This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Virus Assistance

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I received an email from What the Tech and mistakenly clicked on the link downloading a virus. Yeah, I'm a dumbA%s for that!! Any way I believe I've removed it but I would like some assistance to verify it's gone if you'd be so kind.

I'm using Windows XP Pro, SP3, Norton internet security (which has just expired and I want to replace; any recommendation on internet security/antivurs software for a small business on a home network would be very appreciated. I've used trendmicro, avg free, norton system works and internet security all seem to suck and let things thru. I mainly use Mozilla and IE as a backup. Thanks in advance.

Here's my HIjackThis LoG and Malawarebytes log. Plus I've already run ATF Cleaner.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:15:37 AM, on 6/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Maxtor\ManagerApp\msssort.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\WINDOWS\system32\java.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\ACT\Act for Windows\ActSage.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search 2\Toolbar\ToolbarContainer101000311.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\ActSage.exe" -preload
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [mssSort] "C:\Program Files\Maxtor\ManagerApp\msssort.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKCU\..\Run: [Act.Outlook.Service] "C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160443373656
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Maxtor Service (Maxtor Sync Services) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 13085 bytes


_____________________________
MalawareBytes Log

Malwarebytes' Anti-Malware 1.37
Database version: 2214
Windows 5.1.2600 Service Pack 3

6/3/2009 8:31:30 AM
mbam-log-2009-06-03 (08-31-30).txt

Scan type: Full Scan (C:\|)
Objects scanned: 242321
Time elapsed: 13 hour(s), 20 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\15246404 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\95256396 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysldtray (Worm.Koobface) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\All Users\Application Data\15246404 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Application Data\95256396 (Rogue.Multiple.H) -> Quarantined and deleted successfully.

Files Infected:
c:\documents and settings\all users\application data\15246404\15246404.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\15246404\15246404.glu (Rogue.Multiple.H) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\15246404\pc15246404cnf (Rogue.Multiple.H) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\15246404\pc15246404ins (Rogue.Multiple.H) -> Quarantined and deleted successfully.
c:\documents and settings\all users\application data\95256396\95256396.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.
C:\WINDOWS\ld08.exe (Worm.Koobface) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\str.sys (Rootkit.Agent) -> Delete on reboot.
Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous.
  • Most infections require more than one round to properly eradicate.
  • Absence of symptoms does not always mean the job is complete.
  • You can be certain that I will advise you when the computer is clean.
  • Kindly follow my instructions in the order posted.
  • Please resist the urge to run further scans or fix items on your own without my direction.



Please do the following:

STEP #1

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



STEP #2


Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.


Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
So my computer is very sluggish. Before I read your posting this morning I did another Malawarebytes scan and it removed more file as per your statement I'm not doing anything until you instruct me to. However, I cannot disable my scripting for dds because my norton just expired and I need a new one to disable it; even though I didn't know how to disable it in the past either. Do you recommend any good antivirus/internet security software provider or package? I'm also looking for a ghosting software. Anyhow, here's the log from malawarebytes and then I have the dds ones and then germ Malwarebytes' Anti-Malware 1.37 Database version: 2248 Windows 5.1.2600 Service Pack 3 6/8/2009 8:28:24 AM mbam-log-2009-06-08 (08-28-24).txt Scan type: Quick Scan Objects scanned: 89893 Time elapsed: 8 minute(s), 4 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 9 Registry Values Infected: 2 Registry Data Items Infected: 4 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\wininetapp.wininet (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{b360243e-09e8-402f-8721-00b6798089ad} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4b66e1df-4de3-4cda-83b5-11673eadab0b} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{9692be2f-eb8f-49d9-a11c-c24c1ef734d5} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{39fc2065-c9c7-49cd-8942-44cc2dedc844} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39fc2065-c9c7-49cd-8942-44cc2dedc844} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\wininetapp.wininet.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\WinPC Defender (Rogue.WinPCDefender) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Rootkit.Trace) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\Control Panel\don't load\scui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Control Panel\don't load\wscui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\ieocx.dll (Trojan.BHO) -> Quarantined and deleted successfully. c:\documents and settings\Jimmy\local settings\Temp\c.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\487656.bat (Malware.Trace) -> Quarantined and deleted successfully. _______________________________________________________ DDS.txt DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 15:14:52.59 on Mon 06/08/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.371 [GMT -7:00] AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe "C:\WINDOWS\system32\svchost.exe" C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\Explorer.EXE C:\Program Files\Canon\CAL\CALMAIN.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\java.exe C:\Program Files\Maxtor\ManagerApp\msssort.exe C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE C:\PROGRA~1\COPERN~1\DESKTO~1.EXE C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Documents and Settings\Jimmy\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.5\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile: {d5233fcd-d258-4903-89b8-fb1568e7413d} - mscoree.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.5\CoIEPlg.dll TB: Copernic Desktop Search - Home Toolbar: {4a1c6093-14f9-44d7-860e-5d265cfca9d9} - c:\program files\copernic desktop search 2\toolbar\ToolbarContainer101000311.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll TB: {4FC00340-F75E-4EB5-880C-651A8A76965F} - No File TB: {968631B6-4729-440D-9BF4-251F5593EC9A} - No File EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll EB: Copernic Desktop Search - Home Toolbar: {4a1c6093-14f9-44d7-860e-5d265cfca9d9} - c:\program files\copernic desktop search 2\toolbar\ToolbarContainer101000311.dll EB: Copernic Desktop Search - Home: {9c3fca1f-99e3-48f2-a7f4-dd3931b2f99a} - c:\program files\copernic desktop search 2\DeskbandIntegration302000044.dll uRun: [Act.Outlook.Service] "c:\program files\act\act for windows\Act.Outlook.Service.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe uRun: [Copernic Desktop Search - Home] "c:\program files\copernic desktop search 2\DesktopSearchService.exe" /tray mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [Act! Preloader] "c:\program files\act\act for windows\ActSage.exe" -preload mRun: [Acrobat Assistant 7.0] "c:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe" mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [mssSort] "c:\program files\maxtor\managerapp\msssort.exe" mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000002}\SC_Acrobat.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe uPolicies-explorer: NoViewOnDrive = 0 (0x0) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll IE: {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc3.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160443373656 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\google\google toolbar\component\fastsearch_A8904FB862BD9564.dll Notify: igfxcui - igfxdev.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\jimmy\applic~1\mozilla\firefox\profiles\fqbk8c9u.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\program files\google\picasa3\npPicasa3.dll ============= SERVICES / DRIVERS =============== R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-1-25 149352] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-1-25 149352] R2 LinksysUpdater;Linksys Updater;c:\program files\linksys\linksys updater\bin\LinksysUpdater.exe [2008-1-15 204800] R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-1-25 149352] R2 Maxtor Sync Services;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2008-8-5 181600] R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-2-26 101936] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090604.021\NAVENG.SYS [2009-6-4 89104] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090604.021\NAVEX15.SYS [2009-6-4 876144] R3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2008-6-5 1245064] RUnknown zpflnr;zpflnr; [x] S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888] S3 RemoteControl-USBLAN;RemoteControl-USBLAN;c:\windows\system32\drivers\rcblan.sys [2008-1-28 39704] =============== Created Last 30 ================ 2009-06-05 12:06 26,112 a——- c:\windows\system32\stu2.exe ==================== Find3M ==================== 2009-06-08 10:00 1,890 a–sh— c:\windows\system32\KGyGaAvL.sys 2009-06-05 12:06 22,528 a—h— c:\windows\system32\userinit.exe 2009-05-26 13:20 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-26 13:19 19,096 a——- c:\windows\system32\drivers\mbam.sys 2007-03-09 13:41 630,784 ac—— c:\documents and settings\jimmy\GoToAssist_chat2way__317_en.exe 2007-03-14 16:27 88 —shr– c:\windows\system32\7DF316C31A.sys 2008-09-25 15:32 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092520080926\index.dat ============= FINISH: 15:15:16.00 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-05-14.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 10/5/2006 4:53:47 PM System Uptime: 6/8/2009 8:30:48 AM (7 hours ago) Motherboard: Dell Inc. | | Processor: Genuine Intel® CPU T2300 @ 1.66GHz | Microprocessor | 1662/166mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 88 GiB total, 4.224 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP803: 6/5/2009 1:10:10 PM - System Checkpoint RP804: 6/5/2009 1:10:11 PM - 4-11-09 prior to atf.cleaner and mbam RP805: 6/5/2009 1:10:12 PM - 4-11-09 after scan all clean!! RP806: 6/5/2009 1:10:12 PM - System Checkpoint RP807: 6/5/2009 1:10:12 PM - System Checkpoint RP808: 6/5/2009 1:10:13 PM - System Checkpoint RP809: 6/5/2009 1:10:14 PM - System Checkpoint RP810: 6/5/2009 1:10:15 PM - Removed Logitech Desktop Messenger RP811: 6/5/2009 1:10:15 PM - Logitech SetPoint Mouse and Keyboard Device Drivers RP812: 6/5/2009 1:10:16 PM - Software Distribution Service 3.0 RP813: 6/5/2009 1:10:17 PM - Removed J2SE Runtime Environment 5.0 Update 6 RP814: 6/5/2009 1:10:17 PM - Removed J2SE Runtime Environment 5.0 Update 9 RP815: 6/5/2009 1:10:18 PM - System Checkpoint RP816: 6/5/2009 1:10:18 PM - System Checkpoint RP817: 6/5/2009 1:10:18 PM - System Checkpoint RP818: 6/5/2009 1:10:18 PM - System Checkpoint RP819: 6/5/2009 1:10:18 PM - System Checkpoint RP820: 6/5/2009 1:10:18 PM - System Checkpoint RP821: 6/5/2009 1:10:19 PM - Installed Maxtor Central Axis Manager RP822: 6/5/2009 1:10:19 PM - System Checkpoint RP823: 6/5/2009 1:10:19 PM - Software Distribution Service 3.0 RP824: 6/5/2009 1:10:19 PM - System Checkpoint RP825: 6/5/2009 1:10:19 PM - System Checkpoint RP826: 6/5/2009 1:10:19 PM - System Checkpoint RP827: 6/5/2009 1:10:20 PM - System Checkpoint RP828: 6/5/2009 1:10:20 PM - System Checkpoint RP829: 6/5/2009 1:10:20 PM - Software Distribution Service 3.0 RP830: 6/5/2009 1:10:21 PM - System Checkpoint RP831: 6/5/2009 1:10:22 PM - Software Distribution Service 3.0 RP832: 6/5/2009 1:10:22 PM - System Checkpoint RP833: 6/5/2009 1:10:23 PM - Installed Windows XP WgaNotify. RP834: 6/5/2009 1:10:24 PM - System Checkpoint RP835: 6/5/2009 1:10:24 PM - System Checkpoint RP836: 6/5/2009 1:10:24 PM - System Checkpoint RP837: 6/5/2009 1:10:24 PM - System Checkpoint RP838: 6/5/2009 1:10:24 PM - System Checkpoint RP839: 6/5/2009 1:10:24 PM - System Checkpoint RP840: 6/5/2009 1:10:25 PM - System Checkpoint RP841: 6/5/2009 1:10:25 PM - System Checkpoint RP842: 6/5/2009 1:10:25 PM - System Checkpoint RP843: 6/5/2009 1:10:25 PM - System Checkpoint RP844: 6/5/2009 1:10:26 PM - System Checkpoint RP845: 6/5/2009 1:10:26 PM - System Checkpoint RP846: 6/5/2009 1:10:26 PM - System Checkpoint RP847: 6/5/2009 1:10:26 PM - Removed Rhapsody Player Engine RP848: 6/5/2009 1:10:26 PM - System Checkpoint RP849: 6/5/2009 1:10:26 PM - System Checkpoint ==== Installed Programs ====================== ACT! ACT! Standard 9.0 Ad-Aware Adobe Acrobat 7.0 Professional Adobe Acrobat 7.0.9 Professional Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe Camera Raw 4.0 Adobe CMaps Adobe Default Language CS3 Adobe Device Central CS3 Adobe Dreamweaver CS3 Adobe ExtendScript Toolkit 2 Adobe Extension Manager CS3 Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Help Viewer CS3 Adobe PDF Library Files Adobe Photoshop 7.0 Adobe Reader for Palm OS, 3.05 Adobe Setup Adobe Stock Photos CS3 Adobe Type Support Adobe Update Manager CS3 Adobe Version Cue CS3 Client AppCore Apple Mobile Device Support Apple Software Update AviSynth 2.5 Bonjour Broadcom 440x 10/100 Integrated Controller Canon Camera Access Library Canon Camera Support Core Library Canon Camera Window DC_DV 5 for ZoomBrowser EX Canon Camera Window DC_DV 6 for ZoomBrowser EX Canon Camera Window MC 6 for ZoomBrowser EX Canon G.726 WMP-Decoder Canon MovieEdit Task for ZoomBrowser EX Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities EOS Utility Canon Utilities PhotoStitch Canon Utilities ZoomBrowser EX ccCommon CDDRV_Installer Compatibility Pack for the 2007 Office system Component Framework Conexant HDA D110 MDC V.92 Modem Copernic Desktop Search - Home Dell ResourceCD Dell Wireless WLAN Card DellConnect DivX Content Uploader DivX Web Player DVD Decrypter (Remove Only) DVD Shrink 3.2 EphPod Google Toolbar for Internet Explorer High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows XP (KB952287) Intel® Graphics Media Accelerator Driver InterActual Player iTunes Java™ 6 Update 13 KhalInstallWrapper KODAK Gallery Upload Software Linksys Updater LiveUpdate (Symantec Corporation) Logitech Harmony Remote Software 7 Logitech Registration Logitech SetPoint Macromedia Dreamweaver 4 Macromedia Extension Manager Malwarebytes' Anti-Malware Maxtor Central Axis Manager Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft .NET Framework 3.0 Service Pack 1 Microsoft .NET Framework 3.5 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft Internationalized Domain Names Mitigation APIs Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (ACT7) Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft Visual C++ 2005 Redistributable MobileMe Control Panel Mozilla Firefox (3.0.10) MSXML 6.0 Parser (KB933579) Nero 7 Norton AntiVirus Norton AntiVirus Help Norton Confidential Core Norton Internet Security Norton Internet Security (Symantec Corporation) Norton Protection Center Picasa 3 PowerDVD 5.7 QuickTime RealPlayer Remote Control USB Driver ScreenPrint32 v3.5 Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows XP (KB913433) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961373) SigmaTel Audio SPBBC 32bit Spybot - Search & Destroy Symantec Real Time Storage Protection Component Symantec Technical Support Web Controls SymNet Synaptics Pointing Device Driver Turbo Lister 2 Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) WD Diagnostics WebFldrs XP Windows Driver Package - Ricoh Company Memorystick Host Controller (07/09/2005 1.00.01.12) Windows Driver Package - Ricoh Company MMC Host Controller (07/14/2005 1.00.00.06) Windows Driver Package - Ricoh Company xD-Picture Card/SmartMedia Host Controller (07/14/2005 1.00.02.04) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Internet Explorer 7 Windows Media Format Runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 10 Windows XP Service Pack 3 WinZip XML Paper Specification Shared Components Pack 1.0 XviD MPEG-4 Video Codec ==== Event Viewer Messages From Past Week ======== 6/8/2009 8:05:17 AM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 0016CE5236D5. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. 6/3/2009 1:06:18 PM, error: Tcpip [4199] - The system detected an address conflict for IP address 192.168.1.107 with the system having network hardware address 00:21:E9:62:31:23. Network operations on this system may be disrupted as a result. 6/2/2009 8:16:55 AM, error: Service Control Manager [7028] - The cfzwrmkjsvw Registry key denied access to SYSTEM account programs so the Service Control Manager took ownership of the Registry key. 6/1/2009 8:25:26 AM, error: Dhcp [1002] - The IP address lease 192.168.1.112 for the Network Card with network address 0016CE5236D5 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 6/1/2009 3:59:53 PM, error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the machine that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state. ==== End Of File =========================== I'll have the other one shortly just posting this now.

