This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] random pop ups, now no internet connection, slow pc

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yesterday I ran to some websites and the pc froze.
After I restarted it (power button 5 sec), I got random pop ups (although I didn't open any browsers), my new usb drive wasn't detected and today the internet connection doesn't work and my pc slows down.

Another symptoms I observed so far: no folder options in tools menu, registry edit is disabled

I ran various antispyware softwares but the problem persists. Hijackthis log can be seen below.
Any help would be appreciated. Thank you.





Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:36:01 PM, on 4/27/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
c:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\TEMP\sophos_autoupdate1.dir\alupdate.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\DOCUME~1\Eko\LOCALS~1\Temp\3727627676.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Java\jre6\bin\java.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: C:\WINDOWS\system32\yhs783ijfo3fe.dll - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\yhs783ijfo3fe.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIOSurvey] c:\program files\sony\vaio survey\surveysa.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Diagnostic Manager] C:\DOCUME~1\Eko\LOCALS~1\Temp\3727627676.exe
O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\whvn004lv6.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Windows Resurections] C:\WINDOWS\TEMP\whvn004lv6.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\555570992.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] C:\WINDOWS\TEMP\whvn004lv6.exe (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: VPN Client.lnk = ?
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to Vbuzzer RSS list - C:\Program Files\vbuzzer\addurl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\PROGRA~1\Sophos\SOPHOS~1\SOPHOS~1.DLL C:\WINDOWS\system32\kiyivaro.dll c:\windows\system32\hujufutu.dll
O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)
O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - (no file)
O22 - SharedTaskScheduler: jso8joigm409gopgmrlgd - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\yhs783ijfo3fe.dll
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - c:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

–
End of file - 14320 bytes
Due to the large numbers of HJT logs being posted, there are four things that you need to be aware of.

1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.

2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time, I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!

3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.

4) Back-ups can get lost or damaged, so make two if the files are that important to you!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Take a trip to this webpage for download links and instructions for running Combofix by sUBs: http://www.bleepingcomputer.com/combofix/how-to-use-combofix *
  • Please be aware that this tool may require the PC to be rebooted so close any programs you have open before you start.
  • When CF has finished, it will produce a log - C:\ComboFix.txt - copy and paste it into your next reply.
  • Post a fresh HJT log as well.
  • Let me know how the PC is behaving.
* There are two points to note from the instructions page:

1) The Recovery Console.

It is recommended that you install this as, in certain circumstances, it may be the difference between a successful repair and a reformat. If you are uncertain as to whether or not you already have the Recovery Console installed, simply run CF and it will prompt you if it does not detect it.
CF will complete it's removal tasks without the installation of the Console, so you are free to choose whether you want to complete this step, but it is in your interests to do so.

2) Disabling your Anti-Virus.

CF has been the victim of false-positive detections on occasion and a resident AV may incorrectly identify and delete part of the tool which won't do it much good. If you don't disable your AV, you may not get the results you hoped for!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Finally, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Thanks for replying. I have posted the hijackthis log in this forum. As instructed, I have ran the combofix and my pc seems to be fine now. No random pop ups are observed. However, if I search using google, all searches are redirected to some ad websites.

I have attached the log of combofix and the uninstall list. See below for the fresh hijackthis log .


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:14:28 PM, on 4/27/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\WINDOWS\ehome\ehtray.exe
c:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIOSurvey] c:\program files\sony\vaio survey\surveysa.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to Vbuzzer RSS list - C:\Program Files\vbuzzer\addurl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - c:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

–
End of file - 12130 bytes

2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS4
Adobe Bridge Start Meeting
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS4
Adobe Photoshop CS4
Adobe Reader 7.0.7
Adobe Setup
Adobe Shockwave Player 11.5
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Apple Software Update
BitComet 1.10
Bluetooth Stack for Windows by Toshiba
Choice Guard
Cisco Systems VPN Client 5.0.03.0530
Click to DVD 2.0.03 Menu Data
Click to DVD 2.5.30
Combined Community Codec Pack 2008-09-21 16:18
Command & Conquer 3
Critical Update for Windows Media Player 11 (KB959772)
DSD Direct
DSD Playback Plug-in 1.0
DS-Monkey Audio Source 1.00
DVgate Plus
Dynasty Warriors 6
Garena
HDAUDIO SoftV92 Data Fax Modem with SmartCP
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows Media Player 10 (KB910393)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
HouseCall 6.6
HP Photo and Imaging 2.0 - All-in-One
HP Photo and Imaging 2.0 - All-in-One Drivers
ICQ6.5
Image Converter 2 Plus
ImageStation
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Drivers
Intel® PROSet/Wireless Software
InterVideo WinDVD for VAIO
J2SE Runtime Environment 5.0 Update 7
Java™ 6 Update 13
LAN Setting Utility
Macromedia Flash Player 8
Macromedia Flash Player 8 Plugin
Malwarebytes' Anti-Malware
mCore
mDriver
Memory Stick Formatter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Digital Image Starter Edition 2006
Microsoft Office Access MUI (English) 2007
Microsoft Office Access MUI (German) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Excel MUI (German) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove MUI (German) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office InfoPath MUI (German) 2007
Microsoft Office Language Pack 2007 - German/Deutsch
Microsoft Office O MUI (German) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office OneNote MUI (German) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office Outlook MUI (German) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint MUI (German) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (German) 2007
Microsoft Office Proof (Italian) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing (German) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Publisher MUI (German) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared MUI (German) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office SharePoint Designer 2007 Service Pack 1 (SP1)
Microsoft Office SharePoint Designer MUI (German) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Office Word MUI (German) 2007
Microsoft Office X MUI (German) 2007
Microsoft Save as PDF Add-in for 2007 Microsoft Office programs
Microsoft SQL Server Desktop Engine (VAIO_VEDB)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
mMHouse
Mozilla Firefox (3.0.9)
mPfMgr
mProSafe
MSVCRT
MSXML 4.0 SP2 (KB954430)
mWlsSafe
mXML
NVIDIA Drivers
OpenMG AAC Add-on Module 1.0.00
OpenMG Limited Patch 4.5-06-05-12-01
OpenMG Metadata Extractor for Windows Media Player
OpenMG Secure Module 4.5.01
PDF Settings
Photoshop Camera Raw
Quicken 2006
QuickTime
Real Alternative 1.9.0
Roxio DigitalMedia Audio
Roxio DigitalMedia Copy
Roxio DigitalMedia Data
Search Enhancement by AOL Search
SecureW2 EAP Suite 1.1.3 for Windows
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB960003)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB959997)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office Word 2007 (KB956358)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Segoe UI
Setting Utility Series
Shockwave
SigmaTel Audio
Skype™ 4.0
SmartVoip
Sonic Encoders
SonicStage 4.0
SonicStage Mastering Studio 2.2
SonicStage Mastering Studio Audio Filter
SonicStage Mastering Studio Audio Filter Custom Preset
SonicStage Mastering Studio Plugins
Sony Certificate PCH
Sony MP4 Shared Library
Sony USB Mouse
Sony Utilities DLL
Sony Video Shared Library
Sophos Anti-Virus
Sophos AutoUpdate
Spyware Doctor 6.0
SpywareBlaster 4.2
TrueCrypt
Update for Microsoft Office Outlook 2007 (KB952142)
Update for Office 2007 (KB946691)
Update for Outlook 2007 Junk Email Filter (kb962871)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Rollup 2 for Windows XP Media Center Edition 2005
VAIO Backup Utility
VAIO Breeze Wallpaper
VAIO Camera Utility
VAIO Central
VAIO Entertainment Platform
VAIO Event Service
VAIO Hardware Diagnostics
VAIO Light Flo Wallpaper
VAIO Media 5.0
VAIO Media AC3 Decoder 1.0
VAIO Media Integrated Server 5.0
VAIO Media Redistribution 5.0
VAIO Media Registration Tool 5.0
VAIO Original Screen Saver
VAIO Original Screen Saver VAIO Cozy Screen SD Wide Contents
VAIO Power Management
VAIO Registration
VAIO Security Center
VAIO Support Central
VAIO Update 2
VAIO Wireless LAN Setup Utility
VAIOSurveySA
Vbuzzer Messenger
VeohTV BETA
Windows Defender
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10 Hotfix [See KB886612 for more information]
Windows Media Player 11
Windows Media Player 11
Windows XP Media Center Edition 2005 KB925766
Windows XP Service Pack 3
WinRAR archiver
Wireless Switch Setting Utility
Yahoo! Messenger
Your Uninstaller! 2008 Version 6.0
ZumoDrive

