN AutoConfig (Wlansvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Dell Wireless WLAN Tray Service (wltrysvc) C:\Windows\System32\WLTRYSVC.EXE C:\Windows\System32\bcmwltry.exe  - Auto
 WMI Performance Adapter (wmiApSrv) C:\Windows\system32\wbem\WmiApSrv.exe  - Manual
 Windows Media Player Network Sharing Service (WMPNetworkSvc) "C:\Program Files\Windows Media Player\wmpnetwk.exe"  - Manual
 Parental Controls (WPCSvc) C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted  - Manual
 Portable Device Enumerator Service (WPDBusEnum) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto
 Security Center (wscsvc) C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted  - Auto
 Windows Search (WSearch) C:\Windows\system32\SearchIndexer.exe /Embedding  - Auto
 Windows Update (wuauserv) C:\Windows\system32\svchost.exe -k netsvcs  - Auto
 Windows Driver Foundation - User-mode Driver Framework (wudfsvc) C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted  - Auto

====== Uninstall List From Registry ======

Ad-Aware
Adobe AIR
Adobe Flash Player ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop Elements 6.0
Adobe Photoshop Elements 7.0
Advanced Audio FX Engine
BitLord 1.1
Dell Wireless WLAN Card Utility
CCleaner (remove only)
Acrobat.com
Integrated Webcam Driver (1.02.02.0603) 
Dell Video Chat (remove only)
Dell Webcam Central
Google Desktop
Google Updater
GoToAssist 8.0.0.514
HijackThis 2.0.2
Internet Check-Up
Malwarebytes' Anti-Malware
Mozilla Firefox (3.0.6)
O2M 2.0 (Outlook 2002/2003/XP)
OneGlobalConnect
Password Keychain 1.0
Picasa 3
Unity Web Player
ATI Catalyst Control Center
Catalyst Control Center Core Implementation
Roxio Creator Data
Roxio Creator DE
WD Diagnostics
Catalyst Control Center Localization Chinese Standard
Dell DataSafe Online
Microsoft Works
AutoUpdate
Nero 8
Google Earth
Roxio Creator Tools
Google Toolbar for Internet Explorer
Citrix Presentation Server Client - Web Only
FrameManager
OpenOffice.org 2.4
Roxio Update Manager
Java(TM) 6 Update 4
Java(TM) 6 Update 5
Java(TM) 6 Update 7
CCC Help Italian
Catalyst Control Center Localization Chinese Traditional
McAfee VirusScan Enterprise
Catalyst Control Center Localization Norwegian
Catalyst Control Center Graphics Full New
Catalyst Control Center Localization Italian
Catalyst Control Center - Branding
Catalyst Control Center Localization Dutch
neroxml
Browser Address Error Redirector
Live! Cam Avatar Creator
Roxio Express Labeler 3
Cisco PEAP Module
CCC Help Chinese Standard
ccc-core-static
Catalyst Control Center Localization Swedish
Apple Software Update
EDocs
CCC Help German
Cisco EAP-FAST Module
CCC Help Norwegian
Aventail Access Manager
Microsoft Visual C++ 2005 Redistributable
Catalyst Control Center Localization Finnish
Roxio Creator Audio
Catalyst Control Center Localization German
Acrobat.com
Skins
CCC Help Russian
DivX Codec
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center Localization Danish
Dell Getting Started Guide
CCC Help English
Motorola Driver Installation 3.4.0
Catalyst Control Center Localization Portuguese
Cisco LEAP Module
MSXML 4.0 SP2 (KB954430)
DivX Player
QuickTime
Microsoft Office Professional Edition 2003
Compatibility Pack for the 2007 Office system
Catalyst Control Center Localization French
Intel(R) Matrix Storage Manager
Microsoft Office PowerPoint Viewer 2007 (English)
CCC Help French
Catalyst Control Center Graphics Previews Common
CCC Help Danish
Aventail Web Proxy Agent
MediaDirect
Dell Touchpad
Adobe AIR
OneGlobalConnect
Family Tree Maker 2005
CCC Help Japanese
CCC Help Portuguese
Adobe Reader 9
Spelling Dictionaries Support For Adobe Reader 9
DivX Converter
Roxio Creator Copy
DivX Web Player
Motorola Phone Tools
Catalyst Control Center Localization Spanish
MSXML 4.0 SP2 (KB936181)
QuickSet
CCC Help Finnish
MSXML 4.0 SP2 (KB941833)
Adobe Photoshop Elements 7.0
Catalyst Control Center Localization Japanese
ccc-utility
CCC Help Dutch
CCC Help Spanish
Catalyst Control Center Localization Russian
AnswerWorks 5.0 English Runtime
Catalyst Control Center Graphics Full Existing
Ad-Aware
CCC Help Chinese Traditional
Dell Support Center (Support Software)
Quicken 2008
CCC Help Swedish
Catalyst Control Center Graphics Light
Roxio Creator DE
Catalyst Control Center Localization Korean
CCC Help Korean
FrameManager
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Motorola Phone Tools
Adobe Photoshop Elements 6.0
Dell Dock
ITECIR Driver
WD Firewire HID Driver

