Unsolved

This post is more than 5 years old

27 Posts

3790

February 5th, 2007 19:00

Hijack This logfile - computer slow and wonky

All of the problems started yesterday.  First I noticed that the screen was flashing periodically, checked the tech support documents, and disabled NVIDIA power miser.  The flashing stopped, but other problems ensued.  The computer is slow at times, especially in IE; it has frozen up once, pages are slow to load sometimes, other times not.  The touchpad stops scrolling intermittently or is jerky; other times it's fine.  The audio was occasionally distorted, I got "shadows" from previous web pages bleeding into the next page opened.  I downloaded and installed a new driver for the touchpad, did a system restore, and then afterwards, had to reinstall McAfee, which had been disabled by the system restore.  I have tested my internet connection--it's fine.  Nothing has fixed the problem, and some of these things seem to indicate a memory problem (and I should have way more than enough for the tasks I was doing), so I wondered about hijacking.  Thanks.
 
Log:
 
Logfile of HijackThis v1.99.1
Scan saved at 4:02:26 PM, on 2/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\Julia\LOCALS~1\Temp\clclean.0001
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\SiteAdvisor\6009\SiteAdv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program
Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Creative Labs
Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\SiteAdvisor\6009\SAService.exe
C:\WINDOWS\system32\stacsv.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1060908
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL =
www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1060908
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://us.mcafee.com/root/learnmore/learnmore.asp?close=true&lcode=en-us
N3 - Netscape 7: user_pref("browser.startup.homepage",
Settings\Julia\Application
Data\Mozilla\Profiles\default\bi064ixh.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine",
"engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWe
b_01.src"); (C:\Documents and Settings\Julia\Application
Data\Mozilla\Profiles\default\bi064ixh.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program
Files\SiteAdvisor\6009\SiteAdv.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program
Files\GetRight\xx2gr.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -
C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program
files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar5.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} -
c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: Browser Address Error Redirector -
{CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} -
C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar5.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} -
C:\Program Files\SiteAdvisor\6009\SiteAdv.dll
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program
Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE
C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program
Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program
Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common
Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround
Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows
Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program
Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe"
-atboottime
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program
Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop
Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [VideoraiPodConverter] C:\Program
Files\VideoraiPodConverter\VideoraConverter.exe -t
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program
Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6009\SiteAdv.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe"
/startup
O4 - HKCU\..\Run: [swg] C:\Program
Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program
Files\GetRight\getright.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL
Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: Download with GetRight - C:\Program
Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List -
res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print -
res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program
Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program
Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Open with GetRight Browser - C:\Program
Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program
Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
%windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://home.promosquad.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration
Class) - http://support.fastaccess.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software
AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage
Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) -
http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating
System Class) -
http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
_site.cab?1161221925796
O16 - DPF: {7E9522CF-6B95-46D6-8E2F-7638F507313F} (BLS_SpeedOP.systemcheck) -
.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software
AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} -
C:\Program Files\SiteAdvisor\6009\SiteAdv.dll
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program
Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd -
C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. -
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program
Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. -
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program
Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. -
C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. -
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program
files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. -
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. -
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. -
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. -
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. -
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. -
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. -
C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. -
C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program
Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe"
-sMICROSOFTSMLBIZ (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program
Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program
Files\SiteAdvisor\6009\SAService.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program
Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i
MICROSOFTSMLBIZ (file missing)
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. -
C:\WINDOWS\system32\stacsv.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner -
C:\WINDOWS\System32\WLTRYSVC.EXE
 


Message Edited by jmh123 on 02-05-2007 07:02 PM

Message Edited by jmh123 on 02-06-2007 10:54 AM

2 Intern

 • 

5.9K Posts

February 6th, 2007 15:00

Don't see anything obvious in the log.  Let's try a few things.
 
Run one of the online free scanners like:
 
or
 
and see if it comes back with anything but tracking coolies (we don't care about them).
 
Check for High CPU Usage:
When it is running slow: Rightclick on the clock and select Task Manager then select Processes. Click once or twice on the CPU column heading until you get the bigger numbers at the top in that column.  What are the top three processes and what % do they each take.  What does it say for CPU usage at the bottom of the window? 
 
Click on the Memory column header until you get the big numbers at the top of the Memory column.  What are the top three and how much memory do they take.   Let it sit idle for a few minutes and see if the numbers are increasing.
 
Close all active programs and repeat the CPU part of the test.

Blacklight Rootkit Detector:
Download Blacklight trial from here: http://www.f-secure.com/blacklight/
Hit "I accept." It will take you to the download page. Download blbeta.exe and save it to the Desktop. Once saved... double click blbeta.exe (you may not be able to see the .exe) to install the program. Click Accept Agreement and click Scan This app may trigger a warning from your antivirus. Let the driver load. Wait for it to finish. If it displays any items...don't do anything with them yet. Just hit exit (close) It will drop a log on Desktop that starts with fsbl....big number
Please post contents of log in your next reply.
 
A Disk Check:
Run a disk error check and see if your harddrive has problems.  Start, My Computer then right click on Local Drive C and select Properties (verify that it shows you have at least 15% free) then Tools, Error-Checking => Check Now.  Check the 2 boxes then Start.  It will tell you it can't do it now but will be glad to schedule it for your next boot.  Tell it OK. When you reboot it will check your drive which usually takes 30-60 minutes.  Sometimes it will even fix your problems while it is at it.
 
Check the Event logs for errors:
Start, Run, eventvwr.msc, OK then select System.  Look for red marked files that have a time stamp about the time of the slowdown.  Open the event then click on the bottom of the three buttons to copy the text.  Move to a reply and Edit, Paste.  Repeat for any other different errors that happened during the last slowdown period or last reboot.  Please don't go back to the beginning of time and no events from a Safe Mode boot.  Repeat for Application.  If your PC speaks something other than English don't translate it unless it doesn't use the Latin alphabet and then please include the timestamps.
 
Check the Device Manager for problems:
(Start) then rightclick on My Computer and select Manage.  Then Device Manager.  click on each of the + marks to open each item.  Look for yellow marked items and uninstall them or delete them and reboot.  Do they come back with yellow marks?
 
Check for a bad file in System32:
Start, Run, sigverif, OK then press Start and wait for the program to finish.   Look for files with .exe, .dll or .sys extensions.
 
For IE slowness:
 
Start, Run, cmd, OK then in the black cmd window type (with an Enter after each bold line)
 
nslookup att.com
 
(Does it come back quickly with
 

Name:    att.com
Addresses:  144.160.103.104, 144.160.134.80
 
or does it time out?)
 
Close IE, Run HJT, scan only and check all of these then Fix Checked.
 
O2 - BHO: Adobe PDF Reader Link Helper -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat
7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program
Files\SiteAdvisor\6009\SiteAdv.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program
Files\GetRight\xx2gr.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} -
C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program
files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar5.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} -
c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: Browser Address Error Redirector -
{CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} -
C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar5.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} -
C:\Program Files\SiteAdvisor\6009\SiteAdv.dll
Open IE and see if it is a lot faster.  If not then close IE, run HJT, View the list of Backups and RESTORE ALL.
If it helped then just restore a few of them until you isolate the entries that slow you down.
 
Ron

27 Posts

February 7th, 2007 01:00

Thank you.  I will try all of these things tomorrow.  I just quickly checked task manager and was surprised to see 50% usage by WINWORD.EXE.  I don't even have Word running.  Very odd.  I hardly ever use Word.

2 Intern

 • 

5.9K Posts

February 7th, 2007 01:00

Sounds like you already found the problem.  Probably a macro virus.  See if you can highlight winword in Task Manager and Kill Process.
 
I'll post my procedure for removing maco viruses tomorrow.  Don't have it onthis PC.
 
Ron
 
 

27 Posts

February 7th, 2007 03:00

Thank you.  Was able to kill the process and am cautiously optimistic about the results.  I'll check back tomorrow for info on killing the macro virus. 
 
BTW, googled "macro virus" to get more info.  I'm extremely careful about downloading attachments in e-mail.  Are there other ways to catch these?  Looks like they're fairly old news; do you think a new version is circulating?  Should I warn people I correspond with?

2 Intern

 • 

5.9K Posts

February 7th, 2007 12:00

Make sure word is closed and do a Search for normal.dot. 
 
(Start, Search, For Files and Folders then under More Advanced Options, check the top three then put in normal.dot and Search.)
 
Rename all you find to anormal.dot.  Then open Word by using  Start, All Programs, ....  Do not click on an existing document.  Then Tools, Options, Security and set it to Very High then OK.  Then Tools, Options, Save, and click on Prompt to Save Normal template then OK.  Close Word.  It will ask you if you want to save the normal template.  Tell it Yes this time and NO anytime in the future unless you have made changes to the defaults.
There are always new macro viruses out there.  Some people have nothing better to do with their time and macro viruses are very easy to write.
 
Your friends probably already know that you have a virus.  These things usually send out infected emails to all your friends.  That's one way they spread. 
 
We don't yet know if it's a macro virus.  May be a vbs virus like "I love you" was or something stranger.  We will know more if this helps.
 
 
Wouldn't hurt to run an online scan:
 
 
See if it finds anything besides tracking cookies.
 
 
Ron
 
 

2 Intern

 • 

5.9K Posts

February 7th, 2007 17:00

Go back and do the Blacklight then do Silent Runners:
 
 
and post the log.  The Silent Runners log will probably need to be broken up into more than one post since it's usually a bit bigger than the forum likes.
 
Ron

27 Posts

February 7th, 2007 17:00

Geez, I'm batting zero here.  Trendmicro scan won't complete--it gets almost all the way through, but shuts down IE before the scan has completed.  I've tried various options such as adding it to trusted sites, lowering the security level to medium via internet options, using the Java kernel instead of ActiveX (which did download successfully), and nothing has worked.  My version of Word is a trial version, and will give me no access to options under tools.  Meanwhile, the computer is working fine since I stopped the WINWORD.EXE process.  No reports from friends of unwanted e-mails from me.  I still need to make sure the computer is clean.  Thanks.

27 Posts

February 7th, 2007 23:00

Thank you.  Blacklight found no hidden files.  Here's the log:
 
02/07/07 18:45:53 [Info]: BlackLight Engine 1.0.55 initialized
02/07/07 18:45:53 [Info]: OS: 5.1 build 2600 (Service Pack 2)
02/07/07 18:45:53 [Note]: 7019 4
02/07/07 18:45:53 [Note]: 7005 0
02/07/07 18:46:03 [Note]: 7006 0
02/07/07 18:46:03 [Note]: 7011 1744
02/07/07 18:46:04 [Note]: 7026 0
02/07/07 18:46:04 [Note]: 7026 0
02/07/07 18:46:18 [Note]: FSRAW library version 1.7.1021
02/07/07 19:10:02 [Note]: 7007 0
 
In the meantime, just after posting I attempted to download and run Kaspersky.  The computer went completely wacky and I just managed to get rid of the program again.  (Long story short.)  Then I saved a whole bunch of data files just in case.  Now, back to the original list you posted.  Can't do the scan.  Checked the CPU usage as you know.  WINWORD.exe returns every time I reboot, and uses beaucoup resources.  With that process ended, and no other programs running, System Idle uses the bulk of the resources, and very little memory.  CPU usage is in the single digits.
 
 
Event log, system:
 
no errors, 1/2 to 2/4:
 
then:
 
Event Type: Error
Event Source: WinDefend
Event Category: None
Event ID: 2004
Date:  2/4/2007
Time:  11:43:40 PM
User:  N/A
Computer: D9CZLQB1
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
  Signatures Attempted: Current
  Error Code: 0x8050a001
  Error description: The program can't find definition files that help detect unwanted software. Check for updates to the definition files, and then try again. For information on installing updates, see Help and Support.
  Signatures loading: Backup
  Loading signature version: 1.15.2224.9
  Loading engine version: 1.1.2101.0

 
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7024
Date:  2/4/2007
Time:  11:43:53 PM
User:  N/A
Computer: D9CZLQB1
Description:
The McAfee.com McShield service terminated with service-specific error 5022 (0x139E).
 
 
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date:  2/4/2007
Time:  11:44:52 PM
User:  D9CZLQB1\Julia
Computer: D9CZLQB1
Description:
The server {692E988D-1057-4C57-8078-26CF7AE54263} did not register with DCOM within the required timeout.

 
again 1 minute later, and another in 1 minute, and yet again in 1 minute, just like the above
 
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7022
Date:  2/5/2007
Time:  12:08:14 AM
User:  N/A
Computer: D9CZLQB1
Description:
The McAfee SystemGuards service hung on starting.
 
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7022
Date:  2/7/2007
Time:  2:40:58 PM
User:  N/A
Computer: D9CZLQB1
Description:
The Kaspersky Anti-Virus 6.0 service hung on starting.

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7011
Date:  2/7/2007
Time:  2:49:42 PM
User:  N/A
Computer: D9CZLQB1
Description:
Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
 
 
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date:  2/7/2007
Time:  2:51:39 PM
User:  NT AUTHORITY\NETWORK SERVICE
Computer: D9CZLQB1
Description:
The server {73E709EA-5D93-4B2E-BBB0-99B7938DA9E4} did not register with DCOM within the required timeout.

the above again in 4 minutes, and again in 4 minutes
 
another Kaspersky hung on starting msg.
 
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date:  2/7/2007
Time:  3:09:44 PM
User:  N/A
Computer: D9CZLQB1
Description:
The Logitech Process Monitor service terminated unexpectedly.  It has done this 1 time(s).

 
Which happened as Kaspersky provided the one message it got out: "common files/logitech/vmvfm/LVProSrv.exe: detected modification of riskware 'Invader'  PID: 1852.
 

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7011
Date:  2/7/2007
Time:  3:13:47 PM
User:  N/A
Computer: D9CZLQB1
Description:
Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.

 

Another Kaspersky hang msg.

 

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date:  2/7/2007
Time:  3:40:16 PM
User:  N/A
Computer: D9CZLQB1
Description:
The Logitech Process Monitor service terminated unexpectedly.  It has done this 1 time(s).

 

Another Kaspersky hang msg.

 

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date:  2/7/2007
Time:  4:08:01 PM
User:  N/A
Computer: D9CZLQB1
Description:


The Application Layer Gateway Service service terminated unexpectedly.  It has done this 1 time(s).

 

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date:  2/7/2007
Time:  4:09:19 PM
User:  N/A
Computer: D9CZLQB1
Description:
The Logitech Process Monitor service terminated unexpectedly.  It has done this 1 time(s).


 

Applications next post....

27 Posts

February 7th, 2007 23:00

Event Type: Error
Event Source: MPSampleSubmission
Event Category: None
Event ID: 5000
Date:  2/2/2007
Time:  3:00:05 AM
User:  N/A
Computer: D9CZLQB1
Description:
EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1592.0, P5 mpsigdwn.dll, P6 1.1.1592.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Data:
0000: 6d 00 70 00 74 00 65 00   m.p.t.e.
0008: 6c 00 65 00 6d 00 65 00   l.e.m.e.
0010: 74 00 72 00 79 00 2c 00   t.r.y.,.
0018: 20 00 38 00 30 00 32 00    .8.0.2.
0020: 34 00 34 00 30 00 32 00   4.4.0.2.
0028: 63 00 2c 00 20 00 65 00   c.,. .e.
0030: 6e 00 64 00 73 00 65 00   n.d.s.e.
0038: 61 00 72 00 63 00 68 00   a.r.c.h.
0040: 2c 00 20 00 73 00 65 00   ,. .s.e.
0048: 61 00 72 00 63 00 68 00   a.r.c.h.
0050: 2c 00 20 00 31 00 2e 00   ,. .1...
0058: 31 00 2e 00 31 00 35 00   1...1.5.
0060: 39 00 32 00 2e 00 30 00   9.2...0.
0068: 2c 00 20 00 6d 00 70 00   ,. .m.p.
0070: 73 00 69 00 67 00 64 00   s.i.g.d.
0078: 77 00 6e 00 2e 00 64 00   w.n...d.
0080: 6c 00 6c 00 2c 00 20 00   l.l.,. .
0088: 31 00 2e 00 31 00 2e 00   1...1...
0090: 31 00 35 00 39 00 32 00   1.5.9.2.
0098: 2e 00 30 00 2c 00 20 00   ..0.,. .
00a0: 77 00 69 00 6e 00 64 00   w.i.n.d.
00a8: 6f 00 77 00 73 00 20 00   o.w.s. .
00b0: 64 00 65 00 66 00 65 00   d.e.f.e.
00b8: 6e 00 64 00 65 00 72 00   n.d.e.r.
00c0: 2c 00 20 00 4e 00 49 00   ,. .N.I.
00c8: 4c 00 2c 00 20 00 4e 00   L.,. .N.
00d0: 49 00 4c 00 20 00 4e 00   I.L. .N.
00d8: 49 00 4c 00 0d 00 0a 00   I.L.....
 
 
Event Type: Error
Event Source: MPSampleSubmission
Event Category: None
Event ID: 5000
Date:  2/3/2007
Time:  3:00:05 AM
same as above
 
 
Event Type: Error
Event Source: STacSV
Event Category: None
Event ID: 65535
Date:  2/4/2007
Time:  3:06:05 AM
User:  NT AUTHORITY\SYSTEM
Computer: D9CZLQB1
Description:
The description for Event ID ( 65535 ) in Source ( STacSV ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. You may be able to use the /AUXSOURCE= flag to retrieve this description; see Help and Support for details. The following information is part of the event: Connection to BassMgrHDA COM interface failed.

 
 
Event ID: 65535
Date:  2/4/2007
Time:  7:52:23 PM
User:  NT AUTHORITY\SYSTEM
etc. - same as above
 
 
Event Type: Error
Event Source: McLogEvent
Event Category: None
Event ID: 5022
Date:  2/4/2007
Time:  11:43:48 PM
User:  NT AUTHORITY\SYSTEM
Computer: D9CZLQB1
Description:
MCSCAN32 Engine Initialisation failed. Engine returned error : The DAT files failed or are missing.
 
 
Event ID: 65535
Date:  2/4/2007
Time:  11:43:53 PM
User:  NT AUTHORITY\SYSTEM
etc. - same as previous
 

Event ID: 65535
Date:  2/5/2007
Time:  12:06:53 AM
User:  NT AUTHORITY\SYSTEM
etc. - same as previous
 
 
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date:  2/5/2007
Time:  9:27:08 PM
User:  N/A
Computer: D9CZLQB1
Description:
Faulting application iexplore.exe, version 7.0.5730.11, faulting module unknown, version 0.0.0.0, fault address 0x0de52102.
 
Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 69 65 78   ure  iex
0018: 70 6c 6f 72 65 2e 65 78   plore.ex
0020: 65 20 37 2e 30 2e 35 37   e 7.0.57
0028: 33 30 2e 31 31 20 69 6e   30.11 in
0030: 20 75 6e 6b 6e 6f 77 6e    unknown
0038: 20 30 2e 30 2e 30 2e 30    0.0.0.0
0040: 20 61 74 20 6f 66 66 73    at offs
0048: 65 74 20 30 64 65 35 32   et 0de52
0050: 31 30 32 0d 0a            102..  
 
 
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1001
Date:  2/5/2007
Time:  9:27:17 PM
User:  N/A
Computer: D9CZLQB1
Description:
Fault bucket 00000009.

Data:
0000: 42 75 63 6b 65 74 3a 20   Bucket:
0008: 30 30 30 30 30 30 30 39   00000009
0010: 0d 0a                     ..     
Event Type: Error
Event Source: MPSampleSubmission
Event Category: None
Event ID: 5000
Date:  2/6/2007
Time:  3:00:06 AM
User:  N/A
Computer: D9CZLQB1
Description:
EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 1.1.1592.0, P5 mpsigdwn.dll, P6 1.1.1592.0, P7 windows defender, P8 NIL, P9 NIL, P10 NIL.

Data:
0000: 6d 00 70 00 74 00 65 00   m.p.t.e.
0008: 6c 00 65 00 6d 00 65 00   l.e.m.e.
0010: 74 00 72 00 79 00 2c 00   t.r.y.,.
0018: 20 00 38 00 30 00 32 00    .8.0.2.
0020: 34 00 34 00 30 00 32 00   4.4.0.2.
0028: 63 00 2c 00 20 00 65 00   c.,. .e.
0030: 6e 00 64 00 73 00 65 00   n.d.s.e.
0038: 61 00 72 00 63 00 68 00   a.r.c.h.
0040: 2c 00 20 00 73 00 65 00   ,. .s.e.
0048: 61 00 72 00 63 00 68 00   a.r.c.h.
0050: 2c 00 20 00 31 00 2e 00   ,. .1...
0058: 31 00 2e 00 31 00 35 00   1...1.5.
0060: 39 00 32 00 2e 00 30 00   9.2...0.
0068: 2c 00 20 00 6d 00 70 00   ,. .m.p.
0070: 73 00 69 00 67 00 64 00   s.i.g.d.
0078: 77 00 6e 00 2e 00 64 00   w.n...d.
0080: 6c 00 6c 00 2c 00 20 00   l.l.,. .
0088: 31 00 2e 00 31 00 2e 00   1...1...
0090: 31 00 35 00 39 00 32 00   1.5.9.2.
0098: 2e 00 30 00 2c 00 20 00   ..0.,. .
00a0: 77 00 69 00 6e 00 64 00   w.i.n.d.
00a8: 6f 00 77 00 73 00 20 00   o.w.s. .
00b0: 64 00 65 00 66 00 65 00   d.e.f.e.
00b8: 6e 00 64 00 65 00 72 00   n.d.e.r.
00c0: 2c 00 20 00 4e 00 49 00   ,. .N.I.
00c8: 4c 00 2c 00 20 00 4e 00   L.,. .N.
00d0: 49 00 4c 00 20 00 4e 00   I.L. .N.
00d8: 49 00 4c 00 0d 00 0a 00   I.L.....
 

Event ID: 65535
Date:  2/6/2007
Time:  9:32:05 AM
User:  NT AUTHORITY\SYSTEM
 
and again Event ID: 65535 - 2/7, 2:30pm
 
 
all of the following happened after installing Kasparsky:
 
Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date:  2/7/2007
Time:  2:41:09 PM
User:  N/A
Computer: D9CZLQB1
Description:
Faulting application wmiprvse.exe, version 5.1.2600.2180, faulting module kernel32.dll, version 5.1.2600.2945, fault address 0x000edf9c.
 
Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 77 6d 69   ure  wmi
0018: 70 72 76 73 65 2e 65 78   prvse.ex
0020: 65 20 35 2e 31 2e 32 36   e 5.1.26
0028: 30 30 2e 32 31 38 30 20   00.2180
0030: 69 6e 20 6b 65 72 6e 65   in kerne
0038: 6c 33 32 2e 64 6c 6c 20   l32.dll
0040: 35 2e 31 2e 32 36 30 30   5.1.2600
0048: 2e 32 39 34 35 20 61 74   .2945 at
0050: 20 6f 66 66 73 65 74 20    offset
0058: 30 30 30 65 64 66 39 63   000edf9c

 
 
Event Type: Error
Event Source: Application Error
Event Category: None
Event ID: 1000
Date:  2/7/2007
Time:  2:44:19 PM
User:  N/A
Computer: D9CZLQB1
Description:
Faulting application mpfalert.exe, version 8.2.115.0, faulting module , version 0.0.0.0, fault address 0x00000000.
 

Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 6d 70 66   ure  mpf
0018: 61 6c 65 72 74 2e 65 78   alert.ex
0020: 65 20 38 2e 32 2e 31 31   e 8.2.11
0028: 35 2e 30 20 69 6e 20 20   5.0 in 
0030: 30 2e 30 2e 30 2e 30 20   0.0.0.0
0038: 61 74 20 6f 66 66 73 65   at offse
0040: 74 20 30 30 30 30 30 30   t 000000
0048: 30 30 0d 0a               00..   
 
 
65535 again
 
 
Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date:  2/7/2007
Time:  3:03:59 PM
User:  N/A
Computer: D9CZLQB1
Description:
Faulting application wmiprvse.exe, version 5.1.2600.2180, faulting module kernel32.dll, version 5.1.2600.2945, fault address 0x000edf9c.
 

Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 77 6d 69   ure  wmi
0018: 70 72 76 73 65 2e 65 78   prvse.ex
0020: 65 20 35 2e 31 2e 32 36   e 5.1.26
0028: 30 30 2e 32 31 38 30 20   00.2180
0030: 69 6e 20 6b 65 72 6e 65   in kerne
0038: 6c 33 32 2e 64 6c 6c 20   l32.dll
0040: 35 2e 31 2e 32 36 30 30   5.1.2600
0048: 2e 32 39 34 35 20 61 74   .2945 at
0050: 20 6f 66 66 73 65 74 20    offset
0058: 30 30 30 65 64 66 39 63   000edf9c
 
 
65535 again
 
 
Event Type: Error
Event Source: Application Hang
Event Category: (101)
Event ID: 1002
Date:  2/7/2007
Time:  3:47:20 PM
User:  N/A
Computer: D9CZLQB1
Description:
Hanging application msiexec.exe, version 3.1.4000.1823, hang module hungapp, version 0.0.0.0, hang address 0x00000000.

Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 48 61 6e 67   ion Hang
0010: 20 20 6d 73 69 65 78 65     msiexe
0018: 63 2e 65 78 65 20 33 2e   c.exe 3.
0020: 31 2e 34 30 30 30 2e 31   1.4000.1
0028: 38 32 33 20 69 6e 20 68   823 in h
0030: 75 6e 67 61 70 70 20 30   ungapp 0
0038: 2e 30 2e 30 2e 30 20 61   .0.0.0 a
0040: 74 20 6f 66 66 73 65 74   t offset
0048: 20 30 30 30 30 30 30 30    0000000
0050: 30                        0      
 
Event Type: Error
Event Source: Application Hang
Event Category: None
Event ID: 1001
Date:  2/7/2007
Time:  3:49:39 PM
User:  N/A
Computer: D9CZLQB1
Description:
Fault bucket 185665579.

Data:
0000: 42 75 63 6b 65 74 3a 20   Bucket:
0008: 31 38 35 36 36 35 35 37   18566557
0010: 39 0d 0a                  9..    
 
 
Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1004
Date:  2/7/2007
Time:  4:04:38 PM
User:  N/A
Computer: D9CZLQB1
Description:
Faulting application wmiprvse.exe, version 5.1.2600.2180, faulting module kernel32.dll, version 5.1.2600.2945, fault address 0x000edf9c.

Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 77 6d 69   ure  wmi
0018: 70 72 76 73 65 2e 65 78   prvse.ex
0020: 65 20 35 2e 31 2e 32 36   e 5.1.26
0028: 30 30 2e 32 31 38 30 20   00.2180
0030: 69 6e 20 6b 65 72 6e 65   in kerne
0038: 6c 33 32 2e 64 6c 6c 20   l32.dll
0040: 35 2e 31 2e 32 36 30 30   5.1.2600
0048: 2e 32 39 34 35 20 61 74   .2945 at
0050: 20 6f 66 66 73 65 74 20    offset
0058: 30 30 30 65 64 66 39 63   000edf9c
   
 
65535 again
 
 
13 errors in 2 minutes related to Kaspersky as everything goes wack - I won't post all of them unless you think necessary
 
 
Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1004
Date:  2/7/2007
Time:  4:19:17 PM
User:  N/A
Computer: D9CZLQB1
Description:
Faulting application alg.exe, version 5.1.2600.2180, faulting module kernel32.dll, version 5.1.2600.2945, fault address 0x000edf9c.
 
Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 61 6c 67   ure  alg
0018: 2e 65 78 65 20 35 2e 31   .exe 5.1
0020: 2e 32 36 30 30 2e 32 31   .2600.21
0028: 38 30 20 69 6e 20 6b 65   80 in ke
0030: 72 6e 65 6c 33 32 2e 64   rnel32.d
0038: 6c 6c 20 35 2e 31 2e 32   ll 5.1.2
0040: 36 30 30 2e 32 39 34 35   600.2945
0048: 20 61 74 20 6f 66 66 73    at offs
0050: 65 74 20 30 30 30 65 64   et 000ed
0058: 66 39 63                  f9c    
 
 
65535 again
 
 
Event Type: Error
Event Source: Application Error
Event Category: (100)
Event ID: 1000
Date:  2/7/2007
Time:  4:22:26 PM
User:  N/A
Computer: D9CZLQB1
Description:
Faulting application svchost.exe, version 5.1.2600.2180, faulting module msi.dll, version 3.1.4000.2435, fault address 0x00012780.
 

Data:
0000: 41 70 70 6c 69 63 61 74   Applicat
0008: 69 6f 6e 20 46 61 69 6c   ion Fail
0010: 75 72 65 20 20 73 76 63   ure  svc
0018: 68 6f 73 74 2e 65 78 65   host.exe
0020: 20 35 2e 31 2e 32 36 30    5.1.260
0028: 30 2e 32 31 38 30 20 69   0.2180 i
0030: 6e 20 6d 73 69 2e 64 6c   n msi.dl
0038: 6c 20 33 2e 31 2e 34 30   l 3.1.40
0040: 30 30 2e 32 34 33 35 20   00.2435
0048: 61 74 20 6f 66 66 73 65   at offse
0050: 74 20 30 30 30 31 32 37   t 000127
0058: 38 30                     80    
 
 
65535 again
 
 
Everything is again working normally, aside from the fact that WINWORD.EXE returns on reboot. 

27 Posts

February 7th, 2007 23:00

Device manager: no issues
 
Only three files have not been digitally signed: acfpdf.txt and acpdf207.dll and acpdfui207.dll.  All are dated 2002, and are under c:\windows\system32\spool\ddrivers\w32x86\2  (edited to correct filenames)
 
Instantaneous response with ns look-up


Message Edited by jmh123 on 02-07-2007 08:57 PM

27 Posts

February 8th, 2007 01:00

Combofix Log, Part 1:
 
"Julia" - 07-02-07 22:26:35    Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Documents and Settings\Julia\My Documents\JULIA'S FILES\CLAY CLAY CLAY"
((((((((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))

C:\WINDOWS\system32\bszip.dll

(((((((((((((((((((((((((((((((   Files Created from 2007-01-07 to 2007-02-07  ))))))))))))))))))))))))))))))))))
 
 
2007-02-07 14:30   d-------- C:\kav
2007-02-07 11:40   d-------- C:\DOCUME~1\Julia\.housecall6.6
2007-02-06 09:19   d-------- C:\DOCUME~1\Julia\Application Data\SiteAdvisor
2007-02-06 09:13   d-------- C:\DOCUME~1\Julia\Application Data\McAfee
2007-02-05 16:02   d-------- C:\Program Files\Hijackthis
2007-02-05 00:00 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2007-02-04 23:58 71,496 --a------ C:\WINDOWS\system32\drivers\mfeavfk.sys
2007-02-04 23:58 37,480 --a------ C:\WINDOWS\system32\drivers\mfesmfk.sys
2007-02-04 23:58 34,184 --a------ C:\WINDOWS\system32\drivers\mfebopk.sys
2007-02-04 23:58 32,008 --a------ C:\WINDOWS\system32\drivers\mferkdk.sys
2007-02-04 23:58 170,408 --a------ C:\WINDOWS\system32\drivers\mfehidk.sys
2007-02-04 23:58 107,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2007-02-04 23:57   d-------- C:\Program Files\Common Files\McAfee
2007-01-28 17:51 74,604 --a------ C:\WINDOWS\system32\drivers\SvStream.sys
2007-01-28 17:51 40,960 --a------ C:\WINDOWS\system32\ComLib.dll
2007-01-28 17:51 106,496 --a------ C:\WINDOWS\system32\cbrowser.dll
2007-01-28 17:49   d-------- C:\DOCUME~1\Julia\WINDOWS
2007-01-16 02:01   d-------- C:\WINDOWS\WBEM
2007-01-16 02:01   d-------- C:\WINDOWS\system32\en-US
2007-01-16 02:00   d--h-c--- C:\WINDOWS\ie7
2007-01-16 01:59 121,856 --------- C:\WINDOWS\system32\xmllite.dll
2007-01-16 01:58   d-------- C:\WINDOWS\network diagnostic
2007-01-12 01:12   d-------- C:\Program Files\Common Files\xing shared
2007-01-12 01:08   d-------- C:\DOCUME~1\Julia\Application Data\Real
2007-01-07 18:36   d-------- C:\Program Files\Freecell Pro

((((((((((((((((((((((((((((((((((((((((((((((((   Find3M Report   )))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-02-07 22:20 -------- d-------- C:\Program Files\getright
2007-02-05 00:06 -------- d-------- C:\Program Files\mcafee.com
2007-02-05 00:06 -------- d-------- C:\Program Files\mcafee
2007-01-28 17:49 -------- d-------- C:\Program Files\arcsoft
2007-01-27 12:16 -------- d-------- C:\Program Files\dc++
2007-01-26 09:56 -------- d-------- C:\Program Files\google
2007-01-24 14:56 2516 --ahs---- C:\WINDOWS\system32\kgygaavl.sys
2007-01-17 02:05 -------- d-------- C:\DOCUME~1\Julia\Application Data\adobeum
2007-01-12 01:12 -------- d-------- C:\Program Files\Common Files\real
2007-01-07 18:27 -------- d-------- C:\Program Files\freecell
2007-01-02 22:15 -------- d-------- C:\DOCUME~1\Julia\Application Data\snapfish
2006-12-29 23:28 -------- d-------- C:\Program Files\videoraipodconverter
2006-12-29 23:28 -------- d-------- C:\Program Files\avisynth 2.5
2006-12-27 19:54 -------- d-------- C:\Program Files\xilisoft
2006-12-22 12:49 -------- d-------- C:\DOCUME~1\Julia\Application Data\arcsoft
2006-12-22 12:16 -------- d-------- C:\DOCUME~1\Julia\Application Data\corel
2006-12-20 14:52 -------- d-------- C:\DOCUME~1\Julia\Application Data\adobe
2006-12-18 19:59 -------- d-------- C:\Program Files\Common Files\adobe
2006-12-13 23:22 -------- d---s---- C:\DOCUME~1\Julia\Application Data\microsoft
2006-12-13 22:33 -------- d--h----- C:\Program Files\installshield installation information
2006-12-13 22:33 -------- d-------- C:\Program Files\Common Files\sonic shared
2006-12-07 01:40 2362184 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-11-20 12:25 18153 --a------ C:\WINDOWS\system32\nvmodes.dat
2006-11-08 00:06 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\system32\ieakui.dll
2006-11-04 00:57 316 --a------ C:\DOCUME~1\Julia\Application Data\wklnhst.dat
 
 
((((((((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SetDefaultMIDI"="MIDIDef.exe"
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"VoiceCenter"="\"C:\\Program Files\\Creative\\VoiceCenter\\AndreaVC.exe\" /tray"
"MBMon"="Rundll32 CTMBHA.DLL,MBMon"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"SigmatelSysTrayApp"="stsystra.exe"
"nwiz"="nwiz.exe /installquiet"
"NVHotkey"="rundll32.exe nvHotkey.dll,Start"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideo[inspector]"="C:\\Program Files\\Logitech\\Video\\InstallHelper.exe /inspect"
"LogitechCameraAssistant"="C:\\Program Files\\Logitech\\Video\\CameraAssistant.exe"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"DLA"="C:\\WINDOWS\\System32\\DLA\\DLACTRLW.EXE"
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy\\Surround Mixer\\CTSysVol.exe /r"
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"OpwareSE2"="\"C:\\Program Files\\ScanSoft\\OmniPageSE2.0\\OpwareSE2.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"CTSVolFE.exe"="\"C:\\Program Files\\Creative\\Mixer\\CTSVolFE.exe\" /r"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"VideoraiPodConverter"="C:\\Program Files\\VideoraiPodConverter\\VideoraConverter.exe -t"
"MSKDetectorExe"="C:\\Program Files\\McAfee\\SpamKiller\\MSKDetct.exe /uninstall"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\"  -osboot"

2 Intern

 • 

5.9K Posts

February 8th, 2007 01:00

I still need for you to run silentrunners and post its log.  Also do combofix:
 
1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Your reply should include
  • a fresh Hijackthis log
    Your log from Combofix
Note: you may have to post the results in more than one reply
 
This log will be even bigger so you will need to make several posts.
 
Going to bed now.  Talk to you tomorrow.

Ron

27 Posts

February 8th, 2007 01:00

Combofix Log, Part 2:
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\QuickBooks Update Agent.lnk"
"backup"="C:\\WINDOWS\\pss\\QuickBooks Update Agent.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Intuit\\QUICKB~1\\QBUpdate\\qbupdate.exe "
"item"="QuickBooks Update Agent"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="apdproxy"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.0\\Apps\\apdproxy.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WLTRAY"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\WLTRAY.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative MediaSource Go]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTCMSGoU"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Creative\\MediaSource5\\Go\\CTCMSGoU.exe\" /SCB"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DMXLauncher"
"hkey"="HKLM"
"command"="C:\\Program Files\\Dell\\Media Experience\\DMXLauncher.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="netWaiting"
"hkey"="HKCU"
"command"="C:\\Program Files\\NetWaiting\\netWaiting.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="QBReminder"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Intuit\\QuickBooks 2005\\Atom\\QBReminder.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RealPlay"
"hkey"="HKLM"
"command"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UpdReg"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\UpdReg.EXE"
"inimapping"="0"
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"DWQueuedReporting"="\"C:\\PROGRA~1\\COMMON~1\\MICROS~1\\DW\\dwtrig20.exe\" -t"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\MCODS
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ    HTTPFilter\0\0
LocalService REG_MULTI_SZ    Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ    DnsCache\0\0
DcomLaunch REG_MULTI_SZ    DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ    RpcSs\0\0
imgsvc REG_MULTI_SZ    StiSvc\0\0
termsvcs REG_MULTI_SZ    TermService\0\0
bthsvcs REG_MULTI_SZ    BthServ\0\0
 
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\McDefragTask.job
C:\WINDOWS\tasks\McQcTask.job
C:\WINDOWS\tasks\MP Scheduled Scan.job

********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-07 22:30:00

27 Posts

February 8th, 2007 01:00

Finally, a fresh Hijack This log:
 
Logfile of HijackThis v1.99.1
Scan saved at 10:36:03 PM, on 2/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\stacsv.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\stsystra.exe
C:\DOCUME~1\Julia\LOCALS~1\Temp\clclean.0001
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\CameraAssistant.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\GetRight\getright.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=1060908
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/root/learnmore/learnmore.asp?close=true&lcode=en-us
N3 - Netscape 7: user_pref("browser.startup.homepage", " http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Julia\Application Data\Mozilla\Profiles\default\bi064ixh.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Julia\Application Data\Mozilla\Profiles\default\bi064ixh.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar5.dll
O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - c:\program files\mcafee\mps\mcpopup.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar5.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe nvHotkey.dll,Start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideo[inspector]] C:\Program Files\Logitech\Video\InstallHelper.exe /inspect
O4 - HKLM\..\Run: [LogitechCameraAssistant] C:\Program Files\Logitech\Video\CameraAssistant.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [VideoraiPodConverter] C:\Program Files\VideoraiPodConverter\VideoraConverter.exe -t
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://home.promosquad.com
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://support.fastaccess.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1161221925796
O16 - DPF: {7E9522CF-6B95-46D6-8E2F-7638F507313F} (BLS_SpeedOP.systemcheck) - http://www.fastaccess.drivers.bellsouth.net/software/DSLspeedtool/bls_speedop.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: MSSQL$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe" -sMICROSOFTSMLBIZ (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SQLAgent$MICROSOFTSMLBIZ - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE" -i MICROSOFTSMLBIZ (file missing)
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\WINDOWS\system32\stacsv.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
 
 
thanks!!

27 Posts

February 8th, 2007 01:00

Silent Runners Log, Part 2:
 
Group Policies {GPedit.msc branch and setting}:
-----------------------------------------------
Note: detected settings may not have any effect.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"NoCDBurning" = (REG_DWORD) hex:0x00000000
{unrecognized setting}
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\
"shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Shutdown: Allow system to be shut down without having to log on}
"undockwithoutlogon" = (REG_DWORD) hex:0x00000001
{Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
Devices: Allow undock without having to log on}

Active Desktop and Wallpaper:
-----------------------------
Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"
Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "C:\Documents and Settings\Julia\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

Enabled Screen Saver:
---------------------
HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "C:\WINDOWS\system32\ssmypics.scr" [MS]

Startup items in "Julia" & "All Users" startup folders:
-------------------------------------------------------
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]
"Digital Line Detect" -> shortcut to: "C:\Program Files\Digital Line Detect\DLG.exe" ["BVRP Software"]
"GetRight - Tray Icon" -> shortcut to: "C:\Program Files\GetRight\getright.exe" ["Headlight Software, Inc."]
"Service Manager" -> shortcut to: "C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe /n" [MS]

Enabled Scheduled Tasks:
------------------------
"McDefragTask" -> launches: "c:\program files\mcafee\mqc\QcConsol.exe "C:\WINDOWS\system32\defrag.exe" C: -f" ["McAfee, Inc."]
"McQcTask" -> launches: "c:\program files\mcafee\mqc\QcConsol.exe 14 0" ["McAfee, Inc."]
"MP Scheduled Scan" -> launches: "C:\Program Files\Windows Defender\MpCmdRun.exe Scan -RestrictPrivileges" [MS]

Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 21
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05

Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
  -> {HKLM...CLSID} = "&Google"
                   \InProcServer32\(Default) = "c:\program files\google\googletoolbar5.dll" ["Google Inc."]
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}"
  -> {HKLM...CLSID} = "&Google"
                   \InProcServer32\(Default) = "c:\program files\google\googletoolbar5.dll" ["Google Inc."]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{327C2873-E90D-4C37-AA9D-10AC9BABA46C}" = "Easy-WebPrint"
  -> {HKLM...CLSID} = "Easy-WebPrint"
                   \InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]
"{2318C2B1-4965-11D4-9B18-009027A5CD4F}" = (no title provided)
  -> {HKLM...CLSID} = "&Google"
                   \InProcServer32\(Default) = "c:\program files\google\googletoolbar5.dll" ["Google Inc."]
Explorer Bars
HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
{FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "Real.com"
                   \InProcServer32\(Default) = "C:\WINDOWS\system32\Shdocvw.dll" [MS]
HKLM\Software\Classes\CLSID\{03C1C47F-0538-4645-8372-D3109B9FC636}\(Default) = "Easy-WebPrint"
Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
InProcServer32\(Default) = "C:\Program Files\Canon\Easy-WebPrint\Toolband.dll" [null data]
 
No Events found!

Top