
Attachment uploads are currently disabled. This is a temporary situation and will resume as normal in the coming days.
UNSOLVED
system security version 4.51
I need some help to get this out of my computer system. I have a log list if anyone knows what i am talking about. i went on to trend micro hijackthis to find out how to get rid of it and i can't find it in my system..... can anyone help me?
Responses (13)
Solutions (0)
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [DellOSD] C:\Windows\System32\FastUserSwitching.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {2703049B-D81D-4763-A3C6-AF8932FCBD8F} (CheckFileStatus.UserControl1) -
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) -
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Remote Access Media Server (Apache2.2) - Apache Software Foundation - C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: DELLODDSrv - Unknown owner - C:\Windows\System32\WinService.exe
O23 - Service: dldt_device - - C:\Windows\system32\dldtcoms.exe
O23 - Service: Google Desktop Manager 5.8.809.23506 (GoogleDesktopManager-092308-165331) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exeReply StartupList report, 4/7/2009, 8:49:26 AM
StartupList version: 1.52.2
Started from : C:\Users\KAREN HACKETT\Desktop\HijackThis.EXE
Detected: Windows Vista SP1 (WinNT 6.00.1905)
Detected: Internet Explorer v7.00 (7.00.6001.18000)
* Using default options
==================================================Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\System32\FastUserSwitching.exe
C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\UMStor\Res.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Dell V305\dldtmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\MediaButtons.exe
C:\Program Files\Dell Remote Access\ezi_ra.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Users\KAREN HACKETT\Documents\RCA Detective\RCADetective.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\TestUnitReady.exe
C:\Windows\System32\DELLODD.exe
C:\Program Files\Dell V305\dldtMsdMon.exe
C:\Windows\System32\DELLOSD.exe
C:\Windows\System32\mobsync.exe
C:\ProgramData\106570476\106570476.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\windows defender\MSASCui.exe
C:\Users\KAREN HACKETT\Desktop\HijackThis.exe--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Users\KAREN HACKETT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
RCA Detective.lnk = C:\Users\KAREN HACKETT\Documents\RCA Detective\RCADetective.exeShell folders Common Startup:
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
Dell Remote Access.lnk = ?
Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\Windows\system32\userinit.exe,--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunRtHDVCpl = RtHDVCpl.exe
Broadcom Wireless Manager UI = C:\Windows\system32\WLTRAY.exe
DellOSD = C:\Windows\System32\FastUserSwitching.exe
Google Desktop Search = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
PCMService = "C:\Program Files\Dell\MediaDirect\PCMService.exe"
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
Dell DataSafe Online = "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
dellsupportcenter = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
USB Storage Toolbox = C:\Windows\UMStor\Res.EXE
dldtmon.exe = "C:\Program Files\Dell V305\dldtmon.exe"
dldtamon = "C:\Program Files\Dell V305\dldtamon.exe"
Easy Dock = C:\Users\KAREN HACKETT\Documents\RCA EasyRip\EZDock.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
IgfxTray = C:\Windows\system32\igfxtray.exe
HotKeysCmds = C:\Windows\system32\hkcmd.exe
Persistence = C:\Windows\system32\igfxpers.exe
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe"
AVG8_TRAY = C:\PROGRA~1\AVG\AVG8\avgtray.exe--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx(Default) =
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Runswg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
ehTray.exe = C:\Windows\ehome\ehTray.exe
WMPNSCFG = C:\Program Files\Windows Media Player\WMPNSCFG.exe--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run[OptionalComponents]
=--------------------------------------------------
Load/Run keys from C:\Windows\WIN.INI:
load=*INI section not found*
run=*INI section not found*Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll--------------------------------------------------