======== Other Info ========

TOTAL PHYSICAL RAM: 3218 MB

10.4K Posts

February 12th, 2009 07:00


The_Cheif

1. Please download HostsXpert 4.0 - Hosts File Manager
  • And Save it to your Desktop
  • Rt Click Hoster.zip->>Extract all->>Extract it to your Desktop (or your C:\ drive)
  • Open The Hoster folder->>Double Click HostsXpert.exe
  • When the program Opens Click The "Restore MS Hosts File" button in the left pane.
  • Then select "Restore Original Hosts" when prompted.
  • Close the Hoster program when complete
  • Note: If you were using a custom Hosts file you will need to replace any of those entries yourself.

2. Reboot and see if that resolves your issue

3.
Do you use a router?


7 Posts

February 12th, 2009 11:00

I did the "restore original hosts" routine and the issue still remains - google searches get redirected and am unable to update Windows and Adaware.

I am using a router.

Any more suggestions???

Thanks....

10.4K Posts

February 12th, 2009 13:00


The_Chief

Some Malware as set redirect triggers in routers by way of DNS manipulation. The only way to fix this is to do a hard reset on the router.
On most routers the reset button is on the back, but the location could be different depending on the model.
So Disconnect from the interent and do a hard reset on the router.
Reboot and see if that resolves your redirection issue.

If not;

Please download Combofix and save to your desktop:
  • Note: It is important that it is saved directly to your desktop
    Close any open browsers.
    Double click on combofix.exe and follow the prompts.
    When it's finished it will produce a log.
    Post the contents of the C:\ComboFix.txt into your next reply.
    Note: Do not mouseclick combofix's window whilst it's running.
    That may cause the program to freeze/hang.



7 Posts

February 12th, 2009 15:00

Router reset did not solve the issue.

Ran Combofix and here is the log:

 

ComboFix 09-02-12.03 - Chris 2009-02-12 17:26:04.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.3069.1916 [GMT -5:00]
Running from: c:\users\Chris\Desktop\ComboFix.exe
AV: McAfee VirusScan Enterprise *On-access scanning enabled* (Updated)
 * Created a new restore point
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\INSTALL.LOG
c:\windows\system32\drivers\gaopdxtxofcydw.sys
c:\windows\system32\gaopdxncxqitpi.dll
c:\windows\system32\R.txt
D:\resycled
d:\resycled\ntldr.com

.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_gaopdxserv.sys


(((((((((((((((((((((((((   Files Created from 2009-01-12 to 2009-02-12  )))))))))))))))))))))))))))))))
.