Attachments:

So the germ wouldn't load for like 6 tries then I saw it in the task manager. I downloaded another version of it that's more recent via a google search and it started loading. It was scanning for the past 2 hours then all of a sudden the blue screen of death appeared. The error was "page_fault_in_nonpage_area Stop 0x00000050 (0xFFC58D90m 0x00000001, 0x8658E0A3, 0x00000000) I'm having issues booting and it's so sluggish. 10 minutes to get to windows then loads for another 10 or so and I'm just restarting. I'm on another computer right now but any recommendations would be greatly appreciated. I've seen this thing in germ that said it was ulac or something like that. It seems like the computer is trying to connect elsewhere and that's part of my resource/sluggish issues. Any recommendations on germ or another program? I'm going to try that one again "germ" right now. Do you want me to look at anything specific to get back to you?
The one you gave me for gmer will not load at all. I don't know if this helps with insite plus everytime I load up successfully NOrton says this program is trying to run svchost.exe uaclonedwvopqdmu.dll
OK

Please leave that for the moment, from what you have described, there appears to be a rootkit on your system.

Please do the following:

Please download ComboFix from Here or Here to your Desktop.
**Note:  In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  • If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  • During the download, rename Combofix to Combo-Fix as follows:

    [external image: Posted Image]

    [external image: Posted Image]
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

    ———————————————————–

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

      ———————————————————–

    • Close any open browsers.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    ———————————————————–

  • Double click on combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.  
  • Please post the "C:\Combo-Fix.txt" for further review.
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
It just finished and here's the log.


ComboFix 09-06-08.02 - Jimmy 06/08/2009 20:13.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.641 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\IE4 Error Log.txt
c:\windows\system32\drivers\UACkkyejapyevyxlmd.sys
c:\windows\system32\UACankinytghpreqwo.log
c:\windows\system32\UACaoeifsparbutenl.dll
c:\windows\system32\UACcachiqfrkisjmkd.dll
c:\windows\system32\UACctlonedwvopqdmu.dll
c:\windows\system32\uacinit.dll
c:\windows\system32\UACjknskbgrqoewplr.dll
c:\windows\system32\UAClunviodkpihfpqy.log
c:\windows\system32\UACrpjkyxdeulvymrx.dat
c:\windows\system32\uacsr.dat
c:\windows\system32\UACvbsisjdqhqllisu.log
c:\windows\system32\UACvjtxwjyyqgrmath.dll

—– BITS: Possible infected sites —–

hxxp://gnbd1.cn
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_UACd.sys


((((((((((((((((((((((((( Files Created from 2009-05-09 to 2009-06-09 )))))))))))))))))))))))))))))))
.

2009-06-05 19:06 . 2008-04-14 00:12 26112 —-a-w- c:\windows\system32\stu2.exe
2009-06-02 15:42 . 2009-06-02 15:42 3371383 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 03:09 . 2007-05-17 22:31 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-09 00:53 . 2007-05-17 22:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-09 00:02 . 2008-06-05 17:57 94208 —-a-w- c:\windows\DUMP9da7.tmp
2009-06-08 17:00 . 2007-03-10 03:44 1890 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-08 13:39 . 2007-04-18 17:38 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-06-05 20:10 . 2009-06-05 20:10 0 —-a-w- c:\documents and settings\Jimmy\Application Data\~ygw.tmp
2009-06-05 19:06 . 2004-08-04 12:00 22528 —ha-w- c:\windows\system32\userinit.exe
2009-06-02 15:42 . 2009-04-11 18:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-02 15:40 . 2009-01-29 06:34 ——– d—–w- c:\program files\Red Kawa
2009-06-02 15:37 . 2006-10-11 17:35 ——– d—–w- c:\program files\Real
2009-05-27 01:58 . 2007-07-27 02:41 ——– d—–w- c:\documents and settings\Jimmy\Application Data\ZoomBrowser EX
2009-05-26 20:20 . 2009-04-11 18:09 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 20:19 . 2009-04-11 18:09 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-08 19:05 . 2008-11-25 23:16 ——– d—–w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-05-07 19:00 . 2008-08-09 04:36 ——– d—–w- c:\program files\Copernic Desktop Search 2
2009-04-27 23:42 . 2009-04-27 23:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Maxtor
2009-04-27 23:37 . 2006-10-06 00:04 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-04-27 23:36 . 2009-04-27 23:36 ——– d—–w- c:\documents and settings\Jimmy\Application Data\Maxtor Quick Start
2009-04-27 23:36 . 2009-04-27 23:36 ——– d—–w- c:\program files\Maxtor
2009-04-18 16:34 . 2006-10-29 14:35 ——– d—–w- c:\program files\Java
2009-04-17 21:22 . 2006-10-06 02:19 ——– d—–w- c:\program files\Trend Micro
2009-04-16 17:59 . 2009-04-16 17:59 ——– d—–w- c:\documents and settings\Jimmy\Application Data\Logitech
2009-04-16 17:59 . 2009-04-16 17:59 10134 —-a-r- c:\documents and settings\Jimmy\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2009-04-16 17:59 . 2009-04-16 17:59 ——– d—–w- c:\program files\Common Files\LogiShared
2009-04-16 17:56 . 2009-04-16 17:56 10134 —-a-r- c:\documents and settings\Jimmy\Application Data\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe
2009-04-16 17:55 . 2009-04-16 17:54 ——– d—–w- c:\program files\Common Files\Logitech
2009-04-16 17:54 . 2009-04-16 17:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Logitech
2009-04-16 17:54 . 2008-01-29 00:43 ——– d—–w- c:\program files\Logitech
2009-04-16 17:54 . 2009-04-16 17:54 10134 —-a-r- c:\documents and settings\Jimmy\Application Data\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe
2009-04-11 18:09 . 2009-04-11 18:09 ——– d—–w- c:\documents and settings\Jimmy\Application Data\Malwarebytes
2009-04-11 18:09 . 2009-04-11 18:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-11 17:32 . 2009-04-11 17:32 ——– d—–w- c:\documents and settings\Jimmy\Application Data\CyberLink
2009-04-10 22:52 . 2008-06-05 18:17 ——– d—–w- c:\program files\Norton Internet Security
2009-04-09 17:26 . 2009-04-09 17:26 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-01 19:18 . 2009-04-01 19:18 152576 —-a-w- c:\documents and settings\Jimmy\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-01 05:46 . 2008-02-07 04:04 9584 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\NCO20.dll
2009-03-19 23:32 . 2009-03-19 23:32 23400 —-a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 23:32 . 2008-01-29 19:01 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-04-01 05:47 . 2008-06-03 16:22 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2007-03-14 23:27 . 2007-03-10 03:44 88 –sh–r- c:\windows\system32\7DF316C31A.sys
.

