This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis Logfile

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK. Lets see if we can also work on the EXE and COM file issue.

Open C:\windows
Click View> Details> Arrange ICONS by Type.

That should list the files with .exe and .com
Look for files with both extentions. I suggest you rename the .com files to .old.
Example: Regedit.com right click and select Rename. Rename to Regedit.old

Open C:\windows\System32
Click View> Details> Arrange ICONS by Type.

There should be alot more .exe files in this folder.
Wow…

Explorer windows crash often when I need to "browse"



Here's the Combofix File:

Start Time= Sun 07/09/2006 20:16:45.55
Running from: C:\Documents and Settings\[removed]
QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-05 22:07:44 ( .D… ) "C:\Program Files\Eyetide Media"
2006-07-05 20:57:50 ( .D… ) "C:\Program Files\CCleaner"
2006-07-05 20:00:30 ( .D… ) "C:\Program Files\ewido anti-spyware 4.0"
2006-07-05 19:57:58 ( .D… ) "C:\Documents and Settings\Jason\Application Data\Google"
2006-07-04 18:36:50 ( .D… ) "C:\Program Files\HijackThis"
2006-07-04 12:44:42 0 ( A…. ) "C:\Documents and Settings\Jason\Application Data\sversion.ini"
2006-07-04 00:41:40 47564 ( A.SHR ) "C:\NTDETECT.COM"
2006-07-02 21:18:04 ( .D… ) "C:\Documents and Settings\Jason\Application Data\AVG7"
2006-07-02 21:17:26 ( .D… ) "C:\Program Files\Grisoft"
2006-07-02 21:04:16 ( .D… ) "C:\Program Files\TBIView"
2006-07-02 21:04:02 ( .D… ) "C:\Program Files\Image for Windows"
2006-06-23 09:28:56 5512704 ( ….. ) "C:\WINDOWS\system32\ieframe.dll"
2006-06-23 09:28:56 454144 ( ….. ) "C:\WINDOWS\system32\msfeeds.dll"
2006-06-23 09:28:56 413696 ( A…. ) "C:\WINDOWS\system32\vbscript.dll"
2006-06-23 09:28:56 223744 ( A…. ) "C:\WINDOWS\system32\webcheck.dll"
2006-06-23 09:28:56 179200 ( ….. ) "C:\WINDOWS\system32\ieui.dll"
2006-06-23 09:28:56 155648 ( A…. ) "C:\WINDOWS\system32\msls31.dll"
2006-06-23 09:28:56 47616 ( ….. ) "C:\WINDOWS\system32\msfeedsbs.dll"
2006-06-23 05:41:42 172544 ( ….. ) "C:\WINDOWS\system32\WinFXDocObj.exe"
2006-06-23 05:40:44 78848 ( A…. ) "C:\WINDOWS\system32\ieencode.dll"
2006-06-23 05:40:04 40960 ( A…. ) "C:\WINDOWS\system32\url.dll"
2006-06-23 05:39:52 39424 ( A…. ) "C:\WINDOWS\system32\licmgr10.dll"
2006-06-23 05:39:08 99328 ( A…. ) "C:\WINDOWS\system32\occache.dll"
2006-06-23 05:37:18 14336 ( A…. ) "C:\WINDOWS\system32\corpol.dll"
2006-06-23 05:34:30 228864 ( A…. ) "C:\WINDOWS\system32\ieaksie.dll"
2006-06-23 05:34:16 167936 ( A…. ) "C:\WINDOWS\system32\ieakeng.dll"
2006-06-23 05:34:06 81920 ( A…. ) "C:\WINDOWS\system32\admparse.dll"
2006-06-23 05:34:06 50688 ( A…. ) "C:\WINDOWS\system32\ie4uinit.exe"
2006-06-23 05:34:02 372736 ( A…. ) "C:\WINDOWS\system32\iedkcs32.dll"
2006-06-23 05:33:42 54272 ( A…. ) "C:\WINDOWS\system32\iesetup.dll"
2006-06-23 05:33:22 41984 ( A…. ) "C:\WINDOWS\system32\iernonce.dll"
2006-06-23 05:33:00 121856 ( A…. ) "C:\WINDOWS\system32\advpack.dll"
2006-06-23 05:30:22 11776 ( ….. ) "C:\WINDOWS\system32\msfeedssync.exe"
2006-06-23 05:29:56 55296 ( ….. ) "C:\WINDOWS\system32\icardie.dll"
2006-06-23 05:29:22 35328 ( A…. ) "C:\WINDOWS\system32\imgutil.dll"
2006-06-23 05:27:56 251392 ( ….. ) "C:\WINDOWS\system32\iertutil.dll"
2006-06-23 05:26:52 45568 ( A…. ) "C:\WINDOWS\system32\mshta.exe"
2006-06-23 04:46:30 377856 ( ….. ) "C:\WINDOWS\system32\ieapfltr.dll"
2006-06-23 04:45:30 48640 ( A…. ) "C:\WINDOWS\system32\mshtmler.dll"
2006-06-23 04:41:42 172032 ( A…. ) "C:\WINDOWS\system32\ieakui.dll"
2006-06-19 15:18:34 22752 ( A…. ) "C:\WINDOWS\system32\spupdsvc.exe"
2006-06-19 15:18:16 23552 ( ….. ) "C:\WINDOWS\system32\idndl.dll"
2006-06-19 15:18:16 20480 ( ….. ) "C:\WINDOWS\system32\normaliz.dll"
2006-06-12 23:56:18 ( .D… ) "C:\Program Files\Badder Adder"
2006-05-25 01:22:06 53248 ( A…. ) "C:\WINDOWS\bdoscandel.exe"
2006-05-24 11:20:26 ( .D… ) "C:\Program Files\Mozilla Firefox"
2005-12-20 15:53:12 3791064 ( A…. ) "C:\Program Files\hbk4.exe"
2001-11-21 10:10:06 18330960 ( A…. ) "C:\Program Files\Oxpsp1.exe"


(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))