ComboFix 09-04-27.02 - Eko 04/27/2009 16:59.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1513 [GMT -4:00]
Running from: F:\ComboFix.exe
AV: Sophos Anti-Virus *On-access scanning enabled* (Updated)
AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated)
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Eko\Local Settings\Temporary Internet Files\Cpvff.stt
c:\documents and settings\Eko\Local Settings\Temporary Internet Files\fbk.sts
c:\windows\setup.exe
c:\windows\system32\drivers\ovfsthxgoibeevximbwchtsencsppmpuqfqqoo.sys
c:\windows\system32\ovfsthbshjwrdlogttuaihathqosucfgepnnqw.dll
c:\windows\system32\ovfsthbuuhsrnxvslnlagffxilkyyyuwkxqfel.dll
c:\windows\system32\ovfsthimrgwxtmqkoyljkegicijwmpqlvwiona.dat
c:\windows\system32\ovfsthtmfeqfpvnrmkdefsmeqxyvthmugxfncb.dll
c:\windows\system32\ovfsthyswqeeosknmdtgsfvsvshbtmiriatutu.dat
c:\windows\Temp\1360785380.exe
c:\windows\Temp\555570992.exe
c:\windows\Temp\656377676.exe
C:\xcrashdump.dat

—– BITS: Possible infected sites —–

hxxp://83.149.105.228
Infected copy of c:\windows\system32\userinit.exe was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\userinit.exe


.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_ovfsthtvpqsbcrviwwkinidrieqbcxfyxcpxdm


((((((((((((((((((((((((( Files Created from 2009-05-27 to 2009-4-27 )))))))))))))))))))))))))))))))
.

2009-04-27 20:50 . 2009-04-27 20:50 ——– d–h–w c:\windows\PIF
2009-04-27 19:24 . 2009-04-27 19:39 27648 —-a-w c:\windows\system32\lmppcsetup.exe
2009-04-27 19:22 . 2009-04-27 19:22 39936 —-a-w c:\windows\system32\winglsetup.exe
2009-04-27 19:17 . 2009-04-27 19:17 ——– d—–w c:\documents and settings\Eko\Application Data\Malwarebytes
2009-04-27 19:17 . 2009-04-06 19:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-27 19:17 . 2009-04-06 19:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-27 19:17 . 2009-04-27 19:17 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-27 19:17 . 2009-04-27 19:17 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-27 18:30 . 2009-04-27 18:30 ——– d–h–w c:\windows\system32\GroupPolicy
2009-04-27 17:33 . 2009-04-27 17:01 39200 —-a-w c:\windows\system32\drivers\TfSysMon.sys
2009-04-27 17:33 . 2009-04-27 17:01 33056 —-a-w c:\windows\system32\drivers\TfNetMon.sys
2009-04-27 17:33 . 2009-04-27 17:01 12576 —-a-w c:\windows\system32\drivers\TfKbMon.sys
2009-04-27 17:33 . 2009-04-27 17:01 51488 —-a-w c:\windows\system32\drivers\TfFsMon.sys
2009-04-27 17:28 . 2009-04-27 17:28 ——– d—–w c:\program files\Trend Micro
2009-04-27 17:20 . 2007-12-24 21:37 138384 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-04-27 17:14 . 2009-04-27 18:07 ——– d—–w c:\documents and settings\Eko\Application Data\HouseCall 6.6
2009-04-27 17:12 . 2009-04-27 17:15 ——– d—–w c:\program files\SpywareBlaster
2009-04-27 15:31 . 2008-12-11 12:38 159600 —-a-w c:\windows\system32\drivers\pctgntdi.sys
2009-04-27 15:31 . 2008-12-18 16:16 73840 —-a-w c:\windows\system32\drivers\PCTAppEvent.sys
2009-04-27 15:31 . 2009-04-27 17:01 130936 —-a-w c:\windows\system32\drivers\PCTCore.sys
2009-04-27 15:31 . 2009-04-27 15:32 ——– d—–w c:\program files\Common Files\PC Tools
2009-04-27 15:31 . 2008-12-10 16:36 64392 —-a-w c:\windows\system32\drivers\pctplsg.sys
2009-04-27 15:31 . 2009-04-27 17:34 ——– d—–w c:\documents and settings\All Users\Application Data\PC Tools
2009-04-27 15:31 . 2009-04-27 18:02 ——– d—–w c:\program files\Spyware Doctor
2009-04-27 15:31 . 2009-04-27 15:31 ——– d—–w c:\documents and settings\Eko\Application Data\PC Tools
2009-04-27 15:14 . 2009-04-27 15:14 ——– d—–w c:\program files\Windows Defender
2009-04-27 15:01 . 2009-04-27 15:01 ——– d-sh–w c:\windows\system32\config\systemprofile\PrivacIE
2009-04-25 16:17 . 2009-04-25 16:17 ——– d—–w c:\documents and settings\Eko\Application Data\DAEMON Tools Pro
2009-04-25 12:35 . 2009-04-25 12:35 ——– d—–w c:\documents and settings\Eko\Local Settings\Application Data\Sophos
2009-04-23 14:28 . 2001-08-18 02:36 5632 —-a-w c:\windows\system32\ptpusb.dll
2009-04-23 14:28 . 2008-04-13 23:12 159232 —-a-w c:\windows\system32\ptpusd.dll
2009-04-16 11:58 . 2009-04-16 11:58 ——– d—–w c:\documents and settings\Eko\Application Data\Hewlett-Packard
2009-04-16 11:36 . 2009-04-16 11:36 ——– d—–w c:\program files\HP
2009-04-16 11:35 . 2008-04-13 17:45 15104 -c–a-w c:\windows\system32\dllcache\usbscan.sys
2009-04-16 11:35 . 2008-04-13 17:45 15104 —-a-w c:\windows\system32\drivers\usbscan.sys
2009-04-16 11:34 . 2009-04-16 11:34 ——– d—–w c:\program files\Common Files\Hewlett-Packard
2009-04-16 11:34 . 2009-04-16 11:34 ——– d—–w c:\program files\Hewlett-Packard
2009-04-16 11:33 . 2003-04-22 14:24 16606 ——w c:\windows\hpomdl01.dat
2009-04-16 11:33 . 2009-04-16 11:36 19558 —-a-w c:\windows\hpoins01.dat
2009-04-16 11:22 . 2008-04-13 17:47 25856 -c–a-w c:\windows\system32\dllcache\usbprint.sys
2009-04-16 11:22 . 2008-04-13 17:47 25856 —-a-w c:\windows\system32\drivers\usbprint.sys
2009-04-15 09:30 . 2009-03-06 14:22 284160 -c—-w c:\windows\system32\dllcache\pdh.dll
2009-04-15 09:30 . 2009-02-06 10:39 35328 -c—-w c:\windows\system32\dllcache\sc.exe
2009-04-15 09:30 . 2009-02-09 12:10 401408 -c—-w c:\windows\system32\dllcache\rpcss.dll
2009-04-15 09:30 . 2009-02-06 11:11 110592 -c—-w c:\windows\system32\dllcache\services.exe
2009-04-15 09:30 . 2009-02-09 12:10 473600 -c—-w c:\windows\system32\dllcache\fastprox.dll
2009-04-15 09:30 . 2009-02-06 10:10 227840 -c—-w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 09:30 . 2009-02-09 12:10 453120 -c—-w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 09:30 . 2009-02-09 12:10 729088 -c—-w c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 09:30 . 2009-02-09 12:10 617472 -c—-w c:\windows\system32\dllcache\advapi32.dll
2009-04-15 09:30 . 2009-02-09 12:10 714752 -c—-w c:\windows\system32\dllcache\ntdll.dll
2009-04-15 09:29 . 2008-05-03 11:55 2560 ——w c:\windows\system32\xpsp4res.dll
2009-04-15 09:29 . 2008-04-21 12:08 215552 -c—-w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 17:43 . 2009-04-14 17:43 ——– d—–w c:\documents and settings\Eko\Application Data\Thinstall
2009-04-14 17:43 . 2009-04-14 17:43 ——– d—–w c:\documents and settings\Eko\Local Settings\Application Data\Thinstall
2009-04-13 12:45 . 2009-04-13 12:46 ——– d—–w c:\documents and settings\Eko\Application Data\SmartVoip
2009-04-13 12:44 . 2009-04-13 12:44 ——– d—–w c:\program files\SmartVoip.com
2009-04-12 16:13 . 2009-04-12 16:13 ——– d—–w c:\documents and settings\Eko\Application Data\Command & Conquer 3 Tiberium Wars
2009-04-12 14:34 . 2009-04-12 15:02 ——– d—–w c:\documents and settings\Eko\Application Data\Command & Conquer 3 Kane's Wrath
2009-04-12 14:15 . 2008-07-30 10:20 238088 —-a-w c:\windows\system32\xactengine3_2.dll
2009-04-12 14:13 . 2009-04-12 14:13 ——– d—–w c:\windows\Logs
2009-04-12 12:50 . 2009-04-12 12:50 ——– d—–w c:\program files\Team JPN
2009-04-07 23:13 . 2009-04-07 23:13 ——– d—–w c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-04-06 11:03 . 2009-04-06 11:03 ——– d—–w c:\windows\Sun
2009-04-05 19:50 . 2009-04-05 19:50 ——– d—–w C:\Downloads
2009-04-04 15:42 . 2009-04-04 15:42 ——– d—–w c:\documents and settings\Eko\Application Data\Apple Computer
2009-04-04 15:41 . 2009-04-04 15:41 ——– d—–w c:\program files\QuickTime
2009-04-04 15:41 . 2009-04-04 15:41 ——– d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2009-04-04 15:41 . 2009-04-04 15:41 ——– d—–w c:\documents and settings\Eko\Local Settings\Application Data\Apple
2009-04-04 15:41 . 2009-04-04 15:41 ——– d—–w c:\program files\Apple Software Update
2009-04-04 15:41 . 2009-04-04 15:41 ——– d—–w c:\documents and settings\All Users\Application Data\Apple
2009-04-04 15:40 . 2009-04-04 15:40 ——– d—–w c:\documents and settings\Eko\Local Settings\Application Data\Apple Computer
2009-04-04 15:39 . 2009-04-05 13:55 ——– d—–w c:\windows\system32\Adobe
2009-04-03 16:07 . 2009-04-03 16:08 ——– d—–w c:\program files\DS-Monkey Audio Source
2009-04-03 15:47 . 2009-04-05 19:51 ——– d—–w c:\program files\BitComet
2009-04-03 12:37 . 2009-04-03 12:37 ——– d—–w c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-03 01:57 . 2006-11-29 17:06 3426072 —-a-w c:\windows\system32\d3dx9_32.dll
2009-04-03 01:39 . 2009-04-03 01:39 ——– d—–w c:\program files\MSECache
2009-04-03 01:39 . 2009-04-12 15:47 ——– d—–w c:\program files\Electronic Arts
2009-04-03 01:36 . 2008-10-16 18:06 208744 —-a-w c:\windows\system32\muweb.dll
2009-04-03 01:36 . 2008-10-16 18:06 268648 —-a-w c:\windows\system32\mucltui.dll
2009-04-03 01:29 . 2006-10-26 23:56 32592 —-a-w c:\windows\system32\msonpmon.dll
2009-04-03 01:27 . 2009-04-03 01:27 ——– d—–w c:\program files\MSBuild
2009-04-03 01:26 . 2009-04-03 01:26 ——– d—–w c:\program files\Microsoft.NET
2009-04-03 01:24 . 2009-04-03 01:24 ——– d—–w c:\program files\Microsoft Visual Studio 8
2009-04-03 01:24 . 2009-04-03 01:33 ——– d—–w c:\windows\SHELLNEW
2009-04-03 01:23 . 2009-04-03 01:23 ——– d—–w c:\documents and settings\Eko\Local Settings\Application Data\Microsoft Help
2009-04-03 01:23 . 2009-04-15 10:10 ——– d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-03 01:23 . 2009-04-03 01:23 ——– d–h–r C:\MSOCache
2009-04-03 01:16 . 2005-05-26 19:34 2297552 —-a-w c:\windows\system32\d3dx9_26.dll
2009-04-03 00:56 . 2009-04-03 00:56 ——– d—–w c:\documents and settings\Eko\Application Data\DAEMON Tools
2009-04-03 00:56 . 2009-04-03 00:56 ——– d—–w c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-04-03 00:55 . 2009-04-03 00:55 ——– d—–w c:\program files\DAEMON Tools Lite
2009-04-03 00:52 . 2009-04-03 00:57 ——– d—–w c:\documents and settings\Eko\Application Data\DAEMON Tools Lite
2009-04-03 00:34 . 2009-04-03 00:52 717296 —-a-w c:\windows\system32\drivers\sptd.sys
2009-04-03 00:23 . 2009-04-03 01:01 83094 —-a-w c:\windows\War3Unin.dat
2009-04-03 00:23 . 2009-04-03 01:00 2829 —-a-w c:\windows\War3Unin.pif
2009-04-03 00:23 . 2009-04-03 01:00 139264 —-a-w c:\windows\War3Unin.exe
2009-04-03 00:22 . 2009-04-11 16:20 ——– d—–w c:\program files\Warcraft III
2009-04-02 23:12 . 2009-04-02 23:12 ——– d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2009-04-02 22:33 . 2009-04-02 22:33 ——– d—–w c:\program files\Bonjour
2009-04-02 22:27 . 2009-04-02 22:27 ——– d—–w c:\program files\Common Files\Macrovision Shared
2009-04-02 22:10 . 2009-04-02 22:10 ——– d—–w c:\program files\Veoh Networks
2009-04-02 21:50 . 2009-04-02 21:55 ——– d—–w c:\documents and settings\Eko\Application Data\ZumoDrive
2009-04-02 21:50 . 2009-04-01 20:51 146264 —-a-w c:\windows\system32\drivers\cbfs.sys
2009-04-02 21:50 . 2009-04-02 21:50 ——– d—–w c:\program files\Zecter
2009-04-02 21:46 . 2009-04-11 14:23 ——– d—–w c:\program files\Garena
2009-04-02 21:45 . 2009-04-02 21:45 ——– d—–w c:\documents and settings\Eko\Application Data\TrueCrypt
2009-04-02 21:44 . 2009-04-02 21:44 215872 —-a-w c:\windows\system32\drivers\truecrypt.sys
2009-04-02 21:43 . 2009-04-02 21:44 ——– d—–w c:\program files\TrueCrypt
2009-04-02 21:42 . 2009-04-02 21:48 ——– d—–w c:\documents and settings\Eko\Application Data\ICQ
2009-04-02 21:42 . 2009-04-02 21:49 ——– d—–w c:\program files\ICQ6.5
2009-04-02 21:39 . 2009-04-13 12:40 ——– d—–w c:\documents and settings\Eko\Application Data\Vbuzzer Messenger
2009-04-02 21:39 . 2007-11-02 08:06 57344 —-a-w c:\windows\system32\FaxMonitor.dll
2009-04-02 21:39 . 2007-11-02 09:00 245760 —-a-w c:\windows\system32\FaxHelper.exe
2009-04-02 21:39 . 2009-04-02 21:39 ——– d—–w c:\program files\vbuzzer
2009-04-02 21:37 . 2009-04-02 21:37 ——– d—–w c:\documents and settings\Eko\Application Data\Media Player Classic
2009-04-02 21:36 . 2009-04-02 21:36 ——– d—–w c:\documents and settings\Eko\Local Settings\Application Data\Real
2009-04-02 21:36 . 2009-04-02 21:36 ——– d—–w c:\program files\Real Alternative
2009-04-02 21:34 . 2009-04-02 21:34 ——– d—–w c:\program files\Combined Community Codec Pack
2009-04-02 21:19 . 2009-04-02 21:19 ——– d—–w c:\documents and settings\Eko\Local Settings\Application Data\Yahoo
2009-04-02 21:16 . 2009-04-02 21:16 ——– d—–w c:\documents and settings\Eko\Application Data\Yahoo!
2009-04-02 21:15 . 2009-04-02 21:15 56 —ha-w c:\windows\system32\ezsidmv.dat
2009-04-02 21:15 . 2009-04-26 12:25 ——– d—–w c:\documents and settings\Eko\Application Data\skypePM
2009-04-02 21:15 . 2009-04-02 21:19 ——– d—–w c:\documents and settings\All Users\Application Data\Yahoo!

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-27 15:49 . 2009-04-27 15:49 4352 —-a-w c:\windows\Internet Logs\tvDebug.zip
2009-04-03 14:24 . 2006-07-25 23:01 93512 —-a-w c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-03 01:19 . 2006-07-24 18:08 ——– d–h–w c:\program files\InstallShield Installation Information
2009-04-02 22:34 . 2006-07-24 19:35 ——– d—–w c:\program files\Common Files\Adobe
2009-04-02 17:21 . 2006-07-24 17:44 86811 —-a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-04-02 16:58 . 2006-07-24 18:56 ——– d—–w c:\program files\Windows Media Connect
2009-04-02 16:58 . 2009-04-02 15:51 126 —-a-w c:\documents and settings\Eko\Local Settings\Application Data\fusioncache.dat
2009-04-02 15:57 . 2006-07-24 18:53 ——– d—–w c:\program files\Java
2009-04-02 15:51 . 2009-04-02 15:51 0 —ha-r c:\windows\system32\drivers\Sony_VGN-FE790G.mrk
2009-04-02 15:43 . 2009-04-02 15:43 ——– d—–w c:\program files\Common Files\InterVideo
2009-04-02 15:43 . 2009-04-02 15:43 ——– d—–w c:\program files\InterVideo
2009-04-02 15:43 . 2006-07-24 19:27 ——– d—–w c:\program files\Sony
2009-04-02 15:34 . 2006-07-24 18:08 ——– d—–w c:\program files\Common Files\Sony Shared
2009-04-02 15:32 . 2009-04-02 15:31 ——– d—–w c:\program files\Quicken
2009-04-02 15:31 . 2009-04-02 15:31 ——– d—–w c:\program files\Common Files\Palo Alto Software
2009-04-02 15:31 . 2009-04-02 15:31 ——– d—–w c:\program files\Common Files\Intuit
2009-03-16 18:18 . 2009-04-12 14:16 69448 —-a-w c:\windows\system32\XAPOFX1_3.dll
2009-03-16 18:18 . 2009-04-12 14:16 517448 —-a-w c:\windows\system32\XAudio2_4.dll
2009-03-16 18:18 . 2009-04-12 14:16 235352 —-a-w c:\windows\system32\xactengine3_4.dll
2009-03-16 18:18 . 2009-04-12 14:16 22360 —-a-w c:\windows\system32\X3DAudio1_6.dll
2009-03-09 19:27 . 2009-04-12 14:16 453456 —-a-w c:\windows\system32\d3dx10_41.dll
2009-03-09 19:27 . 2009-04-12 14:16 4178264 —-a-w c:\windows\system32\D3DX9_41.dll
2009-03-09 19:27 . 2009-04-12 14:16 1846632 —-a-w c:\windows\system32\D3DCompiler_41.dll
2009-03-08 09:34 . 2006-07-24 17:27 914944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 09:34 . 2006-07-24 17:27 43008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 09:33 . 2006-07-24 17:27 18944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 09:33 . 2006-07-24 17:27 420352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 09:32 . 2006-07-24 17:27 72704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 09:32 . 2006-07-24 17:27 71680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 09:31 . 2006-07-24 17:27 34816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 09:31 . 2006-07-24 17:27 48128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 09:31 . 2006-07-24 17:27 45568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 09:22 . 2006-07-24 17:27 156160 —-a-w c:\windows\system32\msls31.dll
2009-03-06 14:22 . 2006-07-24 17:27 284160 —-a-w c:\windows\system32\pdh.dll
2009-02-09 12:10 . 2006-07-24 17:27 729088 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 12:10 . 2006-07-24 17:27 401408 —-a-w c:\windows\system32\rpcss.dll
2009-02-09 12:10 . 2006-07-24 17:27 714752 —-a-w c:\windows\system32\ntdll.dll
2009-02-09 12:10 . 2006-07-24 17:27 617472 —-a-w c:\windows\system32\advapi32.dll
2009-02-09 11:13 . 2006-07-24 17:27 1846784 —-a-w c:\windows\system32\win32k.sys
2009-02-06 22:52 . 2009-02-06 22:52 49504 —-a-w c:\windows\system32\sirenacm.dll
2009-02-06 11:11 . 2006-07-24 17:27 110592 —-a-w c:\windows\system32\services.exe
2009-02-06 11:06 . 2004-08-03 23:18 2145280 —-a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 10:39 . 2006-07-24 17:27 35328 —-a-w c:\windows\system32\sc.exe
2009-02-06 10:32 . 2004-08-03 22:59 2023936 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 19:59 . 2006-07-24 17:27 56832 —-a-w c:\windows\system32\secur32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00Zecter]
@="{D25B32FE-CB96-491A-98FF-AD59DA382D69}"
[HKEY_CLASSES_ROOT\CLSID\{D25B32FE-CB96-491A-98FF-AD59DA382D69}]
2009-04-01 20:51 634368 —-a-w c:\program files\Zecter\ZumoDrive\ShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\01Zecter]
@="{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}"
[HKEY_CLASSES_ROOT\CLSID\{EB24CA6D-F315-4A81-AC1A-C79CFD77F3F5}]
2009-04-01 20:51 634368 —-a-w c:\program files\Zecter\ZumoDrive\ShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\02Zecter]
@="{B3C78E40-6B64-47C3-AE34-60B770881EB8}"
[HKEY_CLASSES_ROOT\CLSID\{B3C78E40-6B64-47C3-AE34-60B770881EB8}]
2009-04-01 20:51 634368 —-a-w c:\program files\Zecter\ZumoDrive\ShellExt.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\03Zecter]
@="{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}"
[HKEY_CLASSES_ROOT\CLSID\{622AFE52-33F6-4D9F-9966-E0BC52D7D69D}]
2009-04-01 20:51 634368 —-a-w c:\program files\Zecter\ZumoDrive\ShellExt.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-18 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-04-05 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-04-05 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-04-05 118784]
"VAIO Recovery"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-02 148888]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2006-06-28 217088]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-12 151552]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-08 7561216]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2006-02-14 176128]
"VAIOSurvey"="c:\program files\sony\vaio survey\surveysa.exe" [2005-06-13 258048]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-27 69632]
"PartSeal"="c:\windows\Sonysys\VAIO Recovery\PartSeal.exe" [2003-04-20 28672]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2006-03-15 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"Mouse Suite 98 Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2002-03-14 45056]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-24 29696]
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2009-4-2 245760]
Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-2-3 1753088]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-9 28672]
VPN Client.lnk - c:\windows\Installer\{4C271126-C295-4828-A901-5910AE0C258B}\Icon3E5562ED7.ico [2009-4-2 6144]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-03-09 21:51 73728 —-a-w c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\docume~1\ALLUSE~1\APPLIC~1\SPYWAR~1\sp_rsdel.exe \??\c:\docume~1\ALLUSE~1\APPLIC~1\SPYWAR~1\sp_rsdel.dat

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\vbuzzer\\VBuzzer.exe"=
"c:\\Program Files\\ICQ6.5\\ICQ.exe"=
"c:\\Program Files\\Garena\\Garena.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\SmartVoip.com\\SmartVoip\\SmartVoip.exe"=
"c:\\Program Files\\Intel\\Wireless\\Bin\\EvtEng.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16714:TCP"= 16714:TCP:BitComet 16714 TCP
"16714:UDP"= 16714:UDP:BitComet 16714 UDP

R3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [2008-12-10 64392]
R3 pelmouse;Mouse Suite Driver;c:\windows\system32\DRIVERS\pelmouse.sys [2002-06-29 17251]
R3 pelusblf;USB Mouse Low Filter Driver;c:\windows\system32\DRIVERS\pelusblf.sys [2001-07-24 7520]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-07 348752]
R3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-18 311872]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-04-27 33056]
R3 ThreatFire;ThreatFire; [x]
R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [2008-05-23 14976]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2009-04-27 130936]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-04-27 51488]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-04-27 39200]
S1 CbFs;CbFs;c:\windows\system32\drivers\cbfs.sys [2009-04-01 146264]
S1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2008-12-11 159600]
S1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\DRIVERS\savonaccesscontrol.sys [2009-04-02 110848]
S1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\DRIVERS\savonaccessfilter.sys [2009-04-02 38528]
S2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-18 7520337]
S2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2008-09-22 69632]
S2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [2008-08-21 98304]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\DRIVERS\SonyImgF.sys [2006-03-07 30080]
S3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-02-22 226304]


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2009-04-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
- - - - ORPHANS REMOVED - - - -

HKU-Default-Run-Windows Resurections - c:\windows\TEMP\whvn004lv6.exe
HKU-Default-Run-Diagnostic Manager - c:\windows\TEMP\555570992.exe


.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Add to Vbuzzer RSS list - c:\program files\vbuzzer\addurl.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
FF - ProfilePath - c:\documents and settings\Eko\Application Data\Mozilla\Firefox\Profiles\l20z0tc1.default\
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-27 17:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,75,d0,92,a6,be,c0,ef,44,bd,f4,1b,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,75,d0,92,a6,be,c0,ef,44,bd,f4,1b,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1348)
c:\windows\system32\VESWinlogon.dll

- - - - - - - > 'lsass.exe'(1408)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll

- - - - - - - > 'explorer.exe'(2660)
c:\program files\Zecter\ZumoDrive\ShellExt.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Cisco Systems\VPN Client\cvpnd.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
c:\program files\Sophos\AutoUpdate\ALsvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\program files\Apoint\ApntEx.exe
c:\windows\system32\dllhost.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\windows\system32\wscntfy.exe
c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\windows\system32\msiexec.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Sophos\Sophos Anti-Virus\SavMain.exe
.
**************************************************************************
.
Completion time: 2009-04-27 17:09 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-27 21:09

Pre-Run: 107,646,509,056 bytes free
Post-Run: 107,720,216,576 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

420 — E O F — 2009-04-15 16:04
How long have the redirections been occurring, and did you install anything prior to this happening? Also, does it happen with any particular browser, or all of them?
The redirections are observed only with firefox so far. Today, almost every time I search with google (keyword was management test), I had to click the result 4 or 5 times before the right website was shown. My antivirus kept telling me about several strange behaviors from the cache files firefox created and from the files quarantined in Qoobox folder. I did a full scan and removed them. Since then I have been using IE8 with inprivate browsing on.

Except malwarebytes antimalware and sywareblaster which I installed yesterday, the last time I installed something should be last month (it’s a game, Command and Conquer 3).

Just now, I ran full scan with Malwarebytes anti malware and the scanners picked nothing. Any ideas besides reinstalling the windows?




latest hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:01:09 PM, on 4/28/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
c:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\system32\ICO.EXE
C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
O4 - HKLM\..\Run: [VAIOSurvey] c:\program files\sony\vaio survey\surveysa.exe
O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe"
O4 - HKLM\..\Run: [PartSeal] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Add to Vbuzzer RSS list - C:\Program Files\vbuzzer\addurl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - c:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - c:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

–
End of file - 12001 bytes

Any ideas besides reinstalling the windows?

It's a wee bit early for such talk.

Download GooredFix by jpshortstuff from here and save it to your Desktop.
  • Double click the file to run it.
  • Enter 1 to select that option and hit .
  • A text file, Gooredlog.txt will open, and when you close it, it will be saved to your Desktop.
  • Copy the contents into your next reply.
  • Running Option 2 may or may not be advised, so post the log from option 1 first!
Download a copy of DDS by sUBs from one of the following locations: Link1; Link2; Link3
  • Double click the tool to run it.
  • You can read the screen that appears, or not - the tool runs anyway.
  • When the tool has finished, two Notepad windows will appear.
  • You need to save both as they will disappear when closed.
  • File > Save As… from the Toolbar will allow you to do this.
  • Copy and Paste both logs into your next reply.
  • Please check after posting that both logs are complete.
ok, here it is GooredFix v1.92 by jpshortstuff Log created at 15:47 on 29/04/2009 running Option #1 (Eko) Firefox version 3.0.10 (en-US) =====Suspect Goored Entries===== C:\Program Files\Mozilla Firefox\extensions\{3C61A949-D8E6-4FD0-BE19-4CB9215B8250} =====Dumping Registry Values===== [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions] "Plugins"="C:\Program Files\Mozilla Firefox\plugins" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox 3.0.10\extensions] "Components"="C:\Program Files\Mozilla Firefox\components" [HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\extensions] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 15:51:01.23 on Wed 04/29/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1278 [GMT -4:00] AV: Sophos Anti-Virus *On-access scanning enabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe C:\WINDOWS\System32\svchost.exe -k eapsvcs svchost.exe C:\WINDOWS\System32\svchost.exe -k dot3svc C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe c:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe c:\Program Files\Sophos\AutoUpdate\ALsvc.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Apoint\Apoint.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe C:\WINDOWS\system32\ICO.EXE C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Windows Media Player\WMPNSCFG.exe C:\Program Files\Sophos\AutoUpdate\ALMon.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\SNDVOL32.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Eko\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank uInternet Settings,ProxyOverride = *.local BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [VAIO Recovery] c:\windows\sonysys\vaio recovery\PartSeal.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [SonyPowerCfg] "c:\program files\sony\vaio power management\SPMgr.exe" mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe mRun: [VAIO Update 2] "c:\program files\sony\vaio update 2\VAIOUpdt.exe" /Stationary mRun: [Mouse Suite 98 Daemon] ICO.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe mRun: [VAIOSurvey] c:\program files\sony\vaio survey\surveysa.exe mRun: [VAIOCameraUtility] "c:\program files\sony\vaio camera utility\VCUServe.exe" mRun: [PartSeal] c:\windows\sonysys\vaio recovery\PartSeal.exe mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoup~1.lnk - c:\program files\sophos\autoupdate\ALMon.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\toshiba\bluetooth toshiba stack\TosBtMng.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpoddt~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpotdd01.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{4c271126-c295-4828-a901-5910ae0c258b}\Icon3E5562ED7.ico IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm IE: Add to Vbuzzer RSS list - c:\program files\vbuzzer\addurl.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {E59EB121-F339-4851-A3BA-FE49C35617C2} - c:\program files\icq6.5\ICQ.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} - hxxp://esupport.sony.com/VaioInfo.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_07-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll Notify: VESWinlogon - VESWinlogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\eko\applic~1\mozilla\firefox\profiles\l20z0tc1.default\ FF - prefs.js: browser.search.selectedEngine - Wikipedia (en) FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll ============= SERVICES / DRIVERS =============== R1 CbFs;CbFs;c:\windows\system32\drivers\cbfs.sys [2009-4-2 146264] R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2009-4-2 110848] R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2009-4-2 38528] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -svaio_vedb –> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -sVAIO_VEDB [?] R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2008-9-22 69632] R2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2008-8-21 98304] R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2009-4-2 172032] R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\drivers\SonyImgF.sys [2006-7-24 30080] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-7-24 226304] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?] S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?] S3 pctplsg;pctplsg;\??\c:\windows\system32\drivers\pctplsg.sys –> c:\windows\system32\drivers\pctplsg.sys [?] S3 pelmouse;Mouse Suite Driver;c:\windows\system32\drivers\PELMOUSE.SYS [2006-7-24 17251] S3 pelusblf;USB Mouse Low Filter Driver;c:\windows\system32\drivers\pelusblf.sys [2006-7-24 7520] S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.exe -i vaio_vedb –> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.EXE -i VAIO_VEDB [?] S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\tfnetmon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?] S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344] S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2009-4-2 14976] =============== Created Last 30 ================ 2009-04-27 17:49 129,784 ——– c:\windows\system32\pxafs.dll 2009-04-27 17:49 –d—– c:\program files\DivX 2009-04-27 17:49 –d—– c:\program files\common files\DivX Shared 2009-04-27 16:52 a-dshr– C:\cmdcons 2009-04-27 16:51 161,792 a——- c:\windows\SWREG.exe 2009-04-27 16:51 98,816 a——- c:\windows\sed.exe 2009-04-27 16:50 –d-h— c:\windows\PIF 2009-04-27 15:24 27,648 a——- c:\windows\system32\lmppcsetup.exe 2009-04-27 15:17 –d—– c:\docume~1\eko\applic~1\Malwarebytes 2009-04-27 15:17 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-04-27 15:17 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-04-27 15:17 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-04-27 15:17 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-04-27 14:30 –d-h— c:\windows\system32\GroupPolicy 2009-04-27 13:28 –d—– c:\program files\Trend Micro 2009-04-27 13:20 138,384 a——- c:\windows\system32\drivers\tmcomm.sys 2009-04-27 13:12 –d—– c:\program files\SpywareBlaster 2009-04-27 11:31 –d—– c:\docume~1\alluse~1\applic~1\PC Tools 2009-04-25 12:17 –d—– c:\docume~1\eko\applic~1\DAEMON Tools Pro 2009-04-23 