——- Sigcheck ——-

[7] 2004-08-04 12:00 24576 39B1FFB03C2296323832ACBAE50D2AFF c:\windows\$NtServicePackUninstall$\userinit.exe
[7] 2008-04-14 00:12 26112 A93AEE1928A9D7CE3E16D24EC7380F89 c:\windows\ServicePackFiles\i386\userinit.exe
[-] 2009-06-05 19:06 22528 5999BBDB30EEE35025DCEF2A713113B4 c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Act.Outlook.Service"="c:\program files\ACT\ACT for Windows\Act.Outlook.Service.exe" [2007-03-28 9728]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-25 68856]
"Copernic Desktop Search - Home"="c:\program files\Copernic Desktop Search 2\DesktopSearchService.exe" [2009-03-19 1602048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"Act! Preloader"="c:\program files\ACT\ACT for Windows\ActSage.exe" [2007-03-28 1015808]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-13 483328]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2008-02-07 718704]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-02-07 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"mssSort"="c:\program files\Maxtor\ManagerApp\msssort.exe" [2008-08-05 1647960]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-08-05 169312]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-23 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-10-5 25214]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-10-5 113664]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-16 692224]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk
backup=c:\windows\pss\DataViz Inc Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Norton GoBack.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Norton GoBack.lnk
backup=c:\windows\pss\Norton GoBack.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Jimmy^Start Menu^Programs^Startup^palmOne Registration.lnk]
path=c:\documents and settings\Jimmy\Start Menu\Programs\Startup\palmOne Registration.lnk
backup=c:\windows\pss\palmOne Registration.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"MDM"=2 (0x2)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"GBPoll"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"CCALib8"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Adobe LM Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"="0"
"UpdatesDisableNotify"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [1/15/2008 11:28 AM 204800]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [1/25/2008 6:47 PM 149352]
R2 Maxtor Sync Services;Maxtor Service;c:\program files\Maxtor\Sync\SyncServices.exe [8/5/2008 7:54 AM 181600]
R2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/8/2009 5:29 PM 101936]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 7:32 PM 23888]
S3 RemoteControl-USBLAN;RemoteControl-USBLAN;c:\windows\system32\drivers\rcblan.sys [1/28/2008 5:43 PM 39704]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder

2009-06-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-06-08 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Jimmy.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 14:05]
.
- - - - ORPHANS REMOVED - - - -

ShellIconOverlayIdentifiers-{b75ab0c8-03d5-4592-9821-a48d54d66b14} - MssShellExt.dll
SafeBoot-procexp90.Sys


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - c:\documents and settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\fqbk8c9u.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-08 20:19
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{959CDFD9-242F-9381-450EBA075CF8D1EA}\{E4126DDE-B1CF-F46E-6FBC1229E79DA1E8}\{36374683-3A91-E5DA-C1D5F9EB3706FEB8}*]
"1D1OWFM6WKF6TLM3S2BGKKUUDG1"=hex:01,00,01,00,00,00,00,00,71,4a,e0,45,b7,4f,44,
fb,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
Completion time: 2009-06-09 20:22
ComboFix-quarantined-files.txt 2009-06-09 03:22

Pre-Run: 4,518,158,336 bytes free
Post-Run: 5,060,440,064 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

226 — E O F — 2009-05-13 16:21
Hi,

Please do the following:

I would like you to upload a file to be scanned
  • Make sure to use Internet Explorer for this
  • Please go to VirSCAN.org FREE on-line scan service
  • Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:

    c:\windows\system32\stu2.exe


  • Click on the Upload button
  • If a pop-up appears saying the file has been scanned already, please select the ReScan button.
  • Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
  • Paste the contents of the Clipboard in your next reply.


Please do the same for the following files:

c:\windows\system32\userinit.exe
c:\windows\system32\7DF316C31A.sys
c:\windows\ServicePackFiles\i386\userinit.exe




Also, Please describe how your computer is running now and if there are any outstanding issues
So last night norton ran again and said that it deleted a few other viruses. As of this morning I started the computer and it took like 4-5 minutes to load at my login which is better than yesterday but still slow. There are still lots of svchosts.exe in my task manager which is unusual, plus some number programs.exe (i.e. 109836.exe). Plus as soon as it logged in a new system security anitvirus software was scanning and my norton found file (here's the location that norton blocked Process name is "C:\Documents and Settings\Jimmy\Local Settings\Temp\ie8.tmp". - exact details A rule has been created to "block" communications.
Outbound TCP connection.
Remote address, service is (greatmarketingservices.com,http(80)).

Process name is "C:\Documents and Settings\Jimmy\Local Settings\Temp\ie8.tmp".) this is trying to access the internet and have me register a license for their antivirus software. It still has a virus trying to access random software and others slowing down and utllizing resources. Overall still has some issues but I haven't finished the scans your recommended yet either.


I see in my norton that right after this attempted to get approval via firewall here's what happened to my norton
Details: The following Symantec application was implicitly allowed to communicate:
Application: C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
Protocol: UDP
Local IP address,port: JL,0
Remote IP address,port: [removed],domain(53)


Here are the scans you requested.

_______________________________________________

VirSCAN.org Scanned Report :
Scanned time : 2009/06/09 07:18:11 (PDT)
Scanner results: All Scanners reported not find malware!
File Name : stu2.exe
File Size : 26112 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : a93aee1928a9d7ce3e16d24ec7380f89
SHA1 : 513f8bdf67a5a9e09803cfb61f590b39f2683853
Online report : http://virscan.org/report/9a1f3b803a26d236…7e308d417e.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090607195527 2009-06-07 2.35 -
AhnLab V3 2009.06.09.03 2009.06.09 2009-06-09 0.83 -
AntiVir 8.2.0.183 7.1.4.76 2009-06-09 3.51 -
Antiy 2.0.18 2.0.18. 0002-18-00 0.12 -
Arcavir 2009 200906091023 2009-06-09 0.04 -
Authentium 5.1.1 200906081740 2009-06-08 1.11 -
AVAST! 4.7.4 090608-0 2009-06-08 0.01 -
AVG 8.5.286 270.12.58/2164 2009-06-09 5.23 -
BitDefender 7.81008.3347131 7.25888 2009-06-09 3.04 -
CA (VET) 9.0.0.143 31.6.6548 2009-06-09 7.18 -
ClamAV 0.95.1 9441 2009-06-09 0.01 -
Comodo 3.9 1295 2009-06-09 0.78 -
CP Secure 1.1.0.715 2009.06.09 2009-06-09 11.62 -
Dr.Web 4.44.0.9170 2009.06.09 2009-06-09 4.73 -
F-Prot 4.4.4.56 20090608 2009-06-08 1.13 -
F-Secure 5.51.6100 2009.06.09.05 2009-06-09 5.96 -
Fortinet 2.81-3.117 10.480 2009-06-08 0.20 -
GData 19.5722/19.358 20090609 2009-06-09 4.57 -
ViRobot 20090609 2009.06.09 2009-06-09 0.82 -
Ikarus T3.1.01.57 2009.06.03.72814 2009-06-03 3.58 -
JiangMin 11.0.706 2009.06.09 2009-06-09 2.26 -
Kaspersky 5.5.10 2009.06.09 2009-06-09 0.08 -
KingSoft 2009.2.5.15 2009.6.9.21 2009-06-09 0.53 -
McAfee 5.3.00 5640 2009-06-08 3.08 -
Microsoft 1.4701 2009.06.09 2009-06-09 5.89 -
mks_vir 2.01 2009.06.07 2009-06-07 3.18 -
Norman 6.01.09 6.01.00 2009-06-08 2.01 -
Panda 9.05.01 2009.06.08 2009-06-08 2.45 -
Trend Micro 8.700-1004 6.182.02 2009-06-09 0.03 -
Quick Heal 10.00 2009.06.09 2009-06-09 1.30 -
Rising 20.0 21.33.13.00 2009-06-09 1.08 -
Sophos 2.87.1 4.42 2009-06-09 2.41 -
Sunbelt 5176 5176 2009-06-08 0.85 -
Symantec 1.3.0.24 20090608.007 2009-06-08 0.05 -
nProtect 20090609.01 4217261 2009-06-09 5.31 -
The Hacker 6.3.4.3 v00342 2009-06-08 0.67 -
VBA32 3.12.10.6 20090608.1238 2009-06-08 2.08 -
VirusBuster 4.5.11.10 10.107.6/1591776 2009-06-08 2.05 -


_____________________________________________________________
VirSCAN.org Scanned Report :
Scanned time : 2009/06/09 07:22:14 (PDT)
Scanner results: 3% Scanner(1/38) found malware!
File Name : userinit.exe
File Size : 22528 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 5999bbdb30eee35025dcef2a713113b4
SHA1 : 2a08023ab072e4e3552ff6f0e3684d4703a283aa
Online report : http://virscan.org/report/699e7c4647481fe2…a67d18c879.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090607195527 2009-06-07 2.10 -
AhnLab V3 2009.06.09.03 2009.06.09 2009-06-09 0.74 -
AntiVir 8.2.0.183 7.1.4.76 2009-06-09 0.05 -
Antiy 2.0.18 2.0.18. 0002-18-00 0.12 -
Arcavir 2009 200906091023 2009-06-09 0.03 -
Authentium 5.1.1 200906081740 2009-06-08 1.13 -
AVAST! 4.7.4 090608-0 2009-06-08 0.01 -
AVG 8.5.286 270.12.58/2164 2009-06-09 5.23 -
BitDefender 7.81008.3347131 7.25888 2009-06-09 3.06 -
CA (VET) 9.0.0.143 31.6.6548 2009-06-09 4.60 -
ClamAV 0.95.1 9441 2009-06-09 0.04 -
Comodo 3.9 1295 2009-06-09 0.72 -
CP Secure 1.1.0.715 2009.06.09 2009-06-09 9.97 -
Dr.Web 4.44.0.9170 2009.06.09 2009-06-09 4.64 -
F-Prot 4.4.4.56 20090608 2009-06-08 1.13 -
F-Secure 5.51.6100 2009.06.09.05 2009-06-09 0.06 -
Fortinet 2.81-3.117 10.480 2009-06-08 0.25 -
GData 19.5722/19.358 20090609 2009-06-09 6.90 -
ViRobot 20090609 2009.06.09 2009-06-09 0.59 -
Ikarus T3.1.01.57 2009.06.03.72814 2009-06-03 3.57 -
JiangMin 11.0.706 2009.06.09 2009-06-09 2.04 -
Kaspersky 5.5.10 2009.06.09 2009-06-09 0.05 -
KingSoft 2009.2.5.15 2009.6.9.21 2009-06-09 0.49 -
McAfee 5.3.00 5640 2009-06-08 3.06 -
Microsoft 1.4701 2009.06.09 2009-06-09 4.81 TrojanDownloader:Win32/Obitel.gen!A
mks_vir 2.01 2009.06.07 2009-06-07 3.17 -
Norman 6.01.09 6.01.00 2009-06-08 4.01 -
Panda 9.05.01 2009.06.08 2009-06-08 1.43 -
Trend Micro 8.700-1004 6.182.02 2009-06-09 0.03 -
Quick Heal 10.00 2009.06.09 2009-06-09 1.21 -
Rising 20.0 21.33.13.00 2009-06-09 1.00 -
Sophos 2.87.1 4.42 2009-06-09 2.38 -
Sunbelt 5176 5176 2009-06-08 0.89 -
Symantec 1.3.0.24 20090608.007 2009-06-08 0.07 -
nProtect 20090609.01 4217261 2009-06-09 5.87 -
The Hacker 6.3.4.3 v00342 2009-06-08 0.64 -
VBA32 3.12.10.6 20090608.1238 2009-06-08 2.00 -
VirusBuster 4.5.11.10 10.107.6/1591776 2009-06-08 1.93 -

______________________________________________________________
VirSCAN.org Scanned Report :
Scanned time : 2009/06/09 07:26:20 (PDT)
Scanner results: All Scanners reported not find malware!
File Name : 7DF316C31A.sys
File Size : 88 byte
File Type : X11 SNF font data, LSB first
MD5 : e4c0ee0368594ff67a28cb9246f99bbf
SHA1 : 12d46d253954339b52161ffbb979edc66d98d643
Online report : http://virscan.org/report/f2decc2a7c80692d…2bc8b17706.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090607195527 2009-06-07 2.81 -
AhnLab V3 2009.06.09.03 2009.06.09 2009-06-09 0.88 -
AntiVir 8.2.0.183 7.1.4.76 2009-06-09 0.19 -
Antiy 2.0.18 2.0.18. 0002-18-00 0.12 -
Arcavir 2009 200906091023 2009-06-09 0.02 -
Authentium 5.1.1 200906081740 2009-06-08 1.22 -
AVAST! 4.7.4 090608-0 2009-06-08 0.00 -
AVG 8.5.286 270.12.58/2164 2009-06-09 5.24 -
BitDefender 7.81008.3347131 7.25888 2009-06-09 3.06 -
CA (VET) 9.0.0.143 31.6.6548 2009-06-09 9.14 -
ClamAV 0.95.1 9441 2009-06-09 0.00 -
Comodo 3.9 1296 2009-06-09 0.72 -
CP Secure 1.1.0.715 2009.06.09 2009-06-09 9.98 -
Dr.Web 4.44.0.9170 2009.06.09 2009-06-09 4.72 -
F-Prot 4.4.4.56 20090608 2009-06-08 1.12 -
F-Secure 5.51.6100 2009.06.09.05 2009-06-09 0.03 -
Fortinet 2.81-3.117 10.480 2009-06-08 0.15 -
GData 19.5722/19.358 20090609 2009-06-09 4.49 -
ViRobot 20090609 2009.06.09 2009-06-09 0.41 -
Ikarus T3.1.01.57 2009.06.03.72814 2009-06-03 3.12 -
JiangMin 11.0.706 2009.06.09 2009-06-09 1.95 -
Kaspersky 5.5.10 2009.06.09 2009-06-09 0.02 -
KingSoft 2009.2.5.15 2009.6.9.21 2009-06-09 0.49 -
McAfee 5.3.00 5640 2009-06-08 3.01 -
Microsoft 1.4701 2009.06.09 2009-06-09 4.44 -
mks_vir 2.01 2009.06.07 2009-06-07 3.09 -
Norman 6.01.09 6.01.00 2009-06-08 4.00 -
Panda 9.05.01 2009.06.08 2009-06-08 2.66 -
Trend Micro 8.700-1004 6.182.02 2009-06-09 0.02 -
Quick Heal 10.00 2009.06.09 2009-06-09 1.16 -
Rising 20.0 21.33.14.00 2009-06-09 0.27 -
Sophos 2.87.1 4.42 2009-06-09 2.42 -
Sunbelt 5176 5176 2009-06-08 0.83 -
Symantec 1.3.0.24 20090608.007 2009-06-08 0.18 -
nProtect 20090609.01 4217261 2009-06-09 6.61 -
The Hacker 6.3.4.3 v00342 2009-06-08 0.71 -
VBA32 3.12.10.6 20090608.1238 2009-06-08 1.96 -
VirusBuster 4.5.11.10 10.107.6/1591776 2009-06-08 1.93 -

________________________________________________________________


VirSCAN.org Scanned Report :
Scanned time : 2009/06/09 07:31:08 (PDT)
Scanner results: All Scanners reported not find malware!
File Name : userinit.exe
File Size : 26112 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : a93aee1928a9d7ce3e16d24ec7380f89
SHA1 : 513f8bdf67a5a9e09803cfb61f590b39f2683853
Online report : http://virscan.org/report/06904ff5b2a45844…d414f120f4.html

Scanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.5.0.1 20090607195527 2009-06-07 2.50 -
AhnLab V3 2009.06.09.03 2009.06.09 2009-06-09 0.79 -
AntiVir 8.2.0.183 7.1.4.76 2009-06-09 0.18 -
Antiy 2.0.18 2.0.18. 0002-18-00 0.13 -
Arcavir 2009 200906091023 2009-06-09 0.06 -
Authentium 5.1.1 200906081740 2009-06-08 1.12 -
AVAST! 4.7.4 090608-0 2009-06-08 0.01 -
AVG 8.5.286 270.12.58/2164 2009-06-09 5.23 -
BitDefender 7.81008.3347131 7.25888 2009-06-09 3.05 -
CA (VET) 9.0.0.143 31.6.6548 2009-06-09 6.19 -
ClamAV 0.95.1 9441 2009-06-09 0.01 -
Comodo 3.9 1296 2009-06-09 0.75 -
CP Secure 1.1.0.715 2009.06.09 2009-06-09 10.08 -
Dr.Web 4.44.0.9170 2009.06.09 2009-06-09 4.72 -
F-Prot 4.4.4.56 20090608 2009-06-08 1.14 -
F-Secure 5.51.6100 2009.06.09.05 2009-06-09 0.10 -
Fortinet 2.81-3.117 10.480 2009-06-08 0.20 -
GData 19.5722/19.358 20090609 2009-06-09 4.20 -
ViRobot 20090609 2009.06.09 2009-06-09 0.43 -
Ikarus T3.1.01.57 2009.06.03.72814 2009-06-03 3.17 -
JiangMin 11.0.706 2009.06.09 2009-06-09 2.17 -
Kaspersky 5.5.10 2009.06.09 2009-06-09 0.10 -
KingSoft 2009.2.5.15 2009.6.9.21 2009-06-09 0.55 -
McAfee 5.3.00 5640 2009-06-08 3.08 -
Microsoft 1.4701 2009.06.09 2009-06-09 4.41 -
mks_vir 2.01 2009.06.07 2009-06-07 3.25 -
Norman 6.01.09 6.01.00 2009-06-08 4.00 -
Panda 9.05.01 2009.06.08 2009-06-08 2.98 -
Trend Micro 8.700-1004 6.182.02 2009-06-09 0.03 -
Quick Heal 10.00 2009.06.09 2009-06-09 1.22 -
Rising 20.0 21.33.14.00 2009-06-09 0.84 -
Sophos 2.87.1 4.42 2009-06-09 2.37 -
Sunbelt 5176 5176 2009-06-08 0.78 -
Symantec 1.3.0.24 20090608.007 2009-06-08 0.05 -
nProtect 20090609.01 4217261 2009-06-09 5.41 -
The Hacker 6.3.4.3 v00342 2009-06-08 0.67 -
VBA32 3.12.10.6 20090608.1238 2009-06-08 3.03 -
VirusBuster 4.5.11.10 10.107.6/1591776 2009-06-08 1.94 -

Here's what Norton found this morning and last night via it's regular scan which I stopped about 20 minutes in.

As of today just a few minutes ago.
Risk category: Cookie
Overall Risk Impact: Low
Performance: Low
Privacy: Low
Removal: Low
Stealth: Low
Click for more information about this risk : Tracking Cookie
Action taken: Fully removed
Affected Areas:
Network & Browser Items
Cookie:[removed]/
Cookie:[removed]/
Cookie:[removed]/
Cookie:[removed]/
Cookie:[removed]/
Cookie:[removed]/
Cookie:[removed]/
Cookie:[removed]/
Cookie:Orphan Cleanup


Lastnight around 11:30 pm
Risk category: Heuristic Virus
Overall Risk Impact: High
Performance: High
Privacy: High
Removal: High
Stealth: High
Click for more information about this risk : Packed.Generic.200
Action taken: Fully removed
Affected Areas:
Files & Directories
c:\qoobox\quarantine\c\windows\system32\uacaoeifsparbutenl.dll.vir
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACcachiqfrkisjmkd.dll.vir
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACctlonedwvopqdmu.dll.vir
C:\Qoobox\Quarantine\C\WINDOWS\system32\UACjknskbgrqoewplr.dll.vir
Network & Browser Items
Browser Cache

___________________________
simultaneously it had identified this one


Risk category: Virus
Overall Risk Impact: High
Performance: High
Privacy: High
Removal: High
Stealth: High
Click for more information about this risk : Trojan.Fakeavalert
Action taken: Fully removed
Affected Areas:
Files & Directories
c:\qoobox\quarantine\c\windows\system32\uacvjtxwjyyqgrmath.dll.vir
C:\Documents and Settings\All Users\Desktop\Best BDSM P0rn.url
C:\Documents and Settings\All Users\Desktop\Gay Fetish Sex.url
Registry Entries
HKEY_USERS\S-1-5-21-1708537768-1637723038-839522115-1003\Software\Microsoft\Internet Explorer\New Windows\->PopupMgr:yes
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1
HKEY_USERS\S-1-5-21-1708537768-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->Hidden:1
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->HideFileExt:0
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->HideFileExt:0
HKEY_USERS\S-1-5-21-1708537768-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->HideFileExt:0
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->HideFileExt:0
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->SuperHidden:1
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->SuperHidden:1
HKEY_USERS\S-1-5-21-1708537768-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->SuperHidden:1
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\->SuperHidden:1
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoFolderOptions:0
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoFolderOptions:0
HKEY_USERS\S-1-5-21-1708537768-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoFolderOptions:0
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\->NoFolderOptions:0
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableRegistryTools:0
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableRegistryTools:0
HKEY_USERS\S-1-5-21-1708537768-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableRegistryTools:0
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System\->DisableRegistryTools:0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\->aux1:wdmaud.drv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\->aux2:wdmaud.drv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\->midi2:wdmaud.drv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\->mixer2:wdmaud.drv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\->wave2:wdmaud.drv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\->wave1:wdmaud.drv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\->midi1:wdmaud.drv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32\->mixer1:wdmaud.drv
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon->Userinit:C:\WINDOWS\system32\Userinit.exe
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Policies\System->DisableTaskMgr:0
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Policies\System->DisableTaskMgr:0
HKEY_USERS\S-1-5-21-1708537768-1637723038-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Policies\System->DisableTaskMgr:0
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System->DisableTaskMgr:0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system->DisableTaskMgr:0
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\->System
Network & Browser Items
Browser Cache
So most of the programs open relatively quickly. It does seem that something is remaining on my internet or behind the scenes because I'm having to wait 10 seconds for basic html pages to open that are only text. I just wanted to give you an update based on the day today
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

FCopy::
c:\windows\ServicePackFiles\i386\userinit.exe | c:\windows\system32\userinit.exe

File::
C:\Documents and Settings\Jimmy\Local Settings\Temp\ie8.tmp

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]

  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Open your MalwareBytes AntiMalware program
  • Check for updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.

NEXT
Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

  • Open the Kaspersky WebScanner
    page.
  • Click on the 🖼Click to load external image (Posted Image) button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the 🖼Click to load external image (Posted Image) button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the 🖼Click to load external image (Posted Image) …button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the 🖼Click to load external image (Posted Image) button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis.

NEXT

Open HJT click on Do a system scan and save a logfile button
once the scan has completed a notepad should open - copy/paste that log here.
So before I did anything any restart would result in craziness. My desktop was gone, a antivirus would scan and it seems to have been removed by combofix. and malaware. My svchost is still pretty high but I wanted to post these logs before I did Kaspersky because it can take a while.

Combofix

ComboFix 09-06-09.06 - Jimmy 06/09/2009 16:53.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.587 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\Jimmy\Desktop\CFScript.txt
AV: Norton Internet Security *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

FILE ::
"c:\documents and settings\Jimmy\Local Settings\Temp\ie8.tmp"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\14808434
c:\documents and settings\All Users\Application Data\14808434\14808434.exe
c:\documents and settings\All Users\Application Data\14808434\14808434.glu
c:\documents and settings\All Users\Application Data\14808434\pc14808434cnf
c:\documents and settings\All Users\Application Data\14808434\pc14808434ins
c:\documents and settings\All Users\Application Data\94818426
c:\documents and settings\All Users\Application Data\94818426\94818426.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

—– BITS: Possible infected sites —–

hxxp://gnbd1.cn
.
————— FCopy —————

c:\windows\ServicePackFiles\i386\userinit.exe –> c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((( Files Created from 2009-05-09 to 2009-06-09 )))))))))))))))))))))))))))))))
.

2009-06-05 19:06 . 2008-04-14 00:12 26112 —-a-w- c:\windows\system32\stu2.exe
2009-06-02 15:42 . 2009-06-02 15:42 3371383 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-09 23:51 . 2007-05-17 22:31 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-09 15:26 . 2007-03-10 03:44 1890 –sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-09 15:24 . 2007-04-18 17:38 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-06-09 00:53 . 2007-05-17 22:33 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-06-09 00:02 . 2008-06-05 17:57 94208 —-a-w- c:\windows\DUMP9da7.tmp
2009-06-05 20:10 . 2009-06-05 20:10 0 —-a-w- c:\documents and settings\Jimmy\Application Data\~ygw.tmp
2009-06-02 15:42 . 2009-04-11 18:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-06-02 15:40 . 2009-01-29 06:34 ——– d—–w- c:\program files\Red Kawa
2009-06-02 15:37 . 2006-10-11 17:35 ——– d—–w- c:\program files\Real
2009-05-27 01:58 . 2007-07-27 02:41 ——– d—–w- c:\documents and settings\Jimmy\Application Data\ZoomBrowser EX
2009-05-26 20:20 . 2009-04-11 18:09 40160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 20:19 . 2009-04-11 18:09 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-05-08 19:05 . 2008-11-25 23:16 ——– d—–w- c:\documents and settings\All Users\Application Data\ZoomBrowser
2009-05-07 19:00 . 2008-08-09 04:36 ——– d—–w- c:\program files\Copernic Desktop Search 2
2009-04-27 23:42 . 2009-04-27 23:36 ——– d—–w- c:\documents and settings\All Users\Application Data\Maxtor
2009-04-27 23:37 . 2006-10-06 00:04 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-04-27 23:36 . 2009-04-27 23:36 ——– d—–w- c:\documents and settings\Jimmy\Application Data\Maxtor Quick Start
2009-04-27 23:36 . 2009-04-27 23:36 ——– d—–w- c:\program files\Maxtor
2009-04-18 16:34 . 2006-10-29 14:35 ——– d—–w- c:\program files\Java
2009-04-17 21:22 . 2006-10-06 02:19 ——– d—–w- c:\program files\Trend Micro
2009-04-16 17:59 . 2009-04-16 17:59 ——– d—–w- c:\documents and settings\Jimmy\Application Data\Logitech
2009-04-16 17:59 . 2009-04-16 17:59 10134 —-a-r- c:\documents and settings\Jimmy\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2009-04-16 17:59 . 2009-04-16 17:59 ——– d—–w- c:\program files\Common Files\LogiShared
2009-04-16 17:56 . 2009-04-16 17:56 10134 —-a-r- c:\documents and settings\Jimmy\Application Data\Microsoft\Installer\{8CC990CD-87C8-475C-AC32-8A7984E2FCFA}\ARPPRODUCTICON.exe
2009-04-16 17:55 . 2009-04-16 17:54 ——– d—–w- c:\program files\Common Files\Logitech
2009-04-16 17:54 . 2009-04-16 17:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Logitech
2009-04-16 17:54 . 2008-01-29 00:43 ——– d—–w- c:\program files\Logitech
2009-04-16 17:54 . 2009-04-16 17:54 10134 —-a-r- c:\documents and settings\Jimmy\Application Data\Microsoft\Installer\{56918C0C-0D87-4CA6-92BF-4975A43AC719}\ARPPRODUCTICON.exe
2009-04-11 18:09 . 2009-04-11 18:09 ——– d—–w- c:\documents and settings\Jimmy\Application Data\Malwarebytes
2009-04-11 18:09 . 2009-04-11 18:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-11 17:32 . 2009-04-11 17:32 ——– d—–w- c:\documents and settings\Jimmy\Application Data\CyberLink
2009-04-09 17:26 . 2009-04-09 17:26 75048 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-04-01 19:18 . 2009-04-01 19:18 152576 —-a-w- c:\documents and settings\Jimmy\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-01 05:46 . 2008-02-07 04:04 9584 —-a-w- c:\documents and settings\All Users\Application Data\Symantec\LiveUpdate\LuRegManifests\Static\NCO20.dll
2009-03-19 23:32 . 2009-03-19 23:32 23400 —-a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 23:32 . 2008-01-29 19:01 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-04-01 05:47 . 2008-06-03 16:22 324976 —-a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll
2007-03-14 23:27 . 2007-03-10 03:44 88 –sh–r- c:\windows\system32\7DF316C31A.sys
.

((((((((((((((((((((((((((((( SnapShot@2009-06-09_03.19.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2004-08-04 12:00 . 2008-04-14 00:12 26112 c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Act.Outlook.Service"="c:\program files\ACT\ACT for Windows\Act.Outlook.Service.exe" [2007-03-28 9728]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-25 68856]
"Copernic Desktop Search - Home"="c:\program files\Copernic Desktop Search 2\DesktopSearchService.exe" [2009-03-19 1602048]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2005-12-19 1347584]
"Act! Preloader"="c:\program files\ACT\ACT for Windows\ActSage.exe" [2007-03-28 1015808]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-13 483328]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2008-02-07 718704]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-02-07 177472]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"mssSort"="c:\program files\Maxtor\ManagerApp\msssort.exe" [2008-08-05 1647960]
"mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2008-08-05 169312]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-04-11 56080]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-23 39264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2006-10-5 25214]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-10-5 113664]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-16 692224]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoViewOnDrive"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^DataViz Inc Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\DataViz Inc Messenger.lnk
backup=c:\windows\pss\DataViz Inc Messenger.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Norton GoBack.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Norton GoBack.lnk
backup=c:\windows\pss\Norton GoBack.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Desktop Search.lnk
backup=c:\windows\pss\Windows Desktop Search.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Jimmy^Start Menu^Programs^Startup^palmOne Registration.lnk]
path=c:\documents and settings\Jimmy\Start Menu\Programs\Startup\palmOne Registration.lnk
backup=c:\windows\pss\palmOne Registration.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"MDM"=2 (0x2)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"GBPoll"=2 (0x2)
"FLEXnet Licensing Service"=3 (0x3)
"CCALib8"=2 (0x2)
"Bonjour Service"=2 (0x2)
"Adobe LM Service"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [1/25/2008 6:47 PM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [6/8/2009 5:29 PM 101936]
S2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [1/15/2008 11:28 AM 204800]
S2 Maxtor Sync Services;Maxtor Service;c:\program files\Maxtor\Sync\SyncServices.exe [8/5/2008 7:54 AM 181600]
S2 MSSQL$ACT7;SQL Server (ACT7);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [11/24/2008 10:31 PM 29263712]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 7:32 PM 23888]
S3 RemoteControl-USBLAN;RemoteControl-USBLAN;c:\windows\system32\drivers\rcblan.sys [1/28/2008 5:43 PM 39704]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder

2009-06-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]

2009-06-09 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Jimmy.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-02-07 14:05]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-14808434 - c:\documents and settings\All Users\Application Data\14808434\14808434.exe
HKLM-Run-94818426 - c:\documents and settings\All Users\Application Data\94818426\94818426.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - c:\documents and settings\Jimmy\Application Data\Mozilla\Firefox\Profiles\fqbk8c9u.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-09 16:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{959CDFD9-242F-9381-450EBA075CF8D1EA}\{E4126DDE-B1CF-F46E-6FBC1229E79DA1E8}\{36374683-3A91-E5DA-C1D5F9EB3706FEB8}*]
"1D1OWFM6WKF6TLM3S2BGKKUUDG1"=hex:01,00,01,00,00,00,00,00,71,4a,e0,45,b7,4f,44,
fb,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
Completion time: 2009-06-09 17:02
ComboFix-quarantined-files.txt 2009-06-10 00:02
ComboFix2.txt 2009-06-09 03:22

Pre-Run: 4,971,253,760 bytes free
Post-Run: 5,004,492,800 bytes free

215 — E O F — 2009-05-13 16:21


_________________________________________________
Malawarebytes

Malwarebytes' Anti-Malware 1.37
Database version: 2256
Windows 5.1.2600 Service Pack 3

6/9/2009 5:10:32 PM
mbam-log-2009-06-09 (17-10-32).txt

Scan type: Quick Scan
Objects scanned: 86501
Time elapsed: 4 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Here's Kaspersky
——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0 REPORT
Wednesday, June 10, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Wednesday, June 10, 2009 01:00:12
Records in database: 2332781
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 146877
Threat name: 6
Infected objects: 9
Suspicious objects: 0
Duration of the scan: 06:50:48


File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\94818426\94818426.exe.vir Infected: Trojan-Downloader.Win32.FraudLoad.wbxk 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACkkyejapyevyxlmd.sys.vir Infected: Rootkit.Win32.Agent.lhm 1
C:\System Volume Information\_restore{C59C7F46-050E-413D-95AB-D76CD4490D88}\RP849\A0752950.sys Infected: Rootkit.Win32.Agent.lhm 1
C:\System Volume Information\_restore{C59C7F46-050E-413D-95AB-D76CD4490D88}\RP849\A0752951.dll Infected: Packed.Win32.Tdss.m 1
C:\System Volume Information\_restore{C59C7F46-050E-413D-95AB-D76CD4490D88}\RP849\A0752952.dll Infected: Packed.Win32.Tdss.m 1
C:\System Volume Information\_restore{C59C7F46-050E-413D-95AB-D76CD4490D88}\RP849\A0752953.dll Infected: Trojan.Win32.TDSS.adzx 1
C:\System Volume Information\_restore{C59C7F46-050E-413D-95AB-D76CD4490D88}\RP849\A0752954.dll Infected: Trojan.Win32.TDSS.adzz 1
C:\System Volume Information\_restore{C59C7F46-050E-413D-95AB-D76CD4490D88}\RP849\A0752955.dll Infected: Trojan.Win32.TDSS.aegg 1
C:\System Volume Information\_restore{C59C7F46-050E-413D-95AB-D76CD4490D88}\RP850\A0754319.exe Infected: Trojan-Downloader.Win32.FraudLoad.wbxk 1

The selected area was scanned.


Here's Hijack This

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:30:57 AM, on 6/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Maxtor\ManagerApp\msssort.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
C:\WINDOWS\system32\java.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Act.UI.InternetExplorer.Plugins.AttachFile.CAttachFile - {D5233FCD-D258-4903-89B8-FB1568E7413D} - mscoree.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.5\CoIEPlg.dll
O3 - Toolbar: Copernic Desktop Search - Home Toolbar - {4A1C6093-14F9-44D7-860E-5D265CFCA9D9} - C:\Program Files\Copernic Desktop Search 2\Toolbar\ToolbarContainer101000311.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Act! Preloader] "C:\Program Files\ACT\ACT for Windows\ActSage.exe" -preload
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mssSort] "C:\Program Files\Maxtor\ManagerApp\msssort.exe"
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Act.Outlook.Service] "C:\Program Files\ACT\ACT for Windows\Act.Outlook.Service.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Copernic Desktop Search - Home] "C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Attach Web page to ACT! contact - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra 'Tools' menuitem: Attach Web page to ACT! contact… - {6F431AC3-364A-478b-BBDB-89C7CE1B18F6} - mscoree.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1160443373656
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Linksys Updater (LinksysUpdater) - Unknown owner - C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Maxtor Service (Maxtor Sync Services) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 12406 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI