Unsolved

This post is more than 5 years old

58 Posts

3322

September 29th, 2008 17:00

HELP

Last night my computer was opening weird ad-type web pages without any help from me.  The computer seemed very slow so I scanned it with Malware and ad-aware. Malware found 42 things wrong and 12 of them were trojans. I fixed it.  As I type this another ad has popped open on it's own.

 This is what I got from Hijack this

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:38:04 PM, on 9/29/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Micro Innovations\Wireless Laser Mouse\MOUSE32A.DAT
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\?ystem\wuauclt.exe
C:\Program Files\VnrBlock\VnrBlock21.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\Program Files\GetPack\GetPack21.exe
C:\PROGRA~1\SEMBLY~1\scanregw.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: OIN Analytics - {6B221E01-F517-4959-8C41-81948E7F2F17} - C:\Program Files\OINAnalytics\OINAnalytics.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: {8db547de-5b8b-5dc9-b614-4237b4637a09} - {90a7364b-7324-416b-9cd5-b8b5ed745bd8} - C:\WINDOWS\system32\raygcv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [Kejjolnc] "C:\Program Files\Common Files\?ystem\wuauclt.exe"
O4 - HKCU\..\Run: [VnrBlock21] "C:\Program Files\VnrBlock\VnrBlock21.exe"
O4 - HKCU\..\Run: [GetPack21] "C:\Program Files\GetPack\GetPack21.exe"
O4 - HKCU\..\Run: [Aida] "C:\PROGRA~1\SEMBLY~1\scanregw.exe" -vt yazb
O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O18 - Filter hijack: text/html - {cbf3b054-3111-496a-b911-2266d46bbc25} - C:\WINDOWS\system32\msiebbar.dll
O20 - AppInit_DLLs: raygcv.dll
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware  (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe

--
End of file - 8799 bytes

 

thank you,

Linda

10.4K Posts

October 7th, 2008 19:00

lkfort

 

Rerun Combofix and post a fresh Combofix log and lets see if something has changed

 



 

 

 

 

 


"The world is what you make of it"

58 Posts

October 7th, 2008 20:00

ComboFix 08-09-30.01 - Linda Fort 2008-10-07 15:45:14.4 - NTFSx86
Running from: C:\Documents and Settings\Linda Fort\Desktop\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Linda Fort\Cookies\linda_fort@insightexpressai[1].txt

.
(((((((((((((((((((((((((   Files Created from 2008-09-07 to 2008-10-07  )))))))))))))))))))))))))))))))
.

2008-09-29 06:10 . 2008-09-29 06:10 9,662 --a------ C:\WINDOWS\SYSTEM32\ZoneAlarmIconUS.ico
2008-09-28 19:58 . 2008-09-28 20:55 105,984 --------- C:\WINDOWS\SYSTEM32\yyfhxiuf.dll
2008-09-28 19:58 . 2008-09-28 20:55 71,168 --------- C:\WINDOWS\SYSTEM32\pwhsapvb.dll
2008-09-28 19:45 . 2008-09-28 19:45 

 d-------- C:\Program Files\OINAnalytics
2008-09-28 19:44 . 2008-09-28 19:44 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-28 19:44 . 2008-09-28 19:44 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-10 14:01 . 2008-09-10 14:01   d-------- C:\Program Files\MSECache

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-23 01:17 44,422 ----a-w C:\Documents and Settings\Linda Fort\Application Data\wklnhst.dat
2008-09-01 01:24 59,784 -c--a-w C:\Documents and Settings\Linda Fort\Application Data\GDIPFONTCACHEV1.DAT
2008-08-30 15:35 --------- d-----w C:\Documents and Settings\Linda Fort\Application Data\Image Zone Express
2008-08-19 17:08 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-07-19 03:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdm.dll
2008-07-19 03:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\cdm.dll
2008-07-19 03:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
2008-07-19 03:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuauclt.exe
2008-07-19 03:10 45,768 ----a-w C:\WINDOWS\SYSTEM32\wups2.dll
2008-07-19 03:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\wups.dll
2008-07-19 03:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wups.dll
2008-07-19 03:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\wuapi.dll
2008-07-19 03:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuapi.dll
2008-07-19 03:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\wucltui.dll
2008-07-19 03:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wucltui.dll
2008-07-19 03:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\wuweb.dll
2008-07-19 03:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuweb.dll
2008-07-19 03:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
2008-07-19 03:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuaueng.dll
2008-07-19 03:07 270,880 ----a-w C:\WINDOWS\SYSTEM32\mucltui.dll
2008-07-19 03:07 210,976 ----a-w C:\WINDOWS\SYSTEM32\muweb.dll
2008-07-07 20:26 253,952 ----a-w C:\WINDOWS\SYSTEM32\es.dll
2008-07-07 20:26 253,952 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\es.dll
2001-07-26 22:58 47 -c--a-w C:\Program Files\ACMonitor_X73.ini
2001-07-05 18:46 8,116 -c--a-w C:\Program Files\OSLO3071b2.USB
2001-05-11 17:39 53,248 -c--a-w C:\Program Files\ACMonitor_X73.exe
2001-05-08 22:36 114,688 -c--a-w C:\Program Files\lxarscan.dll
2001-04-23 20:22 1,437 -c--a-w C:\Program Files\gtx73.ini
2001-02-22 15:54 768 -c--a-w C:\Program Files\x73_lut.dat
.

(((((((((((((((((((((((((((((   snapshot@2008-09-29_15.04.27.68   )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-15 15:24:00 1,013,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_bcont.exe
+ 2007-11-15 15:24:00 1,013,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_bcont_nm.exe
+ 2007-11-15 15:24:00 1,017,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_dsc.exe
+ 2007-11-15 15:23:56 1,069,056 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_libeay32.dll
+ 2007-09-06 19:16:24 421,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_pcdr2d3dvideodx9.dll
+ 2007-11-15 15:23:56 202,544 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtcmd.exe
+ 2007-11-15 15:23:56 378,408 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtevent.dll
+ 2007-11-15 15:23:56 398,624 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtfod.dll
+ 2007-11-15 15:23:56 116,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprthook.dll
+ 2007-11-15 15:23:56 73,728 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtmessage.dll
+ 2007-11-15 15:23:56 873,760 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtsched.dll
+ 2007-11-15 15:23:56 202,544 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtsvc.exe
+ 2007-11-15 15:23:56 337,448 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprttrigger.dll
+ 2007-11-15 15:23:56 374,048 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtui.dll
+ 2007-11-15 15:23:56 341,280 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_sprtupdate.dll
+ 2007-11-15 15:23:56 200,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_ssleay32.dll
+ 2007-11-15 15:23:56 20,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_SupportSoft.Agent.Sprocket.dll
+ 2007-11-15 15:23:56 24,576 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\55EEFB3E2E930EB49B6698EF8583221C\2.0.7311\file_SupportSoft.Agent.Sprocket.SupportMessage.dll
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"MoneyAgent"="C:\Program Files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 460784]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
"OE"="C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2007-04-12 321040]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-26 68856]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u"
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-08-02 77824]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 155648]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 36975]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"FLMOFFICE4DMOUSE"="C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe" [2006-12-17 806912]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2007-04-12 3429904]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064]

C:\Documents and Settings\Linda Fort\Start Menu\Programs\Startup\
Screen Saver Control.lnk - C:\WINDOWS\FSScrCtl.exe [2007-05-02 249344]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-04 258048]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Micro Innovations\\Wireless Laser Mouse\\uninst00.exe"=
"C:\\Program Files\\MP3-Xtreme\\Shareaza.exe"=
"%windir%\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:MP3-Xtreme TCP port 6346
"6346:UDP"= 6346:UDP:MP3-Xtreme UDP port 6346

.
Contents of the 'Scheduled Tasks' folder
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.yahoo.com/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://www.dell4me.com/myway
O8 -: &Search -
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html
O9 -: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 -: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html -
O9 -: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe -
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-07 15:49:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-10-07 15:50:56
ComboFix-quarantined-files.txt  2008-10-07 20:50:48
ComboFix2.txt  2008-09-30 21:17:42
ComboFix3.txt  2008-09-30 19:50:49
ComboFix4.txt  2008-09-29 20:05:39

Pre-Run: 59,028,037,632 bytes free
Post-Run: 59,056,549,888 bytes free

154 --- E O F --- 2008-09-15 03:38:44

 

Linda

10.4K Posts

October 13th, 2008 13:00

lkfort

 

I have not forgotten your log. I am working on a solution

 



 

 

 


"The world is what you make of it"

58 Posts

October 14th, 2008 00:00

thank you.

 

Linda

 

 

10.4K Posts

October 15th, 2008 19:00

lkfort

Re Run Hijackthis
  • Select " Main window"
    Then select " Open the misc tool section"
    Then select " Open uninstall manager"
    Then " save list" and save it to your desktop



Copy and paste that list as a reply to this thread









 


"The world is what you make of it"




58 Posts

October 15th, 2008 23:00

thank you.

Linda

ps- I have not gotten a pop up in over a week. My Trend did find a couple more trojan that it quarentined.

 

 

Ad-Aware SE Personal
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player ActiveX
Adobe Reader 7.0.9
Broadcom Management Programs
Compatibility Pack for the 2007 Office system
CTAS-VB6
Dell Digital Jukebox Driver
Dell Media Experience
Dell Photo Printer 720
Dell Solution Center
Dell Support Center (Support Software)
DellSupport
Formatta Filler 7.0
GdiplusUpgrade
Google Earth
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HouseCall 6.6
HP Extended Capabilities 4.7
HP Image Zone 4.7
HP Photosmart Essential
HP PSC & OfficeJet 4.7
HP Update
Intel(R) 537EP V9x DF PCI Modem
Intel(R) Extreme Graphics Driver
Internet Explorer Default Page
J2SE Runtime Environment 5.0 Update 6
Jasc Paint Shop Pro 8
KODAK Picture CD
Learn2 Player (Uninstall Only)
Macromedia Flash Player 8
Malwarebytes' Anti-Malware
MGI PhotoSuite 8.1 (Remove Only)
Micro Innovations Wireless Laser Mouse
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Picture It! Photo Premium 9
Microsoft Silverlight
Microsoft Streets and Trips 2004
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Word 2002
Microsoft Works
Microsoft Works 2004 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
MP3 Player Utilities
MP3 Player Utilities 3.57
MP3-Xtreme (uninstall)
MSN Music Assistant
MSXML 4.0 SP2 (KB927978)
oggcodecs 0.71.0946
OIN Analytics
PokerStars.net
QuickTime
RegCure 1.5.0.1
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Shockwave
Shop for HP Supplies
Sonic DLA
Sonic RecordNow!
Sonic Update Manager
Trend Micro PC-cillin Internet Security 2007
Trend Micro PC-cillin Internet Security 2007
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Windows Defender Signatures
Windows Genuine Advantage v1.3.0254.0
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Service Pack 3
WINXP SP2 TCP Fix

 

10.4K Posts

October 16th, 2008 13:00

lkfort

Thats good news so far

Go to Add or Remove Programs (Click Start->> Control Panel ->> Add or Remove Programs)

And uninstall the following program

OIN Analytics

Close Add or Remove Programs ->> Reboot your PC ->> Rerun Hiajckthis and post a fresh Hiajckthis log















 


"The world is what you make of it"




58 Posts

October 16th, 2008 17:00

thank you.

Linda

 

 

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:52 PM, on 10/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Micro Innovations\Wireless Laser Mouse\MOUSE32A.DAT
C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\FSScrCtl.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware  (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe

--
End of file - 7691 bytes

10.4K Posts

October 20th, 2008 14:00

lkfort

1. Go HERE and download File Lister.
  • Save it to your Desktop
    Rt Click ->> Extract all ->> And extract it to your Desktop
    Additional help on extracting zip files can be found HERE
    Open the File Lister Folder.
    Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
    As the program runs, it will appear that nothing is happening.
    When the program is fnished it will produce a log for you C:\Files.txt






Copy and paste the contents of that log in your reply.

You will have to post the results in more than one reply











 


"The world is what you make of it"




58 Posts

October 24th, 2008 01:00

(2nd file from desktop) 

 

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\
  6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Wireless Laser Mouse\\moffice.exe"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security 2007\\pccguide.exe\""
"dscactivate"="\"C:\\Program Files\\Dell Support Center\\gs_agent\\custom\\dsca.exe\""
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

58 Posts

October 24th, 2008 01:00


 COM+ System Application (COMSysApp) C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}  - Manual

 Cryptographic Services (CryptSvc) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Auto

 DCOM Server Process Launcher (DcomLaunch) C:\WINDOWS\system32\svchost -k DcomLaunch  - Auto

 DHCP Client (Dhcp) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Logical Disk Manager Administrative Service (dmadmin) C:\WINDOWS\System32\dmadmin.exe /com  - Manual

 Logical Disk Manager (dmserver) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 DNS Client (Dnscache) C:\WINDOWS\System32\svchost.exe -k NetworkService  - Auto

 Wired AutoConfig (Dot3svc) C:\WINDOWS\System32\svchost.exe -k dot3svc  - Manual

 DSBrokerService (DSBrokerService) "C:\Program Files\DellSupport\brkrsvc.exe"  - Manual

 Extensible Authentication Protocol Service (EapHost) C:\WINDOWS\System32\svchost.exe -k eapsvcs  - Manual

 Error Reporting Service (ERSvc) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Event Log (Eventlog) C:\WINDOWS\system32\services.exe  - Auto

 COM+ Event System (EventSystem) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 Fast User Switching Compatibility (FastUserSwitchingCompatibility) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 Fax (Fax) C:\WINDOWS\system32\fxssvc.exe  - Auto

 Google Updater Service (gusvc) "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"  - Manual

 Help and Support (helpsvc) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Human Interface Device Access (HidServ) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Disabled

 Health Key and Certificate Management Service (hkmsvc) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 HTTP SSL (HTTPFilter) C:\WINDOWS\System32\svchost.exe -k HTTPFilter  - Manual

 IMAPI CD-Burning COM Service (ImapiService) C:\WINDOWS\system32\imapi.exe  - Manual

 Server (lanmanserver) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Auto

 Workstation (lanmanworkstation) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 LexBce Server (LexBceS) C:\WINDOWS\system32\LEXBCES.EXE  - Auto

 TCP/IP NetBIOS Helper (LmHosts) C:\WINDOWS\system32\svchost.exe -k LocalService  - Auto

 Messenger (Messenger) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Disabled

 NetMeeting Remote Desktop Sharing (mnmsrvc) C:\WINDOWS\System32\mnmsrvc.exe  - Manual

 Distributed Transaction Coordinator (MSDTC) C:\WINDOWS\System32\msdtc.exe  - Manual

 Windows Installer (MSIServer) C:\WINDOWS\system32\msiexec.exe /V  - Manual

 Network Access Protection Agent (napagent) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 Network DDE (NetDDE) C:\WINDOWS\system32\netdde.exe  - Disabled

 Network DDE DSDM (NetDDEdsdm) C:\WINDOWS\system32\netdde.exe  - Disabled

 Net Logon (Netlogon) C:\WINDOWS\system32\lsass.exe  - Manual

 Network Connections (Netman) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 Network Location Awareness (NLA) (Nla) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 NT LM Security Support Provider (NtLmSsp) C:\WINDOWS\System32\lsass.exe  - Manual

 Removable Storage (NtmsSvc) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Manual

 Office Source Engine (ose) "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"  - Manual

 Trend Micro Central Control Component (PcCtlCom) C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe  - Auto

 Trend Micro Protection Against Spyware  (PcScnSrv) "C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe"  - Manual

 Plug and Play (PlugPlay) C:\WINDOWS\system32\services.exe  - Auto

 Pml Driver HPZ12 (Pml Driver HPZ12) C:\WINDOWS\system32\HPZipm12.exe  - Auto

 IPSEC Services (PolicyAgent) C:\WINDOWS\system32\lsass.exe  - Auto

 Protected Storage (ProtectedStorage) C:\WINDOWS\system32\lsass.exe  - Auto

 Remote Access Auto Connection Manager (RasAuto) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 Remote Access Connection Manager (RasMan) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 Remote Desktop Help Session Manager (RDSessMgr) C:\WINDOWS\system32\sessmgr.exe  - Manual

 Routing and Remote Access (RemoteAccess) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Disabled

 Remote Procedure Call (RPC) Locator (RpcLocator) C:\WINDOWS\System32\locator.exe  - Manual

 Remote Procedure Call (RPC) (RpcSs) C:\WINDOWS\system32\svchost -k rpcss  - Auto

 QoS RSVP (RSVP) C:\WINDOWS\System32\rsvp.exe  - Manual

 Security Accounts Manager (SamSs) C:\WINDOWS\system32\lsass.exe  - Auto

 Smart Card (SCardSvr) C:\WINDOWS\System32\SCardSvr.exe  - Manual

 Task Scheduler (Schedule) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Secondary Logon (seclogon) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 System Event Notification (SENS) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Auto

 Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Shell Hardware Detection (ShellHWDetection) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Print Spooler (Spooler) C:\WINDOWS\system32\spoolsv.exe  - Auto

 SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter  - Auto

 System Restore Service (srservice) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 SSDP Discovery Service (SSDPSRV) C:\WINDOWS\System32\svchost.exe -k LocalService  - Manual

 Windows Image Acquisition (WIA) (stisvc) C:\WINDOWS\System32\svchost.exe -k imgsvc  - Auto

 MS Software Shadow Copy Provider (SwPrv) C:\WINDOWS\System32\dllhost.exe /Processid:{F79A1568-D6C5-4C69-A086-936CF52DBBE3}  - Manual

 Performance Logs and Alerts (SysmonLog) C:\WINDOWS\system32\smlogsvc.exe  - Manual

 Telephony (TapiSrv) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 Terminal Services (TermService) C:\WINDOWS\System32\svchost -k DComLaunch  - Manual

 Themes (Themes) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Trend Micro Real-time Service (Tmntsrv) C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe  - Auto

 Trend Micro Personal Firewall (TmPfw) C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe  - Auto

 Trend Micro Proxy Service (tmproxy) C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe  - Auto

 Distributed Link Tracking Client (TrkWks) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Auto

 Universal Plug and Play Device Host (upnphost) C:\WINDOWS\System32\svchost.exe -k LocalService  - Manual

58 Posts

October 24th, 2008 01:00

(I am not sure this is what you want. When I right clicked there was no option to extract. All it did when I clicked to open was make 4 other desktop files).

Here is the first one. 

 

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"MoneyAgent"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
"DellSupport"="\"C:\\Program Files\\DellSupport\\DSAgnt.exe\" /startup"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"OE"="\"C:\\Program Files\\Trend Micro\\Internet Security 2007\\TMAS_OE\\TMAS_OEMon.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_9 -reboot

58 Posts

October 24th, 2008 01:00


+++++++++++++++++++++++++++++++++
+
+ File Lister
+
+ Version 1.0.4
+
+  By bamajim / bamajim.com
+
+++++++++++++++++++++++++++++++++


Report ran on --->>>  10/23/2008 9:14:05 PM

====== Values under HKLM\~\Run ======

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"UserFaultCheck"=hex(2):25,73,79,73,74,65,6d,72,6f,6f,74,25,5c,73,79,73,74,65,\
  6d,33,32,5c,64,75,6d,70,72,65,70,20,30,20,2d,75,00
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"HP Software Update"="C:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"
"FLMOFFICE4DMOUSE"="C:\\Program Files\\Micro Innovations\\Wireless Laser Mouse\\moffice.exe"
"pccguide.exe"="\"C:\\Program Files\\Trend Micro\\Internet Security 2007\\pccguide.exe\""
"dscactivate"="\"C:\\Program Files\\Dell Support Center\\gs_agent\\custom\\dsca.exe\""
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"


====== Values under HKCU\~\Run ======

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"MoneyAgent"="\"C:\\Program Files\\Microsoft Money\\System\\mnyexpr.exe\""
"DellSupport"="\"C:\\Program Files\\DellSupport\\DSAgnt.exe\" /startup"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"OE"="\"C:\\Program Files\\Trend Micro\\Internet Security 2007\\TMAS_OE\\TMAS_OEMon.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"
"DellSupportCenter"="\"C:\\Program Files\\Dell Support Center\\bin\\sprtcmd.exe\" /P DellSupportCenter"
"updateMgr"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\AdobeUpdateManager.exe\" AcRdB7_0_9 -reboot 1"


====== Folders and Files from "%\" and "%\Windows" Created Last 30 Days ======

9/29/2008 2:23:02 PM    4120648    C:\QooBox
9/30/2008 4:12:40 PM    16864    C:\QooBox\BackEnv
9/29/2008 2:23:02 PM    2278404    C:\QooBox\Quarantine
9/29/2008 2:25:05 PM    2272900    C:\QooBox\Quarantine\C
9/29/2008 2:30:57 PM    25973    C:\QooBox\Quarantine\C\Documents and Settings
9/29/2008 2:30:57 PM    25973    C:\QooBox\Quarantine\C\Documents and Settings\Linda Fort
9/29/2008 2:30:57 PM    23700    C:\QooBox\Quarantine\C\Documents and Settings\Linda Fort\Cookies
9/29/2008 2:31:22 PM    2273    C:\QooBox\Quarantine\C\Documents and Settings\Linda Fort\Start Menu
9/29/2008 2:31:22 PM    2273    C:\QooBox\Quarantine\C\Documents and Settings\Linda Fort\Start Menu\Programs
9/29/2008 2:31:22 PM    2273    C:\QooBox\Quarantine\C\Documents and Settings\Linda Fort\Start Menu\Programs\Outerinfo
9/29/2008 2:26:08 PM    873526    C:\QooBox\Quarantine\C\Program Files
9/29/2008 2:26:08 PM    660907    C:\QooBox\Quarantine\C\Program Files\Common Files
9/29/2008 2:26:08 PM    618496    C:\QooBox\Quarantine\C\Program Files\Common Files\YSTEM~1
9/29/2008 2:26:10 PM    191571    C:\QooBox\Quarantine\C\Program Files\GetPack
9/29/2008 2:26:12 PM    18935    C:\QooBox\Quarantine\C\Program Files\Outerinfo
9/29/2008 2:26:12 PM    904    C:\QooBox\Quarantine\C\Program Files\Outerinfo\FF
9/29/2008 2:26:13 PM    138    C:\QooBox\Quarantine\C\Program Files\Outerinfo\FF\components
9/29/2008 2:26:15 PM    0    C:\QooBox\Quarantine\C\Program Files\SEMBLY~1
9/29/2008 2:26:15 PM    0    10/7/2008 3:50:57 PM    11125    32    C:\ComboFix.txt
10/23/2008 9:11:39 PM    1822    32    C:\Files.txt
10/16/2008 10:12:23 PM    2467726    C:\WINDOWS\$NtUninstallKB954211$
10/16/2008 10:12:23 PM    622094    C:\WINDOWS\$NtUninstallKB954211$\spuninst
10/16/2008 10:14:35 PM    1272552    C:\WINDOWS\$NtUninstallKB956391$
10/16/2008 10:14:35 PM    621288    C:\WINDOWS\$NtUninstallKB956391$\spuninst
10/16/2008 10:14:52 PM    760875    C:\WINDOWS\$NtUninstallKB956803$
10/16/2008 10:14:52 PM    622379    C:\WINDOWS\$NtUninstallKB956803$\spuninst
10/16/2008 10:11:35 PM    4878729    C:\WINDOWS\$NtUninstallKB956841$
10/16/2008 10:11:35 PM    624009    C:\WINDOWS\$NtUninstallKB956841$\spuninst
10/16/2008 10:14:22 PM    957067    C:\WINDOWS\$NtUninstallKB957095$
10/16/2008 10:14:22 PM    622219    C:\WINDOWS\$NtUninstallKB957095$\spuninst
9/29/2008 2:24:55 PM    79605743    C:\WINDOWS\erdnt
9/29/2008 2:24:55 PM    42454346    C:\WINDOWS\erdnt\Hiv-backup
10/7/2008 3:44:59 PM    5304320    C:\WINDOWS\erdnt\Hiv-backup\Users
10/7/2008 3:44:59 PM    434176    C:\WINDOWS\erdnt\Hiv-backup\Users\00000001
10/7/2008 3:44:59 PM    12288    C:\WINDOWS\erdnt\Hiv-backup\Users\00000002
10/7/2008 3:44:59 PM    434176    C:\WINDOWS\erdnt\Hiv-backup\Users\00000003
10/7/2008 3:44:59 PM    12288    C:\WINDOWS\erdnt\Hiv-backup\Users\00000004
10/7/2008 3:44:59 PM    4304896    C:\WINDOWS\erdnt\Hiv-backup\Users\00000005
10/7/2008 3:44:59 PM    106496    C:\WINDOWS\erdnt\Hiv-backup\Users\00000006
9/29/2008 2:55:08 PM    37151287    C:\WINDOWS\erdnt\subs
10/7/2008 3:48:09 PM    577968    C:\WINDOWS\temp
9/29/2008 2:22:58 PM    89504    32    C:\WINDOWS\fdsv.exe
9/29/2008 2:22:58 PM    80412    32    C:\WINDOWS\grep.exe
10/16/2008 10:12:16 PM    7154    32    C:\WINDOWS\KB954211.log
10/15/2008 2:46:20 AM    23813    32    C:\WINDOWS\KB956390-IE7.log
10/16/2008 10:14:28 PM    13822    32    C:\WINDOWS\KB956391.log
10/16/2008 10:14:46 PM    14267    32    C:\WINDOWS\KB956803.log
10/16/2008 10:10:39 PM    8365    32    C:\WINDOWS\KB956841.log
10/16/2008 10:14:16 PM    14328    32    C:\WINDOWS\KB957095.log
9/30/2008 4:12:07 PM    28672    32    C:\WINDOWS\Nircmd.exe
9/28/2008 7:44:35 PM    1409    32    C:\WINDOWS\QTFont.for
9/28/2008 7:44:35 PM    54156    34    C:\WINDOWS\QTFont.qfn
9/29/2008 2:22:58 PM    98816    32    C:\WINDOWS\sed.exe
9/29/2008 2:22:58 PM    161792    32    C:\WINDOWS\swreg.exe
9/29/2008 2:22:58 PM    136704    32    C:\WINDOWS\SWSC.exe
9/29/2008 2:22:58 PM    212480    32    C:\WINDOWS\swxcacls.exe
9/29/2008 2:22:58 PM    49152    32    C:\WINDOWS\VFind.exe
9/29/2008 2:22:58 PM    68096    32    C:\WINDOWS\zip.exe
9/28/2008 7:54:15 PM    0    32    C:\WINDOWS\SYSTEM32\2b784b52-.txt
9/28/2008 7:58:58 PM    71168    0    C:\WINDOWS\SYSTEM32\pwhsapvb.dll
9/28/2008 7:58:44 PM    105984    0    C:\WINDOWS\SYSTEM32\yyfhxiuf.dll
9/29/2008 6:10:23 AM    9662    32    C:\WINDOWS\SYSTEM32\ZoneAlarmIconUS.ico

====== Files under "\Administrator\Startup" Last 30 Days======

 

====== Files under "\All Users\Startup" Last 30 Days======


====== Folders under "\Program Files" Last 30 Days======


====== Files under "\System32\Drivers" Last 30 Days======


====== Files under "\User\Local Settings\Temp" Last 30 Days======

10/12/2008 10:48:04 PM    49442    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\7478_appcompat.txt
10/8/2008 5:58:53 AM    270    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\AUInst.log
10/13/2008 3:57:11 PM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIO101.tmp
10/10/2008 8:38:50 PM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIO155.tmp
10/10/2008 8:39:51 PM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIO157.tmp
10/20/2008 3:05:37 PM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIO15D.tmp
10/20/2008 3:05:58 PM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIO15F.tmp
10/14/2008 9:41:36 PM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIO185.tmp
10/14/2008 9:41:55 PM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIO187.tmp
10/18/2008 11:00:51 AM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIO77.tmp
10/18/2008 11:01:09 AM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIO79.tmp
10/13/2008 2:13:07 PM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIOA9.tmp
10/13/2008 2:13:08 PM    47122    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\DIOAA.tmp
9/29/2008 3:00:00 PM    81081    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\hpodvd09.log
10/8/2008 6:07:37 AM    7881    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\jusched.log
10/8/2008 5:58:32 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MAR10.tmp
10/19/2008 3:52:49 PM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MAR11.tmp
10/20/2008 6:04:03 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MAR12.tmp
10/18/2008 7:39:54 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MAR13.tmp
10/21/2008 6:03:30 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MAR14.tmp
10/22/2008 6:02:12 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MAR15.tmp
10/23/2008 6:04:25 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MAR16.tmp
10/16/2008 12:33:36 PM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MAR8.tmp
10/11/2008 7:24:19 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MAR9.tmp
10/10/2008 6:04:14 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MARA.tmp
10/9/2008 6:03:51 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MARB.tmp
10/12/2008 7:55:53 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MARC.tmp
10/13/2008 6:03:37 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MARD.tmp
10/14/2008 4:50:00 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MARE.tmp
10/17/2008 6:23:19 AM    1430    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\MARF.tmp
10/19/2008 8:30:27 AM    1428    32    C:\Documents and Settings\Linda Fort\Local Settings\Temp\wmplog00.sqm

====== Files and Folders under "All Users\Application Data" Last 30 Days======


 ====== Possible Rootkit Scan (Note: Items listed here are not necessarily bad)======


====== Values under HKLM\Software\microsoft\shared tools\msconfig\startupreg ======

====== BHO's under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects ======

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}


HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}


====== Services ( Services that are Whitelisted are not shown) ======

 Alerter (Alerter) C:\WINDOWS\System32\svchost.exe -k LocalService  - Disabled

 Application Layer Gateway Service (ALG) C:\WINDOWS\System32\alg.exe  - Manual

 Application Management (AppMgmt) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Disabled

 ASP.NET State Service (aspnet_state) C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe  - Manual

 Windows Audio (AudioSrv) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Background Intelligent Transfer Service (BITS) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Manual

 Computer Browser (Browser) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Auto

 Indexing Service (CiSvc) C:\WINDOWS\system32\cisvc.exe  - Manual

 ClipBook (ClipSrv) C:\WINDOWS\system32\clipsrv.exe  - Disabled

58 Posts

October 24th, 2008 01:00


 Uninterruptible Power Supply (UPS) C:\WINDOWS\System32\ups.exe  - Manual

 Volume Shadow Copy (VSS) C:\WINDOWS\System32\vssvc.exe  - Manual

 Windows Time (w32time) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 WebClient (WebClient) C:\WINDOWS\System32\svchost.exe -k LocalService  - Auto

 Windows Management Instrumentation (winmgmt) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Auto

 Portable Media Serial Number Service (WmdmPmSN) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual

 WMI Performance Adapter (WmiApSrv) C:\WINDOWS\System32\wbem\wmiapsrv.exe  - Manual

 Windows Media Player Network Sharing Service (WMPNetworkSvc) "C:\Program Files\Windows Media Player\WMPNetwk.exe"  - Manual

 Security Center (wscsvc) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Automatic Updates (wuauserv) C:\WINDOWS\system32\svchost.exe -k netsvcs  - Auto

 Windows Driver Foundation - User-mode Driver Framework (WudfSvc) C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup  - Manual

 Wireless Zero Configuration (WZCSVC) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Auto

 Network Provisioning Service (xmlprov) C:\WINDOWS\System32\svchost.exe -k netsvcs  - Manual


====== Running Processes ======

System Idle Process   [0]  
System   [4]  
smss.exe   [860]   \SystemRoot\System32\smss.exe
csrss.exe   [908]  
winlogon.exe   [932]   winlogon.exe
services.exe   [976]   C:\WINDOWS\system32\services.exe
lsass.exe   [988]   C:\WINDOWS\system32\lsass.exe
svchost.exe   [1196]   C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe   [1272]  
svchost.exe   [1392]   C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe   [1448]  
svchost.exe   [1736]  
explorer.exe   [1880]   C:\WINDOWS\Explorer.EXE
LEXBCES.EXE   [2000]   C:\WINDOWS\system32\LEXBCES.EXE
spoolsv.exe   [2024]   C:\WINDOWS\system32\spoolsv.exe
LEXPPS.EXE   [2032]   LEXPPS.EXE
PcCtlCom.exe   [468]   C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
sprtsvc.exe   [624]   "C:\Program Files\Dell Support Center\bin\sprtsvc.exe" /service /p dellsupportcenter
svchost.exe   [660]   C:\WINDOWS\System32\svchost.exe -k imgsvc
Tmntsrv.exe   [1248]   c:\progra~1\trendm~1\intern~2\tmntsrv.exe
TmPfw.exe   [1320]   C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
alg.exe   [2372]  
PCMService.exe   [2772]   "C:\Program Files\Dell\Media Experience\PCMService.exe"
tfswctrl.exe   [2804]   "C:\WINDOWS\system32\dla\tfswctrl.exe"
jusched.exe   [2840]   "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
hpwuSchd2.exe   [2880]   "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
moffice.exe   [2952]   "C:\Program Files\Micro Innovations\Wireless Laser Mouse\moffice.exe"
pccguide.exe   [2996]   "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
DSAgnt.exe   [3132]   "C:\Program Files\DellSupport\DSAgnt.exe" /startup
ctfmon.exe   [3176]   "C:\WINDOWS\system32\ctfmon.exe"
TMAS_OEMon.exe   [3244]   "C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe"
GoogleToolbarNotifier.exe   [3352]   "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
sprtcmd.exe   [3464]   "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
mouse32a.dat   [3740]   "C:\Program Files\Micro Innovations\Wireless Laser Mouse\MOUSE32A.DAT"
hpqtra08.exe   [4080]   "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"
PcScnSrv.exe   [2132]   "C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe"
msmsgs.exe   [3916]   "C:\Program Files\Messenger\msmsgs.exe" -Embedding
tmproxy.exe   [1424]   C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe
iexplore.exe   [1680]   "C:\Program Files\Internet Explorer\IEXPLORE.EXE" -Embedding
wmiprvse.exe   [308]  
wmiprvse.exe   [2400]  
wscript.exe   [3316]   "C:\WINDOWS\System32\WScript.exe" "C:\Documents and Settings\Linda Fort\Desktop\FileLister.vbe"
notepad.exe   [2832]   "C:\WINDOWS\system32\NOTEPAD.EXE" C:\Documents and Settings\Linda Fort\Desktop\P.txt
notepad.exe   [2368]   "C:\WINDOWS\system32\NOTEPAD.EXE" C:\Documents and Settings\Linda Fort\Desktop\R.txt

====== Uninstall List From Registry ======

Ad-Aware SE Personal
Adobe Atmosphere Player for Acrobat and Adobe Reader
Adobe Flash Player ActiveX
CTAS-VB6
Dell Digital Jukebox Driver
Dell Photo Printer 720
Formatta Filler 7.0
HijackThis 2.0.2
HP Image Zone 4.7
HP Extended Capabilities 4.7
Microsoft Internationalized Domain Names Mitigation APIs
Windows Internet Explorer 7
Broadcom Management Programs
Intel(R) 537EP V9x DF PCI Modem
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows XP (KB923689)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Internet Explorer 7 (KB928090)
Hotfix for Windows Media Format 11 SDK (KB929399)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows Internet Explorer 7 (KB939653)
Hotfix for Windows Media Player 11 (KB939683)
Security Update for Windows XP (KB941569)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows XP (KB946648)
Hotfix for Windows Internet Explorer 7 (KB947864)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Update for Windows XP (KB951072-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Update for Windows XP (KB951978)
Hotfix for Windows XP (KB952287)
Security Update for Windows XP (KB952954)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB954211)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Malwarebytes' Anti-Malware
MGI PhotoSuite 8.1 (Remove Only)
Micro Innovations Wireless Laser Mouse
Microsoft .NET Framework 1.1
MP3-Xtreme (uninstall)
Microsoft Compression Client Pack 1.0 for Windows XP
MSN Music Assistant
Microsoft National Language Support Downlevel APIs
oggcodecs 0.71.0946
Microsoft Picture It! Photo Premium 9
PokerStars.net
QuickTime
RegCure 1.5.0.1
Shockwave
Macromedia Flash Player 8
Shop for HP Supplies
Learn2 Player (Uninstall Only)
Trend Micro PC-cillin Internet Security 2007
HouseCall 6.6
Windows Genuine Advantage Notifications (KB905474)
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WINXP SP2 TCP Fix
Windows Media Format 11 runtime
Windows Media Player 11
Microsoft Works 2004 Setup Launcher
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Encarta Encyclopedia Standard 2004
Sonic Update Manager
Scan
Security Update for CAPICOM (KB931906)
1600
Dell Solution Center
Sonic DLA
ScannerCopy
HP Product Assistant
Fax
Microsoft Money 2004
Google Earth
TrayApp
Google Toolbar for Internet Explorer
Dell Media Experience
Unload
J2SE Runtime Environment 5.0 Update 6
Microsoft Works Suite Add-in for Microsoft Word
HP PSC & OfficeJet 4.7
WebFldrs XP
Internet Explorer Default Page
MSXML 4.0 SP2 (KB927978)
ProductContext
Readme
Banctec Service Agreement
KODAK Picture CD
GdiplusUpgrade
MP3 Player Utilities
Windows Genuine Advantage v1.3.0254.0
AiO_Scan
Destinations
Dell Networking Guide
BufferChm
MP3 Player Utilities 3.57
HPSystemDiagnostics
DellSupport
Jasc Paint Shop Pro 8
AiOSoftware
Microsoft Streets and Trips 2004
QFolder
Broadcom Management Programs
Microsoft Silverlight
Intel(R) Extreme Graphics Driver
Microsoft Money 2004 System Pack
Compatibility Pack for the 2007 Office system
Help and Support Customization
Microsoft Office Professional Edition 2003
Microsoft Word 2002
Sonic RecordNow!
Microsoft Visual C++ 2005 Redistributable
Windows Defender Signatures
Adobe Reader 7.0.9
HPSSupply
Director
Microsoft Works
Trend Micro PC-cillin Internet Security 2007
MarketResearch
HP Update
Microsoft .NET Framework 1.1
1600_Help
WebReg
Microsoft Picture It! Photo Premium 9
Google Toolbar for Internet Explorer
Dell Support Center (Support Software)
HP Photosmart Essential
1600Trb
Banctec Service Agreement

======== Other Info ========

TOTAL PHYSICAL RAM: 1340 MB

 

10.4K Posts

October 24th, 2008 18:00

lkfort

o.k.

1. Go HERE and download WormFix

Save it to your Desktop. But do not run it yet.

2. Reboot into Safe Mode
This can be done by
  • Restart your PC, and after it starts, but before you see the Windows Splash screen
    Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
    Use your arrow keys and select Safe Mode and then Enter



3. Close all Internet Explorer Windows and Run WormFix
  • Double click the WormFix.Zip file to unzip it.
    Open the WormFix Folder
    Double Click WormFix.vbe to run the program
    Then Select O.K. at the prompt
    Allow the program to run (Your desktop will disappear, then re-appear. This is normal)
    When it is finished it wil produce a log C:\WormFix.txt
    Copy and paste the results of that log in your reply







4. Then reboot your PC into Normal Windows Mode->> Rerun Hijackthis and post a fresh Hiajckthis log.
As well as the C:\WormFix.txt log





















 


"The world is what you make of it"




No Events found!

Top