Unsolved
This post is more than 5 years old
10 Posts
0
4275
February 6th, 2009 13:00
Search redirect virus
First time here. Thanks in advance for the help.
Past several days I have noticed that when I first click on a site from google search results that I am first redirected to another site. Next time I hit link it takes me to correct site. This morning when I did a google search, I got the expected results but the url's for each site had nothing to do what that site. Checked Yahoo and same results.
I ran malwarebytes, adaware and spybot. Two virus's were caught but problem continues after reboot. Since these weren't successful I downloaded hijack this. I know some of these appear to be legitimate but I don't have the background to start deleting without help.
Thanks again.
Below is the log from hijack this.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:06:03 PM, on 2/6/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://companyweb/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program
Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: DeskBandHelper Class - {9E0B5480-4FF0-4FEE-818B-D4DB0F220D64} -
C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program
Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program
Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: PCLaw Web Timer - {0E1230F8-EA50-42A9-983C-D22ABC2EED4B} -
C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common
Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe"
-start
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter
Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office
X3\Programs\QFSCHD130.EXE"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [MFP1815_S2P] C:\PROGRAM FILES\DELL\DELL LASER MFP
1815\PSU\Scan2Pc.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft
Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader
8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [FirefoxUltimateOptimizer] "C:\Misc\firefox-ultimate-optimizer-11\Firefox Ultimate
Optimizer.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location
Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Startup: PHONEslips.lnk = PSLIPS\PSWIN32.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar
Sync\GoogleCalendarSync.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop
Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common
Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Add to Evernote - res://C:\Program Files\Evernote\Evernote3\enbar.dll/2000
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office
X3\Programs\WPLauncher.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program
Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} -
C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra button: (no name) - {91d9cee5-3906-40f7-b51a-9b013b59c826} -
C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O9 - Extra 'Tools' menuitem: PCLaw Web Timer Help - {91d9cee5-3906-40f7-b51a-9b013b59c826} -
C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9d2169e0-0775-4080-9b4e-90fce9945b4a} -
C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O9 - Extra 'Tools' menuitem: PCLaw Web Timer - {9d2169e0-0775-4080-9b4e-90fce9945b4a} -
C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot -
Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration -
{DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program
Files\Evernote\Evernote3\enbar.dll
O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program
Files\Evernote\Evernote3\enbar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O16 - DPF: PLLiveUpWeb - http://support.pclaw.com/PLLiveUpWeb.CAB
O16 - DPF: PLUpdate - http://www.pclaw.com/PLUpdate.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program
Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1193769629649
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1193769595211
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = johnsonbannonpllp.local
O17 - HKLM\Software\..\Telephony: DomainName = johnsonbannonpllp.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BAA49F9-A31B-480D-8BC9-0A64BEB5E969}: NameServer
= 10.177.176.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = johnsonbannonpllp.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = johnsonbannonpllp.local
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program
Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program
Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program
Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir
PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device
Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c95bd8428515f2) (gupdate1c95bd8428515f2) - Google
Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot
Shield\bin\openvpnas.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common
Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common
Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common
Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program
Files\Maxtor\Sync\SyncServices.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common
Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common
Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner -
C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 15209 bytes
0 events found


Bugbatter
4 Apprentice
•
20.5K Posts
0
February 6th, 2009 14:00
Welcome. Thank you for using Dell Community Forums.
I am reviewing your log. In the meantime, you can help me by addressing the following:
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you have disabled System Restore in an attempt to begin cleaning malware, please enable it now. We will flush System Restore when we are finished cleaning and we are sure that everything is running smoothly.
* If you are using any cracked software, please remove it. Definition of cracked software HERE.
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer. The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a list HERE.
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures. Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using. Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.
* During the course of our cleanup please do not do any additional online work or surfing until we have verified that your system is clean.
* We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case. Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
* Please open Notepad > Format> UNcheck Wordwrap. Close Notepad.
* If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.
I look forward to your reply so we can begin cleaning.
Instructions posted for this user are customized for this user only. The tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a log at the top of this board to start a new forum topic.
collegeguy
10 Posts
0
February 6th, 2009 14:00
I have not posted to another forum.
I have done nothing with system restore.
No cracked software.
No P2P.
My computer.
First time using HijackThis.
Wordwrap in Notepad has been unchecked.
Thanks for the help.
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 6th, 2009 15:00
Right click the running icon of Spybot's TeaTimer, and choose Exit SpyBot S&D - Resident'
While both Teatimer and SpyBot are closed:
Download ResetTeaTimer.bat to remove all entries set by TeaTimer (and preventing TeaTimer from restoring them upon reactivation).
http://downloads.subratam.org/ResetTeaTimer.bat
If you are using Firefox, right click the above link and choose ‘Save As’.
Save it to your desktop.
Save it as resetteatimer.bat
Run Spybot-S&D Go to the Mode menu, and make sure "Advanced Mode" is selected On the left hand side, choose Tools -> Resident Uncheck "Resident TeaTimer" and OK any prompts Restart your computer.
Double click on resetteatimer.bat to run it, and wait for it to finish.
Since it will not be needed again, delete ResetTeaTimer.bat after you run it.
When we are COMPLETELY finished with ALL your fixes, you can turn Teatimer back on again via SpyBot's tools resident page.
We need to see some additional information about what is happening in your machine.
1. DDS.txt
2. Attach.txt
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE.
collegeguy
10 Posts
0
February 6th, 2009 17:00
When I opened DDS I didn't get the Yes prompt for optional scan. However, on its own the two files opened in notepad and are copied below. I assume this is alright.
DDS (Ver_09-02-01.01) - NTFSx86
Run by Todd at 19:21:05.93 on Fri 02/06/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.342 [GMT -6:00]
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)
FW: ZoneAlarm Firewall *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Documents and Settings\Todd.JOHNSONBANNONPL\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://companyweb/
mDefault_Page_URL = hxxp://companyweb
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: DeskBandHelper Class: {9e0b5480-4ff0-4fee-818b-d4db0f220d64} - c:\progra~1\lexisn~1\pclaw\plietool.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\4.1.805.4472\swg.dll
BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.4.2\gears.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: PCLaw Web Timer: {0e1230f8-ea50-42a9-983c-d22abc2eed4b} - c:\progra~1\lexisn~1\pclaw\plietool.dll
uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
uRun: [Microsoft Location Finder] "c:\program files\microsoft location finder\LocationFinder.exe"
uRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [avgnt] "c:\program files\antivir personaledition classic\avgnt.exe" /min
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [QuickFinder Scheduler] "c:\program files\wordperfect office x3\programs\QFSCHD130.EXE"
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [MFP1815_S2P] c:\program files\dell\dell laser mfp 1815\psu\Scan2Pc.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\dell\dell laser mfp 1815\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\dell\dell laser mfp 1815\paperport\IndexSearch.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [FirefoxUltimateOptimizer] "c:\misc\firefox-ultimate-optimizer-11\Firefox Ultimate Optimizer.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
