New HJT Log:
Logfile of HijackThis v1.99.1
Scan saved at 4:04:27 PM, on 7/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\UAlbany\VPN Client\cvpnd.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\explorer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\Maria\Desktop\HijackThis\noname.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://ie.redirect.h...a...o&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL =
http://localhost:9100/proxy.pac
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher\SCActiveBlock.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [hpWirelessAssistant] "C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] "C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" /Start
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MalwareBot] C:\Program Files\MalwareBot\MalwareBot.exe -boot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Post-itŪ Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe
O4 - Global Startup: UAlbany VPN Client.lnk = C:\Program Files\UAlbany\VPN Client\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=presario&pf=laptop
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) -
http://h20278.www2.h...DataManager.CAB
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://by101w.bay101...es/MsnPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebo...otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1175802806968
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) -
http://ax.emsisoft.com/asquared.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cab
O20 - AppInit_DLLs: c:\windows\system32\ddcyywt.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\UAlbany\VPN Client\cvpnd.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
New Vundo report:
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 3:07:58 PM 7/17/2007
Listing files found while scanning....
C:\WINDOWS\system32\tmp1A.tmp.dll
Beginning removal...
Attempting to delete c:\windows\system32\ddcyywt.dll
c:\windows\system32\ddcyywt.dll Could not be deleted.
Attempting to delete C:\WINDOWS\SYSTEM32\mmdseq.dll
C:\WINDOWS\SYSTEM32\mmdseq.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\tmp1A.tmp.dll
C:\WINDOWS\system32\tmp1A.tmp.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete c:\windows\system32\ddcyywt.dll
c:\windows\system32\ddcyywt.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 3:25:35 PM 7/17/2007
Listing files found while scanning....
C:\WINDOWS\system32\tmp3.tmp.dll
VundoFix V6.5.6
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Java version is 1.5.0.11
Scan started at 3:32:31 PM 7/17/2007
Listing files found while scanning....
C:\WINDOWS\system32\tmp3.tmp.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\tmp3.tmp.dll
C:\WINDOWS\system32\tmp3.tmp.dll Has been deleted!
Performing Repairs to the registry.
Done!
ComboFix Report:
"Maria" - 2007-07-17 15:46:10 - ComboFix 07-07-13.8 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\ddcyywt.dll
C:\WINDOWS\system32\gett32.dll
C:\WINDOWS\system32\Cddsvc.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\Maria\APPLIC~1\tmp1.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp13.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp16.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp18.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp19.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp1A.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp1EE.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp2.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp28.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp29.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp3.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp39C.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp39D.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp39E.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp4.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp4B4.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp4B5.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp4F7.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp5.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp55C.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp563.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp58.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp6.tmp.exe
C:\DOCUME~1\Maria\APPLIC~1\tmp65.tmp.exe
C:\WINDOWS\system32\dn0caf33a1.dat
C:\WINDOWS\system32\tmp142.tmp.dll
C:\WINDOWS\system32\tmp146.tmp.dll
C:\WINDOWS\system32\tmp16.tmp.dll
C:\WINDOWS\system32\tmp176.tmp.dll
C:\WINDOWS\system32\tmp185.tmp.dll
C:\WINDOWS\system32\tmp18A.tmp.dll
C:\WINDOWS\system32\tmp18D.tmp.dll
C:\WINDOWS\system32\tmp1A7.tmp.dll
C:\WINDOWS\system32\tmp1F.tmp.dll
C:\WINDOWS\system32\tmp2.tmp.dll
C:\WINDOWS\system32\tmp39D.tmp.dll
C:\WINDOWS\system32\tmp4B4.tmp.dll
C:\WINDOWS\system32\tmp6.tmp.dll
C:\WINDOWS\system32\tmp65.tmp.dll
C:\WINDOWS\system32\tmpACF.tmp.dll
C:\WINDOWS\system32\tmpB4.tmp.dll
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-06-17 to 2007-07-17 )))))))))))))))))))))))))))))))
2007-07-17 15:45 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-07-17 15:21 105,436 --a------ C:\WINDOWS\system32\mlljg.exe
2007-07-17 15:16 105,436 --a------ C:\WINDOWS\system32\gebcd.exe
2007-07-16 22:23 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-07-16 22:16 <DIR> d-------- C:\Program Files\CCleaner
2007-07-16 14:05 0 --a------ C:\WINDOWS\YOURAPP.EXE
2007-07-16 14:05 0 --a------ C:\WINDOWS\system32\CMMGR32.EXE
2007-07-16 14:05 0 --a------ C:\WINDOWS\ORUN32.EXE
2007-07-16 13:57 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-07-16 13:56 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2007-07-16 13:52 3,376 --a------ C:\WINDOWS\system32\tmp.reg
2007-07-16 13:51 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-07-16 13:51 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-07-16 13:51 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-07-16 13:11 <DIR> d-------- C:\WINDOWS\pss
2007-07-16 12:44 <DIR> d-------- C:\VundoFix Backups
2007-07-16 11:59 <DIR> d-------- C:\Program Files\MalwareBot
2007-07-16 10:46 <DIR> d-------- C:\DOCUME~1\Maria\APPLIC~1\Uniblue
2007-07-16 10:22 <DIR> d-------- C:\Program Files\SpywareBlaster
2007-06-27 10:36 22,112 -ra------ C:\WINDOWS\system32\drivers\COH_Mon.sys
2007-06-27 09:21 <DIR> d-------- C:\DOCUME~1\Maria\APPLIC~1\SpywareBot
2007-06-25 22:44 76,560 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-25 22:42 <DIR> d-------- C:\DOCUME~1\Maria\.housecall6.6
2007-06-25 21:28 <DIR> d-------- C:\DOCUME~1\Maria\APPLIC~1\MalwareBot
2007-06-25 20:32 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-06-25 17:16 <DIR> d-------- C:\DOCUME~1\Maria\APPLIC~1\Tenebril
2007-06-25 17:12 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tenebril
2007-06-25 17:04 180,224 --a-s---- C:\WINDOWS\system32\archlib.dll
2007-06-25 17:04 <DIR> d-------- C:\WINDOWS\system32\tenarchlib
2007-06-23 14:10 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2007-06-20 13:06 <DIR> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-06-20 01:23 <DIR> d-------- C:\Program Files\Norton AntiVirus
2007-06-20 01:22 48,776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2007-06-20 01:22 115,000 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-06-20 01:21 <DIR> d-------- C:\Program Files\Symantec
2007-06-20 01:21 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
2007-06-20 01:20 <DIR> d-------- C:\Program Files\Common Files\Symantec Shared
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-07-16 14:02:43 -------- d-----w C:\Program Files\Easy Internet signup
2007-06-27 13:35:21 -------- d-----w C:\DOCUME~1\Maria\APPLIC~1\LimeWire
2007-06-25 21:35:03 -------- d-----w C:\Program Files\Google
2007-06-22 17:56:55 3,930 ----a-w C:\DOCUME~1\Maria\APPLIC~1\wklnhst.dat
2007-06-20 05:24:58 806 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-06-20 05:24:58 8,014 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-06-20 01:50:03 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-19 20:08:20 -------- d-----w C:\DOCUME~1\Maria\APPLIC~1\Viewpoint
2007-06-13 23:40:09 -------- d-----w C:\DOCUME~1\Maria\APPLIC~1\3M
2007-06-13 23:39:27 -------- d-----w C:\Program Files\3M
2007-06-04 15:52:35 -------- d-----w C:\Program Files\AIM6
2007-06-01 01:58:33 -------- d-----w C:\Program Files\iTunes
2007-06-01 01:58:22 -------- d-----w C:\Program Files\iPod
2007-06-01 01:56:20 -------- d-----w C:\Program Files\Apple Software Update
2007-06-01 01:53:36 -------- d-----w C:\Program Files\BitPim
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-17 14:56:16 164 ----a-w C:\install.dat
2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-17 02:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-17 02:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-17 02:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-17 02:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-03-02 20:53:52 797 ----a-w C:\DOCUME~1\Maria\APPLIC~1\waver_2.95.dat
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
2006-12-18 04:16 59032 --a------ C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0A87E45F-537A-40B4-B812-E2544C21A09F}]
C:\Program Files\SpyCatcher\SCActiveBlock.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
2007-03-14 03:43 501400 --a------ C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-11 13:00]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-01 18:11]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 08:12]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 08:11]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 16:24]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 16:54]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-08-06 20:42]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 12:45]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 01:59]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-14 03:11]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-07-16 22:24]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim6"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
"MalwareBot"="C:\Program Files\MalwareBot\MalwareBot.exe" [2007-05-22 13:47]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 08:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\ddcyywt.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d97de1e2-31f3-11db-9bf7-0014a568c6a7}]
AutoRun\command- E:\setupSNK.exe
Contents of the 'Scheduled Tasks' folder
2007-06-26 00:47:03 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-07-16 14:02:42 C:\WINDOWS\tasks\Easy Internet Sign-up.job
2007-07-17 19:39:56 C:\WINDOWS\tasks\MalwareBot Scheduled Scan.job
2007-07-17 19:59:41 C:\WINDOWS\tasks\MP Scheduled Scan.job
2007-06-20 05:35:33 C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Maria.job
2007-06-27 13:22:40 C:\WINDOWS\tasks\SpywareBot Scheduled Scan.job
**************************************************************************
catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-07-17 15:58:53
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-07-17 16:01:34
C:\ComboFix-quarantined-files.txt ... 2007-07-17 16:01
--- E O F ---
at this moment i havent received a pop up yet im not sure though they could come back because they seem to...thank you so much for the help so far! i hope my computer is getting better.
Maria