Shell & screensaver key from C:\Windows\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*Shell & screensaver key from Registry:
Shell=explorer.exe
SCRNSAVE.EXE=C:\Windows\system32\Ribbons.scr
drivers=*Registry value not found*Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*--------------------------------------------------
Enumerating Browser Helper Objects:AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
WormRadar.com IESiteBlocker.NavFilter - C:\Program Files\AVG\AVG8\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
NCO 2.0 IE BHO - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll - {6D53EC84-6AAE-4787-AEEE-F4628F01010C}
(no name) - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL - {A057A204-BACC-4D26-9990-79A187E2698E}
(no name) - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E}
Browser Address Error Redirector - C:\Program Files\Dell\BAE\BAE.dll - {CA6319C0-31B7-401E-A518-A07C3DB8F777}
(no name) - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll - {d2ce3e00-f94a-4740-988e-03dc2f38c34f}
(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}--------------------------------------------------
Enumerating Task Scheduler jobs:
Norton Internet Security - Run Full System Scan - KAREN HACKETT.job
--------------------------------------------------
Enumerating Download Program Files:
[CheckFileStatus.UserControl1]
InProcServer32 = C:\Windows\Downloaded Program Files\CheckFileStatus.ocx
CODEBASE = https://am.hrblock.com/ActivexComponent/CheckFileStatus.CAB[PogoWebLauncher Control]
InProcServer32 = C:\Windows\DOWNLO~1\POGOWE~1.OCX
CODEBASE = http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB[System Requirements Lab Class]
InProcServer32 = C:\Windows\Downloaded Program Files\sysreqlab_ind.dll
CODEBASE = http://www.srtest.com/srl_bin/sysreqlab_ind.cab
OSD = C:\Windows\Downloaded Program Files\sysreqlab.osd[Invoke Solutions Participant Control(MR)]
InProcServer32 = C:\PROGRA~1\INVOKE~1\PARTIC~1\6.2\MILIVE~1.OCX
CODEBASE = http://rms2.invokesolutions.com/events/bin/6.2.0.1450/MILive.cab--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\Windows\system32\NLAapi.dll
NameSpace #2: C:\Windows\system32\napinsp.dll
NameSpace #3: C:\Windows\system32\pnrpnsp.dll
NameSpace #4: C:\Windows\system32\pnrpnsp.dll--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\Windows\system32\webcheck.dll
--------------------------------------------------
End of report, 10,445 bytes
Report generated in 0.171 secondsCommand line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history onlyReply StartupList report, 4/7/2009, 8:49:26 AM
StartupList version: 1.52.2
Started from : C:\Users\KAREN HACKETT\Desktop\HijackThis.EXE
Detected: Windows Vista SP1 (WinNT 6.00.1905)
Detected: Internet Explorer v7.00 (7.00.6001.18000)
* Using default options
==================================================Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\RtHDVCpl.exe
C:\Windows\System32\WLTRAY.EXE
C:\Windows\System32\FastUserSwitching.exe
C:\ProgramData\SingleClick Systems\apache\bin\httpd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Windows\UMStor\Res.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Dell V305\dldtmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\System32\MediaButtons.exe
C:\Program Files\Dell Remote Access\ezi_ra.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Users\KAREN HACKETT\Documents\RCA Detective\RCADetective.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\TestUnitReady.exe
C:\Windows\System32\DELLODD.exe
C:\Program Files\Dell V305\dldtMsdMon.exe
C:\Windows\System32\DELLOSD.exe
C:\Windows\System32\mobsync.exe
C:\ProgramData\106570476\106570476.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\MSN\Toolbar\3.0.0988.2\msntask.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\windows defender\MSASCui.exe
C:\Users\KAREN HACKETT\Desktop\HijackThis.exe--------------------------------------------------
Listing of startup folders:
Shell folders Startup:
[C:\Users\KAREN HACKETT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup]
Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
RCA Detective.lnk = C:\Users\KAREN HACKETT\Documents\RCA Detective\RCADetective.exeShell folders Common Startup:
[C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup]
Dell Remote Access.lnk = ?
Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\Windows\system32\userinit.exe,--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunRtHDVCpl = RtHDVCpl.exe
Broadcom Wireless Manager UI = C:\Windows\system32\WLTRAY.exe
DellOSD = C:\Windows\System32\FastUserSwitching.exe
Google Desktop Search = "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
PCMService = "C:\Program Files\Dell\MediaDirect\PCMService.exe"
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
Dell DataSafe Online = "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
dellsupportcenter = "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
USB Storage Toolbox = C:\Windows\UMStor\Res.EXE
dldtmon.exe = "C:\Program Files\Dell V305\dldtmon.exe"
dldtamon = "C:\Program Files\Dell V305\dldtamon.exe"
Easy Dock = C:\Users\KAREN HACKETT\Documents\RCA EasyRip\EZDock.exe
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
IgfxTray = C:\Windows\system32\igfxtray.exe
HotKeysCmds = C:\Windows\system32\hkcmd.exe
Persistence = C:\Windows\system32\igfxpers.exe
Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
SunJavaUpdateSched = "C:\Program Files\Java\jre6\bin\jusched.exe"
AVG8_TRAY = C:\PROGRA~1\AVG\AVG8\avgtray.exe--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx(Default) =
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Runswg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
ehTray.exe = C:\Windows\ehome\ehTray.exe
WMPNSCFG = C:\Program Files\Windows Media Player\WMPNSCFG.exe--------------------------------------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run[OptionalComponents]
=--------------------------------------------------
Load/Run keys from C:\Windows\WIN.INI:
load=*INI section not found*
run=*INI section not found*Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,avgrsstx.dll--------------------------------------------------
Shell & screensaver key from C:\Windows\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*Shell & screensaver key from Registry:
Shell=explorer.exe
SCRNSAVE.EXE=C:\Windows\system32\Ribbons.scr
drivers=*Registry value not found*Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*--------------------------------------------------
Enumerating Browser Helper Objects:AcroIEHelperStub - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll - {18DF081C-E8AD-4283-A596-FA578C2EBDC3}
WormRadar.com IESiteBlocker.NavFilter - C:\Program Files\AVG\AVG8\avgssie.dll - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
NCO 2.0 IE BHO - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}
Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll - {6D53EC84-6AAE-4787-AEEE-F4628F01010C}
(no name) - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL - {A057A204-BACC-4D26-9990-79A187E2698E}
(no name) - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E}
Browser Address Error Redirector - C:\Program Files\Dell\BAE\BAE.dll - {CA6319C0-31B7-401E-A518-A07C3DB8F777}
(no name) - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll - {d2ce3e00-f94a-4740-988e-03dc2f38c34f}
(no name) - C:\Program Files\Java\jre6\bin\jp2ssv.dll - {DBC80044-A445-435b-BC74-9C25C1C588A9}--------------------------------------------------
Enumerating Task Scheduler jobs:
Norton Internet Security - Run Full System Scan - KAREN HACKETT.job
--------------------------------------------------
Enumerating Download Program Files:
[CheckFileStatus.UserControl1]
InProcServer32 = C:\Windows\Downloaded Program Files\CheckFileStatus.ocx
CODEBASE = https://am.hrblock.com/ActivexComponent/CheckFileStatus.CAB[PogoWebLauncher Control]
InProcServer32 = C:\Windows\DOWNLO~1\POGOWE~1.OCX
CODEBASE = http://www.pogo.com/cdl/launcher/PogoWebLauncherInstaller.CAB[System Requirements Lab Class]
InProcServer32 = C:\Windows\Downloaded Program Files\sysreqlab_ind.dll
CODEBASE = http://www.srtest.com/srl_bin/sysreqlab_ind.cab
OSD = C:\Windows\Downloaded Program Files\sysreqlab.osd[Invoke Solutions Participant Control(MR)]
InProcServer32 = C:\PROGRA~1\INVOKE~1\PARTIC~1\6.2\MILIVE~1.OCX
CODEBASE = http://rms2.invokesolutions.com/events/bin/6.2.0.1450/MILive.cab--------------------------------------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\Windows\system32\NLAapi.dll
NameSpace #2: C:\Windows\system32\napinsp.dll
NameSpace #3: C:\Windows\system32\pnrpnsp.dll
NameSpace #4: C:\Windows\system32\pnrpnsp.dll--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
WebCheck: C:\Windows\system32\webcheck.dll
--------------------------------------------------
End of report, 10,445 bytes
Report generated in 0.171 secondsCommand line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history onlyReply
klhack
1. Go HERE and download File Lister.
- Save it to your Desktop
- Rt Click ->> Extract all ->> And extract it to your Desktop
- Additional help on extracting zip files can be found HERE
- Open the File Lister Folder.
- Note: Leave the FileLister.vbe file in the folder and run it from there.
- Rt Click FileLister.vbe ->>Select Open Then Open to confirm.
- As the program runs, it will appear that nothing is happening.
- When the program is fnished it will produce a log for you C:\Files.txt
Copy and paste the contents of that log in your reply.
Reply this is what i am coming up with... i don't think it is right . how long does the program take?
adp94xx
adpahci
amdide
arcsas
bcm42rly
bcm43xx
blbdrive
bowser
brfiltlo
brfiltup
brserid
brserwdm
brusbmdm
brusbser
circlass
clfs
coh_mon
crusoe
dfsc
dlxpdisplayname
dxgkrnl
e1express
e1g60
ecache
eectrl
elxstor
eraserutilrebootdrv
errdev
fileinfo
filetrace
gagp30kx
hidbth
hidir
hpcisss
iastorv
idsvix86
igfx
ipmidrv
iscsiprt
iteatapi
iteraid
jl2005c
lltdio
lsi_fc
lsi_sas
lsi_scsi
luafv
megasas
megasr
mpio
mpsdrv
mrxsmb10
mrxsmb20
msahci
msdsm
msisadrv
msrpc
nativewifip
nfrd960
nsiproxy
ntrigdigi
nvstor
packet
peauth
ql2300
ql40xx
qwavedrv
r300
rdpencdd
rspndr
rtl8169
rtndpt60
rtstor
sbp2port
sermouse
sffdisk
sffp_mmc
sffp_sd
sisraid2
sisraid4
spbbcdrv
spldr
srtsp
srtspl
srtspx
srv2
srvnet
symim
symndisv
tcpip6
tcpipreg
tdx
tssecsrv
tunmp
tunnel
uagp35
uliagpkx
uliahci
ulsata
ulsata2
umbus
usbcir
viac7
volmgr
volmgrx
vsmraid
wacompen
wanarpv6
wdf01000
wmiacpi
wpdusb
aelookupsvc
aertfilters
apache2.2
appinfo
audioendpointbuilder
automatic liveupdate scheduler
***
certpropsvc
cltnetcnservice
comhost
delloddsrv
dfsr
dldtcatscustconnectservice
dldt_device
dockloginservice
dsl-db
dsl-fs-sync
ehrecvr
ehsched
ehstart
emdmgmt
fdphost
fdrespub
googledesktopmanager-092308-165331
gotoassist
gpsvc
hnmsvc
ikeext
ipbusenum
iphlpsvc
keyiso
ktmrm
liveupdate notice
lltdsvc
mcx2svc
mmcss
mpssvc
msiscsi
netprofm
nlasvc
p2pimsvc
p2psvc
pcasvc
pnrpautoreg
pnrpsvc
profsvc
qwave
scpolicysvc
sdrsvc
sessionenv
slsvc
sluinotify
snmptrap
sprtsvc_dellsupportcenter
stllssvr
sysmain
tabletinputservice
tbs
threadorder
trustedinstaller
ui0detect
uxsms
wcncsvc
wcspluginservice
wdiservicehost
wdisystemhost
wecsvc
wercplsupport
wersvc
windefend
winhttpautoproxysvc
winrm
wlansvc
wltrysvc
wpcsvc
wpdbusenum
wsearchReply
klhack
Please download Malwarebytes' Anti-Malware from Here or Here
Double Click mbam-setup.exe to install the application.
- Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.
Reply Malwarebytes' Anti-Malware 1.36
Database version: 1977
Windows 6.0.6001 Service Pack 14/13/2009 4:04:52 PM
mbam-log-2009-04-13 (16-04-52).txtScan type: Quick Scan
Objects scanned: 70870
Time elapsed: 3 minute(s), 37 second(s)Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2Memory Processes Infected:
(No malicious items detected)Memory Modules Infected:
(No malicious items detected)Registry Keys Infected:
HKEY_CLASSES_ROOT\cpbrkpie.coupon6ctrl.1 (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522b3fb-7a2b-4646-8af6-36e7f593073c} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a85a5e6a-de2c-4f4e-99dc-f469df5a0eec} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e780f0b-bcd6-40cb-b2db-7af47ab4d4a4} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a138be8b-f051-4802-9a3f-a750a6d862d4} (Adware.Coupons) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.Registry Values Infected:
(No malicious items detected)Registry Data Items Infected:
(No malicious items detected)Folders Infected:
(No malicious items detected)Files Infected:
C:\Windows\CouponPrinter.ocx (Adware.Coupons) -> Quarantined and deleted successfully.
C:\Users\KAREN HACKETT\AppData\Local\Temp\Low\cpnprt2.cid (Adware.Agent) -> Quarantined and deleted successfully.Reply

bamajim
10376 Posts
542
0
Posted April 8th, 2009 08:00
klhack
Post your Hijackthis log as a reply to this thread and we will take a look