StartupFolder: c:\docume~1\todd~1.joh\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe
StartupFolder: c:\docume~1\todd~1.joh\startm~1\programs\startup\phones~1.lnk - \\server\clientapps\pslips\PSWIN32.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
uPolicies-explorer: NoWelcomeScreen = 1 (0x1)
uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1)
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
IE: Add to Evernote - c:\program files\evernote\evernote3\enbar.dll/2000
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\wordperfect office x3\programs\WPLauncher.hta
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.4.2\gears.dll
IE: {91d9cee5-3906-40f7-b51a-9b013b59c826} - {836ece4e-a83a-404a-9433-6b15a66cb0fc} - c:\progra~1\lexisn~1\pclaw\plietool.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {9d2169e0-0775-4080-9b4e-90fce9945b4a} - {2741ca04-5b65-4b10-afc0-4e8387fe6bde} - c:\progra~1\lexisn~1\pclaw\plietool.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {E0B8C461-F8FB-49b4-8373-FE32E9252800} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEE1} - c:\program files\evernote\evernote3\enbar.dll
DPF: PLLiveUpWeb - hxxp://support.pclaw.com/PLLiveUpWeb.CAB
DPF: PLUpdate - hxxp://www.pclaw.com/PLUpdate.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1193769629649
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1193769595211
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
TCP: {6BAA49F9-A31B-480D-8BC9-0A64BEB5E969} = 10.177.176.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 nwprovau
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\todd~1.joh\applic~1\mozilla\firefox\profiles\z9fk82ao.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|http://www.yahoo.com
FF - component: c:\documents and settings\todd.johnsonbannonpl\application data\mozilla\firefox\profiles\z9fk82ao.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - component: c:\program files\evernote\evernote3\fftbclipper\components\enbar3.dll
FF - component: c:\program files\google\google gears\firefox\components\gears.dll
FF - plugin: c:\program files\google\google updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPZoneSB.dll
FF - HiddenExtension: XUL Cache: {E8A7EF07-91D9-4E74-A9ED-85027ECC918C} - c:\documents and settings\todd.johnsonbannonpl\local settings\application data\{E8A7EF07-91D9-4E74-A9ED-85027ECC918C}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-6 64160]
R1 avgio;avgio;c:\program files\antivir personaledition classic\avgio.sys [2007-7-5 11840]
R1 LADriver;LADriver;c:\windows\system32\drivers\LADriver.sys [2007-8-5 27136]
R1 LDDriver;LDDriver;c:\windows\system32\drivers\LDDriver.sys [2007-8-5 24064]
R1 LHDriver;LHDriver;c:\windows\system32\drivers\LHDriver.sys [2007-8-5 14336]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-9-27 353680]
R2 AntiVirScheduler;AntiVir PersonalEdition Classic Scheduler;c:\program files\antivir personaledition classic\sched.exe [2007-7-5 68865]
R2 AntiVirService;AntiVir PersonalEdition Classic Guard;c:\program files\antivir personaledition classic\avguard.exe [2007-7-5 151297]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 950096]
R2 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2008-7-21 193888]
R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
R3 avgntflt;avgntflt;c:\program files\antivir personaledition classic\avgntflt.sys [2007-7-5 52032]
S2 gupdate1c95bd8428515f2;Google Update Service (gupdate1c95bd8428515f2);c:\program files\google\update\GoogleUpdate.exe [2008-12-11 133104]
=============== Created Last 30 ================
2009-02-06 14:48
2009-02-06 12:55 15,688 a------- c:\windows\system32\lsdelete.exe
2009-02-06 12:55 194 a---h--- C:\aaw7boot.cmd
2009-02-06 09:10
2009-02-06 09:10 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-06 09:10 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-06 09:10
2009-02-06 09:10
2009-02-06 09:05 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-02-06 09:01
2009-02-04 11:08
2009-01-29 18:42 1,221,008 a------- c:\windows\system32\zpeng25.dll
2009-01-17 16:34 0 a------- c:\windows\system32\drivers\lvuvc.hs
2009-01-17 16:33 6,364,440 a------- c:\windows\system32\drivers\lvuvc.sys
2009-01-17 16:33 494,104 a------- c:\windows\system32\LVUI2.dll
2009-01-17 16:33 432,664 a------- c:\windows\system32\LVUI2RC.dll
2009-01-17 16:33 416,280 a------- c:\windows\system32\lvcodec2.dll
2009-01-17 16:33 195,096 a------- c:\windows\system32\lvci11901262.dll
2009-01-17 16:33 81,110 a------- c:\windows\system32\lvcoinst.ini
2009-01-17 16:33 768,024 a------- c:\windows\system32\drivers\lvrs.sys
2009-01-17 16:33 114,712 a------- c:\windows\system32\drivers\lvpopflt.sys
2009-01-17 16:33 41,752 a------- c:\windows\system32\drivers\LVUSBSta.sys
2009-01-17 16:33 29,562 a------- c:\windows\system32\Repository.reg
2009-01-17 16:33 0 a------- c:\windows\system32\drivers\logiflt.iad
2009-01-17 16:32 23,832 a------- c:\windows\system32\drivers\lvuvcflt.sys
2009-01-16 11:14 56 a---h--- c:\windows\system32\ezsidmv.dat
2009-01-13 13:39 1,933,312 a------- c:\windows\system32\cdintf250.dll
2009-01-13 13:38
2009-01-13 13:38
2009-01-13 13:38
2009-01-13 13:37 226 a------- c:\windows\QUICKEN.INI
2009-01-11 16:58
==================== Find3M ====================
2009-02-06 07:58 4,286 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-01-29 18:43 4,212 a---h--- c:\windows\system32\zllictbl.dat
2008-12-17 14:53 56,912 a------- c:\documents and settings\todd.johnsonbannonpl\g2mdlhlpx.exe
2008-12-16 21:58 25,624 a------- c:\windows\system32\drivers\LVPr2Mon.sys
2008-12-16 21:50 13,584 a------- c:\windows\system32\drivers\iKeyLgFT.dll
2008-12-16 21:38 227,172 a------- c:\windows\system32\drivers\LVFeL000.cfg
2008-12-16 21:38 146,680 a------- c:\windows\system32\drivers\LVFeL001.cfg
2008-12-16 21:38 85,302 a------- c:\windows\system32\drivers\LVFeL002.cfg
2008-12-16 21:38 69,592 a------- c:\windows\system32\drivers\LVFaL000.cfg
2007-07-11 07:25 88 ---shr-- c:\windows\system32\4456077FEA.sys
============= FINISH: 19:21:42.56 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-02-01.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 7/5/2007 4:10:08 PM
System Uptime: 2/6/2009 7:11:44 PM (0 hours ago)
Motherboard: Dell Inc. | | 0GF470
Processor: Intel(R) Core(TM)2 CPU T7200 @ 2.00GHz | Microprocessor | 1995/133mhz
Processor: Intel(R) Core(TM)2 CPU T7200 @ 2.00GHz | Microprocessor | 1995/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 75 GiB total, 36.756 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP419: 11/9/2008 9:22:16 AM - System Checkpoint
RP420: 11/10/2008 1:04:13 PM - System Checkpoint
RP421: 11/11/2008 5:25:53 PM - System Checkpoint
RP422: 11/13/2008 12:58:37 PM - System Checkpoint
RP423: 11/13/2008 3:22:45 PM - Installed Windows Live installer
RP424: 11/16/2008 10:46:09 AM - System Checkpoint
RP425: 11/17/2008 12:59:39 PM - System Checkpoint
RP426: 11/18/2008 1:05:16 PM - System Checkpoint
RP427: 11/19/2008 1:06:11 PM - System Checkpoint
RP428: 11/20/2008 2:03:41 PM - System Checkpoint
RP429: 11/21/2008 2:35:16 PM - System Checkpoint
RP430: 11/22/2008 9:54:20 PM - Installed Evernote
RP431: 11/24/2008 11:41:45 AM - System Checkpoint
RP432: 11/25/2008 12:27:38 PM - System Checkpoint
RP433: 11/28/2008 8:01:36 PM - System Checkpoint
RP434: 11/29/2008 8:06:21 PM - System Checkpoint
RP435: 11/30/2008 8:34:11 PM - System Checkpoint
RP436: 12/1/2008 9:31:15 PM - System Checkpoint
RP437: 12/3/2008 12:16:17 PM - System Checkpoint
RP438: 12/4/2008 6:03:11 PM - System Checkpoint
RP439: 12/5/2008 10:02:14 PM - System Checkpoint
RP440: 12/7/2008 1:35:16 PM - System Checkpoint
RP441: 12/9/2008 9:01:23 AM - System Checkpoint
RP442: 12/10/2008 9:40:45 AM - System Checkpoint
RP443: 12/11/2008 10:46:38 AM - System Checkpoint
RP444: 12/13/2008 6:38:55 PM - System Checkpoint
RP445: 12/15/2008 12:16:46 PM - System Checkpoint
RP446: 12/16/2008 8:11:34 PM - System Checkpoint
RP447: 12/18/2008 10:55:40 AM - System Checkpoint
RP448: 12/19/2008 12:13:24 PM - System Checkpoint
RP449: 12/20/2008 12:31:01 PM - System Checkpoint
RP450: 12/21/2008 5:43:41 PM - System Checkpoint
RP451: 12/22/2008 7:35:36 PM - System Checkpoint
RP452: 12/23/2008 8:02:56 PM - System Checkpoint
RP453: 12/25/2008 3:31:51 PM - System Checkpoint
RP454: 12/30/2008 10:38:37 AM - System Checkpoint
RP455: 12/31/2008 5:02:12 PM - System Checkpoint
RP456: 1/1/2009 9:01:35 PM - System Checkpoint
RP457: 1/2/2009 9:51:10 PM - System Checkpoint
RP458: 1/4/2009 5:19:44 PM - System Checkpoint
RP459: 1/6/2009 8:41:55 AM - System Checkpoint
RP460: 1/7/2009 12:25:00 PM - System Checkpoint
RP461: 1/7/2009 1:16:58 PM - Configured Evernote
RP462: 1/9/2009 10:37:28 AM - System Checkpoint
RP463: 1/11/2009 10:35:54 AM - System Checkpoint
RP464: 1/12/2009 12:07:47 PM - System Checkpoint
RP465: 1/13/2009 12:21:59 PM - System Checkpoint
RP466: 1/13/2009 1:39:13 PM - Printer Driver Amyuni Document Converter 2.50 Installed
RP467: 1/14/2009 8:11:47 PM - System Checkpoint
RP468: 1/16/2009 1:13:57 PM - System Checkpoint
RP469: 1/17/2009 4:32:35 PM - Logitech QuickCam v11.90.1262
RP470: 1/18/2009 5:44:31 PM - System Checkpoint
RP471: 1/22/2009 11:21:03 AM - System Checkpoint
RP472: 1/24/2009 11:12:08 AM - System Checkpoint
RP473: 1/25/2009 7:16:57 PM - System Checkpoint
RP474: 1/26/2009 8:12:42 PM - System Checkpoint
RP475: 1/27/2009 8:23:07 PM - System Checkpoint
RP476: 1/29/2009 12:55:29 PM - System Checkpoint
RP477: 1/30/2009 7:02:13 PM - System Checkpoint
RP478: 1/31/2009 7:48:57 PM - System Checkpoint
RP479: 2/1/2009 8:53:05 PM - System Checkpoint
RP480: 2/2/2009 9:41:12 PM - System Checkpoint
RP481: 2/4/2009 9:34:52 AM - System Checkpoint
RP482: 2/5/2009 12:17:12 PM - System Checkpoint
RP483: 2/6/2009 12:28:44 PM - System Checkpoint
==== Installed Programs ======================
Ad-Aware
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player Plugin
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
Adobe Shockwave Player
Adobe® Photoshop® Album Starter Edition 3.2
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
AutoUpdate
Avira AntiVir Personal - Free Antivirus
Back Link Analyzer v2.0-cp
Bluetooth Stack for Windows by Toshiba
Bonjour
Broadcom Gigabit Integrated Controller
CCleaner (remove only)
CDDRV_Installer
College Aid Calculator - EMD v14.0
College Aid Calculator - EMD v15.0
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
CutePDF Writer 2.7
Dell Laser MFP 1815 Software Uninstall
Dell ResourceCD
Dell Wireless WLAN Card
DivX Codec
DivX Converter
DivX Player
DivX Web Player
Evernote
Google Calendar Sync
Google Earth
Google Gears
Google Update
Google Updater
GoToMeeting 4.0.0.320
Grammar Expert Plus (Evaluation)
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
HotDocs 2008 Player Edition SR1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB926239)
Hotspot Shield 0.941
Intel(R) Graphics Media Accelerator Driver
iTunes
Java(TM) 6 Update 2
Java(TM) 6 Update 3
JD Secure 3.1
KhalInstallWrapper
KhalSetup
LegalEdge Client
LegalEdge Workstation / 32 Bit
LexisNexis PCLaw
Logitech Desktop Messenger
Logitech QuickCam
Logitech QuickCam Driver Package
Logitech SetPoint
Malwarebytes' Anti-Malware
Maxtor Manager
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Location Finder
Microsoft Office Basic Edition 2003
Microsoft Office FrontPage 2003
Microsoft Office Live Meeting 2005
Microsoft Office Outlook Connector
Microsoft Office Small Business Edition 2003
Microsoft Office Standard Edition 2003
Microsoft Streets & Trips 2006
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Modem Helper
MozBackup 1.4.7
Mozilla ActiveX Control v1.7.12
Mozilla Firefox (3.0.6)
Mozilla Thunderbird (2.0.0.19)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB933579)
OZ776 SCR CardBus Windows Driver
palmOne
Pdf995
PDFCreator
PeaZip 2.2
PocketMirror (Standard Edition) 4.3.0
PowerDVD 5.9
QuickBooks Simple Start 2008
Quicken 2007
QuickTime
Ranking-Manager version 6.0.23
RealPlayer
Remove Hidden Data Tool
Rhapsody Player Engine
ScanSoft PaperPort 10
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944653)
SEO SpyGlass
Shadow Copy Client
SigmaTel Audio
Simple File Shredder 3.2
Skype™ 4.0
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SupportSoft Assisted Service
Telexis Link for the Palm OS
Think Ahead, Inc. 2007-2008 Software
Total Backlink Analyzer 2.0
Uninstall Dell PC Fax
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911164)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update Manager
URGE
VC 9.0 Runtime
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Web CEO 7.5
WebEx
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Live installer
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
WordPerfect - MAIL
WordPerfect Office X3
xat.com JPEG Optimizer
Xenu's Link Sleuth
Yahoo! Toolbar
ZoneAlarm
ZoneAlarm Spy Blocker
==== Event Viewer Messages From Past Week ========
1/30/2009 6:08:51 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
1/30/2009 6:08:27 PM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0018F33DEB39. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
1/30/2009 6:08:24 PM, error: NETLOGON [5719] - No Domain Controller is available for domain JOHNSONBANNONPL due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
1/30/2009 6:08:21 PM, error: Service Control Manager [7000] - The DgiVecp service failed to start due to the following error: The system cannot find the file specified.
1/30/2009 6:08:21 PM, error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
2/2/2009 6:19:16 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
2/2/2009 6:49:16 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
2/3/2009 8:17:05 AM, error: Dhcp [1002] - The IP address lease 192.168.1.134 for the Network Card with network address 0015C5AEE38B has been denied by the DHCP server 192.168.1.24 (The DHCP Server sent a DHCPNACK message).
2/3/2009 8:20:05 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
2/3/2009 8:20:05 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
2/3/2009 8:20:05 AM, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/3/2009 6:24:10 PM, error: Dhcp [1002] - The IP address lease 192.168.1.104 for the Network Card with network address 0015C5AEE38B has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
2/4/2009 8:09:12 AM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 0015C5AEE38B has been denied by the DHCP server 192.168.1.24 (The DHCP Server sent a DHCPNACK message).
==== End Of File ===========================
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 6th, 2009 20:00
Teatimer is still running. Did you run resetteatimer.bat ?
collegeguy
10 Posts
0
February 7th, 2009 08:00
I thought teatimer was closed. I followed the directions again and after rebooting opened spybot and confirmed that teatimer was unchecked. I then ran DDS again. Here are the files.
Thanks
DDS (Ver_09-01-07.01) - NTFSx86
Run by Todd at 9:52:17.21 on Sat 02/07/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.397 [GMT -6:00]
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Updated)
FW: ZoneAlarm Firewall *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
svchost.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Documents and Settings\Todd.JOHNSONBANNONPL\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = hxxp://companyweb/
mDefault_Page_URL = hxxp://companyweb
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: DeskBandHelper Class: {9e0b5480-4ff0-4fee-818b-d4db0f220d64} - c:\progra~1\lexisn~1\pclaw\plietool.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\4.1.805.4472\swg.dll
BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.4.2\gears.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: PCLaw Web Timer: {0e1230f8-ea50-42a9-983c-d22abc2eed4b} - c:\progra~1\lexisn~1\pclaw\plietool.dll
uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
uRun: [Microsoft Location Finder] "c:\program files\microsoft location finder\LocationFinder.exe"
uRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [avgnt] "c:\program files\antivir personaledition classic\avgnt.exe" /min
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [QuickFinder Scheduler] "c:\program files\wordperfect office x3\programs\QFSCHD130.EXE"
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [MFP1815_S2P] c:\program files\dell\dell laser mfp 1815\psu\Scan2Pc.exe
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\dell\dell laser mfp 1815\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\dell\dell laser mfp 1815\paperport\IndexSearch.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [FirefoxUltimateOptimizer] "c:\misc\firefox-ultimate-optimizer-11\Firefox Ultimate Optimizer.exe"
mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [Ad-Watch] c:\program files\lavasoft\ad-aware\AAWTray.exe
StartupFolder: c:\docume~1\todd~1.joh\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe
StartupFolder: c:\docume~1\todd~1.joh\startm~1\programs\startup\phones~1.lnk - \\server\clientapps\pslips\PSWIN32.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palmone\Hotsync.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LogitechDesktopMessenger.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
uPolicies-explorer: NoWelcomeScreen = 1 (0x1)
uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1)
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
IE: Add to Evernote - c:\program files\evernote\evernote3\enbar.dll/2000
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\wordperfect office x3\programs\WPLauncher.hta
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.4.2\gears.dll
IE: {91d9cee5-3906-40f7-b51a-9b013b59c826} - {836ece4e-a83a-404a-9433-6b15a66cb0fc} - c:\progra~1\lexisn~1\pclaw\plietool.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
IE: {9d2169e0-0775-4080-9b4e-90fce9945b4a} - {2741ca04-5b65-4b10-afc0-4e8387fe6bde} - c:\progra~1\lexisn~1\pclaw\plietool.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
IE: {E0B8C461-F8FB-49b4-8373-FE32E9252800} - {BC0E0A5D-AB5A-4fa4-A5FA-280E1D58EEE1} - c:\program files\evernote\evernote3\enbar.dll
TCP: {6BAA49F9-A31B-480D-8BC9-0A64BEB5E969} = 10.177.176.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 nwprovau
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\todd~1.joh\applic~1\mozilla\firefox\profiles\z9fk82ao.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|http://www.yahoo.com
FF - component: c:\documents and settings\todd.johnsonbannonpl\application data\mozilla\firefox\profiles\z9fk82ao.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - component: c:\program files\evernote\evernote3\fftbclipper\components\enbar3.dll
FF - component: c:\program files\google\google gears\firefox\components\gears.dll
FF - plugin: c:\program files\google\google updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPZoneSB.dll
FF - HiddenExtension: XUL Cache: {E8A7EF07-91D9-4E74-A9ED-85027ECC918C} - c:\documents and settings\todd.johnsonbannonpl\local settings\application data\{E8A7EF07-91D9-4E74-A9ED-85027ECC918C}
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-6 64160]
R1 avgio;avgio;c:\program files\antivir personaledition classic\avgio.sys [2007-7-5 11840]
R1 LADriver;LADriver;c:\windows\system32\drivers\LADriver.sys [2007-8-5 27136]
R1 LDDriver;LDDriver;c:\windows\system32\drivers\LDDriver.sys [2007-8-5 24064]
R1 LHDriver;LHDriver;c:\windows\system32\drivers\LHDriver.sys [2007-8-5 14336]
R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-9-27 353680]
R3 avgntflt;avgntflt;c:\program files\antivir personaledition classic\avgntflt.sys [2007-7-5 52032]
R4 AntiVirScheduler;AntiVir PersonalEdition Classic Scheduler;c:\program files\antivir personaledition classic\sched.exe [2007-7-5 68865]
R4 AntiVirService;AntiVir PersonalEdition Classic Guard;c:\program files\antivir personaledition classic\avguard.exe [2007-7-5 151297]
R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 950096]
R4 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2008-7-21 193888]
R4 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service --> c:\windows\system32\zonelabs\vsmon.exe -service [?]
S4 gupdate1c95bd8428515f2;Google Update Service (gupdate1c95bd8428515f2);c:\program files\google\update\GoogleUpdate.exe [2008-12-11 133104]
=============== Created Last 30 ================
2009-02-06 14:48
2009-02-06 12:55 15,688 a------- c:\windows\system32\lsdelete.exe
2009-02-06 12:55 194 a---h--- C:\aaw7boot.cmd
2009-02-06 09:10
2009-02-06 09:10 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-06 09:10 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-06 09:10
2009-02-06 09:10
2009-02-06 09:05 64,160 a------- c:\windows\system32\drivers\Lbd.sys
2009-02-06 09:01
2009-02-04 11:08
2009-01-29 18:42 1,221,008 a------- c:\windows\system32\zpeng25.dll
2009-01-17 16:34 0 a------- c:\windows\system32\drivers\lvuvc.hs
2009-01-17 16:33 6,364,440 a------- c:\windows\system32\drivers\lvuvc.sys
2009-01-17 16:33 494,104 a------- c:\windows\system32\LVUI2.dll
2009-01-17 16:33 432,664 a------- c:\windows\system32\LVUI2RC.dll
2009-01-17 16:33 416,280 a------- c:\windows\system32\lvcodec2.dll
2009-01-17 16:33 195,096 a------- c:\windows\system32\lvci11901262.dll
2009-01-17 16:33 81,110 a------- c:\windows\system32\lvcoinst.ini
2009-01-17 16:33 768,024 a------- c:\windows\system32\drivers\lvrs.sys
2009-01-17 16:33 114,712 a------- c:\windows\system32\drivers\lvpopflt.sys
2009-01-17 16:33 41,752 a------- c:\windows\system32\drivers\LVUSBSta.sys
2009-01-17 16:33 29,562 a------- c:\windows\system32\Repository.reg
2009-01-17 16:33 0 a------- c:\windows\system32\drivers\logiflt.iad
2009-01-17 16:32 23,832 a------- c:\windows\system32\drivers\lvuvcflt.sys
2009-01-16 11:14 56 a---h--- c:\windows\system32\ezsidmv.dat
2009-01-13 13:39 1,933,312 a------- c:\windows\system32\cdintf250.dll
2009-01-13 13:38
2009-01-13 13:38
2009-01-13 13:38
2009-01-13 13:37 226 a------- c:\windows\QUICKEN.INI
2009-01-11 16:58
==================== Find3M ====================
2009-02-06 07:58 4,286 a--sh--- c:\windows\system32\KGyGaAvL.sys
2009-01-29 18:43 4,212 a---h--- c:\windows\system32\zllictbl.dat
2008-12-17 14:53 56,912 a------- c:\documents and settings\todd.johnsonbannonpl\g2mdlhlpx.exe
2008-12-16 21:58 25,624 a------- c:\windows\system32\drivers\LVPr2Mon.sys
2008-12-16 21:50 13,584 a------- c:\windows\system32\drivers\iKeyLgFT.dll
2008-12-16 21:38 227,172 a------- c:\windows\system32\drivers\LVFeL000.cfg
2008-12-16 21:38 146,680 a------- c:\windows\system32\drivers\LVFeL001.cfg
2008-12-16 21:38 85,302 a------- c:\windows\system32\drivers\LVFeL002.cfg
2008-12-16 21:38 69,592 a------- c:\windows\system32\drivers\LVFaL000.cfg
2007-07-11 07:25 88 ---shr-- c:\windows\system32\4456077FEA.sys
============= FINISH: 9:52:55.56 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-01-07.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 7/5/2007 4:10:08 PM
System Uptime: 2/7/2009 9:43:13 AM (0 hours ago)
Motherboard: Dell Inc. | | 0GF470
Processor: Intel(R) Core(TM)2 CPU T7200 @ 2.00GHz | Microprocessor | 1994/133mhz
Processor: Intel(R) Core(TM)2 CPU T7200 @ 2.00GHz | Microprocessor | 1994/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 75 GiB total, 36.79 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP419: 11/9/2008 9:22:16 AM - System Checkpoint
RP420: 11/10/2008 1:04:13 PM - System Checkpoint
RP421: 11/11/2008 5:25:53 PM - System Checkpoint
RP422: 11/13/2008 12:58:37 PM - System Checkpoint
RP423: 11/13/2008 3:22:45 PM - Installed Windows Live installer
RP424: 11/16/2008 10:46:09 AM - System Checkpoint
RP425: 11/17/2008 12:59:39 PM - System Checkpoint
RP426: 11/18/2008 1:05:16 PM - System Checkpoint
RP427: 11/19/2008 1:06:11 PM - System Checkpoint
RP428: 11/20/2008 2:03:41 PM - System Checkpoint
RP429: 11/21/2008 2:35:16 PM - System Checkpoint
RP430: 11/22/2008 9:54:20 PM - Installed Evernote
RP431: 11/24/2008 11:41:45 AM - System Checkpoint
RP432: 11/25/2008 12:27:38 PM - System Checkpoint
RP433: 11/28/2008 8:01:36 PM - System Checkpoint
RP434: 11/29/2008 8:06:21 PM - System Checkpoint
RP435: 11/30/2008 8:34:11 PM - System Checkpoint
RP436: 12/1/2008 9:31:15 PM - System Checkpoint
RP437: 12/3/2008 12:16:17 PM - System Checkpoint
RP438: 12/4/2008 6:03:11 PM - System Checkpoint
RP439: 12/5/2008 10:02:14 PM - System Checkpoint
RP440: 12/7/2008 1:35:16 PM - System Checkpoint
RP441: 12/9/2008 9:01:23 AM - System Checkpoint
RP442: 12/10/2008 9:40:45 AM - System Checkpoint
RP443: 12/11/2008 10:46:38 AM - System Checkpoint
RP444: 12/13/2008 6:38:55 PM - System Checkpoint
RP445: 12/15/2008 12:16:46 PM - System Checkpoint
RP446: 12/16/2008 8:11:34 PM - System Checkpoint
RP447: 12/18/2008 10:55:40 AM - System Checkpoint
RP448: 12/19/2008 12:13:24 PM - System Checkpoint
RP449: 12/20/2008 12:31:01 PM - System Checkpoint
RP450: 12/21/2008 5:43:41 PM - System Checkpoint
RP451: 12/22/2008 7:35:36 PM - System Checkpoint
RP452: 12/23/2008 8:02:56 PM - System Checkpoint
RP453: 12/25/2008 3:31:51 PM - System Checkpoint
RP454: 12/30/2008 10:38:37 AM - System Checkpoint
RP455: 12/31/2008 5:02:12 PM - System Checkpoint
RP456: 1/1/2009 9:01:35 PM - System Checkpoint
RP457: 1/2/2009 9:51:10 PM - System Checkpoint
RP458: 1/4/2009 5:19:44 PM - System Checkpoint
RP459: 1/6/2009 8:41:55 AM - System Checkpoint
RP460: 1/7/2009 12:25:00 PM - System Checkpoint
RP461: 1/7/2009 1:16:58 PM - Configured Evernote
RP462: 1/9/2009 10:37:28 AM - System Checkpoint
RP463: 1/11/2009 10:35:54 AM - System Checkpoint
RP464: 1/12/2009 12:07:47 PM - System Checkpoint
RP465: 1/13/2009 12:21:59 PM - System Checkpoint
RP466: 1/13/2009 1:39:13 PM - Printer Driver Amyuni Document Converter 2.50 Installed
RP467: 1/14/2009 8:11:47 PM - System Checkpoint
RP468: 1/16/2009 1:13:57 PM - System Checkpoint
RP469: 1/17/2009 4:32:35 PM - Logitech QuickCam v11.90.1262
RP470: 1/18/2009 5:44:31 PM - System Checkpoint
RP471: 1/22/2009 11:21:03 AM - System Checkpoint
RP472: 1/24/2009 11:12:08 AM - System Checkpoint
RP473: 1/25/2009 7:16:57 PM - System Checkpoint
RP474: 1/26/2009 8:12:42 PM - System Checkpoint
RP475: 1/27/2009 8:23:07 PM - System Checkpoint
RP476: 1/29/2009 12:55:29 PM - System Checkpoint
RP477: 1/30/2009 7:02:13 PM - System Checkpoint
RP478: 1/31/2009 7:48:57 PM - System Checkpoint
RP479: 2/1/2009 8:53:05 PM - System Checkpoint
RP480: 2/2/2009 9:41:12 PM - System Checkpoint
RP481: 2/4/2009 9:34:52 AM - System Checkpoint
RP482: 2/5/2009 12:17:12 PM - System Checkpoint
RP483: 2/6/2009 12:28:44 PM - System Checkpoint
==== Installed Programs ======================
Ad-Aware
Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
Adobe Flash Player Plugin
Adobe Reader 8.1.2
Adobe Reader 8.1.2 Security Update 1 (KB403742)
Adobe Shockwave Player
Adobe® Photoshop® Album Starter Edition 3.2
ALPS Touch Pad Driver
Apple Mobile Device Support
Apple Software Update
AutoUpdate
Avira AntiVir Personal - Free Antivirus
Back Link Analyzer v2.0-cp
Bluetooth Stack for Windows by Toshiba
Bonjour
Broadcom Gigabit Integrated Controller
CCleaner (remove only)
CDDRV_Installer
College Aid Calculator - EMD v14.0
College Aid Calculator - EMD v15.0
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
CutePDF Writer 2.7
Dell Laser MFP 1815 Software Uninstall
Dell ResourceCD
Dell Wireless WLAN Card
DivX Codec
DivX Converter
DivX Player
DivX Web Player
Evernote
Google Calendar Sync
Google Earth
Google Gears
Google Update
Google Updater
GoToMeeting 4.0.0.320
Grammar Expert Plus (Evaluation)
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
HotDocs 2008 Player Edition SR1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB926239)
Hotspot Shield 0.941
Intel(R) Graphics Media Accelerator Driver
iTunes
Java(TM) 6 Update 2
Java(TM) 6 Update 3
JD Secure 3.1
KhalInstallWrapper
KhalSetup
LegalEdge Client
LegalEdge Workstation / 32 Bit
LexisNexis PCLaw
Logitech Desktop Messenger
Logitech QuickCam
Logitech QuickCam Driver Package
Logitech SetPoint
Malwarebytes' Anti-Malware
Maxtor Manager
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Location Finder
Microsoft Office Basic Edition 2003
Microsoft Office FrontPage 2003
Microsoft Office Live Meeting 2005
Microsoft Office Outlook Connector
Microsoft Office Small Business Edition 2003
Microsoft Office Standard Edition 2003
Microsoft Streets & Trips 2006
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Modem Helper
MozBackup 1.4.7
Mozilla ActiveX Control v1.7.12
Mozilla Firefox (3.0.6)
Mozilla Thunderbird (2.0.0.19)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 Parser and SDK
MSXML 6.0 Parser (KB933579)
OZ776 SCR CardBus Windows Driver
palmOne
Pdf995
PDFCreator
PeaZip 2.2
PocketMirror (Standard Edition) 4.3.0
PowerDVD 5.9
QuickBooks Simple Start 2008
Quicken 2007
QuickTime
Ranking-Manager version 6.0.23
RealPlayer
Remove Hidden Data Tool
Rhapsody Player Engine
ScanSoft PaperPort 10
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944653)
SEO SpyGlass
Shadow Copy Client
SigmaTel Audio
Simple File Shredder 3.2
Skype™ 4.0
Spelling Dictionaries Support For Adobe Reader 8
Spybot - Search & Destroy
Spybot - Search & Destroy 1.5.2.20
SupportSoft Assisted Service
Telexis Link for the Palm OS
Think Ahead, Inc. 2007-2008 Software
Total Backlink Analyzer 2.0
Uninstall Dell PC Fax
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911164)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update Manager
URGE
VC 9.0 Runtime
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Web CEO 7.5
WebEx
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Live installer
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
WordPerfect - MAIL
WordPerfect Office X3
xat.com JPEG Optimizer
Xenu's Link Sleuth
Yahoo! Toolbar
ZoneAlarm
ZoneAlarm Spy Blocker
==== Event Viewer Messages From Past Week ========
2/3/2009 6:25:12 PM, error: NETLOGON [5719] - No Domain Controller is available for domain JOHNSONBANNONPL due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
2/3/2009 6:24:49 PM, error: Service Control Manager [7000] - The DgiVecp service failed to start due to the following error: The system cannot find the file specified.
2/3/2009 6:24:49 PM, error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
2/3/2009 6:24:10 PM, error: Dhcp [1002] - The IP address lease 192.168.1.104 for the Network Card with network address 0015C5AEE38B has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
2/3/2009 8:20:05 AM, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/3/2009 8:20:05 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
2/3/2009 8:20:05 AM, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
2/3/2009 8:17:05 AM, error: Dhcp [1002] - The IP address lease 192.168.1.134 for the Network Card with network address 0015C5AEE38B has been denied by the DHCP server 192.168.1.24 (The DHCP Server sent a DHCPNACK message).
2/2/2009 6:49:16 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
2/2/2009 6:19:16 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
2/2/2009 6:04:15 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
2/1/2009 9:12:25 PM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0018F33DEB39. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
2/4/2009 8:09:12 AM, error: Dhcp [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 0015C5AEE38B has been denied by the DHCP server 192.168.1.24 (The DHCP Server sent a DHCPNACK message).
==== End Of File ===========================
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 7th, 2009 09:00
Please visit this webpage for download links, and instructions for running ComboFix:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
IMPORTANT! * Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log for further review.
* Additional information on A/V control HERE
collegeguy
10 Posts
0
February 7th, 2009 10:00
Here is the combofix log file followed by the latest hijackthis scan.
Thanks.
ComboFix 09-02-06.04 - Todd 2009-02-07 12:12:40.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1014.505 [GMT -6:00]
Running from: c:\documents and settings\Todd.JOHNSONBANNONPL\Desktop\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
FW: ZoneAlarm Firewall *disabled*
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\wdmaud.sys
----- BITS: Possible infected sites -----
hxxp://server:8530
.
((((((((((((((((((((((((( Files Created from 2009-01-07 to 2009-02-07 )))))))))))))))))))))))))))))))
.
2009-02-06 14:48 . 2009-02-06 14:48
2009-02-06 12:55 . 2009-02-06 09:05 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-06 12:55 . 2009-02-06 12:55 194 --ah----- C:\aaw7boot.cmd
2009-02-06 09:10 . 2009-02-06 09:10
2009-02-06 09:10 . 2009-02-06 09:10
2009-02-06 09:10 . 2009-02-06 09:10
2009-02-06 09:10 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-06 09:10 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-06 09:05 . 2009-02-06 09:05 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-06 09:01 . 2009-02-06 09:01
2009-02-04 11:08 . 2009-02-04 11:08
2009-02-04 11:08 . 2009-02-04 11:08
2009-01-29 18:42 . 2008-11-13 15:18 1,221,008 --a------ c:\windows\system32\zpeng25.dll
2009-01-17 16:34 . 2009-01-17 16:34 0 --a------ c:\windows\system32\drivers\lvuvc.hs
2009-01-17 16:33 . 2008-12-17 00:01 6,364,440 --a------ c:\windows\system32\drivers\lvuvc.sys
2009-01-17 16:33 . 2008-12-17 00:00 768,024 --a------ c:\windows\system32\drivers\lvrs.sys
2009-01-17 16:33 . 2008-12-17 00:00 494,104 --a------ c:\windows\system32\LVUI2.dll
2009-01-17 16:33 . 2008-12-17 00:01 432,664 --a------ c:\windows\system32\LVUI2RC.dll
2009-01-17 16:33 . 2008-12-16 23:55 416,280 --a------ c:\windows\system32\lvcodec2.dll
2009-01-17 16:33 . 2008-12-16 23:55 195,096 --a------ c:\windows\system32\lvci11901262.dll
2009-01-17 16:33 . 2008-12-16 23:58 114,712 --a------ c:\windows\system32\drivers\lvpopflt.sys
2009-01-17 16:33 . 2008-12-16 23:37 81,110 --a------ c:\windows\system32\lvcoinst.ini
2009-01-17 16:33 . 2008-12-17 00:01 41,752 --a------ c:\windows\system32\drivers\LVUSBSta.sys
2009-01-17 16:33 . 2008-12-16 23:37 29,562 --a------ c:\windows\system32\Repository.reg
2009-01-17 16:33 . 2009-01-17 16:33 0 --a------ c:\windows\system32\drivers\logiflt.iad
2009-01-17 16:32 . 2008-12-17 00:02 23,832 --a------ c:\windows\system32\drivers\lvuvcflt.sys
2009-01-16 11:14 . 2009-02-07 09:34
2009-01-16 11:14 . 2009-01-16 11:14 56 --ah----- c:\windows\system32\ezsidmv.dat
2009-01-16 11:08 . 2009-02-07 11:49
2009-01-16 11:07 . 2009-02-04 11:08
2009-01-13 13:39 . 2006-04-12 10:11 1,933,312 --a------ c:\windows\system32\cdintf250.dll
2009-01-13 13:38 . 2009-01-13 13:44
2009-01-13 13:38 . 2009-01-13 13:38
2009-01-13 13:38 . 2009-01-13 13:38
2009-01-13 13:37 . 2009-01-13 13:45 226 --a------ c:\windows\QUICKEN.INI
2009-01-11 16:58 . 2009-01-11 16:58
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-07 18:05 --------- d-----w c:\program files\Mozilla Thunderbird
2009-02-07 15:25 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-02-06 20:11 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-06 18:57 --------- d-----w c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition Classic
2009-02-06 15:01 --------- d-----w c:\program files\Lavasoft
2009-02-04 00:24 19,481,038 ----a-w c:\windows\Internet Logs\tvDebug.zip
2009-01-31 00:01 35,840 ----a-w c:\windows\Internet Logs\xDB1D.tmp
2009-01-30 23:57 108,348 ----a-w c:\windows\Internet Logs\vsmon_2nd_2009_01_30_17_56_16_small.dmp.zip
2009-01-30 23:56 2,711,552 ----a-w c:\windows\Internet Logs\xDB1C.tmp
2009-01-24 01:24 3,317,248 ----a-w c:\windows\Internet Logs\xDB1B.tmp
2009-01-17 22:51 --------- d-----w c:\documents and settings\Todd.JOHNSONBANNONPL\Application Data\Logitech
2009-01-17 22:34 --------- d-----w c:\program files\Common Files\Logishrd
2009-01-17 22:32 --------- d-----w c:\program files\Logitech
2009-01-17 22:32 --------- d-----w c:\documents and settings\All Users\Application Data\LogiShrd
2009-01-13 19:37 --------- d-----w c:\documents and settings\All Users\Application Data\Intuit
2009-01-12 04:00 3,260,928 ----a-w c:\windows\Internet Logs\xDB1A.tmp
2009-01-04 01:12 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-01 00:16 --------- d-----w c:\program files\CCleaner
2008-12-28 22:09 --------- d-----w c:\program files\SEOSpyGlass
2008-12-17 20:53 56,912 ----a-w c:\documents and settings\Todd.JOHNSONBANNONPL\g2mdlhlpx.exe
2008-12-17 03:58 25,624 ----a-w c:\windows\system32\drivers\LVPr2Mon.sys
2008-12-17 03:50 13,584 ----a-w c:\windows\system32\drivers\iKeyLgFT.dll
2008-12-17 03:38 85,302 ----a-w c:\windows\system32\drivers\LVFeL002.cfg
2008-12-17 03:38 69,592 ----a-w c:\windows\system32\drivers\LVFaL000.cfg
2008-12-17 03:38 227,172 ----a-w c:\windows\system32\drivers\LVFeL000.cfg
2008-12-17 03:38 146,680 ----a-w c:\windows\system32\drivers\LVFeL001.cfg
2008-12-11 21:34 --------- d-----w c:\program files\Google
2008-11-07 04:38 3,071,488 ----a-w c:\windows\Internet Logs\xDB19.tmp
2008-02-05 20:51 44,360 ----a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2008-02-05 20:51 107,928 ----a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
2007-07-11 13:25 88 --sh--r c:\windows\system32\4456077FEA.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-10-30 67128]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-01-29 23975720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-12-13 98304]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-12-13 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-12-13 118784]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2005-10-07 176128]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"avgnt"="c:\program files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-21 266497]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"QuickFinder Scheduler"="c:\program files\WordPerfect Office X3\Programs\QFSCHD130.EXE" [2007-01-02 83568]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2006-04-06 49152]
"MFP1815_S2P"="c:\program files\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe" [2006-04-12 258048]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe" [2006-02-20 36864]
"IndexSearch"="c:\program files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe" [2006-02-20 40960]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-02-14 185896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-07-21 169312]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-12-20 2656528]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 981904]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-06 509784]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2006-02-28 c:\windows\system32\bthprops.cpl]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
c:\documents and settings\Todd.JOHNSONBANNONPL\Start Menu\Programs\Startup\
palmOne Registration.lnk - c:\program files\palmOne\register.exe [2005-01-28 2301952]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 1724416]
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-02 546288]
HotSync Manager.lnk - c:\program files\palmOne\Hotsync.exe [2004-06-09 471040]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-10-30 67128]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-08-06 805392]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2008-02-27 972064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)
"ForceStartMenuLogOff"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"= wdmaud.sys
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-06 64160]
R1 LADriver;LADriver;c:\windows\system32\drivers\LADriver.sys [2007-08-05 27136]
R1 LDDriver;LDDriver;c:\windows\system32\drivers\LDDriver.sys [2007-08-05 24064]
R1 LHDriver;LHDriver;c:\windows\system32\drivers\LHDriver.sys [2007-08-05 14336]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S2 gupdate1c95bd8428515f2;Google Update Service (gupdate1c95bd8428515f2);c:\program files\Google\Update\GoogleUpdate.exe [2008-12-11 133104]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0f52cb81-8167-11dc-90f6-0016419087c3}]
\Shell\AutoRun\command - .\Encryption Tool\MaxtorEncryption.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d6a731d5-16b4-11dd-a995-0016419087c3}]
\Shell\AutoRun\command - e:\jdsecure\Windows\JDSecure31.exe
.
Contents of the 'Scheduled Tasks' folder
2009-02-06 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-06 09:05]
2009-02-07 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-12-11 15:34]
2009-01-15 c:\windows\Tasks\Rescue Reminder for 2HAA0HK8.job
- c:\program files\Maxtor\ManagerApp\MaxUtilities.exe [2008-07-21 15:52]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-FirefoxUltimateOptimizer - c:\misc\firefox-ultimate-optimizer-11\Firefox Ultimate Optimizer.exe
.
------- Supplementary Scan -------
.
uStart Page = hxxp://companyweb/
uInternet Settings,ProxyOverride = *.local
IE: Add to Evernote - c:\program files\Evernote\Evernote3\enbar.dll/2000
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
IE: { {91d9cee5-3906-40f7-b51a-9b013b59c826} - {836ece4e-a83a-404a-9433-6b15a66cb0fc} - c:\progra~1\LEXISN~1\PCLaw\plietool.dll
IE: { {9d2169e0-0775-4080-9b4e-90fce9945b4a} - {2741ca04-5b65-4b10-afc0-4e8387fe6bde} - c:\progra~1\LEXISN~1\PCLaw\plietool.dll
TCP: {6BAA49F9-A31B-480D-8BC9-0A64BEB5E969} = 10.177.176.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: PLLiveUpWeb - hxxp://support.pclaw.com/PLLiveUpWeb.CAB
DPF: PLUpdate - hxxp://www.pclaw.com/PLUpdate.cab
FF - ProfilePath - c:\documents and settings\Todd.JOHNSONBANNONPL\Application Data\Mozilla\Firefox\Profiles\z9fk82ao.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/| http://www.yahoo.com
FF - component: c:\documents and settings\Todd.JOHNSONBANNONPL\Application Data\Mozilla\Firefox\Profiles\z9fk82ao.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\Evernote\Evernote3\FfTbClipper\components\enbar3.dll
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPZoneSB.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-07 12:20:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1364)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
c:\windows\system32\msv1_0.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\windows\system32\scardsvr.exe
c:\program files\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Hotspot Shield\bin\openvpnas.exe
c:\program files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
c:\windows\system32\LxrJD31s.exe
c:\program files\Maxtor\Sync\SyncServices.exe
c:\windows\system32\PSIService.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Apoint\hidfind.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-02-07 12:25:21 - machine was rebooted
ComboFix-quarantined-files.txt 2009-02-07 18:25:17
Pre-Run: 39,429,726,208 bytes free
Post-Run: 39,543,590,912 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
283 --- E O F --- 2007-08-29 22:01:56
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:31, on 2009-02-07
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Hotspot Shield\bin\openvpnas.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://companyweb/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: DeskBandHelper Class - {9E0B5480-4FF0-4FEE-818B-D4DB0F220D64} - C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: PCLaw Web Timer - {0E1230F8-EA50-42A9-983C-D22ABC2EED4B} - C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [MFP1815_S2P] C:\PROGRAM FILES\DELL\DELL LASER MFP 1815\PSU\Scan2Pc.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\DELL\Dell Laser MFP 1815\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Startup: PHONEslips.lnk = PSLIPS\PSWIN32.EXE
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Google Calendar Sync.lnk = C:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Add to Evernote - res://C:\Program Files\Evernote\Evernote3\enbar.dll/2000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with WordPerfect - C:\Program Files\WordPerfect Office X3\Programs\WPLauncher.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra button: (no name) - {91d9cee5-3906-40f7-b51a-9b013b59c826} - C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O9 - Extra 'Tools' menuitem: PCLaw Web Timer Help - {91d9cee5-3906-40f7-b51a-9b013b59c826} - C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {9d2169e0-0775-4080-9b4e-90fce9945b4a} - C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O9 - Extra 'Tools' menuitem: PCLaw Web Timer - {9d2169e0-0775-4080-9b4e-90fce9945b4a} - C:\PROGRA~1\LEXISN~1\PCLaw\plietool.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
O9 - Extra 'Tools' menuitem: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E9252800} - C:\Program Files\Evernote\Evernote3\enbar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O16 - DPF: PLLiveUpWeb - http://support.pclaw.com/PLLiveUpWeb.CAB
O16 - DPF: PLUpdate - http://www.pclaw.com/PLUpdate.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1193769629649
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1193769595211
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = johnsonbannonpllp.local
O17 - HKLM\Software\..\Telephony: DomainName = johnsonbannonpllp.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{6BAA49F9-A31B-480D-8BC9-0A64BEB5E969}: NameServer = 10.177.176.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = johnsonbannonpllp.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = johnsonbannonpllp.local
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: intu-help-qb1 - {9B0F96C7-2E4B-433E-ABF3-043BA1B54AE3} - C:\Program Files\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll
O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate1c95bd8428515f2) (gupdate1c95bd8428515f2) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Hotspot Shield Service (HotspotShieldService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
--
End of file - 15021 bytes
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 7th, 2009 11:00
Set Explorer to view Hidden Files and Folders:
Please submit a sample of these files (one at a time):
C:\WINDOWS\System32\ezsidmv.dat
c:\windows\system32\cdintf250.dll
to Virus Total --
http://www.virustotal.com/en/indexf.html
At the top of the page you will see:
Select file>Browse>Send
Just follow the prompts.
The submission will then be tested against many different AV vendors� scanners.
That will give you an idea what it is and who recognizes it. In addition, unless told
otherwise, Virus Total will provide the sample to all participating vendors.
When you get the report, please post back the exact results.
Also, please go back and rehide protected system files:
Go to Start>Search and at the top select Tools>Folder Options
Select the View tab
Display the contents of system folders
Show hidden files and folders
Check: Hide protected operating system files
Click on Apply.
We will have some more work to do, but I will wait for the report from Virus Total before we proceed.
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 7th, 2009 12:00
That's good. In that case, we have just a leftover we have to restore to its default settings...
Please run Notepad and paste the text between the lines into a new file. Do not copy the dotted lines.
* Make sure that Word Wrap is turned off in Notepad - (click the Format menu and uncheck Word Wrap)
Important:
Make sure there are NO blank lines before REGEDIT4 Make sure there is one blank line at the end of the file
Make sure that you have copied all of the text (e.g. Don't miss the first 'R'.)
------------------------------------------------------------------------------------------
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"="wdmaud.drv"
-------------------------------------------------------------------------------------------
Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files".
Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.
Next: * Click Start then Run
Copy and paste next command in the field:
ComboFix /u
Make sure there's a space between Combofix and / Then hit enter.
This will uninstall ComboFix. It will also implement some cleanup procedures and reset System Restore points.
Finally, please let me know how things are running after that.
collegeguy
10 Posts
0
February 7th, 2009 12:00
Here are the results from virus total. It appears that neither file shows any virus.
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Estimated start time is between ___ and ___ .
Do not close the window until scan is complete.
If you are waiting for more than five minutes you have to resend your file.
results will be shown as they're generated.
c9619ed068116f621cc03f5f6bfb8ee7d85082700571ae7409f9bbbdceb6eeab
Unknown!
Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
Estimated start time is between 42 and 60 seconds.
Do not close the window until scan is complete.
If you are waiting for more than five minutes you have to resend your file.
results will be shown as they're generated.
49787f3bc0e8efee8aa87e87226456f2c5b956f84140ce07b50dbede76a3f84a
V041muvTARUQcYq4jV5t
DirectShow filter (58.3%)
Windows OCX File (35.7%)
Win32 Executable Generic (2.4%)
Win32 Dynamic Link Library (generic) (2.1%)
Generic Win/DOS Executable (0.5%)
( base data )
entrypointaddress.: 0x11e707
timedatestamp.....: 0x443c659e (Wed Apr 12 02:27:42 2006)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x150b0e 0x151000 6.60 f4a906eb95ab8eb33d65c38dd109294b
.rdata 0x152000 0x3cb59 0x3d000 5.57 f6e0d05beeabd44d13cbf93f3308bd4a
.data 0x18f000 0x2e455 0x29000 5.39 77809e00d81fe2090943c227976b82d5
.rsrc 0x1be000 0x5400 0x6000 4.03 9e77f542f155e0b0d3af51a856328153
.reloc 0x1c4000 0x19e80 0x1a000 5.72 ed0af1c41e74c09d0b57852a6d8a09e7
( 16 imports )
> WSOCK32.dll: -, -, -, -, -, -, -, -, -, -, -
> VERSION.dll: GetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoSizeA
> KERNEL32.dll: GetStringTypeW, IsBadCodePtr, CompareStringA, CompareStringW, SetEnvironmentVariableA, GetStringTypeA, SetUnhandledExceptionFilter, LCMapStringW, LCMapStringA, LocalFree, lstrcpynA, FormatMessageA, GetEnvironmentStringsW, lstrlenA, FreeLibrary, GetProcAddress, LoadLibraryA, WideCharToMultiByte, lstrlenW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, IsBadWritePtr, VirtualAlloc, VirtualFree, HeapCreate, HeapDestroy, GetEnvironmentVariableA, GetStartupInfoA, GetStdHandle, SetHandleCount, SetStdHandle, GetACP, TerminateProcess, ExitProcess, RaiseException, IsBadReadPtr, GetCommandLineA, HeapSize, HeapReAlloc, HeapAlloc, HeapFree, GetFileType, GetLocalTime, GetSystemTime, GetTimeZoneInformation, RtlUnwind, lstrcpyW, SystemTimeToFileTime, MultiByteToWideChar, CloseHandle, OpenFileMappingA, UnmapViewOfFile, SetEvent, MapViewOfFile, GetLastError, CreateEventA, CreateMutexA, WaitForSingleObject, ReleaseMutex, GetCurrentThreadId, Sleep, GetTickCount, GetVersionExA, GetCurrentProcess, GetModuleHandleA, ResetEvent, GlobalFree, GlobalUnlock, GlobalHandle, GlobalLock, GlobalAlloc, WriteProfileStringA, lstrcmpiA, GetProfileStringA, SetLastError, CopyFileA, lstrcatA, GetModuleFileNameA, LocalFileTimeToFileTime, GetOEMCP, GetCPInfo, GetDiskFreeSpaceA, GetFileTime, SetFileTime, GetFileAttributesA, GetProcessVersion, WritePrivateProfileStringA, GlobalFlags, SetErrorMode, TlsGetValue, LocalReAlloc, TlsSetValue, TlsFree, TlsAlloc, LocalAlloc, GetShortPathNameA, GetThreadLocale, GetStringTypeExA, GetFullPathNameA, GetVolumeInformationA, MoveFileA, SetEndOfFile, UnlockFile, LockFile, FlushFileBuffers, DuplicateHandle, GlobalReAlloc, FileTimeToLocalFileTime, FileTimeToSystemTime, IsDBCSLeadByte, GetVersion, GlobalGetAtomNameA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, GetCurrentThread, FlushInstructionCache, GetDateFormatA, GetTimeFormatA, GlobalSize, FindResourceA, LoadResource, LockResource, SizeofResource, SetFilePointer, ReadFile, WriteFile, DeleteFileA, GetCurrentDirectoryA, SetCurrentDirectoryA, CreateFileA, GetFileSize, GetProfileIntA, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, InterlockedIncrement, lstrcmpA, MulDiv, GetUserDefaultLCID, GetLocaleInfoA, InterlockedDecrement, GetTempPathA, GetTempFileNameA, CreateFileMappingA, FindFirstFileA, FindNextFileA, FindClose, lstrcpyA
> USER32.dll: MapDialogRect, SetWindowContextHelpId, CharNextA, DestroyIcon, GetSysColorBrush, GetMenuStringA, InsertMenuA, CopyAcceleratorTableA, InSendMessage, EndDialog, CreateDialogIndirectParamA, GetWindowDC, ClientToScreen, GetClassNameA, GrayStringA, TabbedTextOutA, SetRectEmpty, CreateMenu, GetDesktopWindow, DrawEdge, SetParent, MoveWindow, SetWindowTextA, LoadIconA, SendDlgItemMessageA, SetActiveWindow, EqualRect, CopyRect, ScrollWindow, GetScrollInfo, SetScrollInfo, ShowScrollBar, GetScrollRange, SetScrollRange, GetScrollPos, SetScrollPos, GetTopWindow, WinHelpA, GetClassInfoA, RegisterClassA, GetMenu, GetMenuItemCount, GetSubMenu, GetMenuItemID, GetClassLongA, SetPropA, GetPropA, RemovePropA, GetMessagePos, GetForegroundWindow, SetForegroundWindow, GetWindowPlacement, GetSystemMetrics, IsRectEmpty, FindWindowA, SystemParametersInfoA, GetWindow, GetDlgCtrlID, IsIconic, IsChild, AdjustWindowRectEx, GetMenuCheckMarkDimensions, GetMenuState, ModifyMenuA, SetMenuItemBitmaps, CheckMenuItem, EnableMenuItem, GetNextDlgTabItem, GetMessageA, GetActiveWindow, ValidateRect, GetLastActivePopup, IsWindowEnabled, PostQuitMessage, GetClassInfoExA, PostMessageA, GetWindowTextA, UnionRect, PtInRect, LoadBitmapA, LoadStringA, RemoveMenu, DrawTextA, CreatePopupMenu, AppendMenuA, TrackPopupMenu, DestroyMenu, GetPriorityClipboardFormat, ScreenToClient, GetCapture, GetKeyState, UnhookWindowsHookEx, CallWindowProcA, GetWindowLongA, SetWindowLongA, RegisterClipboardFormatA, OpenClipboard, EmptyClipboard, SetClipboardData, CloseClipboard, GetClipboardData, DestroyWindow, GetCursorPos, ReleaseCapture, SetCapture, CreateCaret, ShowCaret, SetCursor, HideCaret, IsWindow, SetCaretPos, MessageBeep, GetParent, SetFocus, GetCaretPos, BeginPaint, IsWindowVisible, EndPaint, DefWindowProcA, UnregisterClassA, RegisterClassExA, UpdateWindow, InflateRect, OffsetRect, GetSysColor, SetWindowsHookExA, IsDialogMessageA, CallNextHookEx, CharUpperW, CharUpperA, LoadCursorA, RedrawWindow, IntersectRect, IsDlgButtonChecked, GetDlgItem, SendMessageA, ShowWindow, GetWindowRect, MapWindowPoints, SetWindowPos, CreateWindowExA, CheckDlgButton, GetClientRect, GetTabbedTextExtentA, GetNextDlgGroupItem, GetDCEx, PostThreadMessageA, InvalidateRect, GetDC, ReleaseDC, GetFocus, MessageBoxA, SetRect, PeekMessageA, TranslateMessage, DispatchMessageA, MsgWaitForMultipleObjects, SendMessageTimeoutA, FillRect, RegisterWindowMessageA, EnableWindow, KillTimer, SetTimer, wsprintfA, GetMessageTime
> GDI32.dll: ExtTextOutA, ExtTextOutW, SetROP2, GetBkMode, SetBkMode, SetMiterLimit, ExtCreatePen, GetPath, SetTextColor, SelectClipPath, EndPath, BeginPath, SetTextAlign, PolyBezierTo, MoveToEx, LineTo, Arc, Chord, FillPath, SetPolyFillMode, GetObjectA, GetTextAlign, LineDDA, Rectangle, CreateFontA, SetViewportOrgEx, CreatePen, TextOutA, GetTextColor, GetBkColor, GetTextExtentPoint32A, CreateEnhMetaFileA, GetEnhMetaFileBits, CloseEnhMetaFile, GetDIBits, RestoreDC, SaveDC, PtInRegion, GetTextMetricsA, LPtoDP, DPtoLP, GetClipBox, CloseMetaFile, CreateMetaFileA, CombineRgn, PtVisible, RectVisible, Escape, OffsetViewportOrgEx, SetStretchBltMode, ScaleViewportExtEx, ScaleWindowExtEx, GetCurrentPositionEx, CreateRectRgn, GetViewportExtEx, GetWindowExtEx, CreatePatternBrush, CopyMetaFileA, GetMapMode, PatBlt, SetRectRgn, CreateRectRgnIndirect, UnrealizeObject, ResetDCA, CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, SetMapMode, SetWindowExtEx, SetViewportExtEx, SetWindowOrgEx, SelectClipRgn, BitBlt, DeleteObject, EnumFontFamiliesExA, ExtEscape, GetStockObject, CreateDCA, GetEnhMetaFileA, GetFontData, CreateFontIndirectA, AddFontResourceA, RemoveFontResourceA, StretchDIBits, SetDIBitsToDevice, CreateBitmap, SetBkColor, StretchBlt, CreateSolidBrush, EndPage, GetOutlineTextMetricsA, DeleteEnhMetaFile, DeleteDC, CreatePolygonRgn, DeleteMetaFile, EndDoc, PlayEnhMetaFile, StartPage, StartDocA, GetDeviceCaps
> comdlg32.dll: PrintDlgA, ReplaceTextW, ChooseFontA, GetOpenFileNameA, GetFileTitleA, FindTextW
> WINSPOOL.DRV: DeviceCapabilitiesA, GetPrinterDriverA, GetJobA, DocumentPropertiesA, SetPrinterA, GetPrinterA, DeletePrintProcessorA, DeleteMonitorA, DeletePrinterDriverA, DeletePrinter, ClosePrinter, AddPrinterA, AddPrinterDriverA, GetPrinterDriverDirectoryA, OpenPrinterA, EnumPortsA, AddPrintProcessorA, GetPrintProcessorDirectoryA, GetPrinterDataA, SetPrinterDataA
> ADVAPI32.dll: CryptAcquireContextA, RegSetValueExA, GetFileSecurityA, SetFileSecurityA, RegQueryValueA, RegCreateKeyA, RegSetValueA, RegOpenKeyA, RegEnumKeyA, CryptHashData, CryptGetHashParam, CryptCreateHash, CryptDestroyHash, CryptReleaseContext, CryptGetUserKey, RegDeleteKeyA, RegSetKeySecurity, RegDeleteValueA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ControlService, OpenSCManagerA, OpenServiceA, CloseServiceHandle, QueryServiceStatus, StartServiceA, RegOpenKeyExA, RegQueryValueExA, RegCreateKeyExA, RegCloseKey
> SHELL32.dll: ExtractIconA, ShellExecuteA, ShellExecuteW, ShellExecuteExA
> COMCTL32.dll: -
> oledlg.dll: -, -
> ole32.dll: WriteFmtUserTypeStg, CoTreatAsClass, ReadClassStm, OleLoadFromStream, OleFlushClipboard, OleIsCurrentClipboard, OleGetClipboard, OleInitialize, OleUninitialize, CoFreeUnusedLibraries, CoGetClassObject, CoRegisterMessageFilter, CreateBindCtx, CoRegisterClassObject, OleIsRunning, CoCreateInstanceEx, StgCreateDocfile, WriteClassStg, ProgIDFromCLSID, CoTaskMemFree, SetConvertStg, CreateGenericComposite, CreateItemMoniker, CreateStreamOnHGlobal, WriteClassStm, OleGetIconOfClass, GetHGlobalFromILockBytes, StgOpenStorageOnILockBytes, CreateILockBytesOnHGlobal, StgCreateDocfileOnILockBytes, OleSave, OleLoad, OleCreate, OleCreateLinkToFile, OleCreateFromFile, OleCreateStaticFromData, OleSetContainedObject, StringFromCLSID, OleLockRunning, StgIsStorageFile, StgOpenStorage, CreateFileMoniker, OleRun, CLSIDFromString, CLSIDFromProgID, CreateOleAdviseHolder, ReleaseStgMedium, CreateDataAdviseHolder, OleDuplicateData, CoDisconnectObject, OleSetMenuDescriptor, ReadClassStg, ReadFmtUserTypeStg, OleRegGetUserType, CoCreateInstance, OleDestroyMenuDescriptor, OleCreateMenuDescriptor, OleSaveToStream, CoTaskMemAlloc, CreateDataCache, StringFromGUID2, CoRevokeClassObject
> OLEPRO32.DLL: -, -, -, -
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> RPCRT4.dll: UuidCreate
> CRYPT32.dll: CryptVerifyMessageSignature, CryptAcquireCertificatePrivateKey, CertFreeCertificateContext, CertCloseStore, CertGetNameStringA, CertOpenStore, CertFindCertificateInStore, CryptSignMessage
( 175 exports )
BatchConvertEx, CDICreateDC, CDISetDefaultPrinter, CaptureEvents, ConcatenateFiles, DllCanUnloadNow, DllGetClassObject, DllRegisterServer, DllUnregisterServer, DocAppend, DocAutoBookmarksA, DocAutoBookmarksW, DocAutoHyperLinksA, DocAutoHyperLinksW, DocClose, DocConvertToEXCELA, DocConvertToEXCELW, DocConvertToHTMLA, DocConvertToHTMLW, DocConvertToJPEGA, DocConvertToJPEGW, DocConvertToRTFA, DocConvertToRTFW, DocConvertToTIFFA, DocConvertToTIFFW, DocDigitalSignatureA, DocDigitalSignatureW, DocEmailMapiA, DocEmailMapiW, DocEmailSmtpA, DocEmailSmtpW, DocEncrypt128A, DocEncrypt128W, DocEncryptA, DocEncryptW, DocLinearize, DocMerge, DocOpenA, DocOpenW, DocOptimize, DocPrintA, DocPrintW, DocSaveA, DocSaveW, DocSetAuthorA, DocSetBookmarkXYA, DocSetBookmarkXYW, DocSetCreatorA, DocSetHyperLinkInternal, DocSetHyperLinkURLA, DocSetHyperLinkURLW, DocSetKeywordsA, DocSetSubjectA, DocSetTitleA, DocSplitA, DocSplitW, DocSplitXYA, DocSplitXYW, DriverEnd, DriverInit, EMFDriverInit, EnablePrinter, EncryptPDFDocument, EncryptPDFDocument128, GLock, GUnlock, GetCompression, GetDevmodeFlags, GetDocumentTitle, GetEmailOptions, GetEncryption, GetFontEmbedding, GetGeneratedFilename, GetHorizontalMargin, GetImageOptions, GetInlineImageMaxSize, GetJPEGCompression, GetJPegLevel, GetLastErrorMsg, GetOrientation, GetOwnerPassword, GetPaperLength, GetPaperSize, GetPaperWidth, GetPermissions, GetPrinterAttributes, GetPrinterLanguage, GetPrinterParamInt, GetPrinterParamStr, GetResolution, GetSimPostscript, GetUserPassword, GetVersionInformation, GetVerticalMargin, HTMLDriverInit, KeepPreProcessed, LinearizePDFDocument, Lock, MergeFiles, PDF2EXCEL, PDF2HTML, PDF2JPEG, PDF2RTF, PDF2TIFF, PDFDriverInit, PPEndDoc, PPEndObject, PPEndPage, PPInit, PPStartDoc, PPStartObject, PPStartPage, PPWriteBuffer, PrintPDFDocument, PrintPDFDocumentEx, RTFDriverInit, RestoreDefaultPrinter, SendMail, SendMailW, SendMessagesTo, SendSmtpMail, SendSmtpMailW, SetBookmark, SetCompression, SetDefaultConfig, SetDefaultConfigEx, SetDefaultDirectory, SetDefaultFileName, SetDefaultPrinter, SetDevmodeFlags, SetDocFileProps, SetEmailFieldBCC, SetEmailFieldCC, SetEmailFieldFrom, SetEmailFieldTo, SetEmailMessage, SetEmailOptions, SetEmailPrompt, SetEmailSubject, SetEncryption, SetFileNameOptions, SetFontEmbedding, SetHorizontalMargin, SetHyperLink, SetImageOptions, SetInlineImageMaxSize, SetJPEGCompression, SetJPegLevel, SetLicenseKeyA, SetLicenseKeyW, SetOrientation, SetOwnerPassword, SetPageProcessor, SetPaperLength, SetPaperSize, SetPaperWidth, SetPermissions, SetPrinterAttributes, SetPrinterConfig, SetPrinterLanguage, SetPrinterParamInt, SetPrinterParamStr, SetResolution, SetServerAddress, SetServerPort, SetServerUsername, SetSimPostscript, SetSmtpPort, SetSmtpServer, SetTargetPrinterName, SetUserPassword, SetVerticalMargin, SetWatermark, TestLock, Unlock
collegeguy
10 Posts
0
February 18th, 2009 13:00
Everything has seemed to be running fine until yesterday. I started to notice redirects again when I would do a search and then hit a url. Not all the time and not as bad as before but I still appear to have some malware lurking.
Should I try to follow all of the previous steps or is this something that you need to review?
As always, thanks for your time.
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 18th, 2009 16:00
Your system was clean. You must have visited a website that is installing this junk. See if MBAM will clean it.
Bugbatter
4 Apprentice
•
20.5K Posts
0
February 19th, 2009 14:00
Please download DrWeb-CureIt & save it to your desktop. DO NOT perform a scan yet.
Reboot your computer in SAFE MODE using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".
Scan with DrWeb-CureIt as follows:
collegeguy
10 Posts
0
February 19th, 2009 14:00
I ran MBAM and it didn't show any file to be infected.
Next?
Thanks.