profits
Topic Starter
have run spybot, ad aware and ewido as instructed below is my ewido log and my hijackthis log please help, thanks
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 3:16:05 PM 8/4/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\H323TSP -> Adware.Look2Me : No action taken.
[596] C:\WINDOWS\system32\mwidntld.dll -> Adware.Look2Me : No action taken.
[672] C:\WINDOWS\system32\mwidntld.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temp\5.dlb -> Downloader.Small.dgk : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temp\2.dlb -> Downloader.Tibs.gc : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temporary Internet Files\Content.IE5\94TPAM4M\win32[1].exe -> Downloader.Tibs.gc : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temporary Internet Files\Content.IE5\NKURLDW6\dfndrff_7[1].exe -> Hijacker.VB.ly : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temp\Temporary Internet Files\Content.IE5\1HW7QTST\xp-cydoor-728[1].swf -> Not-A-Virus.Hoax.SWF.Alerter.a : No action taken.
C:\RECYCLER\S-1-5-21-2907963596-1212456468-2938977831-1005\Dc89.exe -> Trojan.Dialer.pw : No action taken.
::Report end
Logfile of HijackThis v1.99.1
Scan saved at 3:22:21 PM, on 8/4/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Sony\Giga Pocket\shwserv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec
Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Sony Shared\VAIO
Entertainment\VzCdb\VzFw.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Symantec Shared\Security
Center\UsrPrmpt.exe
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Common
Files\AOL\1147593701\ee\AOLSoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\kybrdff_7.exe
C:\WINDOWS\System32\wfxqhv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Money\System\reminder.exe
C:\WINDOWS\DOBE~1\netdde.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\Common
Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\sony\usbsircs\usbsircs.exe
C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Sony\Giga Pocket\gps.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ANTHON~1\LOCALS~1\Temp\Rar$EX00.187\HijackThis.ex
e
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://v4.windowsupdate.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) -
{943CBC39-29DE-0575-D7FC-2917B4825AC2} -
C:\WINDOWS\System32\mdu.dll (file missing)
R3 - URLSearchHook: (no name) -
{7CA8B8F5-7248-07E8-15F9-2C2727FBEDCE} -
C:\WINDOWS\System32\yhsbax.dll (file missing)
R3 - URLSearchHook: (no name) -
{EB17C8AB-534F-28BF-1F24-5410942071C3} -
C:\WINDOWS\System32\ordtiuh.dll (file missing)
F2 - REG:system.ini: UserInit=userinit.exe
N3 - Netscape 7: user_pref("browser.search.defaultengine",
"http://www.google.com/"); (C:\Documents and Settings\Anthony
Marsh\Application
Data\Mozilla\Profiles\default\drs0awdv.slt\prefs.js)
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66}
- (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467}
- C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus -
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program
Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google -
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar3.dll
O3 - Toolbar: AOL Toolbar -
{DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program
Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI
Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO
Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton
Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO
Recovery\PartSeal.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common
Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\Program Files\Internet
Explorer\IEXPLORE.EXE
O4 - HKLM\..\Run: [sysqh.exe] C:\WINDOWS\sysqh.exe
O4 - HKLM\..\Run: [crai32.exe] C:\WINDOWS\crai32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program
Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26
"EPSON Stylus CX4600 Series" /O6 "USB003" /M "Stylus CX4600"
O4 - HKLM\..\Run: [NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common
Files\AOL\1147593701\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program
Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common
Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_7.exe
O4 - HKLM\..\Run: [k6mmN5IOU]
"C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [pms2d117] RUNDLL32.EXE w1586d50.dll,n
0022d115000000031586d50
O4 - HKCU\..\Run: [MSMSGS] "C:\Program
Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft
Money\System\reminder.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common
Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US
ee://aol/imApp
O4 - HKCU\..\Run: [Iinl] "C:\WINDOWS\DOBE~1\netdde.exe" -vt
yazr
O4 - HKCU\..\Run: [ofmf] C:\PROGRA~1\COMMON~1\ofmf\ofmfm.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System
Files\System.exe"
O4 - HKCU\..\Run: [Ewdowjbo] C:\Documents and
Settings\Anthony Marsh\My Documents\S?mantec\??anregw.exe
O4 - HKCU\..\Run: [Pop up Blocker] "C:\Program Files\Pop up
Blocker\pd.exe" Minimize
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program
Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program
Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program
Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk =
C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Remocon Driver.lnk = ?
O4 - Global Startup: Timer Recording Manager.lnk = C:\Program
Files\Sony\Giga Pocket\ReserveModule.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program
Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search -
c:\program files\aol\aol toolbar
3.1\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search -
res://c:\program
files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://c:\program
files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links -
res://c:\program
files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages -
res://c:\program
files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: AOL Toolbar -
{3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program
Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Research -
{92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet -
{94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program
Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet -
{94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program
Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PD -
{9C0D7DB8-4D4C-4CD0-A120-05171D90E299} - C:\Program Files\Pop
up Blocker\pd.exe
O14 - IERESET.INF:
START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Filter: text/html -
{B5F86455-BF18-4E12-965A-6642A0AC0549} -
C:\WINDOWS\System32\xeymi.dll
O20 - AppInit_DLLs: cmd.dll
O20 - Winlogon Notify: Reliability -
C:\WINDOWS\system32\m4po0e73eh.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec
Corporation - C:\Program Files\Common Files\Symantec
Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec
Corporation - C:\Program Files\Common Files\Symantec
Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) -
Symantec Corporation - C:\Program Files\Common Files\Symantec
Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) -
Symantec Corporation - C:\Program Files\Common Files\Symantec
Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware
Development a.s. - C:\Program Files\ewido anti-spyware
4.0\guard.exe
O23 - Service: Giga Pocket Hardware Detector - Sony
Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer,
Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program
Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto Protect Service
(navapsvc) - Symantec Corporation - C:\Program Files\Norton
AntiVirus\navapsvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program
Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program
Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec
Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) -
Symantec Corporation - C:\Program Files\Common Files\Symantec
Shared\SNDSrvc.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation -
C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation -
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation
- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony
Corporation - C:\Program Files\Common Files\Sony
Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation -
C:\Program Files\Common Files\Symantec
Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation
- C:\Program Files\Common Files\Symantec Shared\Security
Center\SymWSC.exe
O23 - Service: VAIO Entertainment Aggregation and Control
Service - Sony Corporation - C:\Program Files\Common
Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony
Corporation - C:\Program Files\Common Files\Sony Shared\VAIO
Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration
Service - Sony Corporation - C:\Program Files\Common
Files\Sony Shared\VAIO
Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResour
ceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony
Corporation - C:\Program Files\Common Files\Sony Shared\VAIO
Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server
(VAIOMediaPlatform-IntegratedServer-AppServer) - Sony
Corporation - C:\Program Files\Sony\vaio media integrated
server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP)
(VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner -
C:\Program Files\Sony\vaio media integrated
server\Platform\SV_Httpd.exe"
/Service=VAIOMediaPlatform-IntegratedServer-HTTP
/RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0"
/RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP)
(VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation
- C:\Program Files\Sony\vaio media integrated
server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server
(VAIOMediaPlatform-Mobile-Gateway) - Unknown owner -
C:\Program Files\Sony\vaio media integrated
server\Platform\VmGateway.exe"
/Service=VAIOMediaPlatform-Mobile-Gateway
/RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0"
/RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO
Media Gateway Server (file missing)
O23 - Service: VAIO Media Video Server
(VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner -
C:\Program Files\Sony\vaio media integrated
server\Video\GPVSvr.exe"
/Service=VAIOMediaPlatform-VideoServer-AppServer
/DisplayName="VAIO Media Video Server (file missing)
O23 - Service: VAIO Media Video Server (HTTP)
(VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner -
C:\Program Files\Sony\vaio media integrated
server\Platform\SV_Httpd.exe"
/Service=VAIOMediaPlatform-VideoServer-HTTP
/RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0"
/RegExt="\Applications\VideoServer\HTTP (file missing)
O23 - Service: VAIO Media Video Server (UPnP)
(VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation -
C:\Program Files\Sony\vaio media integrated
server\Platform\UPnPFramework.exe
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 3:16:05 PM 8/4/2006
+ Scan result:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\H323TSP -> Adware.Look2Me : No action taken.
[596] C:\WINDOWS\system32\mwidntld.dll -> Adware.Look2Me : No action taken.
[672] C:\WINDOWS\system32\mwidntld.dll -> Adware.Look2Me : No action taken.
C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temp\5.dlb -> Downloader.Small.dgk : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temp\2.dlb -> Downloader.Tibs.gc : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temporary Internet Files\Content.IE5\94TPAM4M\win32[1].exe -> Downloader.Tibs.gc : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temporary Internet Files\Content.IE5\NKURLDW6\dfndrff_7[1].exe -> Hijacker.VB.ly : No action taken.
C:\Documents and Settings\Anthony Marsh\Local Settings\Temp\Temporary Internet Files\Content.IE5\1HW7QTST\xp-cydoor-728[1].swf -> Not-A-Virus.Hoax.SWF.Alerter.a : No action taken.
C:\RECYCLER\S-1-5-21-2907963596-1212456468-2938977831-1005\Dc89.exe -> Trojan.Dialer.pw : No action taken.
::Report end
Logfile of HijackThis v1.99.1
Scan saved at 3:22:21 PM, on 8/4/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Sony\Giga Pocket\shwserv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec
Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Sony Shared\VAIO
Entertainment\VzCdb\VzFw.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control
Panel\atiptaxx.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Common Files\Symantec Shared\Security
Center\UsrPrmpt.exe
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Common
Files\AOL\1147593701\ee\AOLSoftware.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\kybrdff_7.exe
C:\WINDOWS\System32\wfxqhv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Money\System\reminder.exe
C:\WINDOWS\DOBE~1\netdde.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\Common
Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\sony\usbsircs\usbsircs.exe
C:\Program Files\Sony\Giga Pocket\ReserveModule.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Sony\Giga Pocket\gps.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ANTHON~1\LOCALS~1\Temp\Rar$EX00.187\HijackThis.ex
e
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search
Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = http://v4.windowsupdate.microsoft.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page =
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,CustomizeSearch =
http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) -
{943CBC39-29DE-0575-D7FC-2917B4825AC2} -
C:\WINDOWS\System32\mdu.dll (file missing)
R3 - URLSearchHook: (no name) -
{7CA8B8F5-7248-07E8-15F9-2C2727FBEDCE} -
C:\WINDOWS\System32\yhsbax.dll (file missing)
R3 - URLSearchHook: (no name) -
{EB17C8AB-534F-28BF-1F24-5410942071C3} -
C:\WINDOWS\System32\ordtiuh.dll (file missing)
F2 - REG:system.ini: UserInit=userinit.exe
N3 - Netscape 7: user_pref("browser.search.defaultengine",
"http://www.google.com/"); (C:\Documents and Settings\Anthony
Marsh\Application
Data\Mozilla\Profiles\default\drs0awdv.slt\prefs.js)
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66}
- (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467}
- C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus -
{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program
Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google -
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar3.dll
O3 - Toolbar: AOL Toolbar -
{DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program
Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI
Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO
Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [ezShieldProtector for Px]
C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common
Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton
Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO
Recovery\PartSeal.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program
Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common
Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\Program Files\Internet
Explorer\IEXPLORE.EXE
O4 - HKLM\..\Run: [sysqh.exe] C:\WINDOWS\sysqh.exe
O4 - HKLM\..\Run: [crai32.exe] C:\WINDOWS\crai32.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common
Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program
Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus CX4600 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9AA.EXE /P26
"EPSON Stylus CX4600 Series" /O6 "USB003" /M "Stylus CX4600"
O4 - HKLM\..\Run: [NeroCheck]
C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SsAAD.exe]
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common
Files\AOL\1147593701\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program
Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common
Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_7.exe
O4 - HKLM\..\Run: [k6mmN5IOU]
"C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [pms2d117] RUNDLL32.EXE w1586d50.dll,n
0022d115000000031586d50
O4 - HKCU\..\Run: [MSMSGS] "C:\Program
Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Reminder] C:\Program Files\Microsoft
Money\System\reminder.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common
Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US
ee://aol/imApp
O4 - HKCU\..\Run: [Iinl] "C:\WINDOWS\DOBE~1\netdde.exe" -vt
yazr
O4 - HKCU\..\Run: [ofmf] C:\PROGRA~1\COMMON~1\ofmf\ofmfm.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System
Files\System.exe"
O4 - HKCU\..\Run: [Ewdowjbo] C:\Documents and
Settings\Anthony Marsh\My Documents\S?mantec\??anregw.exe
O4 - HKCU\..\Run: [Pop up Blocker] "C:\Program Files\Pop up
Blocker\pd.exe" Minimize
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program
Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program
Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program
Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program
Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk =
C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Remocon Driver.lnk = ?
O4 - Global Startup: Timer Recording Manager.lnk = C:\Program
Files\Sony\Giga Pocket\ReserveModule.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program
Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search -
c:\program files\aol\aol toolbar
3.1\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search -
res://c:\program
files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word -
res://c:\program
files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links -
res://c:\program
files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page -
res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages -
res://c:\program
files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English -
res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: AOL Toolbar -
{3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program
Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Research -
{92780B25-18CC-41C8-B9BE-3C9C571A8263} -
C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: UltimateBet -
{94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program
Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet -
{94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program
Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PD -
{9C0D7DB8-4D4C-4CD0-A120-05171D90E299} - C:\Program Files\Pop
up Blocker\pd.exe
O14 - IERESET.INF:
START_PAGE_URL=http://www.sony.com/vaiopeople
O18 - Filter: text/html -
{B5F86455-BF18-4E12-965A-6642A0AC0549} -
C:\WINDOWS\System32\xeymi.dll
O20 - AppInit_DLLs: cmd.dll
O20 - Winlogon Notify: Reliability -
C:\WINDOWS\system32\m4po0e73eh.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec
Corporation - C:\Program Files\Common Files\Symantec
Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec
Corporation - C:\Program Files\Common Files\Symantec
Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) -
Symantec Corporation - C:\Program Files\Common Files\Symantec
Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) -
Symantec Corporation - C:\Program Files\Common Files\Symantec
Shared\ccSetMgr.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware
Development a.s. - C:\Program Files\ewido anti-spyware
4.0\guard.exe
O23 - Service: Giga Pocket Hardware Detector - Sony
Corporation - C:\Program Files\Sony\Giga Pocket\shwserv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer,
Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program
Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto Protect Service
(navapsvc) - Symantec Corporation - C:\Program Files\Norton
AntiVirus\navapsvc.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program
Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program
Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec
Corporation -
C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) -
Symantec Corporation - C:\Program Files\Common Files\Symantec
Shared\SNDSrvc.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation -
C:\Program Files\Sony\Giga Pocket\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation -
C:\Program Files\Sony\Giga Pocket\RM_SV.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation
- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony
Corporation - C:\Program Files\Common Files\Sony
Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation -
C:\Program Files\Common Files\Symantec
Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation
- C:\Program Files\Common Files\Symantec Shared\Security
Center\SymWSC.exe
O23 - Service: VAIO Entertainment Aggregation and Control
Service - Sony Corporation - C:\Program Files\Common
Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe
O23 - Service: VAIO Entertainment File Import Service - Sony
Corporation - C:\Program Files\Common Files\Sony Shared\VAIO
Entertainment\VzCdb\VzFw.exe
O23 - Service: VAIO Entertainment TV Device Arbitration
Service - Sony Corporation - C:\Program Files\Common
Files\Sony Shared\VAIO
Entertainment\VzCs\VzHardwareResourceManager\VzHardwareResour
ceManager.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter - Sony
Corporation - C:\Program Files\Common Files\Sony Shared\VAIO
Entertainment\VCSW\VCSW.exe
O23 - Service: VAIO Media Integrated Server
(VAIOMediaPlatform-IntegratedServer-AppServer) - Sony
Corporation - C:\Program Files\Sony\vaio media integrated
server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP)
(VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner -
C:\Program Files\Sony\vaio media integrated
server\Platform\SV_Httpd.exe"
/Service=VAIOMediaPlatform-IntegratedServer-HTTP
/RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0"
/RegExt="Applications\IntegratedServer\HTTP (file missing)
O23 - Service: VAIO Media Integrated Server (UPnP)
(VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation
- C:\Program Files\Sony\vaio media integrated
server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server
(VAIOMediaPlatform-Mobile-Gateway) - Unknown owner -
C:\Program Files\Sony\vaio media integrated
server\Platform\VmGateway.exe"
/Service=VAIOMediaPlatform-Mobile-Gateway
/RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0"
/RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO
Media Gateway Server (file missing)
O23 - Service: VAIO Media Video Server
(VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner -
C:\Program Files\Sony\vaio media integrated
server\Video\GPVSvr.exe"
/Service=VAIOMediaPlatform-VideoServer-AppServer
/DisplayName="VAIO Media Video Server (file missing)
O23 - Service: VAIO Media Video Server (HTTP)
(VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner -
C:\Program Files\Sony\vaio media integrated
server\Platform\SV_Httpd.exe"
/Service=VAIOMediaPlatform-VideoServer-HTTP
/RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0"
/RegExt="\Applications\VideoServer\HTTP (file missing)
O23 - Service: VAIO Media Video Server (UPnP)
(VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation -
C:\Program Files\Sony\vaio media integrated
server\Platform\UPnPFramework.exe