10:28 5,632 a——- c:\windows\system32\ptpusb.dll 2009-04-23 10:28 159,232 a——- c:\windows\system32\ptpusd.dll 2009-04-16 07:38 521 a——- C:\hpfr3420.xml 2009-04-16 07:36 –d—– c:\program files\HP 2009-04-16 07:36 214 a——- c:\windows\HP_48BitScanUpdatePatch.ini 2009-04-16 07:35 15,104 ac—— c:\windows\system32\dllcache\usbscan.sys 2009-04-16 07:35 15,104 a——- c:\windows\system32\drivers\usbscan.sys 2009-04-16 07:34 –d—– c:\program files\common files\Hewlett-Packard 2009-04-16 07:33 19,558 a——- c:\windows\hpoins01.dat 2009-04-16 07:33 16,606 ——– c:\windows\hpomdl01.dat 2009-04-16 07:22 25,856 ac—— c:\windows\system32\dllcache\usbprint.sys 2009-04-16 07:22 25,856 a——- c:\windows\system32\drivers\usbprint.sys 2009-04-15 16:24 90,112 a——- c:\windows\system32\dpl100.dll 2009-04-15 16:24 823,296 a——- c:\windows\system32\divx_xx0c.dll 2009-04-15 16:24 823,296 a——- c:\windows\system32\divx_xx07.dll 2009-04-15 16:24 815,104 a——- c:\windows\system32\divx_xx0a.dll 2009-04-15 16:24 802,816 a——- c:\windows\system32\divx_xx11.dll 2009-04-15 16:24 684,032 a——- c:\windows\system32\DivX.dll 2009-04-15 05:30 401,408 -c—— c:\windows\system32\dllcache\rpcss.dll 2009-04-15 05:30 284,160 -c—— c:\windows\system32\dllcache\pdh.dll 2009-04-15 05:30 35,328 -c—— c:\windows\system32\dllcache\sc.exe 2009-04-15 05:30 729,088 -c—— c:\windows\system32\dllcache\lsasrv.dll 2009-04-15 05:30 617,472 -c—— c:\windows\system32\dllcache\advapi32.dll 2009-04-15 05:30 473,600 -c—— c:\windows\system32\dllcache\fastprox.dll 2009-04-15 05:30 453,120 -c—— c:\windows\system32\dllcache\wmiprvsd.dll 2009-04-15 05:30 227,840 -c—— c:\windows\system32\dllcache\wmiprvse.exe 2009-04-15 05:30 110,592 -c—— c:\windows\system32\dllcache\services.exe 2009-04-15 05:30 714,752 -c—— c:\windows\system32\dllcache\ntdll.dll 2009-04-15 05:29 2,560 ——– c:\windows\system32\xpsp4res.dll 2009-04-15 05:29 1,203,922 -c—— c:\windows\system32\dllcache\sysmain.sdb 2009-04-15 05:29 215,552 -c—— c:\windows\system32\dllcache\wordpad.exe 2009-04-14 13:43 –d—– c:\docume~1\eko\applic~1\Thinstall 2009-04-13 08:45 –d—– c:\docume~1\eko\applic~1\SmartVoip 2009-04-13 08:44 –d—– c:\program files\SmartVoip.com 2009-04-12 12:13 –d—– c:\docume~1\eko\applic~1\Command & Conquer 3 Tiberium Wars 2009-04-12 10:34 –d—– c:\docume~1\eko\applic~1\Command & Conquer 3 Kane's Wrath 2009-04-12 10:15 1,493,528 a——- c:\windows\system32\D3DCompiler_39.dll 2009-04-12 10:13 –d—– c:\windows\Logs 2009-04-12 08:50 –d—– c:\program files\Team JPN 2009-04-05 15:50 –d—– C:\Downloads 2009-04-04 11:39 –d—– c:\windows\system32\Adobe 2009-04-03 12:07 –d—– c:\program files\DS-Monkey Audio Source 2009-04-03 11:47 –d—– c:\program files\BitComet 2009-04-03 08:37 –d—– c:\program files\Microsoft CAPICOM 2.1.0.2 2009-04-02 21:57 3,426,072 a——- c:\windows\system32\d3dx9_32.dll 2009-04-02 21:39 –d—– c:\program files\MSECache 2009-04-02 21:36 268,648 a——- c:\windows\system32\mucltui.dll 2009-04-02 21:36 208,744 a——- c:\windows\system32\muweb.dll 2009-04-02 21:36 27,496 a——- c:\windows\system32\mucltui.dll.mui 2009-04-02 21:29 32,592 a——- c:\windows\system32\msonpmon.dll 2009-04-02 21:24 –d—– c:\program files\Microsoft Visual Studio 8 2009-04-02 21:24 –d—– c:\windows\SHELLNEW 2009-04-02 21:16 2,297,552 a——- c:\windows\system32\d3dx9_26.dll 2009-04-02 20:56 –d—– c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite 2009-04-02 20:55 –d—– c:\program files\DAEMON Tools Lite 2009-04-02 20:52 –d—– c:\docume~1\eko\applic~1\DAEMON Tools Lite 2009-04-02 20:34 717,296 a——- c:\windows\system32\drivers\sptd.sys 2009-04-02 20:23 139,264 a——- c:\windows\War3Unin.exe 2009-04-02 20:23 83,094 a——- c:\windows\War3Unin.dat 2009-04-02 20:23 2,829 a——- c:\windows\War3Unin.pif 2009-04-02 19:54 0 a——- c:\windows\tosOBEX.INI 2009-04-02 19:42 98 a——- c:\windows\WirelessFTP.INI 2009-04-02 18:33 –d—– c:\program files\Bonjour 2009-04-02 18:27 –d—– c:\program files\common files\Macrovision Shared 2009-04-02 18:10 –d—– c:\program files\Veoh Networks 2009-04-02 17:53 –d—– c:\windows\pss 2009-04-02 17:50 –d—– c:\docume~1\eko\applic~1\ZumoDrive 2009-04-02 17:50 146,264 a——- c:\windows\system32\drivers\cbfs.sys 2009-04-02 17:50 –d—– c:\program files\Zecter 2009-04-02 17:46 –d—– c:\program files\Garena 2009-04-02 17:45 –d—– c:\docume~1\eko\applic~1\TrueCrypt 2009-04-02 17:44 215,872 a——- c:\windows\system32\drivers\truecrypt.sys 2009-04-02 17:43 –d—– c:\program files\TrueCrypt 2009-04-02 17:42 –d—– c:\program files\ICQ6.5 2009-04-02 17:39 –d—– c:\docume~1\eko\applic~1\Vbuzzer Messenger 2009-04-02 17:39 245,760 a——- c:\windows\system32\FaxHelper.exe 2009-04-02 17:39 57,344 a——- c:\windows\system32\FaxMonitor.dll 2009-04-02 17:39 –d—– c:\program files\vbuzzer 2009-04-02 17:36 –d—– c:\program files\Real Alternative 2009-04-02 17:34 –d—– c:\program files\Combined Community Codec Pack 2009-04-02 17:15 56 a—h— c:\windows\system32\ezsidmv.dat 2009-04-02 17:15 –d—– c:\program files\Yahoo! 2009-04-02 17:13 –d–r– c:\program files\Skype 2009-04-02 16:54 –d—– c:\documents and settings\eko\Tracing 2009-04-02 16:51 –d—– c:\program files\Microsoft 2009-04-02 16:51 –d—– c:\program files\Windows Live SkyDrive 2009-04-02 16:47 –d—– c:\program files\common files\Windows Live 2009-04-02 14:37 –d—– c:\program files\MSXML 4.0 2009-04-02 14:15 21,504 a——- c:\windows\system32\hidserv.dll 2009-04-02 14:15 14,592 a——- c:\windows\system32\drivers\kbdhid.sys 2009-04-02 14:15 32,128 a——- c:\windows\system32\drivers\usbccgp.sys 2009-04-02 14:07 130,104 a——- c:\windows\system32\sdccoinstaller.dll 2009-04-02 14:07 –d—– c:\program files\SecureW2 2009-04-02 14:07 –d—– c:\program files\common files\Cisco Systems 2009-04-02 14:07 23,552 a——- c:\windows\system32\SophosBootTasks.exe 2009-04-02 14:07 –d—– c:\windows\tracing 2009-04-02 14:07 –d—– c:\program files\Sophos 2009-04-02 14:07 –d—– c:\docume~1\alluse~1\applic~1\Sophos 2009-04-02 14:05 110,848 a——- c:\windows\system32\drivers\savonaccesscontrol.sys 2009-04-02 14:05 38,528 a——- c:\windows\system32\drivers\savonaccessfilter.sys 2009-04-02 14:05 14,976 a——- c:\windows\system32\drivers\SophosBootDriver.sys 2009-04-02 14:05 –d—– C:\savwsa 2009-04-02 13:58 185,344 ac—— c:\windows\system32\dllcache\thawbrkr.dll 2009-04-02 13:57 125,328 a——- c:\windows\system32\drivers\dne2000.sys 2009-04-02 13:57 106,768 a——- c:\windows\system32\dneinobj.dll 2009-04-02 13:57 –d—– c:\program files\common files\Deterministic Networks 2009-04-02 13:57 –d—– c:\program files\Cisco Systems 2009-04-02 13:57 1,594 a——- c:\windows\VPNInstall.MIF 2009-04-02 13:18 –d—– c:\windows\system32\scripting 2009-04-02 13:18 –d—– c:\windows\system32\en 2009-04-02 13:18 –d—– c:\windows\system32\bits 2009-04-02 13:18 –d—– c:\windows\l2schemas 2009-04-02 13:17 –d—– c:\windows\ServicePackFiles 2009-04-02 13:16 –d—– c:\windows\network diagnostic 2009-04-02 13:00 –d—– c:\program files\Windows Media Connect 2 2009-04-02 12:59 –d—– c:\windows\system32\LogFiles 2009-04-02 12:45 –dsh— c:\documents and settings\eko\PrivacIE 2009-04-02 12:45 –dsh— c:\documents and settings\eko\IECompatCache 2009-04-02 12:43 –dsh— c:\documents and settings\eko\IETldCache 2009-04-02 12:42 –d—– c:\windows\ie8updates 2009-04-02 12:29 -cd-h— c:\windows\ie8 2009-04-02 12:24 –d—– c:\docume~1\eko\applic~1\URSoft 2009-04-02 12:24 –d—– c:\program files\Your Uninstaller 2008 2009-04-02 12:14 272,128 -c—— c:\windows\system32\dllcache\bthport.sys 2009-04-02 12:14 2,145,280 -c—— c:\windows\system32\dllcache\ntkrnlmp.exe 2009-04-02 12:14 2,189,056 -c—— c:\windows\system32\dllcache\ntoskrnl.exe 2009-04-02 12:14 2,023,936 -c—— c:\windows\system32\dllcache\ntkrpamp.exe 2009-04-02 12:14 2,066,048 -c—— c:\windows\system32\dllcache\ntkrnlpa.exe 2009-04-02 12:13 105,984 -c—— c:\windows\system32\dllcache\iecompat.dll 2009-04-02 12:10 203,136 -c—— c:\windows\system32\dllcache\rmcast.sys 2009-04-02 12:10 455,296 -c—— c:\windows\system32\dllcache\mrxsmb.sys 2009-04-02 12:10 333,952 -c—— c:\windows\system32\dllcache\srv.sys 2009-04-02 12:10 331,776 -c—— c:\windows\system32\dllcache\msadce.dll 2009-04-02 12:10 691,712 -c—— c:\windows\system32\dllcache\inetcomm.dll 2009-04-02 12:10 247,326 -c—— c:\windows\system32\dllcache\strmdll.dll 2009-04-02 12:10 337,408 -c—— c:\windows\system32\dllcache\netapi32.dll 2009-04-02 12:10 1,106,944 -c—— c:\windows\system32\dllcache\msxml3.dll 2009-04-02 12:09 –d—– c:\windows\system32\PreInstall 2009-04-02 11:58 410,984 a——- c:\windows\system32\deploytk.dll 2009-04-02 11:58 73,728 a——- c:\windows\system32\javacpl.cpl 2009-04-02 11:51 –d—– c:\docume~1\eko\applic~1\Intuit 2009-04-02 11:51 –d—– c:\documents and settings\Eko 2009-04-02 11:51 0 a—hr– c:\windows\system32\drivers\Sony_VGN-FE790G.mrk 2009-04-02 11:49 –d—– c:\windows\system32\SoftwareDistribution 2009-04-02 11:44 759,296 ac—— c:\windows\system32\dllcache\VGX.dll 2009-04-02 11:44 802,104 a——- c:\windows\WINDOWSXP-KB925486-X86-ENU.bak 2009-04-02 11:44 726,528 ac—— c:\windows\system32\dllcache\jscript.dll 2009-04-02 11:43 –d—– c:\program files\common files\InterVideo 2009-04-02 11:43 –d—– c:\program files\InterVideo 2009-04-02 11:42 4 a——- c:\windows\Pix11.dat 2009-04-02 11:42 –d—– c:\program files\Microsoft Digital Image 2006 2009-04-02 11:41 2,041 a—h— C:\IPH.PH 2009-04-02 11:41 –d—– c:\program files\common files\AOL 2009-04-02 11:40 –d—– c:\program files\Toshiba 2009-04-02 11:37 10,344 a——- c:\windows\system32\drivers\symlcbrd.sys 2009-04-02 11:35 –d—– c:\program files\common files\Symantec Shared 2009-04-02 11:35 –d—– c:\documents and settings\all users\ImageConverter2 2009-04-02 11:33 –d—– c:\docume~1\alluse~1\applic~1\VAIO Media Platform 2009-04-02 11:32 2,981,888 a——- c:\windows\system32\iplw7.dll 2009-04-02 11:32 2,973,696 a——- c:\windows\system32\ipla6.dll 2009-04-02 11:32 2,785,280 a——- c:\windows\system32\iplm6.dll 2009-04-02 11:32 2,686,976 a——- c:\windows\system32\iplm5.dll 2009-04-02 11:32 2,531,328 a——- c:\windows\system32\iplp6.dll 2009-04-02 11:32 2,502,656 a——- c:\windows\system32\iplpx.dll 2009-04-02 11:32 53,248 a——- c:\windows\system32\ipl.dll 2009-04-02 11:32 19,968 a——- c:\windows\system32\Cpuinf32.dll 2009-04-02 11:32 –d—– c:\windows\Downloaded Installations 2009-04-02 11:32 1,667,072 a——- c:\windows\system32\cdintf250.dll 2009-04-02 11:31 –d—– c:\program files\common files\Palo Alto Software 2009-04-02 11:31 –d—– c:\program files\common files\Intuit 2009-04-02 11:31 –d—– c:\program files\Quicken 2009-04-02 11:31 174 a——- c:\windows\QUICKEN.INI 2009-04-02 11:31 –d—– c:\docume~1\alluse~1\applic~1\Intuit 2009-04-02 11:30 376 a——- c:\windows\ODBC.INI 2009-04-02 11:30 24,816 a——- c:\windows\system32\mdimon.dll 2009-04-02 11:27 –d—– c:\docume~1\alluse~1\applic~1\Digital Interactive Systems Corporation 2009-04-02 11:25 2,154 a——- c:\windows\system32\tmmute.ini 2009-04-02 11:25 –d—– c:\documents and settings\all users\DSD Direct 2009-04-02 11:25 91,648 a——- c:\windows\system32\SonyAIds.dll 2009-04-02 11:25 75,776 a——- c:\windows\system32\SonyAIwo.dll 2009-04-02 11:25 38,400 a——- c:\windows\system32\SonyAIwd.dll 2009-04-02 11:24 –d—– c:\documents and settings\all users\SonicStage Mastering Studio 2009-04-02 11:23 770,048 a——- c:\windows\system32\CDDBUISony.dll 2009-04-02 11:23 643,072 a——- c:\windows\system32\CDDBControlSony.dll 2009-04-02 11:23 585,728 a——- c:\windows\system32\CddbMusicIDSony.dll 2009-04-02 11:23 520,192 a——- c:\windows\system32\CddbPlaylist2Sony.dll 2009-04-02 11:23 73,728 a——- c:\windows\system32\CddbLinkSony.dll ==================== Find3M ==================== 2009-04-15 16:25 120,056 ——– c:\windows\system32\pxcpyi64.exe 2009-04-15 16:25 118,520 ——– c:\windows\system32\pxinsi64.exe 2009-04-15 16:25 43,528 ——– c:\windows\system32\drivers\pxhelp20.sys 2009-04-02 13:21 86,811 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2009-03-16 14:18 517,448 a——- c:\windows\system32\XAudio2_4.dll 2009-03-16 14:18 235,352 a——- c:\windows\system32\xactengine3_4.dll 2009-03-16 14:18 69,448 a——- c:\windows\system32\XAPOFX1_3.dll 2009-03-16 14:18 22,360 a——- c:\windows\system32\X3DAudio1_6.dll 2009-03-09 15:27 4,178,264 a——- c:\windows\system32\D3DX9_41.dll 2009-03-09 15:27 1,846,632 a——- c:\windows\system32\D3DCompiler_41.dll 2009-03-09 15:27 453,456 a——- c:\windows\system32\d3dx10_41.dll 2009-03-08 05:34 914,944 a——- c:\windows\system32\wininet.dll 2009-03-08 05:34 43,008 a——- c:\windows\system32\licmgr10.dll 2009-03-08 05:33 18,944 a——- c:\windows\system32\corpol.dll 2009-03-08 05:33 420,352 a——- c:\windows\system32\vbscript.dll 2009-03-08 05:32 72,704 a——- c:\windows\system32\admparse.dll 2009-03-08 05:32 71,680 a——- c:\windows\system32\iesetup.dll 2009-03-08 05:31 34,816 a——- c:\windows\system32\imgutil.dll 2009-03-08 05:31 48,128 a——- c:\windows\system32\mshtmler.dll 2009-03-08 05:31 45,568 a——- c:\windows\system32\mshta.exe 2009-03-08 05:22 156,160 a——- c:\windows\system32\msls31.dll 2009-03-06 10:22 284,160 a——- c:\windows\system32\pdh.dll 2009-02-09 08:10 729,088 a——- c:\windows\system32\lsasrv.dll 2009-02-09 08:10 714,752 a——- c:\windows\system32\ntdll.dll 2009-02-09 08:10 617,472 a——- c:\windows\system32\advapi32.dll 2009-02-09 08:10 401,408 a——- c:\windows\system32\rpcss.dll 2009-02-09 07:13 1,846,784 a——- c:\windows\system32\win32k.sys 2009-02-06 18:52 49,504 a——- c:\windows\system32\sirenacm.dll 2009-02-06 07:11 110,592 a——- c:\windows\system32\services.exe 2009-02-06 07:06 2,145,280 a——- c:\windows\system32\ntoskrnl.exe 2009-02-06 06:39 35,328 a——- c:\windows\system32\sc.exe 2009-02-06 06:32 2,023,936 a——- c:\windows\system32\ntkrnlpa.exe 2009-02-03 15:59 56,832 a——- c:\windows\system32\secur32.dll ============= FINISH: 15:51:31.04 ===============

Attachments:

Looks like GooredFix spotted something it didn't like - we'll see if this is what is causing your redirects.
Ensure that all Firefox windows are closed and then run Option 2 in GooredFix - you'll need to answer y at the appropriate moment.
Let me have the contents of the log that appears and also give the browser a run out and let me know how the computer is behaving now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI