Spyware / Malware / Virus Removal
HijackThis Logfile
14 min read
← Previous
Page 2 of 4
Next →
This thread's last reply is from July 14, 2006, 9:09 PM UTC . Advice, software, and links
below may be out of date — treat specific steps and download links with caution.
Looking for the outcome? ✨ Ask AI
OK. Lets see if we can also work on the EXE and COM file issue.
Open C:\windows
Click View> Details> Arrange ICONS by Type.
That should list the files with .exe and .com
Look for files with both extentions. I suggest you rename the .com files to .old.
Example: Regedit.com right click and select Rename. Rename to Regedit.old
Open C:\windows\System32
Click View> Details> Arrange ICONS by Type.
There should be alot more .exe files in this folder.
Wow…
Explorer windows crash often when I need to "browse"
Here's the Combofix File:
Start Time= Sun 07/09/2006 20:16:45.55
Running from: C:\Documents and Settings\[removed]
QuickScan did not find any signs of infected files
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-07-05 22:07:44 ( .D… ) "C:\Program Files\Eyetide Media"
2006-07-05 20:57:50 ( .D… ) "C:\Program Files\CCleaner"
2006-07-05 20:00:30 ( .D… ) "C:\Program Files\ewido anti-spyware 4.0"
2006-07-05 19:57:58 ( .D… ) "C:\Documents and Settings\Jason\Application Data\Google"
2006-07-04 18:36:50 ( .D… ) "C:\Program Files\HijackThis"
2006-07-04 12:44:42 0 ( A…. ) "C:\Documents and Settings\Jason\Application Data\sversion.ini"
2006-07-04 00:41:40 47564 ( A.SHR ) "C:\NTDETECT.COM"
2006-07-02 21:18:04 ( .D… ) "C:\Documents and Settings\Jason\Application Data\AVG7"
2006-07-02 21:17:26 ( .D… ) "C:\Program Files\Grisoft"
2006-07-02 21:04:16 ( .D… ) "C:\Program Files\TBIView"
2006-07-02 21:04:02 ( .D… ) "C:\Program Files\Image for Windows"
2006-06-23 09:28:56 5512704 ( ….. ) "C:\WINDOWS\system32\ieframe.dll"
2006-06-23 09:28:56 454144 ( ….. ) "C:\WINDOWS\system32\msfeeds.dll"
2006-06-23 09:28:56 413696 ( A…. ) "C:\WINDOWS\system32\vbscript.dll"
2006-06-23 09:28:56 223744 ( A…. ) "C:\WINDOWS\system32\webcheck.dll"
2006-06-23 09:28:56 179200 ( ….. ) "C:\WINDOWS\system32\ieui.dll"
2006-06-23 09:28:56 155648 ( A…. ) "C:\WINDOWS\system32\msls31.dll"
2006-06-23 09:28:56 47616 ( ….. ) "C:\WINDOWS\system32\msfeedsbs.dll"
2006-06-23 05:41:42 172544 ( ….. ) "C:\WINDOWS\system32\WinFXDocObj.exe"
2006-06-23 05:40:44 78848 ( A…. ) "C:\WINDOWS\system32\ieencode.dll"
2006-06-23 05:40:04 40960 ( A…. ) "C:\WINDOWS\system32\url.dll"
2006-06-23 05:39:52 39424 ( A…. ) "C:\WINDOWS\system32\licmgr10.dll"
2006-06-23 05:39:08 99328 ( A…. ) "C:\WINDOWS\system32\occache.dll"
2006-06-23 05:37:18 14336 ( A…. ) "C:\WINDOWS\system32\corpol.dll"
2006-06-23 05:34:30 228864 ( A…. ) "C:\WINDOWS\system32\ieaksie.dll"
2006-06-23 05:34:16 167936 ( A…. ) "C:\WINDOWS\system32\ieakeng.dll"
2006-06-23 05:34:06 81920 ( A…. ) "C:\WINDOWS\system32\admparse.dll"
2006-06-23 05:34:06 50688 ( A…. ) "C:\WINDOWS\system32\ie4uinit.exe"
2006-06-23 05:34:02 372736 ( A…. ) "C:\WINDOWS\system32\iedkcs32.dll"
2006-06-23 05:33:42 54272 ( A…. ) "C:\WINDOWS\system32\iesetup.dll"
2006-06-23 05:33:22 41984 ( A…. ) "C:\WINDOWS\system32\iernonce.dll"
2006-06-23 05:33:00 121856 ( A…. ) "C:\WINDOWS\system32\advpack.dll"
2006-06-23 05:30:22 11776 ( ….. ) "C:\WINDOWS\system32\msfeedssync.exe"
2006-06-23 05:29:56 55296 ( ….. ) "C:\WINDOWS\system32\icardie.dll"
2006-06-23 05:29:22 35328 ( A…. ) "C:\WINDOWS\system32\imgutil.dll"
2006-06-23 05:27:56 251392 ( ….. ) "C:\WINDOWS\system32\iertutil.dll"
2006-06-23 05:26:52 45568 ( A…. ) "C:\WINDOWS\system32\mshta.exe"
2006-06-23 04:46:30 377856 ( ….. ) "C:\WINDOWS\system32\ieapfltr.dll"
2006-06-23 04:45:30 48640 ( A…. ) "C:\WINDOWS\system32\mshtmler.dll"
2006-06-23 04:41:42 172032 ( A…. ) "C:\WINDOWS\system32\ieakui.dll"
2006-06-19 15:18:34 22752 ( A…. ) "C:\WINDOWS\system32\spupdsvc.exe"
2006-06-19 15:18:16 23552 ( ….. ) "C:\WINDOWS\system32\idndl.dll"
2006-06-19 15:18:16 20480 ( ….. ) "C:\WINDOWS\system32\normaliz.dll"
2006-06-12 23:56:18 ( .D… ) "C:\Program Files\Badder Adder"
2006-05-25 01:22:06 53248 ( A…. ) "C:\WINDOWS\bdoscandel.exe"
2006-05-24 11:20:26 ( .D… ) "C:\Program Files\Mozilla Firefox"
2005-12-20 15:53:12 3791064 ( A…. ) "C:\Program Files\hbk4.exe"
2001-11-21 10:10:06 18330960 ( A…. ) "C:\Program Files\Oxpsp1.exe"
(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))
2006-07-09 20:10 536,268,800 C:\hiberfil.sys
2006-07-04 12:34 117,760 C:\WINDOWS\system32\xmllite.dll
2006-07-04 00:48 937,984 C:\WINDOWS\system32\winbrand.dll
2006-07-04 00:48 9,216 C:\WINDOWS\system32\proxycfg.exe
2006-07-04 00:48 88,064 C:\WINDOWS\system32\p2pnetsh.dll
2006-07-04 00:48 870,784 C:\WINDOWS\system32\ati3d1ag.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\p2pgasvc.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\mdmxsdk.dll
2006-07-04 00:48 81,408 C:\WINDOWS\system32\wscsvc.dll
2006-07-04 00:48 8,192 C:\WINDOWS\system32\smbinst.exe
2006-07-04 00:48 78,848 C:\WINDOWS\system32\ieencode.dll
2006-07-04 00:48 75,776 C:\WINDOWS\system32\strmfilt.dll
2006-07-04 00:48 73,832 C:\WINDOWS\system32\slcoinst.dll
2006-07-04 00:48 73,796 C:\WINDOWS\system32\slserv.exe
2006-07-04 00:48 71,680 C:\WINDOWS\system32\blastcln.exe
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsno.dll
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsfi.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdukx.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdno1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdfi1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\hccoin.dll
2006-07-04 00:48 60,416 C:\WINDOWS\system32\fwcfg.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinmal.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinben.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt48.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt47.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdinbe1.dll
2006-07-04 00:48 59,392 C:\WINDOWS\system32\logman.exe
2006-07-04 00:48 537,088 C:\WINDOWS\system32\msftedit.dll
2006-07-04 00:48 526,848 C:\WINDOWS\system32\p2psvc.dll
2006-07-04 00:48 516,768 C:\WINDOWS\system32\ativvaxx.dll
2006-07-04 00:48 50,688 C:\WINDOWS\system32\btpanui.dll
2006-07-04 00:48 50,176 C:\WINDOWS\system32\xmlprovi.dll
2006-07-04 00:48 5,632 C:\WINDOWS\system32\kbdmaori.dll
2006-07-04 00:48 49,152 C:\WINDOWS\system32\powercfg.exe
2006-07-04 00:48 48,640 C:\WINDOWS\system32\pnrpnsp.dll
2006-07-04 00:48 44,032 C:\WINDOWS\system32\twext.dll
2006-07-04 00:48 4,096 C:\WINDOWS\system32\dsprpres.dll
2006-07-04 00:48 397,056 C:\WINDOWS\system32\s3gnb.dll
2006-07-04 00:48 377,984 C:\WINDOWS\system32\ati2dvaa.dll
2006-07-04 00:48 32,866 C:\WINDOWS\system32\slrundll.exe
2006-07-04 00:48 32,866 C:\WINDOWS\slrundll.exe
2006-07-04 00:48 32,768 C:\WINDOWS\system32\ativtmxx.dll
2006-07-04 00:48 32,285 C:\WINDOWS\system32\hsfcisp2.dll
2006-07-04 00:48 312,320 C:\WINDOWS\system32\p2pgraph.dll
2006-07-04 00:48 30,208 C:\WINDOWS\system32\bthserv.dll
2006-07-04 00:48 29,184 C:\WINDOWS\system32\sdhcinst.dll
2006-07-04 00:48 286,792 C:\WINDOWS\system32\slextspk.dll
2006-07-04 00:48 270,848 C:\WINDOWS\system32\sbe.dll
2006-07-04 00:48 24,576 C:\WINDOWS\system32\httpapi.dll
2006-07-04 00:48 229,376 C:\WINDOWS\system32\ati2cqag.dll
2006-07-04 00:48 22,528 C:\WINDOWS\system32\fltmc.exe
2006-07-04 00:48 201,728 C:\WINDOWS\system32\ati2dvag.dll
2006-07-04 00:48 20,992 C:\WINDOWS\system32\bthci.dll
2006-07-04 00:48 20,480 C:\WINDOWS\system32\encapi.dll
2006-07-04 00:48 2,113,536 C:\WINDOWS\system32\dxdiagn.dll
2006-07-04 00:48 193,024 C:\WINDOWS\system32\fsquirt.exe
2006-07-04 00:48 188,508 C:\WINDOWS\system32\slgen.dll
2006-07-04 00:48 187,392 C:\WINDOWS\system32\xpsp1res.dll
2006-07-04 00:48 186,368 C:\WINDOWS\system32\encdec.dll
2006-07-04 00:48 17,408 C:\WINDOWS\system32\winshfhc.dll
2006-07-04 00:48 16,896 C:\WINDOWS\system32\fltlib.dll
2006-07-04 00:48 159,232 C:\WINDOWS\system32\sbeio.dll
2006-07-04 00:48 15,872 C:\WINDOWS\system32\w3ssl.dll
2006-07-04 00:48 14,336 C:\WINDOWS\system32\auditusr.exe
2006-07-04 00:48 134,656 C:\WINDOWS\system32\mssap.dll
2006-07-04 00:48 13,824 C:\WINDOWS\system32\wscntfy.exe
2006-07-04 00:48 13,824 C:\WINDOWS\system32\cmsetacl.dll
2006-07-04 00:48 129,536 C:\WINDOWS\system32\xmlprov.dll
2006-07-04 00:48 118,784 C:\WINDOWS\system32\msdadiag.dll
2006-07-04 00:48 116,224 C:\WINDOWS\system32\p2p.dll
2006-07-04 00:48 108,032 C:\WINDOWS\system32\wshbth.dll
2006-07-04 00:48 1,888,992 C:\WINDOWS\system32\ati3duag.dll
2006-07-04 00:48 1,737,856 C:\WINDOWS\system32\mtxparhd.dll
2006-07-04 00:48 1,689,088 C:\WINDOWS\system32\d3d9.dll
2006-07-04 00:43 92,224 C:\WINDOWS\system32\krnl386.exe
2006-07-04 00:42 2,897,920 C:\WINDOWS\system32\xpsp2res.dll
2006-06-23 09:28 5,512,704 C:\WINDOWS\system32\ieframe.dll
2006-06-23 09:28 47,616 C:\WINDOWS\system32\msfeedsbs.dll
2006-06-23 09:28 454,144 C:\WINDOWS\system32\msfeeds.dll
2006-06-23 09:28 179,200 C:\WINDOWS\system32\ieui.dll
2006-06-23 05:41 172,544 C:\WINDOWS\system32\WinFXDocObj.exe
2006-06-23 05:30 11,776 C:\WINDOWS\system32\msfeedssync.exe
2006-06-23 05:29 55,296 C:\WINDOWS\system32\icardie.dll
2006-06-23 05:27 251,392 C:\WINDOWS\system32\iertutil.dll
2006-06-23 04:46 377,856 C:\WINDOWS\system32\ieapfltr.dll
2006-06-19 15:18 23,552 C:\WINDOWS\system32\idndl.dll
2006-06-19 15:18 20,480 C:\WINDOWS\system32\normaliz.dll
2006-06-12 23:56 101,888 C:\WINDOWS\system32\VB6STKIT.DLL
2006-05-25 01:22 53,248 C:\WINDOWS\bdoscandel.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"FreeMem Pro"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e0,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^LimeWire On Startup.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"item"="LimeWire On Startup.lnk"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OpenOffice.org 1.1.3.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\OpenOffice.org 1.1.3.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"item"="OpenOffice.org 1.1.3.lnk"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dinst"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\dinst.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeMem Pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="freemem"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="P2P Networking"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\P2P Networking\\P2P Networking.exe /AUTOSTART"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TeaTimer"
"hkey"="HKCU"
"command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPEnh"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System service79]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pokapoka79"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\\\\\etb\\\\pokapoka79.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tpjmncp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="vadxdi"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\vadxdi.exe r"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VPTray"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~2\\VPTray.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vwvjzbn]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ordtccs"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\ordtccs.exe r"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymSecurePort"=dword:00000002
"Symantec AntiVirus"=dword:00000002
"SvcProc"=dword:00000002
"SPBBCSvc"=dword:00000003
"SNDSrvc"=dword:00000002
"SavRoam"=dword:00000003
"NVSvc"=dword:00000002
"ISSVC"=dword:00000002
"DefWatch"=dword:00000002
"Crypkey License"=dword:00000002
"ccSetMgr"=dword:00000002
"ccPwdSvc"=dword:00000003
"ccProxy"=dword:00000002
"ccEvtMgr"=dword:00000002
"AvidStartup"=dword:00000002
"AvidSDMService"=dword:00000002
"ALG"=dword:00000003
"mnmsrvc"=dword:00000003
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
@=""
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Registration reminder 1.job
C:\WINDOWS\tasks\Registration reminder 2.job
C:\WINDOWS\tasks\Registration reminder 3.job
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: Sun 07/09/2006 20:17:14.31
ComboFix ver 06.07.08 - This logfile is located at C:\ComboFix.txt
HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 8:19:51 PM, on 7/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Shortcut to linkfile_fix.lnk = TomCoyote\linkfile_fix.reg
O4 - Startup: Shortcut to xp_com_fix.lnk = TomCoyote\xp_com_fix.reg
O4 - Startup: Shortcut to xp_exe_fix.lnk = TomCoyote\xp_exe_fix.reg
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
Next, launch Notepad (Start>All Programs>Accessories), and copy/paste all the BOLD REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save
REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dinst]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System service79]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared Tools\msconfig\startupreg\tpjmncp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vwvjzbn]
On the desktop, doubleclick fix.reg and allow it to run. Let it merge.
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
Close ALL windows and browsers except HijackThis and click "Fix checked"
Delete these Files if listed:
C:\WINDOWS\dinst.exe
C:\WINDOWS\etb\pokapoka79.exe
C:\WINDOWS\System32\vadxdi.exe
C:\WINDOWS\system32\ordtccs.exe
Empty Recycle Bin
Restart your computer.
Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
I could Ping Google from normal mode. This is an improvement!!! Start>Run>regedit launches regedit.exe. This is an improvement!!!! Start>run>launches a command window. This is an improvement!!!
IE still doesn't find the internet, Grisoft AVG couldn't update. None of those files appeared to be on the drive to delete, but seemed to still be listed by Combofix.
Here's the logfile:
Logfile of HijackThis v1.99.1
Scan saved at 9:24:19 PM, on 7/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Shortcut to linkfile_fix.lnk = TomCoyote\linkfile_fix.reg
O4 - Startup: Shortcut to xp_com_fix.lnk = TomCoyote\xp_com_fix.reg
O4 - Startup: Shortcut to xp_exe_fix.lnk = TomCoyote\xp_exe_fix.reg
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
And Combofix again:
Start Time= Sun 07/09/2006 21:26:41.33
Running from: C:\Documents and Settings\[removed]\My Documents\Downloads\TomCoyote\Combofix
QuickScan did not find any signs of infected files
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-07-05 22:07:44 ( .D… ) "C:\Program Files\Eyetide Media"
2006-07-05 20:57:50 ( .D… ) "C:\Program Files\CCleaner"
2006-07-05 20:00:30 ( .D… ) "C:\Program Files\ewido anti-spyware 4.0"
2006-07-05 19:57:58 ( .D… ) "C:\Documents and Settings\Jason\Application Data\Google"
2006-07-04 18:36:50 ( .D… ) "C:\Program Files\HijackThis"
2006-07-04 12:44:42 0 ( A…. ) "C:\Documents and Settings\Jason\Application Data\sversion.ini"
2006-07-04 00:41:40 47564 ( A.SHR ) "C:\NTDETECT.COM"
2006-07-02 21:18:04 ( .D… ) "C:\Documents and Settings\Jason\Application Data\AVG7"
2006-07-02 21:17:26 ( .D… ) "C:\Program Files\Grisoft"
2006-07-02 21:04:16 ( .D… ) "C:\Program Files\TBIView"
2006-07-02 21:04:02 ( .D… ) "C:\Program Files\Image for Windows"
2006-06-23 09:28:56 5512704 ( ….. ) "C:\WINDOWS\system32\ieframe.dll"
2006-06-23 09:28:56 454144 ( ….. ) "C:\WINDOWS\system32\msfeeds.dll"
2006-06-23 09:28:56 413696 ( A…. ) "C:\WINDOWS\system32\vbscript.dll"
2006-06-23 09:28:56 223744 ( A…. ) "C:\WINDOWS\system32\webcheck.dll"
2006-06-23 09:28:56 179200 ( ….. ) "C:\WINDOWS\system32\ieui.dll"
2006-06-23 09:28:56 155648 ( A…. ) "C:\WINDOWS\system32\msls31.dll"
2006-06-23 09:28:56 47616 ( ….. ) "C:\WINDOWS\system32\msfeedsbs.dll"
2006-06-23 05:41:42 172544 ( ….. ) "C:\WINDOWS\system32\WinFXDocObj.exe"
2006-06-23 05:40:44 78848 ( A…. ) "C:\WINDOWS\system32\ieencode.dll"
2006-06-23 05:40:04 40960 ( A…. ) "C:\WINDOWS\system32\url.dll"
2006-06-23 05:39:52 39424 ( A…. ) "C:\WINDOWS\system32\licmgr10.dll"
2006-06-23 05:39:08 99328 ( A…. ) "C:\WINDOWS\system32\occache.dll"
2006-06-23 05:37:18 14336 ( A…. ) "C:\WINDOWS\system32\corpol.dll"
2006-06-23 05:34:30 228864 ( A…. ) "C:\WINDOWS\system32\ieaksie.dll"
2006-06-23 05:34:16 167936 ( A…. ) "C:\WINDOWS\system32\ieakeng.dll"
2006-06-23 05:34:06 81920 ( A…. ) "C:\WINDOWS\system32\admparse.dll"
2006-06-23 05:34:06 50688 ( A…. ) "C:\WINDOWS\system32\ie4uinit.exe"
2006-06-23 05:34:02 372736 ( A…. ) "C:\WINDOWS\system32\iedkcs32.dll"
2006-06-23 05:33:42 54272 ( A…. ) "C:\WINDOWS\system32\iesetup.dll"
2006-06-23 05:33:22 41984 ( A…. ) "C:\WINDOWS\system32\iernonce.dll"
2006-06-23 05:33:00 121856 ( A…. ) "C:\WINDOWS\system32\advpack.dll"
2006-06-23 05:30:22 11776 ( ….. ) "C:\WINDOWS\system32\msfeedssync.exe"
2006-06-23 05:29:56 55296 ( ….. ) "C:\WINDOWS\system32\icardie.dll"
2006-06-23 05:29:22 35328 ( A…. ) "C:\WINDOWS\system32\imgutil.dll"
2006-06-23 05:27:56 251392 ( ….. ) "C:\WINDOWS\system32\iertutil.dll"
2006-06-23 05:26:52 45568 ( A…. ) "C:\WINDOWS\system32\mshta.exe"
2006-06-23 04:46:30 377856 ( ….. ) "C:\WINDOWS\system32\ieapfltr.dll"
2006-06-23 04:45:30 48640 ( A…. ) "C:\WINDOWS\system32\mshtmler.dll"
2006-06-23 04:41:42 172032 ( A…. ) "C:\WINDOWS\system32\ieakui.dll"
2006-06-19 15:18:34 22752 ( A…. ) "C:\WINDOWS\system32\spupdsvc.exe"
2006-06-19 15:18:16 23552 ( ….. ) "C:\WINDOWS\system32\idndl.dll"
2006-06-19 15:18:16 20480 ( ….. ) "C:\WINDOWS\system32\normaliz.dll"
2006-06-12 23:56:18 ( .D… ) "C:\Program Files\Badder Adder"
2006-05-25 01:22:06 53248 ( A…. ) "C:\WINDOWS\bdoscandel.exe"
2006-05-24 11:20:26 ( .D… ) "C:\Program Files\Mozilla Firefox"
2005-12-20 15:53:12 3791064 ( A…. ) "C:\Program Files\hbk4.exe"
2001-11-21 10:10:06 18330960 ( A…. ) "C:\Program Files\Oxpsp1.exe"
(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))
2006-07-09 21:19 536,268,800 C:\hiberfil.sys
2006-07-04 12:34 117,760 C:\WINDOWS\system32\xmllite.dll
2006-07-04 00:48 937,984 C:\WINDOWS\system32\winbrand.dll
2006-07-04 00:48 9,216 C:\WINDOWS\system32\proxycfg.exe
2006-07-04 00:48 88,064 C:\WINDOWS\system32\p2pnetsh.dll
2006-07-04 00:48 870,784 C:\WINDOWS\system32\ati3d1ag.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\p2pgasvc.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\mdmxsdk.dll
2006-07-04 00:48 81,408 C:\WINDOWS\system32\wscsvc.dll
2006-07-04 00:48 8,192 C:\WINDOWS\system32\smbinst.exe
2006-07-04 00:48 78,848 C:\WINDOWS\system32\ieencode.dll
2006-07-04 00:48 75,776 C:\WINDOWS\system32\strmfilt.dll
2006-07-04 00:48 73,832 C:\WINDOWS\system32\slcoinst.dll
2006-07-04 00:48 73,796 C:\WINDOWS\system32\slserv.exe
2006-07-04 00:48 71,680 C:\WINDOWS\system32\blastcln.exe
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsno.dll
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsfi.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdukx.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdno1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdfi1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\hccoin.dll
2006-07-04 00:48 60,416 C:\WINDOWS\system32\fwcfg.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinmal.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinben.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt48.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt47.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdinbe1.dll
2006-07-04 00:48 59,392 C:\WINDOWS\system32\logman.exe
2006-07-04 00:48 537,088 C:\WINDOWS\system32\msftedit.dll
2006-07-04 00:48 526,848 C:\WINDOWS\system32\p2psvc.dll
2006-07-04 00:48 516,768 C:\WINDOWS\system32\ativvaxx.dll
2006-07-04 00:48 50,688 C:\WINDOWS\system32\btpanui.dll
2006-07-04 00:48 50,176 C:\WINDOWS\system32\xmlprovi.dll
2006-07-04 00:48 5,632 C:\WINDOWS\system32\kbdmaori.dll
2006-07-04 00:48 49,152 C:\WINDOWS\system32\powercfg.exe
2006-07-04 00:48 48,640 C:\WINDOWS\system32\pnrpnsp.dll
2006-07-04 00:48 44,032 C:\WINDOWS\system32\twext.dll
2006-07-04 00:48 4,096 C:\WINDOWS\system32\dsprpres.dll
2006-07-04 00:48 397,056 C:\WINDOWS\system32\s3gnb.dll
2006-07-04 00:48 377,984 C:\WINDOWS\system32\ati2dvaa.dll
2006-07-04 00:48 32,866 C:\WINDOWS\system32\slrundll.exe
2006-07-04 00:48 32,866 C:\WINDOWS\slrundll.exe
2006-07-04 00:48 32,768 C:\WINDOWS\system32\ativtmxx.dll
2006-07-04 00:48 32,285 C:\WINDOWS\system32\hsfcisp2.dll
2006-07-04 00:48 312,320 C:\WINDOWS\system32\p2pgraph.dll
2006-07-04 00:48 30,208 C:\WINDOWS\system32\bthserv.dll
2006-07-04 00:48 29,184 C:\WINDOWS\system32\sdhcinst.dll
2006-07-04 00:48 286,792 C:\WINDOWS\system32\slextspk.dll
2006-07-04 00:48 270,848 C:\WINDOWS\system32\sbe.dll
2006-07-04 00:48 24,576 C:\WINDOWS\system32\httpapi.dll
2006-07-04 00:48 229,376 C:\WINDOWS\system32\ati2cqag.dll
2006-07-04 00:48 22,528 C:\WINDOWS\system32\fltmc.exe
2006-07-04 00:48 201,728 C:\WINDOWS\system32\ati2dvag.dll
2006-07-04 00:48 20,992 C:\WINDOWS\system32\bthci.dll
2006-07-04 00:48 20,480 C:\WINDOWS\system32\encapi.dll
2006-07-04 00:48 2,113,536 C:\WINDOWS\system32\dxdiagn.dll
2006-07-04 00:48 193,024 C:\WINDOWS\system32\fsquirt.exe
2006-07-04 00:48 188,508 C:\WINDOWS\system32\slgen.dll
2006-07-04 00:48 187,392 C:\WINDOWS\system32\xpsp1res.dll
2006-07-04 00:48 186,368 C:\WINDOWS\system32\encdec.dll
2006-07-04 00:48 17,408 C:\WINDOWS\system32\winshfhc.dll
2006-07-04 00:48 16,896 C:\WINDOWS\system32\fltlib.dll
2006-07-04 00:48 159,232 C:\WINDOWS\system32\sbeio.dll
2006-07-04 00:48 15,872 C:\WINDOWS\system32\w3ssl.dll
2006-07-04 00:48 14,336 C:\WINDOWS\system32\auditusr.exe
2006-07-04 00:48 134,656 C:\WINDOWS\system32\mssap.dll
2006-07-04 00:48 13,824 C:\WINDOWS\system32\wscntfy.exe
2006-07-04 00:48 13,824 C:\WINDOWS\system32\cmsetacl.dll
2006-07-04 00:48 129,536 C:\WINDOWS\system32\xmlprov.dll
2006-07-04 00:48 118,784 C:\WINDOWS\system32\msdadiag.dll
2006-07-04 00:48 116,224 C:\WINDOWS\system32\p2p.dll
2006-07-04 00:48 108,032 C:\WINDOWS\system32\wshbth.dll
2006-07-04 00:48 1,888,992 C:\WINDOWS\system32\ati3duag.dll
2006-07-04 00:48 1,737,856 C:\WINDOWS\system32\mtxparhd.dll
2006-07-04 00:48 1,689,088 C:\WINDOWS\system32\d3d9.dll
2006-07-04 00:43 92,224 C:\WINDOWS\system32\krnl386.exe
2006-07-04 00:42 2,897,920 C:\WINDOWS\system32\xpsp2res.dll
2006-06-23 09:28 5,512,704 C:\WINDOWS\system32\ieframe.dll
2006-06-23 09:28 47,616 C:\WINDOWS\system32\msfeedsbs.dll
2006-06-23 09:28 454,144 C:\WINDOWS\system32\msfeeds.dll
2006-06-23 09:28 179,200 C:\WINDOWS\system32\ieui.dll
2006-06-23 05:41 172,544 C:\WINDOWS\system32\WinFXDocObj.exe
2006-06-23 05:30 11,776 C:\WINDOWS\system32\msfeedssync.exe
2006-06-23 05:29 55,296 C:\WINDOWS\system32\icardie.dll
2006-06-23 05:27 251,392 C:\WINDOWS\system32\iertutil.dll
2006-06-23 04:46 377,856 C:\WINDOWS\system32\ieapfltr.dll
2006-06-19 15:18 23,552 C:\WINDOWS\system32\idndl.dll
2006-06-19 15:18 20,480 C:\WINDOWS\system32\normaliz.dll
2006-06-12 23:56 101,888 C:\WINDOWS\system32\VB6STKIT.DLL
2006-05-25 01:22 53,248 C:\WINDOWS\bdoscandel.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"FreeMem Pro"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e0,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^LimeWire On Startup.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"item"="LimeWire On Startup.lnk"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OpenOffice.org 1.1.3.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\OpenOffice.org 1.1.3.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"item"="OpenOffice.org 1.1.3.lnk"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeMem Pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="freemem"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TeaTimer"
"hkey"="HKCU"
"command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPEnh"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VPTray"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~2\\VPTray.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymSecurePort"=dword:00000002
"Symantec AntiVirus"=dword:00000002
"SvcProc"=dword:00000002
"SPBBCSvc"=dword:00000003
"SNDSrvc"=dword:00000002
"SavRoam"=dword:00000003
"NVSvc"=dword:00000002
"ISSVC"=dword:00000002
"DefWatch"=dword:00000002
"Crypkey License"=dword:00000002
"ccSetMgr"=dword:00000002
"ccPwdSvc"=dword:00000003
"ccProxy"=dword:00000002
"ccEvtMgr"=dword:00000002
"AvidStartup"=dword:00000002
"AvidSDMService"=dword:00000002
"ALG"=dword:00000003
"mnmsrvc"=dword:00000003
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
@=""
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Registration reminder 1.job
C:\WINDOWS\tasks\Registration reminder 2.job
C:\WINDOWS\tasks\Registration reminder 3.job
C:\WINDOWS\tasks\Symantec NetDetect.job
Completion time: Sun 07/09/2006 21:27:09.34
ComboFix ver 06.07.08 - This logfile is located at C:\ComboFix.txt
ComboFix.2006-07-09.212641.txt
None of those files appeared to be on the drive to delete, but seemed to still be listed by Combofix.
I don't see the ones I had you delete. It also looks like the regfix worked
You need To disable TeaTimer, it can stop our fix.
1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts
Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a
Check in the box on the left side on these:
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {F5DE8ADB-4A69-4e56-96AB-823171C8E9D8} - (no file)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} -
Close
ALL windows and browsers
except HijackThis and click
"Fix checked"
I'm not sure why these are there.
O4 - Startup: Shortcut to linkfile_fix.lnk = TomCoyote\linkfile_fix.reg
O4 - Startup: Shortcut to xp_com_fix.lnk = TomCoyote\xp_com_fix.reg
O4 - Startup: Shortcut to xp_exe_fix.lnk = TomCoyote\xp_exe_fix.reg
Lets try this one instead.
Download the REG file here
http://www.kellys-korner-xp.com/regs_edits/xp_exe_fix.reg
and save it to your hard drive. Double click the file you just saved and answer yes to the import prompt.
Empty Recycle Bin
Reboot and "
copy/paste " a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
At first I couldn't ping Google.com. There were four timeouts. But then in a couple of minutes I could ping google.com but it resolved to a different IP…
Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.
C:\Documents and Settings\Jason>ping google.com
Pinging google.com [72.14.207.99] with 32 bytes of data:
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Ping statistics for 72.14.207.99:
Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
C:\Documents and Settings\Jason>ping 192.168.0.1
Pinging 192.168.0.1 with 32 bytes of data:
Reply from 192.168.0.1: bytes=32 time<1ms TTL=128
Reply from 192.168.0.1: bytes=32 time<1ms TTL=128
Reply from 192.168.0.1: bytes=32 time<1ms TTL=128
Reply from 192.168.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 192.168.0.1:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
C:\Documents and Settings\Jason>ipconfig /all
Windows IP Configuration
Host Name . . . . . . . . . . . . : JMay
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Mixed
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : www.advanced-houston.com
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . : www.advanced-houston.com
Description . . . . . . . . . . . : Intel® PRO/100 VE Network Connecti
on
Physical Address. . . . . . . . . : 00-00-39-4F-53-DD
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.0.108
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.0.1
DHCP Server . . . . . . . . . . . : 192.168.0.1
DNS Servers . . . . . . . . . . . : 192.168.0.1
Lease Obtained. . . . . . . . . . : Sunday, July 09, 2006 10:16:34 PM
Lease Expires . . . . . . . . . . : Sunday, July 16, 2006 10:16:34 PM
C:\Documents and Settings\Jason>ping google.com
Pinging google.com [64.233.167.99] with 32 bytes of data:
Reply from 64.233.167.99: bytes=32 time=57ms TTL=240
Reply from 64.233.167.99: bytes=32 time=59ms TTL=240
Reply from 64.233.167.99: bytes=32 time=56ms TTL=240
Reply from 64.233.167.99: bytes=32 time=58ms TTL=240
Ping statistics for 64.233.167.99:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 56ms, Maximum = 59ms, Average = 57ms
C:\Documents and Settings\Jason>
Here's the log file:
Logfile of HijackThis v1.99.1
Scan saved at 10:21:17 PM, on 7/9/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Internet Explorer\iexplore.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
And Combofix:
Start Time= Sun 07/09/2006 22:22:05.97
Running from: C:\Documents and Settings\[removed]
QuickScan did not find any signs of infected files
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report
)))))))))))))))))))))))))))))))))))))))))))))))))))))
2006-07-05 22:07:44 ( .D… ) "C:\Program
Files\Eyetide Media"
2006-07-05 20:57:50 ( .D… ) "C:\Program
Files\CCleaner"
2006-07-05 20:00:30 ( .D… ) "C:\Program
Files\ewido anti-spyware 4.0"
2006-07-05 19:57:58 ( .D… ) "C:\Documents and
Settings\Jason\Application Data\Google"
2006-07-04 18:36:50 ( .D… ) "C:\Program
Files\HijackThis"
2006-07-04 12:44:42 0 ( A…. ) "C:\Documents and
Settings\Jason\Application Data\sversion.ini"
2006-07-04 00:41:40 47564 ( A.SHR ) "C:\NTDETECT.COM"
2006-07-02 21:18:04 ( .D… ) "C:\Documents and
Settings\Jason\Application Data\AVG7"
2006-07-02 21:17:26 ( .D… ) "C:\Program
Files\Grisoft"
2006-07-02 21:04:16 ( .D… ) "C:\Program
Files\TBIView"
2006-07-02 21:04:02 ( .D… ) "C:\Program
Files\Image for Windows"
2006-06-23 09:28:56 5512704 ( ….. )
"C:\WINDOWS\system32\ieframe.dll"
2006-06-23 09:28:56 454144 ( ….. )
"C:\WINDOWS\system32\msfeeds.dll"
2006-06-23 09:28:56 413696 ( A…. )
"C:\WINDOWS\system32\vbscript.dll"
2006-06-23 09:28:56 223744 ( A…. )
"C:\WINDOWS\system32\webcheck.dll"
2006-06-23 09:28:56 179200 ( ….. )
"C:\WINDOWS\system32\ieui.dll"
2006-06-23 09:28:56 155648 ( A…. )
"C:\WINDOWS\system32\msls31.dll"
2006-06-23 09:28:56 47616 ( ….. )
"C:\WINDOWS\system32\msfeedsbs.dll"
2006-06-23 05:41:42 172544 ( ….. )
"C:\WINDOWS\system32\WinFXDocObj.exe"
2006-06-23 05:40:44 78848 ( A…. )
"C:\WINDOWS\system32\ieencode.dll"
2006-06-23 05:40:04 40960 ( A…. )
"C:\WINDOWS\system32\url.dll"
2006-06-23 05:39:52 39424 ( A…. )
"C:\WINDOWS\system32\licmgr10.dll"
2006-06-23 05:39:08 99328 ( A…. )
"C:\WINDOWS\system32\occache.dll"
2006-06-23 05:37:18 14336 ( A…. )
"C:\WINDOWS\system32\corpol.dll"
2006-06-23 05:34:30 228864 ( A…. )
"C:\WINDOWS\system32\ieaksie.dll"
2006-06-23 05:34:16 167936 ( A…. )
"C:\WINDOWS\system32\ieakeng.dll"
2006-06-23 05:34:06 81920 ( A…. )
"C:\WINDOWS\system32\admparse.dll"
2006-06-23 05:34:06 50688 ( A…. )
"C:\WINDOWS\system32\ie4uinit.exe"
2006-06-23 05:34:02 372736 ( A…. )
"C:\WINDOWS\system32\iedkcs32.dll"
2006-06-23 05:33:42 54272 ( A…. )
"C:\WINDOWS\system32\iesetup.dll"
2006-06-23 05:33:22 41984 ( A…. )
"C:\WINDOWS\system32\iernonce.dll"
2006-06-23 05:33:00 121856 ( A…. )
"C:\WINDOWS\system32\advpack.dll"
2006-06-23 05:30:22 11776 ( ….. )
"C:\WINDOWS\system32\msfeedssync.exe"
2006-06-23 05:29:56 55296 ( ….. )
"C:\WINDOWS\system32\icardie.dll"
2006-06-23 05:29:22 35328 ( A…. )
"C:\WINDOWS\system32\imgutil.dll"
2006-06-23 05:27:56 251392 ( ….. )
"C:\WINDOWS\system32\iertutil.dll"
2006-06-23 05:26:52 45568 ( A…. )
"C:\WINDOWS\system32\mshta.exe"
2006-06-23 04:46:30 377856 ( ….. )
"C:\WINDOWS\system32\ieapfltr.dll"
2006-06-23 04:45:30 48640 ( A…. )
"C:\WINDOWS\system32\mshtmler.dll"
2006-06-23 04:41:42 172032 ( A…. )
"C:\WINDOWS\system32\ieakui.dll"
2006-06-19 15:18:34 22752 ( A…. )
"C:\WINDOWS\system32\spupdsvc.exe"
2006-06-19 15:18:16 23552 ( ….. )
"C:\WINDOWS\system32\idndl.dll"
2006-06-19 15:18:16 20480 ( ….. )
"C:\WINDOWS\system32\normaliz.dll"
2006-06-12 23:56:18 ( .D… ) "C:\Program
Files\Badder Adder"
2006-05-25 01:22:06 53248 ( A…. )
"C:\WINDOWS\bdoscandel.exe"
2006-05-24 11:20:26 ( .D… ) "C:\Program
Files\Mozilla Firefox"
2005-12-20 15:53:12 3791064 ( A…. ) "C:\Program
Files\hbk4.exe"
2001-11-21 10:10:06 18330960 ( A…. ) "C:\Program
Files\Oxpsp1.exe"
(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days
)))))))))))))))))))))))))))))))))))))))))))
2006-07-09 22:01 536,268,800 C:\hiberfil.sys
2006-07-04 12:34 117,760 C:\WINDOWS\system32\xmllite.dll
2006-07-04 00:48 937,984 C:\WINDOWS\system32\winbrand.dll
2006-07-04 00:48 9,216 C:\WINDOWS\system32\proxycfg.exe
2006-07-04 00:48 88,064 C:\WINDOWS\system32\p2pnetsh.dll
2006-07-04 00:48 870,784 C:\WINDOWS\system32\ati3d1ag.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\p2pgasvc.dll
2006-07-04 00:48 86,016 C:\WINDOWS\system32\mdmxsdk.dll
2006-07-04 00:48 81,408 C:\WINDOWS\system32\wscsvc.dll
2006-07-04 00:48 8,192 C:\WINDOWS\system32\smbinst.exe
2006-07-04 00:48 78,848 C:\WINDOWS\system32\ieencode.dll
2006-07-04 00:48 75,776 C:\WINDOWS\system32\strmfilt.dll
2006-07-04 00:48 73,832 C:\WINDOWS\system32\slcoinst.dll
2006-07-04 00:48 73,796 C:\WINDOWS\system32\slserv.exe
2006-07-04 00:48 71,680 C:\WINDOWS\system32\blastcln.exe
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsno.dll
2006-07-04 00:48 7,680 C:\WINDOWS\system32\kbdsmsfi.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdukx.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdno1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\kbdfi1.dll
2006-07-04 00:48 7,168 C:\WINDOWS\system32\hccoin.dll
2006-07-04 00:48 60,416 C:\WINDOWS\system32\fwcfg.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinmal.dll
2006-07-04 00:48 6,656 C:\WINDOWS\system32\kbdinben.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt48.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdmlt47.dll
2006-07-04 00:48 6,144 C:\WINDOWS\system32\kbdinbe1.dll
2006-07-04 00:48 59,392 C:\WINDOWS\system32\logman.exe
2006-07-04 00:48 537,088 C:\WINDOWS\system32\msftedit.dll
2006-07-04 00:48 526,848 C:\WINDOWS\system32\p2psvc.dll
2006-07-04 00:48 516,768 C:\WINDOWS\system32\ativvaxx.dll
2006-07-04 00:48 50,688 C:\WINDOWS\system32\btpanui.dll
2006-07-04 00:48 50,176 C:\WINDOWS\system32\xmlprovi.dll
2006-07-04 00:48 5,632 C:\WINDOWS\system32\kbdmaori.dll
2006-07-04 00:48 49,152 C:\WINDOWS\system32\powercfg.exe
2006-07-04 00:48 48,640 C:\WINDOWS\system32\pnrpnsp.dll
2006-07-04 00:48 44,032 C:\WINDOWS\system32\twext.dll
2006-07-04 00:48 4,096 C:\WINDOWS\system32\dsprpres.dll
2006-07-04 00:48 397,056 C:\WINDOWS\system32\s3gnb.dll
2006-07-04 00:48 377,984 C:\WINDOWS\system32\ati2dvaa.dll
2006-07-04 00:48 32,866 C:\WINDOWS\system32\slrundll.exe
2006-07-04 00:48 32,866 C:\WINDOWS\slrundll.exe
2006-07-04 00:48 32,768 C:\WINDOWS\system32\ativtmxx.dll
2006-07-04 00:48 32,285 C:\WINDOWS\system32\hsfcisp2.dll
2006-07-04 00:48 312,320 C:\WINDOWS\system32\p2pgraph.dll
2006-07-04 00:48 30,208 C:\WINDOWS\system32\bthserv.dll
2006-07-04 00:48 29,184 C:\WINDOWS\system32\sdhcinst.dll
2006-07-04 00:48 286,792 C:\WINDOWS\system32\slextspk.dll
2006-07-04 00:48 270,848 C:\WINDOWS\system32\sbe.dll
2006-07-04 00:48 24,576 C:\WINDOWS\system32\httpapi.dll
2006-07-04 00:48 229,376 C:\WINDOWS\system32\ati2cqag.dll
2006-07-04 00:48 22,528 C:\WINDOWS\system32\fltmc.exe
2006-07-04 00:48 201,728 C:\WINDOWS\system32\ati2dvag.dll
2006-07-04 00:48 20,992 C:\WINDOWS\system32\bthci.dll
2006-07-04 00:48 20,480 C:\WINDOWS\system32\encapi.dll
2006-07-04 00:48 2,113,536
C:\WINDOWS\system32\dxdiagn.dll
2006-07-04 00:48 193,024 C:\WINDOWS\system32\fsquirt.exe
2006-07-04 00:48 188,508 C:\WINDOWS\system32\slgen.dll
2006-07-04 00:48 187,392 C:\WINDOWS\system32\xpsp1res.dll
2006-07-04 00:48 186,368 C:\WINDOWS\system32\encdec.dll
2006-07-04 00:48 17,408 C:\WINDOWS\system32\winshfhc.dll
2006-07-04 00:48 16,896 C:\WINDOWS\system32\fltlib.dll
2006-07-04 00:48 159,232 C:\WINDOWS\system32\sbeio.dll
2006-07-04 00:48 15,872 C:\WINDOWS\system32\w3ssl.dll
2006-07-04 00:48 14,336 C:\WINDOWS\system32\auditusr.exe
2006-07-04 00:48 134,656 C:\WINDOWS\system32\mssap.dll
2006-07-04 00:48 13,824 C:\WINDOWS\system32\wscntfy.exe
2006-07-04 00:48 13,824 C:\WINDOWS\system32\cmsetacl.dll
2006-07-04 00:48 129,536 C:\WINDOWS\system32\xmlprov.dll
2006-07-04 00:48 118,784 C:\WINDOWS\system32\msdadiag.dll
2006-07-04 00:48 116,224 C:\WINDOWS\system32\p2p.dll
2006-07-04 00:48 108,032 C:\WINDOWS\system32\wshbth.dll
2006-07-04 00:48 1,888,992
C:\WINDOWS\system32\ati3duag.dll
2006-07-04 00:48 1,737,856
C:\WINDOWS\system32\mtxparhd.dll
2006-07-04 00:48 1,689,088 C:\WINDOWS\system32\d3d9.dll
2006-07-04 00:43 92,224 C:\WINDOWS\system32\krnl386.exe
2006-07-04 00:42 2,897,920
C:\WINDOWS\system32\xpsp2res.dll
2006-06-23 09:28 5,512,704
C:\WINDOWS\system32\ieframe.dll
2006-06-23 09:28 47,616 C:\WINDOWS\system32\msfeedsbs.dll
2006-06-23 09:28 454,144 C:\WINDOWS\system32\msfeeds.dll
2006-06-23 09:28 179,200 C:\WINDOWS\system32\ieui.dll
2006-06-23 05:41 172,544 C:\WINDOWS\system32\WinFXDocObj.exe
2006-06-23 05:30 11,776 C:\WINDOWS\system32\msfeedssync.exe
2006-06-23 05:29 55,296 C:\WINDOWS\system32\icardie.dll
2006-06-23 05:27 251,392 C:\WINDOWS\system32\iertutil.dll
2006-06-23 04:46 377,856 C:\WINDOWS\system32\ieapfltr.dll
2006-06-19 15:18 23,552 C:\WINDOWS\system32\idndl.dll
2006-06-19 15:18 20,480 C:\WINDOWS\system32\normaliz.dll
2006-06-12 23:56 101,888 C:\WINDOWS\system32\VB6STKIT.DLL
2006-05-25 01:22 53,248 C:\WINDOWS\bdoscandel.exe
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points
))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries are not shown
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"FreeMem Pro"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=dword:00000000
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e0,02,00,00,00
,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff
,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,f2,01,00,00,23,00,00,00,7c,00,00,00,72,00
,\
00,00,01,00,00,00
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explo
rer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"
[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explo
rer]
"NoDriveTypeAutoRun"=dword:00000091
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shared
taskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{553858A7-4922-4e7e-B1C1-97140C1C16EF}"="IE Component Categories cache
daemon"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelle
xecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]
[HKEY_LOCAL_MACHINE\software\microsoft\shared
tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start
Menu^Programs^Startup^LimeWire On Startup.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start
Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\LimeWire On Startup.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start
Menu\\Programs\\Startup\\LimeWire On Startup.lnk.disabled"
"item"="LimeWire On Startup.lnk"
[HKEY_LOCAL_MACHINE\software\microsoft\shared
tools\msconfig\startupfolder\C:^Documents and Settings^Jason^Start
Menu^Programs^Startup^OpenOffice.org 1.1.3.lnk.disabled]
"path"="C:\\Documents and Settings\\Jason\\Start
Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"backup"="C:\\WINDOWS\\pss\\OpenOffice.org 1.1.3.lnk.disabledStartup"
"location"="Startup"
"command"="C:\\Documents and Settings\\Jason\\Start
Menu\\Programs\\Startup\\OpenOffice.org 1.1.3.lnk.disabled"
"item"="OpenOffice.org 1.1.3.lnk"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]
[HKEY_LOCAL_MACHINE\software\microsoft\shared
tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared
tools\msconfig\startupreg\FreeMem Pro]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="freemem"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\FreeMem Standard\\freemem.exe\" Startup"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared
tools\msconfig\startupreg\SpybotSD TeaTimer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TeaTimer"
"hkey"="HKCU"
"command"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared
tools\msconfig\startupreg\SynTPEnh]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPEnh"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared
tools\msconfig\startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared
tools\msconfig\startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common
Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared
tools\msconfig\startupreg\vptray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="VPTray"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~2\\VPTray.exe"
"inimapping"="0"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymSecurePort"=dword:00000002
"Symantec AntiVirus"=dword:00000002
"SvcProc"=dword:00000002
"SPBBCSvc"=dword:00000003
"SNDSrvc"=dword:00000002
"SavRoam"=dword:00000003
"NVSvc"=dword:00000002
"ISSVC"=dword:00000002
"DefWatch"=dword:00000002
"Crypkey License"=dword:00000002
"ccSetMgr"=dword:00000002
"ccPwdSvc"=dword:00000003
"ccProxy"=dword:00000002
"ccEvtMgr"=dword:00000002
"AvidStartup"=dword:00000002
"AvidSDMService"=dword:00000002
"ALG"=dword:00000003
"mnmsrvc"=dword:00000003
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
@=""
Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Registration reminder 1.job
C:\WINDOWS\tasks\Registration reminder 2.job
C:\WINDOWS\tasks\Registration r
Wow…Thanks
-kp
oh yeah, still no internet access
Lets try FireFox as a browser.
http://www.mozilla.com/firefox/
If that still doesn't work, try this:
Get a copy of winsockxpfix.exe You just run it and
things should work OK after it reboots your system.
http://www.snapfiles.com/get/winsockxpfix.html
I'm off to bed
Yeah, my head hurt after all that yesterday. Then I hit the ground running this morning.
But still no internet access, except in safe-mode. I can ping, but no internet and no AVG update, no Spybot update.
Here's the logfile after the last fix attempt:
Logfile of HijackThis v1.99.1
Scan saved at 9:27:24 PM, on 7/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\regedit.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
Thanks,
-kp
Also, no Mozilla internet access.
When in normal-mode I have no "network connection" in "My Network Places">properties. But Task Manager shows an active adaptor and I can ping.
I don't remember if I asked you this already but do you have your windows CD?
If so try this:
use windows sfc (system file checker) You'd need your XP CD to make this work.
Click Start> Run> type sfc /scannow Note the space.
(Note that there is a space between sfc and /scannow)
Yeah, you asked me and I told you I'd run sfc /scannow. Also, I ran it again when I went to bed last night. No change I could see.
Also, I noticed when I started IE7 that I'm getting some wierd info in the Status Bar. Some knid of a dnserror.html flashes by. Too fast really to get fully. I also tried uninstalling the Network Adaptor. Windows did not "find new hardware" the Device Manager had No (none, zero) devices, or it was blanked. I ran the "add new hardware" wizard and it did detect the adaptor.
Lets try this:
Please download hoster from the link below.
http://www.funkytoad.com/download/hoster.zip
Unzip Hoster.zip
Open Hoster.exe.
Then click on "Restore Original Hosts"
Close program when complete.
Empty Recycle Bin
Reboot and "copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Same thing. Wow, this thing is screwed UP!!!!
Got any more ideas?
Logfile of HijackThis v1.99.1
Scan saved at 1:23:29 PM, on 7/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5450.0004)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
By chance did this start after you installed Internet Explorer v7.00 ?