2009-02-12 08:40 . 2009-02-12 08:40    0    --ah-----    c:\windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
2009-02-05 17:03 . 2009-02-05 17:03   

    d--------    c:\program files\CCleaner
2009-02-05 16:44 . 2009-02-05 16:44        d--------    c:\program files\Trend Micro
2009-02-04 09:12 . 2009-02-04 09:12        d--------    c:\users\Chris\AppData\Roaming\Malwarebytes
2009-02-04 09:12 . 2009-02-04 09:12        d--------    c:\users\All Users\Malwarebytes
2009-02-04 09:12 . 2009-02-04 09:12        d--------    c:\programdata\Malwarebytes
2009-02-04 09:12 . 2009-02-04 09:12        d--------    c:\program files\Malwarebytes' Anti-Malware
2009-02-04 09:12 . 2009-01-14 16:11    38,496    --a------    c:\windows\System32\drivers\mbamswissarmy.sys
2009-02-04 09:12 . 2009-01-14 16:11    15,504    --a------    c:\windows\System32\drivers\mbam.sys
2009-02-02 15:58 . 2009-02-02 15:59        d--------    C:\Temp
2009-01-28 14:43 . 2009-01-18 16:35    15,688    --a------    c:\windows\System32\lsdelete.exe
2009-01-28 10:57 . 2009-01-28 10:57        d----c---    c:\windows\System32\DRVSTORE
2009-01-28 10:57 . 2009-01-28 10:57        d--------    c:\users\All Users\Lavasoft
2009-01-28 10:57 . 2009-01-28 10:57        d--h-c---    c:\users\All Users\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-28 10:57 . 2009-01-28 10:57        d--------    c:\programdata\Lavasoft
2009-01-28 10:57 . 2009-01-28 10:57        d--h-c---    c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-01-28 10:57 . 2009-01-28 10:57        d--------    c:\program files\Lavasoft
2009-01-28 10:57 . 2009-01-18 16:30    64,160    --a------    c:\windows\System32\drivers\Lbd.sys
2009-01-25 16:52 . 2009-01-25 16:52        d--------    C:\My_Outlook_Files
2009-01-25 16:52 . 2009-01-25 16:52    71    --a------    c:\windows\34h929a.o2m
2009-01-25 16:52 . 2009-01-25 16:52    0    --a------    c:\windows\j38fnbs1.tmp
2009-01-25 16:52 . 2009-01-25 16:52    0    --a------    C:\temp.000
2009-01-25 16:45 . 2009-01-25 16:52        d--------    c:\program files\O2M
2009-01-23 13:09 . 2008-06-24 13:45    1,414,440    --a------    c:\windows\System32\ShellManager310E2D762.dll
2009-01-23 13:09 . 2008-06-23 17:36    773,120    --a------    c:\windows\System32\NEROINSTAEC43759.DB
2009-01-23 13:09 . 2009-01-23 13:09    0    --a------    c:\windows\Irremote.ini
2009-01-22 14:02 . 2009-01-31 21:07    8,318,896    --a------    c:\users\Chris\AppData\Roaming\DataSafeDotNet.exe
2009-01-22 13:55 . 2001-07-03 18:08    385,024    --a------    c:\windows\System32\rts8891u.dll
2009-01-22 13:55 . 1998-10-29 16:45    306,688    --a------    c:\windows\IsUninst.exe
2009-01-22 13:55 . 2001-07-03 18:08    253,952    --a------    c:\windows\System32\hpgtulbz.dll
2009-01-22 13:55 . 2001-07-03 18:08    249,856    --a------    c:\windows\System32\hpgud32.dll
2009-01-22 13:55 . 2001-07-03 18:06    225,280    --a------    c:\windows\System32\hpgtpusd.dll
2009-01-22 13:55 . 2001-07-27 15:48    118,784    --a------    c:\windows\System32\hpsjvset.dll
2009-01-22 13:55 . 2001-07-03 18:08    106,496    --a------    c:\windows\System32\hpguapi.dll
2009-01-22 13:55 . 2001-07-03 18:08    40,960    --a------    c:\windows\System32\hpg4400.dll
2009-01-22 13:54 . 2009-01-22 13:54        d--------    c:\users\Chris\AppData\Roaming\Share-to-Web Upload Folder
2009-01-22 13:54 . 2009-01-22 13:54        d--------    c:\program files\Common Files\Hewlett-Packard
2009-01-22 13:53 . 2009-01-22 14:22        d--------    c:\program files\Hewlett-Packard
2009-01-22 13:51 . 2009-01-22 13:51    1,409    --a------    c:\windows\System32\tmpDE535.FOT
2009-01-22 13:51 . 2009-01-22 13:51    1,409    --a------    c:\windows\System32\tmp7B635.FOT
2009-01-22 13:51 . 2009-01-22 13:51    1,409    --a------    c:\windows\System32\tmp67435.FOT
2009-01-22 13:51 . 2009-01-22 13:51    1,409    --a------    c:\windows\System32\tmp4C435.FOT
2009-01-22 13:51 . 2009-01-22 13:51    1,409    --a------    c:\windows\System32\tmp35735.FOT
2009-01-22 13:51 . 2009-01-22 13:51    1,409    --a------    c:\windows\System32\tmp07535.FOT
2009-01-21 10:29 . 2009-01-21 10:29        d--------    c:\users\All Users\WindowsSearch
2009-01-21 10:29 . 2009-01-21 10:29        d--------    c:\programdata\WindowsSearch
2009-01-13 16:04 . 2008-12-15 21:42    288,768    --a------    c:\windows\System32\drivers\srv.sys
2009-01-13 08:40 . 2009-01-13 08:40        d--------    c:\users\Chris\AppData\Roaming\Motive
2009-01-12 09:26 . 2009-01-12 09:26        d--------    c:\users\Chris\AppData\Roaming\FTW
2009-01-12 09:26 . 2009-01-12 09:34    74    --a------    c:\windows\MPLAYER.INI
2009-01-12 09:25 . 2009-01-12 09:34        d--------    c:\program files\Family Tree Maker 2005

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-12 22:12    ---------    d-----w    c:\users\Chris\AppData\Roaming\OpenOffice.org2
2009-02-12 19:03    ---------    d-----w    c:\programdata\Google Updater
2009-01-23 18:12    ---------    d-----w    c:\program files\Common Files\Nero
2009-01-23 18:10    ---------    d-----w    c:\programdata\Nero
2009-01-22 19:20    ---------    d--h--w    c:\program files\InstallShield Installation Information
2009-01-14 08:02    ---------    d-----w    c:\program files\Windows Mail
2009-01-11 00:57    ---------    d-----w    c:\program files\Google
2009-01-09 14:06    ---------    d-----w    c:\program files\Samsung
2009-01-05 22:33    3,751,995    ----a-w    c:\windows\System32\GPhotos.scr
2009-01-05 19:26    ---------    d-----w    c:\program files\Password Keychain
2009-01-05 19:13    ---------    d-----w    c:\program files\Password Keeper 3
2009-01-05 16:59    ---------    d-----w    c:\users\Chris\AppData\Roaming\AG Software
2009-01-05 07:59    ---------    d-----w    c:\programdata\Motive
2009-01-05 04:14    0    ---ha-w    c:\windows\system32\drivers\Msft_Kernel_motport_01005.Wdf
2009-01-05 04:14    0    ---ha-w    c:\windows\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2009-01-05 04:14    0    ---ha-w    c:\windows\system32\drivers\Msft_Kernel_motccgpfl_01005.Wdf
2009-01-05 04:14    0    ---ha-w    c:\windows\system32\drivers\Msft_Kernel_motccgp_01005.Wdf
2009-01-05 02:01    ---------    d-----w    c:\program files\Common Files\Motive
2009-01-05 01:59    ---------    d-----w    c:\program files\BellCanada
2008-12-28 21:22    ---------    d-----w    c:\program files\Common Files\Adobe AIR
2008-12-28 21:07    ---------    d-----w    c:\program files\Quicken
2008-12-28 21:06    ---------    d-----w    c:\program files\Common Files\AnswerWorks 5.0
2008-12-28 20:43    ---------    d-----w    c:\users\Chris\AppData\Roaming\Intuit
2008-12-28 20:43    ---------    d-----w    c:\program files\Common Files\Palo Alto Software
2008-12-28 20:42    ---------    d-----w    c:\programdata\Intuit
2008-12-28 20:42    ---------    d-----w    c:\program files\Common Files\Intuit
2008-12-12 13:32    972,072    ----a-w    c:\windows\UNNeroMediaHome.exe
2008-01-21 02:43    174    --sha-w    c:\program files\desktop.ini
2008-09-24 20:46    76    --sh--r    c:\windows\CT4CET.bin
.

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-24 68856]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-08-08 490952]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-12-12 1840424]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-06-30 196608]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-06-25 442467]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-24 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-02-19 438403]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-01-14 132392]
"Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline.exe" [2008-07-24 993520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2007-10-16 111952]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2007-10-25 136512]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-12-02 2221352]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-28 413696]
"BellCanada_McciTrayApp"="c:\program files\BellCanada\McciTrayApp.exe" [2008-12-07 1471488]
"Password Keychain"="c:\program files\Password Keychain\Passkeychain.exe" [2003-07-16 1437696]
"FrameManager"="c:\program files\Samsung\FrameManager\FrameManager.exe" [2008-08-12 512000]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-01-18 506712]
"WD Button Manager"="WDBtnMgr.exe" [2008-10-03 c:\windows\System32\WDBtnMgr.exe]

c:\users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-07-15 1226024]
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-05-02 1211472]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-09-24 15:49 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{44E6FE93-0704-4700-8C1A-129EAFDD6DF5}"= UDP:c:\program files\Dell Video Chat\DellVideoChat.exe:Dell Video Chat
"{2CB42DA0-2B61-4016-8A53-7C8E6FEB1246}"= TCP:c:\program files\Dell Video Chat\DellVideoChat.exe:Dell Video Chat
"{CD5F073A-D515-4C56-8429-30465F199AF4}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{743EEF1B-6698-49BF-88A5-8E57816516A2}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{DDE4710C-6907-4606-91F1-A7816EA928CF}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{551720D0-ADE6-444F-A0EF-054CAE10B843}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{BF74B9CB-53C1-45C1-88C3-270310356B48}"= UDP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{120C0C6D-EA48-43F3-8536-ABC2ADFE90A8}"= TCP:c:\program files\McAfee\Common Framework\FrameworkService.exe:McAfee Framework Service
"{848E9101-426F-4803-B3AF-1A62D071E4AC}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{FF1CB75E-B800-47F6-97CB-69039F8F2AB4}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"TCP Query User{9AA98B98-EC4E-450B-9A29-DAA2C0F704D2}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{24C12CC9-389D-49FC-ADA5-EADBA0042779}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{70642695-B02C-4A5B-81AB-A658CF0F0FBE}c:\\program files\\bitlord\\bitlord.exe"= UDP:c:\program files\bitlord\bitlord.exe:BitLord
"UDP Query User{51362A93-3F09-4B57-A007-DE5E5588E517}c:\\program files\\bitlord\\bitlord.exe"= TCP:c:\program files\bitlord\bitlord.exe:BitLord
"TCP Query User{B62AACFF-9ECD-4A55-939F-A54F3C072C87}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{C5DFE0BD-FC9D-46CF-A3E8-758D898B8E2D}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{C7D55760-2565-407F-B9E8-9B11748F1798}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{3D1AF9E0-1597-46FB-9A0D-C486C756D3C3}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-01-28 64160]
R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-10 124832]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\AEstSrv.exe [2008-09-24 73728]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2008-05-02 161048]
R2 FrameManager Service;FrameManager Service;c:\program files\Samsung\FrameManager\sam_service.exe [2009-01-09 188416]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 921936]
R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [2008-09-24 54784]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\k57nd60x.sys [2008-09-24 203264]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\System32\drivers\OA001Ufd.sys [2008-09-24 144672]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\System32\drivers\OA001Vid.sys [2008-09-24 277504]
R3 SODI;SODI;c:\windows\System32\drivers\sam_miniport.sys [2009-01-09 18616]
S3 miniusb;FrameManager Display Adapter;c:\windows\System32\drivers\sam_miniusb.sys [2009-01-09 17336]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\System32\drivers\motccgp.sys [2007-11-02 18176]
S3 motccgpfl;MotCcgpFlService;c:\windows\System32\drivers\motccgpfl.sys [2007-01-22 7680]
S3 motport;Motorola USB Diagnostic Port;c:\windows\System32\drivers\motport.sys [2007-06-18 23680]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - g:\wd_windows_tools\setup.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0a0509a-8f31-11dd-af68-00217084631c}]
\shell\AutoRun\command - g:\wd_windows_tools\setup.exe
.
Contents of the 'Scheduled Tasks' folder

2009-02-11 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 16:34]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-zzzHPSETUP - E:\Setup.exe


.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\ql9jcgr1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
FF - prefs.js: keyword.URL - about:neterror?e=query&u=
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-12 17:42:53
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files:

**************************************************************************
.
Completion time: 2009-02-12 17:44:20
ComboFix-quarantined-files.txt  2009-02-12 22:44:17

Pre-Run: 120,265,695,232 bytes free
Post-Run: 120,232,005,632 bytes free

228    --- E O F ---    2009-01-27 05:58:20

10.4K Posts

February 13th, 2009 06:00

The_Chief

Nice work

Rerun Hijackthis and post a fresh Hiajckthis log.

And in your reply tell me how your PC is running now

7 Posts

February 13th, 2009 13:00

I believe the observed issues have been repaired, namely the redirected google searches and the ability to update Windows and Adaware.

Here is the log from Hijackthis .....

Let me know if there appears to be any residual problems.

Thanks again

----------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:15:15 PM, on 13/02/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe
C:\Program Files\BellCanada\McciTrayApp.exe
C:\Program Files\Password Keychain\Passkeychain.exe
C:\Program Files\Samsung\FrameManager\FrameManager.exe
C:\Windows\system32\conime.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Google\Picasa3\PicasaPhotoViewer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=4080924
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe"
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [BellCanada_McciTrayApp] C:\Program Files\BellCanada\McciTrayApp.exe
O4 - HKLM\..\Run: [Password Keychain] C:\Program Files\Password Keychain\Passkeychain.exe /H
O4 - HKLM\..\Run: [FrameManager] C:\Program Files\Samsung\FrameManager\FrameManager.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [MRT] "C:\Windows\system32\MRT.exe" /R
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {474F00F5-3853-492C-AC3A-476512BBC336} (UploadListView Class) - http://picasaweb.google.com/s/v/44.10/uploader2.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Active File Monitor V7 (AdobeActiveFileMonitor7.0) - Adobe Systems Incorporated - C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\aestsrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FrameManager Service - Samsung India Software Center - C:\Program Files\Samsung\FrameManager\sam_service.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_238116a1\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE

--
End of file - 11102 bytes

10.4K Posts

February 16th, 2009 06:00


The_Chief

Thats good news.

Let's Remove Combofix

Select Start ->> Run ->> type in combofix /u (there is a space between x and /) Then O.K.

user posted image

You may now remove/delete/uninstall the other tools we used to clean your PC

Now that your log is clean

There are some final notes:

Lets create a clean System Restore point
To create a Clean System Restore Point in Vista
  • Click Start (the Vista icon) ->> All Programs ->> Accessories ->> System Tools ->> System Restore
    The System restore Window will open. Select Open System Protection
    Another window will open, Hilite The C:\ Drive in the window
    Then Select Create. Yet another window will open type in todays date 05262008 (or what ever you would like to remind you of this Restore Point) in the Create a restore point window.
    Then Select Create. Windows will then create a restore point.
    Once done you will receive notification that a System Restore point has been Created.
    Close all the open widows and you are done.








Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of
    Java Runtime Environment (JRE) 6.u11.
    Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
    Click the " Download" button to the right.
    Check the box that says: " Accept License Agreement".
    The page will refresh.
    Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    Close any programs you may have running - especially your web browser.
    Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    Click the Remove or Change/Remove button.
    Repeat as many times as necessary to remove each Java versions.
    Reboot your computer once all Java components are removed.
    Then from your desktop double-click on jre-6u11-windowsi586-p.exe to install the newest version.













Update your Anti Virus Software

Use and maintain a Firewall

Visit Microsoft's Windows Update Site Frequently for critical updates

Backup your Important Documents and Files on a regular basis
  • To a disc or a USB key, not your Hardrive

You may want to read this article" So how did I get infected in the first place" by Tony Klein

surf safe




































No Events found!

Top