Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93104 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Think Computer Has Been Hijacked


  • This topic is locked This topic is locked
No replies to this topic

#1 RedmanT

RedmanT

    New Member

  • New Member
  • Pip
  • 1 posts

Posted 17 June 2007 - 07:32 PM

The last few days whenever I turn on my computer it takes much longer for it to come up. When I run my Outlook to recieve mail thru Charter.net, I get 20 or better "Returned e-mail" messages. E-mails that I never sent. Here is a sample of the returned e-mails:
From Subject Received Size
Internet Mail Delivery Delivery Notification: Delivery has failed Sun 6/17/2007 8:28 PM 6 KB
From Subject Received Size
postmaster@port-to-port.com Delivery Status Notification (Failure) Sun 6/17/2007 8:14 PM 6 KB
From Subject Received Size
postmaster@CONNORGFI.CONNORSOLUTIONS.COM Delivery Status Notification (Failure) Sun 6/17/2007 8:01 PM 6 KB
From Subject Received Size
MAILER-DAEMON@mail14i.g14.rapidsite.net failure notice Sun 6/17/2007 7:53 PM 4 KB

I ran Hijack this & have the logs, which I will post below...Thank you very much for any help...also please let me know what "donation" amount is helpful to keep you-all running...I'm a 53 year old retired Federal Security Agent, & it irks me that I was "Gotten" !
Logfile of HijackThis v1.99.1
Scan saved at 9:04:29 PM, on 6/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\csrss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Secure PC Solutions\1 Click Spy Clean\1ClickSpyClean.exe
F:\Program Files\McAfee.com\VSO\mcvsshld.exe
F:\Program Files\McAfee.com\VSO\oasclnt.exe
F:\PROGRA~1\mcafee.com\agent\mcagent.exe
F:\WINDOWS\CTHELPER.EXE
F:\Program Files\Spyware Doctor\SDTrayApp.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
f:\progra~1\mcafee.com\vso\mcvsescn.exe
F:\Program Files\Windows Media Player\WMPNSCFG.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Program Files\Windows Desktop Search\WindowsSearch.exe
F:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
F:\WINDOWS\system32\cisvc.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\LightScribe\LSSrvc.exe
F:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
f:\program files\mcafee.com\agent\mcdetect.exe
f:\PROGRA~1\mcafee.com\vso\mcshield.exe
f:\PROGRA~1\mcafee.com\agent\mctskshd.exe
F:\WINDOWS\System32\msdtc.exe
F:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
F:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
F:\WINDOWS\system32\PnkBstrA.exe
F:\WINDOWS\System32\SCardSvr.exe
F:\Program Files\Spyware Doctor\svcntaux.exe
F:\Program Files\Spyware Doctor\swdsvc.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
F:\Program Files\Windows Media Player\WMPNetwk.exe
F:\WINDOWS\System32\mqsvc.exe
F:\WINDOWS\System32\mqtgsvc.exe
F:\WINDOWS\System32\alg.exe
F:\WINDOWS\system32\SearchIndexer.exe
F:\Program Files\Webroot\Spy Sweeper\SSU.EXE
F:\Program Files\Internet Explorer\iexplore.exe
F:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
F:\WINDOWS\system32\cidaemon.exe
F:\WINDOWS\system32\cidaemon.exe
F:\WINDOWS\system32\SearchProtocolHost.exe
F:\WINDOWS\system32\SearchFilterHost.exe
F:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.c...//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - (no file)
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Advanced Searchbar - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - (no file)
O3 - Toolbar: (no name) - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - F:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [SecurePCSolutionsBootCheck] "F:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\BootCheck.exe"
O4 - HKLM\..\Run: [SpyClean] "F:\Program Files\Secure PC Solutions\1 Click Spy Clean\1ClickSpyClean.exe" /startup
O4 - HKLM\..\Run: [1ClickFixerPlus] "F:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\1ClickFixerPlus.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "F:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "F:\Program Files\McAfee.com\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [OASClnt] "F:\Program Files\McAfee.com\VSO\oasclnt.exe"
O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [PC Pitstop Optimize Scheduler] "F:\Program Files\PCPitstop\Optimize\PCPOptimize.exe" -boot
O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SDTray] "F:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SpySweeper] F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [updateMgr] "F:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [WMPNSCFG] "F:\Program Files\Windows Media Player\WMPNSCFG.exe"
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Update Service] "F:\Program Files\Common Files\Teknum Systems\update.exe" /startup
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = F:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: &Windows Live Search - res://F:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - (no file)
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: f:\program files\spyware doctor\filterlsp.dll
O10 - Unknown file in Winsock LSP: f:\program files\spyware doctor\filterlsp.dll
O10 - Unknown file in Winsock LSP: f:\program files\spyware doctor\filterlsp.dll
O10 - Unknown file in Winsock LSP: f:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: f:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: f:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: f:\program files\common files\pc tools\lsp\pctlsp.dll
O10 - Unknown file in Winsock LSP: f:\program files\spyware doctor\filterlsp.dll
O11 - Options group: [INTERNATIONAL] International*
O15 - Trusted Zone: http://www.msi.com.tw
O15 - Trusted Zone: http://www.rivcoproducts.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.micr...ActiveX/odc.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - F:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.2.2.89.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...01/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1133913983718
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1133913974250
O16 - DPF: {8167C273-DF59-4416-B647-C8BB2C7EE83E} (WebSDev Control) - http://liveupdate.ms...ine/install.cab
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - F:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - F:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - F:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MaxBackServiceInt - Unknown owner - F:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - f:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - f:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - f:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: MaxSyncService (NTService1) - - F:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: Pml Driver HPZ12 - HP - F:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - F:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - F:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - F:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - F:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

StartupList report, 6/17/2007, 9:08:30 PM
StartupList version: 1.52.2
Started from : F:\Program Files\Hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16473)
* Using default options
==================================================

Running processes:

F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\csrss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Secure PC Solutions\1 Click Spy Clean\1ClickSpyClean.exe
F:\Program Files\McAfee.com\VSO\mcvsshld.exe
F:\Program Files\McAfee.com\VSO\oasclnt.exe
F:\PROGRA~1\mcafee.com\agent\mcagent.exe
F:\WINDOWS\CTHELPER.EXE
F:\Program Files\Spyware Doctor\SDTrayApp.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
f:\progra~1\mcafee.com\vso\mcvsescn.exe
F:\Program Files\Windows Media Player\WMPNSCFG.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Program Files\Windows Desktop Search\WindowsSearch.exe
F:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
F:\WINDOWS\system32\cisvc.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\LightScribe\LSSrvc.exe
F:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
f:\program files\mcafee.com\agent\mcdetect.exe
f:\PROGRA~1\mcafee.com\vso\mcshield.exe
f:\PROGRA~1\mcafee.com\agent\mctskshd.exe
F:\WINDOWS\System32\msdtc.exe
F:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
F:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe
F:\WINDOWS\system32\PnkBstrA.exe
F:\WINDOWS\System32\SCardSvr.exe
F:\Program Files\Spyware Doctor\svcntaux.exe
F:\Program Files\Spyware Doctor\swdsvc.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
F:\Program Files\Windows Media Player\WMPNetwk.exe
F:\WINDOWS\System32\mqsvc.exe
F:\WINDOWS\System32\mqtgsvc.exe
F:\WINDOWS\System32\alg.exe
F:\WINDOWS\system32\SearchIndexer.exe
F:\Program Files\Webroot\Spy Sweeper\SSU.EXE
F:\Program Files\Internet Explorer\iexplore.exe
F:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
F:\WINDOWS\system32\cidaemon.exe
F:\WINDOWS\system32\cidaemon.exe
F:\Program Files\Hijackthis\HijackThis.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:
[F:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
Logitech SetPoint.lnk = ?
Windows Desktop Search.lnk = F:\Program Files\Windows Desktop Search\WindowsSearch.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = F:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

NvCplDaemon = "RUNDLL32.EXE" F:\WINDOWS\system32\NvCpl.dll,NvStartup
nwiz = "nwiz.exe" /install
Kernel and Hardware Abstraction Layer = KHALMNPR.EXE
SecurePCSolutionsBootCheck = "F:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\BootCheck.exe"
SpyClean = "F:\Program Files\Secure PC Solutions\1 Click Spy Clean\1ClickSpyClean.exe" /startup
1ClickFixerPlus = "F:\Program Files\Secure PC Solutions\1 Click Fixer PLUS\1ClickFixerPlus.exe"
VSOCheckTask = "F:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
VirusScan Online = "F:\Program Files\McAfee.com\VSO\mcvsshld.exe"
OASClnt = "F:\Program Files\McAfee.com\VSO\oasclnt.exe"
MCAgentExe = f:\PROGRA~1\mcafee.com\agent\mcagent.exe
MCUpdateExe = F:\PROGRA~1\mcafee.com\agent\mcupdate.exe
PC Pitstop Optimize Scheduler = "F:\Program Files\PCPitstop\Optimize\PCPOptimize.exe" -boot
NvMediaCenter = "RUNDLL32.EXE" F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
CTHelper = CTHELPER.EXE
CTxfiHlp = CTXFIHLP.EXE
SDTray = "F:\Program Files\Spyware Doctor\SDTrayApp.exe"
SpySweeper = F:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

updateMgr = "F:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
WMPNSCFG = "F:\Program Files\Windows Media Player\WMPNSCFG.exe"
ctfmon.exe = F:\WINDOWS\system32\ctfmon.exe
Update Service = "F:\Program Files\Common Files\Teknum Systems\update.exe" /startup

--------------------------------------------------

Shell & screensaver key from F:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=F:\WINDOWS\System32\ssstars.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - (no file) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}
(no name) - (no file) - {B56A7D7D-6927-48C8-A975-17DF180C71AC}
(no name) - F:\Program Files\Windows Live Toolbar\msntb.dll - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
(no name) - (no file) - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0}

--------------------------------------------------

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
Check Updates for Windows Live Toolbar.job
defrag.job
MP Scheduled Scan.job

--------------------------------------------------

Enumerating Download Program Files:

[{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}]
CODEBASE = http://a1540.g.akama...ex/qtplugin.cab

[Windows Genuine Advantage Validation Tool]
InProcServer32 = F:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://download.micr...heckControl.cab

[Microsoft Data Collection Control]
InProcServer32 = F:\WINDOWS\system32\odc.dll
CODEBASE = https://support.micr...ActiveX/odc.cab

[YInstStarter Class]
InProcServer32 = F:\PROGRA~1\Yahoo!\Common\yinsthelper.dll
CODEBASE = F:\Program Files\Yahoo!\Common\yinsthelper.dll

[FilePlanet Download Control Class]
InProcServer32 = F:\Program Files\IGN\Download Manager\FPDC.dll
CODEBASE = http://www.fileplane...DC_2.2.2.89.cab

[Office Update Installation Engine]
InProcServer32 = F:\WINDOWS\opuc.dll
CODEBASE = http://office.micros...ntent/opuc3.cab

[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://a1540.g.akama...meInstaller.exe

[McAfee.com Operating System Class]
InProcServer32 = F:\WINDOWS\system32\mcinsctl.dll
CODEBASE = http://download.mcaf...01/mcinsctl.cab

[WUWebControl Class]
InProcServer32 = F:\WINDOWS\system32\wuweb.dll
CODEBASE = http://update.micros...b?1133913983718

[MUWebControl Class]
InProcServer32 = F:\WINDOWS\system32\muweb.dll
CODEBASE = http://update.micros...b?1133913974250

[WebSDev Control]
InProcServer32 = F:\PROGRA~1\MSI\MSIWDev\WebSDev.ocx
CODEBASE = http://liveupdate.ms...ine/install.cab

[Office Update Installation Engine]
InProcServer32 = F:\WINDOWS\opuc.dll
CODEBASE = http://office.micros...ntent/opuc4.cab

[Shockwave Flash Object]
InProcServer32 = F:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx
CODEBASE = http://fpdownload.ma...ent/swflash.cab

--------------------------------------------------

Enumerating Winsock LSP files:

Protocol #1: F:\Program Files\Spyware Doctor\FilterLSP.dll
Protocol #2: F:\Program Files\Spyware Doctor\FilterLSP.dll
Protocol #3: F:\Program Files\Spyware Doctor\FilterLSP.dll
Protocol #4: F:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Protocol #5: F:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Protocol #6: F:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Protocol #14: F:\Program Files\Common Files\PC Tools\LSP\PCTLsp.dll
Protocol #15: F:\Program Files\Spyware Doctor\FilterLSP.dll

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: F:\WINDOWS\system32\SHELL32.dll
CDBurn: F:\WINDOWS\system32\SHELL32.dll
WebCheck: F:\WINDOWS\system32\webcheck.dll
SysTray: F:\WINDOWS\System32\stobject.dll
WPDShServiceObj: F:\WINDOWS\system32\WPDShServiceObj.dll

--------------------------------------------------
End of report, 9,884 bytes
Report generated in 0.062 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only

Once again,
Thank You Very Much.........
Wallace

    Advertisements

Register to Remove

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users