2006-07-09 20:10 536,268,800 C:\hiberfil.sys
2006-07-04 12:34 117,760 C:\WINDOWS\system32\xmllite.dll
2006-07-04 00:48 937,984 C:\WINDOWS\system32\winbrand.dll
2006-07-04 00:48 9,216 C:\WINDOWS\system32\proxycfg.exe
2006-07-04 00:48 88,064 C:\WINDOWS\system32\p2pnetsh.dll
2006-07-04 00:48 870,784 C:\WINDOWS\system32\ati3d1ag.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\p2pgasvc.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\mdmxsdk.dll
2006-07-04 00:48 81,408 C:\WINDOWS\system32\wscsvc.dll
2006-07-04 00:48 8,192 C:\WINDOWS\system32\smbinst.exe
2006-07-04 00:48 78,848 C:\WINDOWS\system32\ieencode.dll
2006-07-04 00:48 75,776 C:\WINDOWS\system32\strmfilt.dll
2006-07-04 00:48 73,832 C:\WINDOWS\system32\slcoinst.dll
2006-07-04 00:48 73,796 C:\WINDOWS\system32\slserv.exe
2006-07-04 00:48 71,680 C:\WINDOWS\system32\blastcln.exe
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsno.dll
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsfi.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdukx.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdno1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdfi1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\hccoin.dll
2006-07-04 00:48 60,416 C:\WINDOWS\system32\fwcfg.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinmal.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinben.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt48.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt47.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdinbe1.dll
2006-07-04 00:48 59,392 C:\WINDOWS\system32\logman.exe
2006-07-04 00:48 537,088 C:\WINDOWS\system32\msftedit.dll
2006-07-04 00:48 526,848 C:\WINDOWS\system32\p2psvc.dll
2006-07-04 00:48 516,768 C:\WINDOWS\system32\ativvaxx.dll
2006-07-04 00:48 50,688 C:\WINDOWS\system32\btpanui.dll
2006-07-04 00:48 50,176 C:\WINDOWS\system32\xmlprovi.dll
2006-07-04 00:48 5,632 C:\WINDOWS\system32\kbdmaori.dll
2006-07-04 00:48 49,152 C:\WINDOWS\system32\powercfg.exe
2006-07-04 00:48 48,640 C:\WINDOWS\system32\pnrpnsp.dll
2006-07-04 00:48 44,032 C:\WINDOWS\system32\twext.dll
2006-07-04 00:48 4,096 C:\WINDOWS\system32\dsprpres.dll
2006-07-04 00:48 397,056 C:\WINDOWS\system32\s3gnb.dll
2006-07-04 00:48 377,984 C:\WINDOWS\system32\ati2dvaa.dll
2006-07-04 00:48 32,866 C:\WINDOWS\system32\slrundll.exe
2006-07-04 00:48 32,866 C:\WINDOWS\slrundll.exe
2006-07-04 00:48 32,768 C:\WINDOWS\system32\ativtmxx.dll
2006-07-04 00:48 32,285 C:\WINDOWS\system32\hsfcisp2.dll
2006-07-04 00:48 312,320 C:\WINDOWS\system32\p2pgraph.dll
2006-07-04 00:48 30,208 C:\WINDOWS\system32\bthserv.dll
2006-07-04 00:48 29,184 C:\WINDOWS\system32\sdhcinst.dll
2006-07-04 00:48 286,792 C:\WINDOWS\system32\slextspk.dll
2006-07-04 00:48 270,848 C:\WINDOWS\system32\sbe.dll
2006-07-04 00:48 24,576 C:\WINDOWS\system32\httpapi.dll
2006-07-04 00:48 229,376 C:\WINDOWS\system32\ati2cqag.dll
2006-07-04 00:48 22,528 C:\WINDOWS\system32\fltmc.exe
2006-07-04 00:48 201,728 C:\WINDOWS\system32\ati2dvag.dll
2006-07-04 00:48 20,992 C:\WINDOWS\system32\bthci.dll
2006-07-04 00:48 20,480 C:\WINDOWS\system32\encapi.dll
2006-07-04 00:48 2,113,536 C:\WINDOWS\system32\dxdiagn.dll
2006-07-04 00:48 193,024 C:\WINDOWS\system32\fsquirt.exe
2006-07-04 00:48 188,508 C:\WINDOWS\system32\slgen.dll
2006-07-04 00:48 187,392 C:\WINDOWS\system32\xpsp1res.dll
2006-07-04 00:48 186,368 C:\WINDOWS\system32\encdec.dll
2006-07-04 00:48 17,408 C:\WINDOWS\system32\winshfhc.dll
2006-07-04 00:48 16,896 C:\WINDOWS\system32\fltlib.dll
2006-07-04 00:48 159,232 C:\WINDOWS\system32\sbeio.dll
2006-07-04 00:48 15,872 C:\WINDOWS\system32\w3ssl.dll
2006-07-04 00:48 14,336 C:\WINDOWS\system32\auditusr.exe
2006-07-04 00:48 134,656 C:\WINDOWS\system32\mssap.dll
2006-07-04 00:48 13,824 C:\WINDOWS\system32\wscntfy.exe
2006-07-04 00:48 13,824 C:\WINDOWS\system32\cmsetacl.dll
2006-07-04 00:48 129,536 C:\WINDOWS\system32\xmlprov.dll
2006-07-04 00:48 118,784 C:\WINDOWS\system32\msdadiag.dll
2006-07-04 00:48 116,224 C:\WINDOWS\system32\p2p.dll
2006-07-04 00:48 108,032 C:\WINDOWS\system32\wshbth.dll
2006-07-04 00:48 1,888,992 C:\WINDOWS\system32\ati3duag.dll
2006-07-04 00:48 1,737,856 C:\WINDOWS\system32\mtxparhd.dll
2006-07-04 00:48 1,689,088 C:\WINDOWS\system32\d3d9.dll
2006-07-04 00:43 92,224 C:\WINDOWS\system32\krnl386.exe
2006-07-04 00:42 2,897,920 C:\WINDOWS\system32\xpsp2res.dll
2006-06-23 09:28 5,512,704 C:\WINDOWS\system32\ieframe.dll
2006-06-23 09:28 47,616 C:\WINDOWS\system32\msfeedsbs.dll
2006-06-23 09:28 454,144 C:\WINDOWS\system32\msfeeds.dll
2006-06-23 09:28 179,200 C:\WINDOWS\system32\ieui.dll
2006-06-23 05:41 172,544 C:\WINDOWS\system32\WinFXDocObj.exe
2006-06-23 05:30 11,776 C:\WINDOWS\system32\msfeedssync.exe
2006-06-23 05:29 55,296 C:\WINDOWS\system32\icardie.dll
2006-06-23 05:27 251,392 C:\WINDOWS\system32\iertutil.dll
2006-06-23 04:46 377,856 C:\WINDOWS\system32\ieapfltr.dll
2006-06-19 15:18 23,552 C:\WINDOWS\system32\idndl.dll
2006-06-19 15:18 20,480 C:\WINDOWS\system32\normaliz.dll
2006-06-12 23:56 101,888 C:\WINDOWS\system32\VB6STKIT.DLL
2006-05-25 01:22 53,248 C:\WINDOWS\bdoscandel.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"FreeMem Pro"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e0,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^LimeWire On Startup.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"item"="LimeWire On Startup.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OpenOffice.org 1.1.3.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\OpenOffice.org 1.1.3.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"item"="OpenOffice.org 1.1.3.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dinst"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\dinst.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeMem Pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="freemem"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="P2P Networking"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\P2P Networking\\P2P Networking.exe /AUTOSTART"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TeaTimer"
"hkey"="HKCU"
"command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPEnh"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System service79]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pokapoka79"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\\\\\etb\\\\pokapoka79.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tpjmncp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vadxdi"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\vadxdi.exe r"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VPTray"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~2\\VPTray.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vwvjzbn]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ordtccs"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\ordtccs.exe r"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymSecurePort"=dword:00000002
"Symantec AntiVirus"=dword:00000002
"SvcProc"=dword:00000002
"SPBBCSvc"=dword:00000003
"SNDSrvc"=dword:00000002
"SavRoam"=dword:00000003
"NVSvc"=dword:00000002
"ISSVC"=dword:00000002
"DefWatch"=dword:00000002
"Crypkey License"=dword:00000002
"ccSetMgr"=dword:00000002
"ccPwdSvc"=dword:00000003
"ccProxy"=dword:00000002
"ccEvtMgr"=dword:00000002
"AvidStartup"=dword:00000002
"AvidSDMService"=dword:00000002
"ALG"=dword:00000003
"mnmsrvc"=dword:00000003

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
@=""



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Registration reminder 1.job
C:\WINDOWS\tasks\Registration reminder 2.job
C:\WINDOWS\tasks\Registration reminder 3.job
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Sun 07/09/2006 20:17:14.31
ComboFix ver 06.07.08 - This logfile is located at C:\ComboFix.txt

HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 8:19:51 PM, on 7/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Shortcut to linkfile_fix.lnk = TomCoyote\linkfile_fix.reg
O4 - Startup: Shortcut to xp_com_fix.lnk = TomCoyote\xp_com_fix.reg
O4 - Startup: Shortcut to xp_exe_fix.lnk = TomCoyote\xp_exe_fix.reg
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
Next, launch Notepad (Start>All Programs>Accessories), and copy/paste all the BOLD REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System service79]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared Tools\msconfig\startupreg\tpjmncp]

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vwvjzbn]



On the desktop, doubleclick fix.reg and allow it to run. Let it merge.





Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -


Close ALL windows and browsers except HijackThis and click "Fix checked"


Delete these Files if listed:
C:\WINDOWS\dinst.exe
C:\WINDOWS\etb\pokapoka79.exe
C:\WINDOWS\System32\vadxdi.exe
C:\WINDOWS\system32\ordtccs.exe




Empty Recycle Bin

Restart your computer.

Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
I could Ping Google from normal mode. This is an improvement!!! Start>Run>regedit launches regedit.exe. This is an improvement!!!! Start>run>launches a command window. This is an improvement!!!
IE still doesn't find the internet, Grisoft AVG couldn't update. None of those files appeared to be on the drive to delete, but seemed to still be listed by Combofix.

Here's the logfile:

Logfile of HijackThis v1.99.1
Scan saved at 9:24:19 PM, on 7/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Shortcut to linkfile_fix.lnk = TomCoyote\linkfile_fix.reg
O4 - Startup: Shortcut to xp_com_fix.lnk = TomCoyote\xp_com_fix.reg
O4 - Startup: Shortcut to xp_exe_fix.lnk = TomCoyote\xp_exe_fix.reg
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe

And Combofix again:

Start Time= Sun 07/09/2006 21:26:41.33
Running from: C:\Documents and Settings\[removed]\My Documents\Downloads\TomCoyote\Combofix

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-05 22:07:44 ( .D… ) "C:\Program Files\Eyetide Media"
2006-07-05 20:57:50 ( .D… ) "C:\Program Files\CCleaner"
2006-07-05 20:00:30 ( .D… ) "C:\Program Files\ewido anti-spyware 4.0"
2006-07-05 19:57:58 ( .D… ) "C:\Documents and Settings\Jason\Application Data\Google"
2006-07-04 18:36:50 ( .D… ) "C:\Program Files\HijackThis"
2006-07-04 12:44:42 0 ( A…. ) "C:\Documents and Settings\Jason\Application Data\sversion.ini"
2006-07-04 00:41:40 47564 ( A.SHR ) "C:\NTDETECT.COM"
2006-07-02 21:18:04 ( .D… ) "C:\Documents and Settings\Jason\Application Data\AVG7"
2006-07-02 21:17:26 ( .D… ) "C:\Program Files\Grisoft"
2006-07-02 21:04:16 ( .D… ) "C:\Program Files\TBIView"
2006-07-02 21:04:02 ( .D… ) "C:\Program Files\Image for Windows"
2006-06-23 09:28:56 5512704 ( ….. ) "C:\WINDOWS\system32\ieframe.dll"
2006-06-23 09:28:56 454144 ( ….. ) "C:\WINDOWS\system32\msfeeds.dll"
2006-06-23 09:28:56 413696 ( A…. ) "C:\WINDOWS\system32\vbscript.dll"
2006-06-23 09:28:56 223744 ( A…. ) "C:\WINDOWS\system32\webcheck.dll"
2006-06-23 09:28:56 179200 ( ….. ) "C:\WINDOWS\system32\ieui.dll"
2006-06-23 09:28:56 155648 ( A…. ) "C:\WINDOWS\system32\msls31.dll"
2006-06-23 09:28:56 47616 ( ….. ) "C:\WINDOWS\system32\msfeedsbs.dll"
2006-06-23 05:41:42 172544 ( ….. ) "C:\WINDOWS\system32\WinFXDocObj.exe"
2006-06-23 05:40:44 78848 ( A…. ) "C:\WINDOWS\system32\ieencode.dll"
2006-06-23 05:40:04 40960 ( A…. ) "C:\WINDOWS\system32\url.dll"
2006-06-23 05:39:52 39424 ( A…. ) "C:\WINDOWS\system32\licmgr10.dll"
2006-06-23 05:39:08 99328 ( A…. ) "C:\WINDOWS\system32\occache.dll"
2006-06-23 05:37:18 14336 ( A…. ) "C:\WINDOWS\system32\corpol.dll"
2006-06-23 05:34:30 228864 ( A…. ) "C:\WINDOWS\system32\ieaksie.dll"
2006-06-23 05:34:16 167936 ( A…. ) "C:\WINDOWS\system32\ieakeng.dll"
2006-06-23 05:34:06 81920 ( A…. ) "C:\WINDOWS\system32\admparse.dll"
2006-06-23 05:34:06 50688 ( A…. ) "C:\WINDOWS\system32\ie4uinit.exe"
2006-06-23 05:34:02 372736 ( A…. ) "C:\WINDOWS\system32\iedkcs32.dll"
2006-06-23 05:33:42 54272 ( A…. ) "C:\WINDOWS\system32\iesetup.dll"
2006-06-23 05:33:22 41984 ( A…. ) "C:\WINDOWS\system32\iernonce.dll"
2006-06-23 05:33:00 121856 ( A…. ) "C:\WINDOWS\system32\advpack.dll"
2006-06-23 05:30:22 11776 ( ….. ) "C:\WINDOWS\system32\msfeedssync.exe"
2006-06-23 05:29:56 55296 ( ….. ) "C:\WINDOWS\system32\icardie.dll"
2006-06-23 05:29:22 35328 ( A…. ) "C:\WINDOWS\system32\imgutil.dll"
2006-06-23 05:27:56 251392 ( ….. ) "C:\WINDOWS\system32\iertutil.dll"
2006-06-23 05:26:52 45568 ( A…. ) "C:\WINDOWS\system32\mshta.exe"
2006-06-23 04:46:30 377856 ( ….. ) "C:\WINDOWS\system32\ieapfltr.dll"
2006-06-23 04:45:30 48640 ( A…. ) "C:\WINDOWS\system32\mshtmler.dll"
2006-06-23 04:41:42 172032 ( A…. ) "C:\WINDOWS\system32\ieakui.dll"
2006-06-19 15:18:34 22752 ( A…. ) "C:\WINDOWS\system32\spupdsvc.exe"
2006-06-19 15:18:16 23552 ( ….. ) "C:\WINDOWS\system32\idndl.dll"
2006-06-19 15:18:16 20480 ( ….. ) "C:\WINDOWS\system32\normaliz.dll"
2006-06-12 23:56:18 ( .D… ) "C:\Program Files\Badder Adder"
2006-05-25 01:22:06 53248 ( A…. ) "C:\WINDOWS\bdoscandel.exe"
2006-05-24 11:20:26 ( .D… ) "C:\Program Files\Mozilla Firefox"
2005-12-20 15:53:12 3791064 ( A…. ) "C:\Program Files\hbk4.exe"
2001-11-21 10:10:06 18330960 ( A…. ) "C:\Program Files\Oxpsp1.exe"


(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))


2006-07-09 21:19 536,268,800 C:\hiberfil.sys
2006-07-04 12:34 117,760 C:\WINDOWS\system32\xmllite.dll
2006-07-04 00:48 937,984 C:\WINDOWS\system32\winbrand.dll
2006-07-04 00:48 9,216 C:\WINDOWS\system32\proxycfg.exe
2006-07-04 00:48 88,064 C:\WINDOWS\system32\p2pnetsh.dll
2006-07-04 00:48 870,784 C:\WINDOWS\system32\ati3d1ag.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\p2pgasvc.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\mdmxsdk.dll
2006-07-04 00:48 81,408 C:\WINDOWS\system32\wscsvc.dll
2006-07-04 00:48 8,192 C:\WINDOWS\system32\smbinst.exe
2006-07-04 00:48 78,848 C:\WINDOWS\system32\ieencode.dll
2006-07-04 00:48 75,776 C:\WINDOWS\system32\strmfilt.dll
2006-07-04 00:48 73,832 C:\WINDOWS\system32\slcoinst.dll
2006-07-04 00:48 73,796 C:\WINDOWS\system32\slserv.exe
2006-07-04 00:48 71,680 C:\WINDOWS\system32\blastcln.exe
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsno.dll
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsfi.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdukx.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdno1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdfi1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\hccoin.dll
2006-07-04 00:48 60,416 C:\WINDOWS\system32\fwcfg.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinmal.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinben.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt48.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt47.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdinbe1.dll
2006-07-04 00:48 59,392 C:\WINDOWS\system32\logman.exe
2006-07-04 00:48 537,088 C:\WINDOWS\system32\msftedit.dll
2006-07-04 00:48 526,848 C:\WINDOWS\system32\p2psvc.dll
2006-07-04 00:48 516,768 C:\WINDOWS\system32\ativvaxx.dll
2006-07-04 00:48 50,688 C:\WINDOWS\system32\btpanui.dll
2006-07-04 00:48 50,176 C:\WINDOWS\system32\xmlprovi.dll
2006-07-04 00:48 5,632 C:\WINDOWS\system32\kbdmaori.dll
2006-07-04 00:48 49,152 C:\WINDOWS\system32\powercfg.exe
2006-07-04 00:48 48,640 C:\WINDOWS\system32\pnrpnsp.dll
2006-07-04 00:48 44,032 C:\WINDOWS\system32\twext.dll
2006-07-04 00:48 4,096 C:\WINDOWS\system32\dsprpres.dll
2006-07-04 00:48 397,056 C:\WINDOWS\system32\s3gnb.dll
2006-07-04 00:48 377,984 C:\WINDOWS\system32\ati2dvaa.dll
2006-07-04 00:48 32,866 C:\WINDOWS\system32\slrundll.exe
2006-07-04 00:48 32,866 C:\WINDOWS\slrundll.exe
2006-07-04 00:48 32,768 C:\WINDOWS\system32\ativtmxx.dll
2006-07-04 00:48 32,285 C:\WINDOWS\system32\hsfcisp2.dll
2006-07-04 00:48 312,320 C:\WINDOWS\system32\p2pgraph.dll
2006-07-04 00:48 30,208 C:\WINDOWS\system32\bthserv.dll
2006-07-04 00:48 29,184 C:\WINDOWS\system32\sdhcinst.dll
2006-07-04 00:48 286,792 C:\WINDOWS\system32\slextspk.dll
2006-07-04 00:48 270,848 C:\WINDOWS\system32\sbe.dll
2006-07-04 00:48 24,576 C:\WINDOWS\system32\httpapi.dll
2006-07-04 00:48 229,376 C:\WINDOWS\system32\ati2cqag.dll
2006-07-04 00:48 22,528 C:\WINDOWS\system32\fltmc.exe
2006-07-04 00:48 201,728 C:\WINDOWS\system32\ati2dvag.dll
2006-07-04 00:48 20,992 C:\WINDOWS\system32\bthci.dll
2006-07-04 00:48 20,480 C:\WINDOWS\system32\encapi.dll
2006-07-04 00:48 2,113,536 C:\WINDOWS\system32\dxdiagn.dll
2006-07-04 00:48 193,024 C:\WINDOWS\system32\fsquirt.exe
2006-07-04 00:48 188,508 C:\WINDOWS\system32\slgen.dll
2006-07-04 00:48 187,392 C:\WINDOWS\system32\xpsp1res.dll
2006-07-04 00:48 186,368 C:\WINDOWS\system32\encdec.dll
2006-07-04 00:48 17,408 C:\WINDOWS\system32\winshfhc.dll
2006-07-04 00:48 16,896 C:\WINDOWS\system32\fltlib.dll
2006-07-04 00:48 159,232 C:\WINDOWS\system32\sbeio.dll
2006-07-04 00:48 15,872 C:\WINDOWS\system32\w3ssl.dll
2006-07-04 00:48 14,336 C:\WINDOWS\system32\auditusr.exe
2006-07-04 00:48 134,656 C:\WINDOWS\system32\mssap.dll
2006-07-04 00:48 13,824 C:\WINDOWS\system32\wscntfy.exe
2006-07-04 00:48 13,824 C:\WINDOWS\system32\cmsetacl.dll
2006-07-04 00:48 129,536 C:\WINDOWS\system32\xmlprov.dll
2006-07-04 00:48 118,784 C:\WINDOWS\system32\msdadiag.dll
2006-07-04 00:48 116,224 C:\WINDOWS\system32\p2p.dll
2006-07-04 00:48 108,032 C:\WINDOWS\system32\wshbth.dll
2006-07-04 00:48 1,888,992 C:\WINDOWS\system32\ati3duag.dll
2006-07-04 00:48 1,737,856 C:\WINDOWS\system32\mtxparhd.dll
2006-07-04 00:48 1,689,088 C:\WINDOWS\system32\d3d9.dll
2006-07-04 00:43 92,224 C:\WINDOWS\system32\krnl386.exe
2006-07-04 00:42 2,897,920 C:\WINDOWS\system32\xpsp2res.dll
2006-06-23 09:28 5,512,704 C:\WINDOWS\system32\ieframe.dll
2006-06-23 09:28 47,616 C:\WINDOWS\system32\msfeedsbs.dll
2006-06-23 09:28 454,144 C:\WINDOWS\system32\msfeeds.dll
2006-06-23 09:28 179,200 C:\WINDOWS\system32\ieui.dll
2006-06-23 05:41 172,544 C:\WINDOWS\system32\WinFXDocObj.exe
2006-06-23 05:30 11,776 C:\WINDOWS\system32\msfeedssync.exe
2006-06-23 05:29 55,296 C:\WINDOWS\system32\icardie.dll
2006-06-23 05:27 251,392 C:\WINDOWS\system32\iertutil.dll
2006-06-23 04:46 377,856 C:\WINDOWS\system32\ieapfltr.dll
2006-06-19 15:18 23,552 C:\WINDOWS\system32\idndl.dll
2006-06-19 15:18 20,480 C:\WINDOWS\system32\normaliz.dll
2006-06-12 23:56 101,888 C:\WINDOWS\system32\VB6STKIT.DLL
2006-05-25 01:22 53,248 C:\WINDOWS\bdoscandel.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"FreeMem Pro"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e0,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^LimeWire On Startup.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"item"="LimeWire On Startup.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OpenOffice.org 1.1.3.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\OpenOffice.org 1.1.3.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"item"="OpenOffice.org 1.1.3.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeMem Pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="freemem"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TeaTimer"
"hkey"="HKCU"
"command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPEnh"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VPTray"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~2\\VPTray.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymSecurePort"=dword:00000002
"Symantec AntiVirus"=dword:00000002
"SvcProc"=dword:00000002
"SPBBCSvc"=dword:00000003
"SNDSrvc"=dword:00000002
"SavRoam"=dword:00000003
"NVSvc"=dword:00000002
"ISSVC"=dword:00000002
"DefWatch"=dword:00000002
"Crypkey License"=dword:00000002
"ccSetMgr"=dword:00000002
"ccPwdSvc"=dword:00000003
"ccProxy"=dword:00000002
"ccEvtMgr"=dword:00000002
"AvidStartup"=dword:00000002
"AvidSDMService"=dword:00000002
"ALG"=dword:00000003
"mnmsrvc"=dword:00000003

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
@=""



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Registration reminder 1.job
C:\WINDOWS\tasks\Registration reminder 2.job
C:\WINDOWS\tasks\Registration reminder 3.job
C:\WINDOWS\tasks\Symantec NetDetect.job

Completion time: Sun 07/09/2006 21:27:09.34
ComboFix ver 06.07.08 - This logfile is located at C:\ComboFix.txt

ComboFix.2006-07-09.212641.txt

None of those files appeared to be on the drive to delete, but seemed to still be listed by Combofix.

I don't see the ones I had you delete. It also looks like the regfix worked :thumbup:


You need To disable TeaTimer, it can stop our fix.

1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -


Close ALL windows and browsers except HijackThis and click "Fix checked"



I'm not sure why these are there. :scratch:
O4 - Startup: Shortcut to linkfile_fix.lnk = TomCoyote\linkfile_fix.reg
O4 - Startup: Shortcut to xp_com_fix.lnk = TomCoyote\xp_com_fix.reg
O4 - Startup: Shortcut to xp_exe_fix.lnk = TomCoyote\xp_exe_fix.reg

Lets try this one instead.
Download the REG file here http://www.kellys-korner-xp.com/regs_edits/xp_exe_fix.reg
and save it to your hard drive. Double click the file you just saved and answer yes to the import prompt.

Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
At first I couldn't ping Google.com. There were four timeouts. But then in a couple of minutes I could ping google.com but it resolved to a different IP…

Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.

C:\Documents and Settings\Jason>ping google.com

Pinging google.com [72.14.207.99] with 32 bytes of data:

Request timed out.
Request timed out.
Request timed out.
Request timed out.

Ping statistics for 72.14.207.99:
Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),

C:\Documents and Settings\Jason>ping 192.168.0.1

Pinging 192.168.0.1 with 32 bytes of data:

Reply from 192.168.0.1: bytes=32 time<1ms TTL=128
Reply from 192.168.0.1: bytes=32 time<1ms TTL=128
Reply from 192.168.0.1: bytes=32 time<1ms TTL=128
Reply from 192.168.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 192.168.0.1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms

C:\Documents and Settings\Jason>ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : JMay
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Mixed
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : www.advanced-houston.com

Ethernet adapter Local Area Connection:

Connection-specific DNS Suffix . : www.advanced-houston.com
Description . . . . . . . . . . . : Intel® PRO/100 VE Network Connecti
on
Physical Address. . . . . . . . . : 00-00-39-4F-53-DD
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.0.108
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.0.1
DHCP Server . . . . . . . . . . . : 192.168.0.1
DNS Servers . . . . . . . . . . . : 192.168.0.1
Lease Obtained. . . . . . . . . . : Sunday, July 09, 2006 10:16:34 PM
Lease Expires . . . . . . . . . . : Sunday, July 16, 2006 10:16:34 PM

C:\Documents and Settings\Jason>ping google.com

Pinging google.com [64.233.167.99] with 32 bytes of data:

Reply from 64.233.167.99: bytes=32 time=57ms TTL=240
Reply from 64.233.167.99: bytes=32 time=59ms TTL=240
Reply from 64.233.167.99: bytes=32 time=56ms TTL=240
Reply from 64.233.167.99: bytes=32 time=58ms TTL=240

Ping statistics for 64.233.167.99:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 56ms, Maximum = 59ms, Average = 57ms

C:\Documents and Settings\Jason>


Here's the log file:

Logfile of HijackThis v1.99.1
Scan saved at 10:21:17 PM, on 7/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe

And Combofix:

Start Time= Sun 07/09/2006 22:22:05.97
Running from: C:\Documents and Settings\[removed]
QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report

)))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-07-05 22:07:44 ( .D… ) "C:\Program

Files\Eyetide Media"
2006-07-05 20:57:50 ( .D… ) "C:\Program

Files\CCleaner"
2006-07-05 20:00:30 ( .D… ) "C:\Program

Files\ewido anti-spyware 4.0"
2006-07-05 19:57:58 ( .D… ) "C:\Documents and

Settings\Jason\Application Data\Google"
2006-07-04 18:36:50 ( .D… ) "C:\Program

Files\HijackThis"
2006-07-04 12:44:42 0 ( A…. ) "C:\Documents and

Settings\Jason\Application Data\sversion.ini"
2006-07-04 00:41:40 47564 ( A.SHR ) "C:\NTDETECT.COM"
2006-07-02 21:18:04 ( .D… ) "C:\Documents and

Settings\Jason\Application Data\AVG7"
2006-07-02 21:17:26 ( .D… ) "C:\Program

Files\Grisoft"
2006-07-02 21:04:16 ( .D… ) "C:\Program

Files\TBIView"
2006-07-02 21:04:02 ( .D… ) "C:\Program

Files\Image for Windows"
2006-06-23 09:28:56 5512704 ( ….. )

"C:\WINDOWS\system32\ieframe.dll"
2006-06-23 09:28:56 454144 ( ….. )

"C:\WINDOWS\system32\msfeeds.dll"
2006-06-23 09:28:56 413696 ( A…. )

"C:\WINDOWS\system32\vbscript.dll"
2006-06-23 09:28:56 223744 ( A…. )

"C:\WINDOWS\system32\webcheck.dll"
2006-06-23 09:28:56 179200 ( ….. )

"C:\WINDOWS\system32\ieui.dll"
2006-06-23 09:28:56 155648 ( A…. )

"C:\WINDOWS\system32\msls31.dll"
2006-06-23 09:28:56 47616 ( ….. )

"C:\WINDOWS\system32\msfeedsbs.dll"
2006-06-23 05:41:42 172544 ( ….. )

"C:\WINDOWS\system32\WinFXDocObj.exe"
2006-06-23 05:40:44 78848 ( A…. )

"C:\WINDOWS\system32\ieencode.dll"
2006-06-23 05:40:04 40960 ( A…. )

"C:\WINDOWS\system32\url.dll"
2006-06-23 05:39:52 39424 ( A…. )

"C:\WINDOWS\system32\licmgr10.dll"
2006-06-23 05:39:08 99328 ( A…. )

"C:\WINDOWS\system32\occache.dll"
2006-06-23 05:37:18 14336 ( A…. )

"C:\WINDOWS\system32\corpol.dll"
2006-06-23 05:34:30 228864 ( A…. )

"C:\WINDOWS\system32\ieaksie.dll"
2006-06-23 05:34:16 167936 ( A…. )

"C:\WINDOWS\system32\ieakeng.dll"
2006-06-23 05:34:06 81920 ( A…. )

"C:\WINDOWS\system32\admparse.dll"
2006-06-23 05:34:06 50688 ( A…. )

"C:\WINDOWS\system32\ie4uinit.exe"
2006-06-23 05:34:02 372736 ( A…. )

"C:\WINDOWS\system32\iedkcs32.dll"
2006-06-23 05:33:42 54272 ( A…. )

"C:\WINDOWS\system32\iesetup.dll"
2006-06-23 05:33:22 41984 ( A…. )

"C:\WINDOWS\system32\iernonce.dll"
2006-06-23 05:33:00 121856 ( A…. )

"C:\WINDOWS\system32\advpack.dll"
2006-06-23 05:30:22 11776 ( ….. )

"C:\WINDOWS\system32\msfeedssync.exe"
2006-06-23 05:29:56 55296 ( ….. )

"C:\WINDOWS\system32\icardie.dll"
2006-06-23 05:29:22 35328 ( A…. )

"C:\WINDOWS\system32\imgutil.dll"
2006-06-23 05:27:56 251392 ( ….. )

"C:\WINDOWS\system32\iertutil.dll"
2006-06-23 05:26:52 45568 ( A…. )

"C:\WINDOWS\system32\mshta.exe"
2006-06-23 04:46:30 377856 ( ….. )

"C:\WINDOWS\system32\ieapfltr.dll"
2006-06-23 04:45:30 48640 ( A…. )

"C:\WINDOWS\system32\mshtmler.dll"
2006-06-23 04:41:42 172032 ( A…. )

"C:\WINDOWS\system32\ieakui.dll"
2006-06-19 15:18:34 22752 ( A…. )

"C:\WINDOWS\system32\spupdsvc.exe"
2006-06-19 15:18:16 23552 ( ….. )

"C:\WINDOWS\system32\idndl.dll"
2006-06-19 15:18:16 20480 ( ….. )

"C:\WINDOWS\system32\normaliz.dll"
2006-06-12 23:56:18 ( .D… ) "C:\Program

Files\Badder Adder"
2006-05-25 01:22:06 53248 ( A…. )

"C:\WINDOWS\bdoscandel.exe"
2006-05-24 11:20:26 ( .D… ) "C:\Program

Files\Mozilla Firefox"
2005-12-20 15:53:12 3791064 ( A…. ) "C:\Program

Files\hbk4.exe"
2001-11-21 10:10:06 18330960 ( A…. ) "C:\Program

Files\Oxpsp1.exe"


(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days

)))))))))))))))))))))))))))))))))))))))))))


2006-07-09 22:01 536,268,800 C:\hiberfil.sys
2006-07-04 12:34 117,760 C:\WINDOWS\system32\xmllite.dll
2006-07-04 00:48 937,984 C:\WINDOWS\system32\winbrand.dll
2006-07-04 00:48 9,216 C:\WINDOWS\system32\proxycfg.exe
2006-07-04 00:48 88,064 C:\WINDOWS\system32\p2pnetsh.dll
2006-07-04 00:48 870,784 C:\WINDOWS\system32\ati3d1ag.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\p2pgasvc.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\mdmxsdk.dll
2006-07-04 00:48 81,408 C:\WINDOWS\system32\wscsvc.dll
2006-07-04 00:48 8,192 C:\WINDOWS\system32\smbinst.exe
2006-07-04 00:48 78,848 C:\WINDOWS\system32\ieencode.dll
2006-07-04 00:48 75,776 C:\WINDOWS\system32\strmfilt.dll
2006-07-04 00:48 73,832 C:\WINDOWS\system32\slcoinst.dll
2006-07-04 00:48 73,796 C:\WINDOWS\system32\slserv.exe
2006-07-04 00:48 71,680 C:\WINDOWS\system32\blastcln.exe
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsno.dll
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsfi.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdukx.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdno1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdfi1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\hccoin.dll
2006-07-04 00:48 60,416 C:\WINDOWS\system32\fwcfg.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinmal.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinben.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt48.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt47.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdinbe1.dll
2006-07-04 00:48 59,392 C:\WINDOWS\system32\logman.exe
2006-07-04 00:48 537,088 C:\WINDOWS\system32\msftedit.dll
2006-07-04 00:48 526,848 C:\WINDOWS\system32\p2psvc.dll
2006-07-04 00:48 516,768 C:\WINDOWS\system32\ativvaxx.dll
2006-07-04 00:48 50,688 C:\WINDOWS\system32\btpanui.dll
2006-07-04 00:48 50,176 C:\WINDOWS\system32\xmlprovi.dll
2006-07-04 00:48 5,632 C:\WINDOWS\system32\kbdmaori.dll
2006-07-04 00:48 49,152 C:\WINDOWS\system32\powercfg.exe
2006-07-04 00:48 48,640 C:\WINDOWS\system32\pnrpnsp.dll
2006-07-04 00:48 44,032 C:\WINDOWS\system32\twext.dll
2006-07-04 00:48 4,096 C:\WINDOWS\system32\dsprpres.dll
2006-07-04 00:48 397,056 C:\WINDOWS\system32\s3gnb.dll
2006-07-04 00:48 377,984 C:\WINDOWS\system32\ati2dvaa.dll
2006-07-04 00:48 32,866 C:\WINDOWS\system32\slrundll.exe
2006-07-04 00:48 32,866 C:\WINDOWS\slrundll.exe
2006-07-04 00:48 32,768 C:\WINDOWS\system32\ativtmxx.dll
2006-07-04 00:48 32,285 C:\WINDOWS\system32\hsfcisp2.dll
2006-07-04 00:48 312,320 C:\WINDOWS\system32\p2pgraph.dll
2006-07-04 00:48 30,208 C:\WINDOWS\system32\bthserv.dll
2006-07-04 00:48 29,184 C:\WINDOWS\system32\sdhcinst.dll
2006-07-04 00:48 286,792 C:\WINDOWS\system32\slextspk.dll
2006-07-04 00:48 270,848 C:\WINDOWS\system32\sbe.dll
2006-07-04 00:48 24,576 C:\WINDOWS\system32\httpapi.dll
2006-07-04 00:48 229,376 C:\WINDOWS\system32\ati2cqag.dll
2006-07-04 00:48 22,528 C:\WINDOWS\system32\fltmc.exe
2006-07-04 00:48 201,728 C:\WINDOWS\system32\ati2dvag.dll
2006-07-04 00:48 20,992 C:\WINDOWS\system32\bthci.dll
2006-07-04 00:48 20,480 C:\WINDOWS\system32\encapi.dll
2006-07-04 00:48 2,113,536

C:\WINDOWS\system32\dxdiagn.dll
2006-07-04 00:48 193,024 C:\WINDOWS\system32\fsquirt.exe
2006-07-04 00:48 188,508 C:\WINDOWS\system32\slgen.dll
2006-07-04 00:48 187,392 C:\WINDOWS\system32\xpsp1res.dll
2006-07-04 00:48 186,368 C:\WINDOWS\system32\encdec.dll
2006-07-04 00:48 17,408 C:\WINDOWS\system32\winshfhc.dll
2006-07-04 00:48 16,896 C:\WINDOWS\system32\fltlib.dll
2006-07-04 00:48 159,232 C:\WINDOWS\system32\sbeio.dll
2006-07-04 00:48 15,872 C:\WINDOWS\system32\w3ssl.dll
2006-07-04 00:48 14,336 C:\WINDOWS\system32\auditusr.exe
2006-07-04 00:48 134,656 C:\WINDOWS\system32\mssap.dll
2006-07-04 00:48 13,824 C:\WINDOWS\system32\wscntfy.exe
2006-07-04 00:48 13,824 C:\WINDOWS\system32\cmsetacl.dll
2006-07-04 00:48 129,536 C:\WINDOWS\system32\xmlprov.dll
2006-07-04 00:48 118,784 C:\WINDOWS\system32\msdadiag.dll
2006-07-04 00:48 116,224 C:\WINDOWS\system32\p2p.dll
2006-07-04 00:48 108,032 C:\WINDOWS\system32\wshbth.dll
2006-07-04 00:48 1,888,992

C:\WINDOWS\system32\ati3duag.dll
2006-07-04 00:48 1,737,856

C:\WINDOWS\system32\mtxparhd.dll
2006-07-04 00:48 1,689,088 C:\WINDOWS\system32\d3d9.dll
2006-07-04 00:43 92,224 C:\WINDOWS\system32\krnl386.exe
2006-07-04 00:42 2,897,920

C:\WINDOWS\system32\xpsp2res.dll
2006-06-23 09:28 5,512,704

C:\WINDOWS\system32\ieframe.dll
2006-06-23 09:28 47,616 C:\WINDOWS\system32\msfeedsbs.dll
2006-06-23 09:28 454,144 C:\WINDOWS\system32\msfeeds.dll
2006-06-23 09:28 179,200 C:\WINDOWS\system32\ieui.dll
2006-06-23 05:41 172,544 C:\WINDOWS\system32\WinFXDocObj.exe
2006-06-23 05:30 11,776 C:\WINDOWS\system32\msfeedssync.exe
2006-06-23 05:29 55,296 C:\WINDOWS\system32\icardie.dll
2006-06-23 05:27 251,392 C:\WINDOWS\system32\iertutil.dll
2006-06-23 04:46 377,856 C:\WINDOWS\system32\ieapfltr.dll
2006-06-19 15:18 23,552 C:\WINDOWS\system32\idndl.dll
2006-06-19 15:18 20,480 C:\WINDOWS\system32\normaliz.dll
2006-06-12 23:56 101,888 C:\WINDOWS\system32\VB6STKIT.DLL
2006-05-25 01:22 53,248 C:\WINDOWS\bdoscandel.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points

))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"FreeMem Pro"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e0,02,00,00,00

,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff

,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00

,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explo

rer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explo

rer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shared

taskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache

daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelle

xecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start

Menu^Programs^Startup^LimeWire On Startup.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start

Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start

Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"item"="LimeWire On Startup.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start

Menu^Programs^Startup^OpenOffice.org 1.1.3.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start

Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\OpenOffice.org 1.1.3.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start

Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"item"="OpenOffice.org 1.1.3.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupreg\FreeMem Pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="freemem"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupreg\SpybotSD TeaTimer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TeaTimer"
"hkey"="HKCU"
"command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupreg\SynTPEnh]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPEnh"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common

Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared

tools\msconfig\startupreg\vptray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VPTray"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~2\\VPTray.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymSecurePort"=dword:00000002
"Symantec AntiVirus"=dword:00000002
"SvcProc"=dword:00000002
"SPBBCSvc"=dword:00000003
"SNDSrvc"=dword:00000002
"SavRoam"=dword:00000003
"NVSvc"=dword:00000002
"ISSVC"=dword:00000002
"DefWatch"=dword:00000002
"Crypkey License"=dword:00000002
"ccSetMgr"=dword:00000002
"ccPwdSvc"=dword:00000003
"ccProxy"=dword:00000002
"ccEvtMgr"=dword:00000002
"AvidStartup"=dword:00000002
"AvidSDMService"=dword:00000002
"ALG"=dword:00000003
"mnmsrvc"=dword:00000003

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
@=""



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Registration reminder 1.job
C:\WINDOWS\tasks\Registration reminder 2.job
C:\WINDOWS\tasks\Registration r


Wow…Thanks

-kp
Yeah, my head hurt after all that yesterday. Then I hit the ground running this morning.

But still no internet access, except in safe-mode. I can ping, but no internet and no AVG update, no Spybot update.

Here's the logfile after the last fix attempt:

Logfile of HijackThis v1.99.1
Scan saved at 9:27:24 PM, on 7/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\regedit.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe

Thanks,

-kp
Also, no Mozilla internet access. When in normal-mode I have no "network connection" in "My Network Places">properties. But Task Manager shows an active adaptor and I can ping.
I don't remember if I asked you this already but do you have your windows CD?

If so try this:

use windows sfc (system file checker) You'd need your XP CD to make this work.
Click Start> Run> type sfc /scannow Note the space.
(Note that there is a space between sfc and /scannow)
Yeah, you asked me and I told you I'd run sfc /scannow. Also, I ran it again when I went to bed last night. No change I could see. Also, I noticed when I started IE7 that I'm getting some wierd info in the Status Bar. Some knid of a dnserror.html flashes by. Too fast really to get fully. I also tried uninstalling the Network Adaptor. Windows did not "find new hardware" the Device Manager had No (none, zero) devices, or it was blanked. I ran the "add new hardware" wizard and it did detect the adaptor.
Same thing. Wow, this thing is screwed UP!!!!

Got any more ideas?




Logfile of HijackThis v1.99.1
Scan saved at 1:23:29 PM, on 7/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI