This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Hjt Fails To Remove Ddccy.dll And Xxyvvwt.dll

57 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup

what do these do?

O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"

what does this do?

O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe

This gives a system tray icon. When I bring it up, it tells me that my network card isn't working. It lists two problems:

1) The system has not enabled IO address mapping for the device you have installed.
The device driver will not work correctly on this adapter.

It says the solution to this is to disable plug and play in my bios.

2) The network driver for this adapter failed to load.

It says the solution is to restart teh system, if that doesn't work then I need to reinstall the drivers.
I have DSL which runs through my USB port, so I'm not using the card anyway and never have.

O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

This has something to do with my Soundblaster card, what exactly I don't know. The only thing is, I have SB Audigy Audio [D880].

O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE

Why does this run? What does it do?

O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

This is for my sound card, I guess.

O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

I guess this is a driver to allow drag and drop to a writable CD.

O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe

This is my DLS networking.

O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE

There is an arc of hotkeys on the top of my keyboard, I think this is the driver for them,
but I've never used them, not even once.

O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE

Several virus warnings about this in the above log, is it running correctly?

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit

No idea what an NVMediaCenter is.

O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe

Well, I have Works, but the only part of it I use is Word, which I bring up from a shortcut on my destop. Do I need this?

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\System32\ctfmon.exe

OK, this has something to do with the language bar, which I need,
sometimes I need to type spanish characters so I need to switch langs so the keyboard works right.

O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m

starts up spyeraser in the background.

O12 - Plugin for .edf: C:\Program Files\Internet Explorer\PLUGINS\NPInfotl.dll

This has to do with ebrary, an online library of about 20K books.

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

Some part of adobe acrobat 5.0?

O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.historytoday.com/CFIDE/classes/CFJava.cab

No idea why this is on my comp.

O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB

What does this do?

O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs6b.instantservice.com/jars/customerxsigned32.cab

No idea what this does, and the web site doesn't seem to exist anymore, if it ever did.

O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB

I don't know what this is.

O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

http://acs.pandasoftware.com/activescan/as5free/asinst.cab

This is new since the panda AV scan.

O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab

No idea what this is, unless it's part of MS gaming zone? tracert to fdl.msn.com times out.

O16 - DPF: {BB5C5554-2B89-4D18-9938-D7EFEDDB2346} (ebcardatl Class) - http://fast.ebrary.com/support/plugins/ebraryReader.exe

part of ebrary.

O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton

AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet

Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet

Security\NISUM.EXE

All Norton, if all these are actually legit and haven't been replaced by something.

O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe

Why is there an intel driver?

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe

Tray icon for video driver.

O23 - Service: Remote Access Connection Manager RasManaspnet_state (RasManaspnet_state) - Unknown owner -

C:\WINNT\System32\accwizt.exe (file missing)

This looks really bogus. accwizt.exe got removed by one of the earlier cleanups you did.

O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

This is the only part of Norton I ever see actually work. I get malicious script warnings from things in the browser at times, and a

few from cleanup batch files you provided.

O23 - Service: Smart Card Helper SCardDrvNtmsSvc (SCardDrvNtmsSvc) - Unknown owner - C:\WINNT\System32\a3db.exe (file missing)
O23 - Service: Smart Card Helper SCardDrvSCardDrv (SCardDrvSCardDrv) - Unknown owner - C:\WINNT\System32\adsldpx.exe (file missing)

These look bogus, the files disappeared during one of your cleanups.

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\SNDSrvc.exe

Dunno.

O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet

Security\SymProxySvc.exe

Does this figure out IP addresses in a secure way to prevent connecting to bogus sites?
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup

Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card

Not absolutely necessary at start up - can be killed


O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"

Millenium Multi-Function Keyboard driver

Needed


O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe

This gives a system tray icon. When I bring it up, it tells me that my network card isn't working. It lists two problems:

1) The system has not enabled IO address mapping for the device you have installed.
The device driver will not work correctly on this adapter.

It says the solution to this is to disable plug and play in my bios.

2) The network driver for this adapter failed to load.

It says the solution is to restart teh system, if that doesn't work then I need to reinstall the drivers.
I have DSL which runs through my USB port, so I'm not using the card anyway and never have.

It's just to get at the diagnostic features I believe. Not needed.


O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE

This has something to do with my Soundblaster card, what exactly I don't know. The only thing is, I have SB Audigy Audio [D880].

CTHELPER is a background task that is a plug-in manager for Creative drivers. The theory is that 3rd party manufacturers can use the CTHELPER plug-in interface to produce drivers, add-on features, and fixes that will integrate with a tighter fit with Creative�s sound drivers and utilities. Given its purpose CTHELPER would normally be classified as a "leave alone" background task. It also allows Creative speaker setup to be synchronized with Windows Control Panel speaker setting. Without it running that check box in Creative speaker setting is not functional (settings are not in sync). Unfortunately there are often problems with CTHELPER, most notably that it can use 100% of CPU time so it's best left disabled unless you need it
I would kill it.


O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE

Why does this run? What does it do?

Reminder to register Creative Labs SoundBlaster Live! cards
I would kill it.


O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe

This is for my sound card, I guess.

Added with SoundBlaster Live! or Audigy soundcards for headphone autodetection
I would kill it if not needed.


O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"

I guess this is a driver to allow drag and drop to a writable CD.

Yes, DirectCD primarily allows you to drag and drop files onto a suitably formatted CD-RW disc. Unless you use this on a frequent basis it isn't required and is available via Start -> Programs. Start the program before inserting a DirectCD formatted CD-RW in the drive. A re-boot is recommended if you close Adaptec DirectCD before re-opening it again later
I would kill it.


O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe

This is my DLS networking.

Yes, for 2Wire
Leave it


O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE

There is an arc of hotkeys on the top of my keyboard, I think this is the driver for them,
but I've never used them, not even once.

Yes, Multimedia keyboard manager - required if you use any special keys
Kill it if not needed

O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE

Several virus warnings about this in the above log, is it running correctly?

Norton Anti-Virus's background scanning process
Those I believe are false positives - they should go when you remove Norton (hopefully, you already got my take on that).


O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit

No idea what an NVMediaCenter is.

System Tray icon used to manage settings for nVidia based graphics cards. May be required for some 3D applications to recognize your card correctly - such as the game "Everquest". Otherwise, settings can be changed manually via Display Properties
Up to you, kill it if not needed


O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe

Well, I have Works, but the only part of it I use is Word, which I bring up from a shortcut on my destop. Do I need this?
Checks for updates to MS Works
Can be killed - you can still do it manually, this just does it automatically

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\System32\ctfmon.exe

OK, this has something to do with the language bar, which I need,
sometimes I need to type spanish characters so I need to switch langs so the keyboard works right.

CTFMon is involved with the language/alternative input services in Office XP. CTFMON.exe will continue to put itself back into MSConfig when you run the Office XP apps as long as the Text Services and Speech applets in the Control Panel are enabled. Not required if you don\'t need these features. For more info on ctfmon See_Here ;en-us;282599 . CTFMON can be disabled from Control Panel, Text & Speech Services. NOTE: The file will always be located in the System32 folder. If it is located elsewhere, it will likely be a worm or trojan!
Keep it…does no harm where it is. Although I've never quite totally understood this one because even if you kill it I believe it will come back, like magic (MS magic)


O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m

starts up spyeraser in the background.

Yes, keep


O12 - Plugin for .edf: C:\Program Files\Internet Explorer\PLUGINS\NPInfotl.dll

This has to do with ebrary, an online library of about 20K books.

Yes, keep


O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

Some part of adobe acrobat 5.0?
Yes, safe to keep


All the 016's in HJT are Active X Controls. If you want to know more about them simple google Active X. Even if you were to nuke em all, which I don't recommend, they would come back next time you visited the site. So no harm done, just slow you down a little next time.


O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.historytoday.com/CFIDE/classes/CFJava.cab

No idea why this is on my comp.

Has to do with ColdFusion?

O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB

What does this do?

Related to the Help and Support Center feature. For more information Click: http://www.updatexp.com/kb825119.html


O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs6b.instantservice.com/jars/customerxsigned32.cab

No idea what this does, and the web site doesn't seem to exist anymore, if it ever did.

Instant service utility: http://instantservice.com/
Up to you as all the 016's are


O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB

I don't know what this is.

Related to the Help and Support Center feature. For more information Click_Here (see above)


O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

http://acs.pandasoftware.com/activescan/as5free/asinst.cab

This is new since the panda AV scan.

Yes, tis Panda


O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab

No idea what this is, unless it's part of MS gaming zone? tracert to fdl.msn.com times out.

MSN Heartbeat ActiveX control
???


O16 - DPF: {BB5C5554-2B89-4D18-9938-D7EFEDDB2346} (ebcardatl Class) - http://fast.ebrary.com/support/plugins/ebraryReader.exe

part of ebrary.

Yes, I think


O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton

AntiVirus\navapsvc.exe

O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet

Security\NISSERV.EXE

O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet

Security\NISUM.EXE

All Norton, if all these are actually legit and haven't been replaced by something.

They are OK…again should go away when replaced


O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe

Why is there an intel driver?

NIC Management Service - diagnostics program for Intel Pro family network cards
Keep!

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe

Tray icon for video driver.
Yes, keep

O23 - Service: Remote Access Connection Manager RasManaspnet_state (RasManaspnet_state) - Unknown owner -

C:\WINNT\System32\accwizt.exe (file missing)

This looks really bogus. accwizt.exe got removed by one of the earlier cleanups you did.

Good catch! I missed it in my last review. It's bogus. I'll give fix below.


O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

This is the only part of Norton I ever see actually work. I get malicious script warnings from things in the browser at times, and a

Will go away when replaced


few from cleanup batch files you provided.


O23 - Service: Smart Card Helper SCardDrvNtmsSvc (SCardDrvNtmsSvc) - Unknown owner - C:\WINNT\System32\a3db.exe (file missing)
O23 - Service: Smart Card Helper SCardDrvSCardDrv (SCardDrvSCardDrv) - Unknown owner - C:\WINNT\System32\adsldpx.exe (file missing)

These look bogus, the files disappeared during one of your cleanups

Yup, bingo again, good catch. See below for complete fix.

O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec

Shared\SNDSrvc.exe

Norton….


O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet

Security\SymProxySvc.exe

Does this figure out IP addresses in a secure way to prevent connecting to bogus sites?

Ya, related to firewall…you wanna make sure your new "security package" has a firewall, or install one of the free ones. Better than the Windows one. I can give you recommendations if you like.


THE FIX:

Please copy (Ctrl C) and paste (Ctrl V) the following text in the quote to Notepad. Save it as "All Files" and name it FixServices.bat. Please save it on your desktop.

sc stop RasManaspnet_state
sc delete RasManaspnet_state

sc stop SCardDrvNtmsSvc
sc delete SCardDrvNtmsSvc

sc stop SCardDrvSCardDrv
sc delete SCardDrvSCardDrv

exit

Double click FixServices.bat. A window will open and close. This is normal.

—————————————————————————-

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O23 - Service: Remote Access Connection Manager RasManaspnet_state (RasManaspnet_state) - Unknown owner - C:\WINNT\System32\accwizt.exe
O23 - Service: Smart Card Helper SCardDrvNtmsSvc (SCardDrvNtmsSvc) - Unknown owner - C:\WINNT\System32\a3db.exe (file missing)
O23 - Service: Smart Card Helper SCardDrvSCardDrv (SCardDrvSCardDrv) - Unknown owner - C:\WINNT\System32\adsldpx.exe (file missing)

Then close all windows except this one and press Fix checked.

Reboot and post a fresh HJT log. Let me know how it's running too.

Still no word on the reg fix yet but we'll get that in later.

Also, had to note this. Have you ever considered doing this as a ""career""? Seriously, you appear to be very inquiring and seem to have pretty solid understanding of computers. We have a classroom here (see my sig) and there are good ones elsewhere also. I don't usually mention this to people I'm helping but a few have signed up. Seems to spark interest. Let me know if you are and would have time for it….it does take a time commitment.
Hi David,

Instead of a reg edit we're going to use combofix again with a script.

Open Notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\ddccy

Registry::
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll"


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

This will run Combofix

Then post the results log.
OK, after running the batch file the 3 023 items you listed are gone from HJT. When you say I can kill stuff, does that mean check the box in HJT to eliminate it? Also, I looked at the "security suite" I got from Gateway, it's 4 programs- Spy Sweeper - anti-spyware Personal Data Vault - file encryption Window Washer - I think it cleans up temp files, as it talks about cookies and browser caches Search and Recover - recovers deleted files from disk So- I need some tough AV and firewall to replace my flaky Norton, I can afford to pay a bit for it, although free is always better, but I want stuff that will keep this carp** off my comp in the future. I installed ad-aware a while back, it didn't do a good job, and spy eraser isn't very hot either. I have a degree in computer science, but my skills are mostly in C programming in a UNIX environment and in-line SQL coding. What goes on under the hood of Windows has always been kind of a mystery to me, MS tries to hide a lot of the details, especially how startup, the program environment, and the registry work. I'm kinda free at the moment though, I saw the thing about the malware university, and it kind of interests me, these guys who write this stuff and diseminate it really piss me off. Oh, one last question, briefly in the last couple days I saw a STARTUP icon in control panel, and was able to open a window that let me look at stuff windows does on startup, but it's gone again. How can I look at it again?

these guys who write this stuff and diseminate it really piss me off.


That is one of the main reasons I do this! I got infected back in 2003/2004 with the original "about:blank" infection and there were no "canned fixes" for it back then. It was brutal. Took me two weeks to get it I think. But I type this now on the same computer I had then and have never had to re-install Windows. And it's squeaky clean too…

I have a degree in computer science, but my skills are mostly in C programming in a UNIX environment and in-line SQL coding.


If you can learn that stuff you can do this too…it just takes time and commitment. Just like learning dreaded C. Took a couple of courses myself in it but…

Yes, that won't do it for your security. I'll give you some suggestions when you're all clean, which I think is real close. Just get through the rest of what I posted and we'll go from there.
Oh, just saw the end of your last post. In Control Panel you saw startups? Don't think I've ever seen it there. There are many ways Windows will do that….3 or 4 I think??

Off the top of my head…
start > All Programs -> Start Up
The registry can do it
msconfig…not recommend for permanent solution. Is that where you saw it?
scripts

This article has some good info. on that along with some other stuff…

http://reviews.cnet.com/4520-10165_7-5554402-1.html
Can I just check off those items in HJT and hit FIX to kill them from startup?

Should I just delete all the quarantined stuff that panda complained about? I'd like to run it again once you think I'm clean, and see what pops up, I'd like to see a short list.

I included HJT log below, also.


==============================================================================

ComboFix 07-09-05.5 - "Owner" 2007-09-06 17:11:17.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.672 [GMT -5:00]
* Created a new restore point

FILE::
C:\WINDOWS\system32\ddccy


((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))


2007-09-06 10:18 73,728 –a—— C:\WINNT\system32\pv.exe
2007-09-06 10:18 39,184 –a—— C:\WINNT\system32\Ntrights.exe
2007-09-06 10:18 175,616 –a—— C:\WINNT\system32\strings.exe
2007-09-06 10:18 16,384 –a—— C:\WINNT\system32\restart.exe
2007-09-06 10:18 126,976 –a—— C:\WINNT\system32\zip.exe
2007-09-06 10:18 11,254 –a—— C:\WINNT\system32\locate.com
2007-09-05 22:17 d——– C:\WINNT\system32\ActiveScan
2007-09-05 12:18 d——– C:\VundoFix Backups
2007-09-05 10:05 51,200 –a—— C:\WINNT\NirCmd.exe
2007-09-05 09:47 d——– C:\BRIDAL
2007-09-05 00:54 d——– C:\HJT
2007-09-04 23:46 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-09-04 23:46 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\InterVideo
2007-09-04 23:46 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\InterTrust
2007-09-04 21:11 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon
2007-08-20 17:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-17 00:34 d——– C:\Program Files\Security Task Manager
2007-08-17 00:34 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan
2007-08-14 11:09 21,760 –a—— C:\WINNT\system32\dllcache\usbstor.sys
2007-08-14 10:27 d——– C:\music library
2007-08-13 23:32 d——– C:\Program Files\Real
2007-08-13 23:27 d——– C:\DOCUME~1\Owner\APPLIC~1\Real
2007-08-13 23:13 d——– C:\Program Files\Best Buy Rhapsody
2007-08-13 22:56 10,368 –a—— C:\WINNT\system32\iviaspi.sys
2007-08-13 22:56 10,368 –a—— C:\WINNT\system32\drivers\_iviaspi.sys
2007-08-13 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-13 22:55 d——– C:\Program Files\Sandisk


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-06 17:14 ——— d——– C:\Program Files\Norton Internet Security
2007-09-06 17:14 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-09-05 22:53 ——— d——– C:\Program Files\Norton AntiVirus
2007-08-17 03:15 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-08-16 20:54 ——— d——– C:\Program Files\Symantec
2007-08-14 08:57 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-13 22:56 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-13 22:32 ——— d——– C:\Program Files\2Wire


((((((((((((((((((((((((((((( snapshot_2007-09-05_101611.60 )))))))))))))))))))))))))))))))))))))))))

—-a-w 141,424 2006-08-24 13:28:54 C:\WINNT\Downloaded Program Files\asinst.dll
—-a-w 73,728 2006-08-02 17:39:06 C:\WINNT\system32\asuninst.exe
—-a-w 11,776 2003-03-25 23:53:50 C:\WINNT\system32\ZPORT4AS.dll
—-a-w 110,592 2007-03-29 14:20:50 C:\WINNT\system32\ActiveScan\as.dll
—-a-w 233,472 2006-10-05 21:15:26 C:\WINNT\system32\ActiveScan\ascontrol.dll
—-a-w 96,256 2005-06-03 19:03:18 C:\WINNT\system32\ActiveScan\asmdat.dll
—-a-w 36,864 2003-08-01 16:00:16 C:\WINNT\system32\ActiveScan\certdll.dll
—-a-w 86,016 2005-05-20 18:42:44 C:\WINNT\system32\ActiveScan\instlsp.dll
—-a-w 4,608 2006-02-16 23:20:20 C:\WINNT\system32\ActiveScan\memvfile.dll
—-a-w 348,160 2005-10-25 23:08:32 C:\WINNT\system32\ActiveScan\msvcr71.dll
—-a-w 139,264 2004-05-04 20:01:02 C:\WINNT\system32\ActiveScan\pavaleas.dll
—-a-w 45,056 2006-07-14 18:04:10 C:\WINNT\system32\ActiveScan\pavdr.exe
—-a-w 159,832 2006-04-10 15:50:02 C:\WINNT\system32\ActiveScan\pavexcom.dll
—-a-w 94,208 2006-02-14 18:05:38 C:\WINNT\system32\ActiveScan\pavinas.dll
—-a-w 180,224 2006-02-16 23:35:38 C:\WINNT\system32\ActiveScan\pavoe.dll
—-a-w 122,880 2006-10-05 21:15:38 C:\WINNT\system32\ActiveScan\pavpz.dll
—-a-w 8,704 2006-06-30 19:13:38 C:\WINNT\system32\ActiveScan\pfdnnt.exe
—-a-w 49,152 2004-02-04 19:08:42 C:\WINNT\system32\ActiveScan\port32.dll
—-a-w 69,632 2006-08-01 18:23:10 C:\WINNT\system32\ActiveScan\pscpu.dll
—-a-w 1,388,544 2006-08-23 18:06:08 C:\WINNT\system32\ActiveScan\pskahk.dll
—-a-w 10,752 2006-08-17 16:38:14 C:\WINNT\system32\ActiveScan\pskalloc.dll
—-a-w 61,440 2006-09-04 16:49:54 C:\WINNT\system32\ActiveScan\pskas.dll
—-a-w 779,264 2006-08-18 13:46:18 C:\WINNT\system32\ActiveScan\pskavs.dll
—-a-w 417,792 2007-03-26 19:25:34 C:\WINNT\system32\ActiveScan\pskcmp.dll
—-a-w 90,112 2006-08-09 15:42:24 C:\WINNT\system32\ActiveScan\pskfss.dll
—-a-w 208,896 2006-07-19 15:55:58 C:\WINNT\system32\ActiveScan\pskhtml.dll
—-a-w 9,728 2006-01-20 21:57:00 C:\WINNT\system32\ActiveScan\pskmas.dll
—-a-w 14,336 2006-05-17 14:50:12 C:\WINNT\system32\ActiveScan\pskmdfs.dll
—-a-w 33,280 2006-08-16 15:58:12 C:\WINNT\system32\ActiveScan\pskpack.dll
—-a-w 266,240 2006-06-30 19:42:36 C:\WINNT\system32\ActiveScan\pskscs.dll
—-a-w 62,976 2006-08-17 19:33:14 C:\WINNT\system32\ActiveScan\pskutil.dll
—-a-w 13,312 2006-08-08 18:13:10 C:\WINNT\system32\ActiveScan\pskvfile.dll
—-a-w 69,632 2006-08-18 13:53:08 C:\WINNT\system32\ActiveScan\pskvfs.dll
—-a-w 167,936 2006-08-18 13:49:50 C:\WINNT\system32\ActiveScan\pskvm.dll
—-a-w 353,840 2007-04-18 22:16:04 C:\WINNT\system32\ActiveScan\psscan.dll
—-a-w 35,328 2007-01-22 19:42:48 C:\WINNT\system32\ActiveScan\rawvfile.dll
—-a-w 9,488 1997-09-18 11:12:32 C:\WINNT\system32\ActiveScan\sporder.dll
—-a-w 69,632 2006-02-28 22:23:40 C:\WINNT\system32\ActiveScan\tcpvfile.dll
—-a-w 262,144 2007-09-06 22:10:30 C:\WINNT\system32\config\systemprofile\ntuser.dat
—-a-w 16,384 2007-09-06 22:14:33 C:\WINNT\system32\config\systemprofile\Cookies\index.dat
—-a-w 32,768 2007-09-06 22:14:33 C:\WINNT\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
—-a-w 32,768 2007-09-06 22:14:33 C:\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

—-a-w 262,144 2007-09-05 15:06:01 C:\WINNT\system32\config\systemprofile\ntuser.dat
—-a-w 16,384 2007-08-18 20:00:00 C:\WINNT\system32\config\systemprofile\Cookies\index.dat
—-a-w 32,768 2007-08-18 20:00:00 C:\WINNT\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
—-a-w 32,768 2007-08-18 20:00:00 C:\WINNT\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINNT\System32\NvCpl.dll" [2004-03-03 11:29]
"Keyboard Preload Check"="C:\OEMDRVRS\KEYB\Preload.exe" []
"PROMon.exe"="PROMon.exe" [2002-04-18 18:32 C:\WINNT\system32\PROMon.exe]
"CTHelper"="CTHELPER.EXE" [2002-07-02 17:56 C:\WINNT\system32\cthelper.exe]
"UpdReg"="C:\WINNT\UpdReg.EXE" []
"Jet Detection"="C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2007-09-05 22:48]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2006-11-18 14:19]
"2wSysTray"="C:\Program Files\2Wire\2PortalMon.exe" [2007-09-05 22:46]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 14:50 C:\WINNT\system32\SK9910DM.EXE]
"NAV Agent"="C:\PROGRA~1\NORTON~1\navapw32.exe" [2007-09-05 22:53]
"iamapp"="C:\Program Files\Norton Internet Security\IAMAPP.EXE" [2007-09-05 22:53]
"NvMediaCenter"="C:\WINNT\System32\NvMcTray.dll" [2004-03-03 11:29]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" []
"ctfmon.exe"="C:\WINNT\System32\ctfmon.exe" [2002-08-29 05:41]
"Uniblue SpyEraser"="C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" [2007-07-24 13:21]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DriverLoad"=
"DriverCheck"=
"SystemDriverLoad"=
"SystemDriver"=
"FDriver"=
"ADriver"=
"CDriver"=
"DDriver"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\\WINNT\\System32\\ddccy

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverCheck]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverLoad]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriverLoad]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvcAudioSrv"=2 (0x2)
"mnmsrvc"=3 (0x3)

R1 cdudf_xp;cdudf_xp;C:\WINNT\System32\drivers\cdudf_xp.sys
R1 pwd_2k;pwd_2k;C:\WINNT\System32\drivers\pwd_2k.sys
R1 Sk9920nt;PS/2 Keyboard Filter Driver for NT 4.0;C:\WINNT\System32\DRIVERS\Sk9920nt.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINNT\System32\drivers\UdfReadr_xp.sys
R2 NISSERV;Norton Internet Security Service;C:\Program Files\Norton Internet Security\NISSERV.EXE
R2 NMSSvc;Intel® NMS;C:\WINNT\System32\NMSSvc.exe
R2 RioPNP;RioPNP;C:\WINNT\System32\drivers\RioPNP.sys
R3 2WIREPCP;2Wire USB;C:\WINNT\System32\DRIVERS\2WirePCP.sys
R3 GTWModem;GTW V.92 Voicemodem;C:\WINNT\System32\DRIVERS\GWMDM.sys
R3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINNT\System32\drivers\NMSCFG.SYS
R3 Sk99202k;PS/2 Keyboard Filter Driver for Win2000;C:\WINNT\System32\DRIVERS\Sk99202k.sys
S3 BCMModem;BCM V.90 56K Modem;C:\WINNT\System32\DRIVERS\BCMDM.sys
S3 dvd_2K;dvd_2K;C:\WINNT\System32\drivers\dvd_2K.sys
S3 mmc_2K;mmc_2K;C:\WINNT\System32\drivers\mmc_2K.sys
S3 PCDRDRV;Pcdr Helper Driver;\??\C:\Atf\Qctest\PCDoc\PCDRDRV.sys
S4 mnmsrvcAudioSrv;NetMeeting Remote Desktop Sharing mnmsrvcAudioSrv;C:\WINNT\System32\2052b.exe srv

*Newly Created Service* - NMSCFG
*Newly Created Service* - NMSSVC
*Newly Created Service* - SYMTDI

Contents of the 'Scheduled Tasks' folder
"2007-09-06 22:15:33 C:\WINNT\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-09-05 03:45:23 C:\WINNT\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-06 17:14:44
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-06 17:16:19 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-09-06 17:16
C:\ComboFix2.txt … 2007-09-05 13:11
C:\ComboFix3.txt … 2007-09-05 10:17

— E O F —


====================================================================


Logfile of HijackThis v1.99.1
Scan saved at 5:22:22 PM, on 9/6/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINNT\System32\PROMon.exe
C:\WINNT\System32\CTHELPER.EXE
C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
C:\WINNT\System32\SK9910DM.EXE
C:\WINNT\System32\RUNDLL32.EXE
C:\WINNT\System32\ctfmon.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsl.sbc.yahoo.com/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [PROMon.exe] PROMon.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINNT\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\System32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O12 - Plugin for .edf: C:\Program Files\Internet Explorer\PLUGINS\NPInfotl.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.historytoday.com/CFIDE/classes/CFJava.cab
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs6b.instantservice.com/jars/customerxsigned32.cab
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {BB5C5554-2B89-4D18-9938-D7EFEDDB2346} (ebcardatl Class) - http://fast.ebrary.com/support/plugins/ebraryReader.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
Hmm, I just found this, looks like it checks hash totals on files to make sure they haven't been replaced by something dangerous.

http://www.runscanner.net/

BTW, my comp is rebooting faster, although it's still slower than I'd like, because of all the stuff that runs at startup. Why can't Windows load crisply out of the box? I'm running a 2 Ghz P4 for God's sake.

Can I just check off those items in HJT and hit FIX to kill them from startup?


Yes, that is how to do it.

Should I just delete all the quarantined stuff that panda complained about? I'd like to run it again once you think I'm clean, and see what pops up, I'd like to see a short list.


Yes…

Sorry but I missed something on the last Combofix script. I'm still working on those skills as that's a new process for me, and many here in the forums. Very powerful as you can see though.

One more time:

Open Notepad and copy/paste the text in the quotebox below into it:

Registry::
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HJT log.

I would actually really like to see a Kaspersky log here but not sure what's going on there as everyone I've had run it in the last few days comes up with the same error, including me on my XP box. My Vista laptop was fine? There's a discussion in one of the classrooms on it but no answers yet.
The startup control window had a bunch of tabs, for run once, run for user, etc, I don't remember them all, I only saw it once.

OK, here are the latest logs:

===============================================================
ComboFix 07-09-05.5 - "Owner" 2007-09-06 18:32:58.4 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.1.1252.1.1033.18.723 [GMT -5:00]
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point


((((((((((((((((((((((((( Files Created from 2007-08-06 to 2007-09-06 )))))))))))))))))))))))))))))))


2007-09-06 10:18 73,728 –a—— C:\WINNT\system32\pv.exe
2007-09-06 10:18 39,184 –a—— C:\WINNT\system32\Ntrights.exe
2007-09-06 10:18 175,616 –a—— C:\WINNT\system32\strings.exe
2007-09-06 10:18 16,384 –a—— C:\WINNT\system32\restart.exe
2007-09-06 10:18 126,976 –a—— C:\WINNT\system32\zip.exe
2007-09-06 10:18 11,254 –a—— C:\WINNT\system32\locate.com
2007-09-05 22:17 d——– C:\WINNT\system32\ActiveScan
2007-09-05 12:18 d——– C:\VundoFix Backups
2007-09-05 10:05 51,200 –a—— C:\WINNT\NirCmd.exe
2007-09-05 09:47 d——– C:\BRIDAL
2007-09-05 00:54 d——– C:\HJT
2007-09-04 23:46 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
2007-09-04 23:46 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\InterVideo
2007-09-04 23:46 d——– C:\DOCUME~1\ADMINI~1\APPLIC~1\InterTrust
2007-09-04 21:11 d——– C:\DOCUME~1\LOCALS~1\APPLIC~1\NetMon
2007-08-20 17:57 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
2007-08-17 00:34 d——– C:\Program Files\Security Task Manager
2007-08-17 00:34 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\SecTaskMan
2007-08-14 11:09 21,760 –a—— C:\WINNT\system32\dllcache\usbstor.sys
2007-08-14 10:27 d——– C:\music library
2007-08-13 23:32 d——– C:\Program Files\Real
2007-08-13 23:27 d——– C:\DOCUME~1\Owner\APPLIC~1\Real
2007-08-13 23:13 d——– C:\Program Files\Best Buy Rhapsody
2007-08-13 22:56 10,368 –a—— C:\WINNT\system32\iviaspi.sys
2007-08-13 22:56 10,368 –a—— C:\WINNT\system32\drivers\_iviaspi.sys
2007-08-13 22:56 d——– C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-13 22:55 d——– C:\Program Files\Sandisk


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-09-06 17:14 ——— d——– C:\Program Files\Norton Internet Security
2007-09-06 17:14 ——— d——– C:\Program Files\Common Files\Symantec Shared
2007-09-05 22:53 ——— d——– C:\Program Files\Norton AntiVirus
2007-08-17 03:15 ——— d——– C:\DOCUME~1\Owner\APPLIC~1\Apple Computer
2007-08-16 20:54 ——— d——– C:\Program Files\Symantec
2007-08-14 08:57 ——— d–h—– C:\Program Files\InstallShield Installation Information
2007-08-13 22:56 ——— d——– C:\Program Files\Common Files\InstallShield
2007-08-13 22:32 ——— d——– C:\Program Files\2Wire


((((((((((((((((((((((((((((( snapshot_2007-09-05_101611.60 )))))))))))))))))))))))))))))))))))))))))

—-a-w 141,424 2006-08-24 13:28:54 C:\WINNT\Downloaded Program Files\asinst.dll
—-a-w 73,728 2006-08-02 17:39:06 C:\WINNT\system32\asuninst.exe
—-a-w 11,776 2003-03-25 23:53:50 C:\WINNT\system32\ZPORT4AS.dll
—-a-w 110,592 2007-03-29 14:20:50 C:\WINNT\system32\ActiveScan\as.dll
—-a-w 233,472 2006-10-05 21:15:26 C:\WINNT\system32\ActiveScan\ascontrol.dll
—-a-w 96,256 2005-06-03 19:03:18 C:\WINNT\system32\ActiveScan\asmdat.dll
—-a-w 36,864 2003-08-01 16:00:16 C:\WINNT\system32\ActiveScan\certdll.dll
—-a-w 86,016 2005-05-20 18:42:44 C:\WINNT\system32\ActiveScan\instlsp.dll
—-a-w 4,608 2006-02-16 23:20:20 C:\WINNT\system32\ActiveScan\memvfile.dll
—-a-w 348,160 2005-10-25 23:08:32 C:\WINNT\system32\ActiveScan\msvcr71.dll
—-a-w 139,264 2004-05-04 20:01:02 C:\WINNT\system32\ActiveScan\pavaleas.dll
—-a-w 45,056 2006-07-14 18:04:10 C:\WINNT\system32\ActiveScan\pavdr.exe
—-a-w 159,832 2006-04-10 15:50:02 C:\WINNT\system32\ActiveScan\pavexcom.dll
—-a-w 94,208 2006-02-14 18:05:38 C:\WINNT\system32\ActiveScan\pavinas.dll
—-a-w 180,224 2006-02-16 23:35:38 C:\WINNT\system32\ActiveScan\pavoe.dll
—-a-w 122,880 2006-10-05 21:15:38 C:\WINNT\system32\ActiveScan\pavpz.dll
—-a-w 8,704 2006-06-30 19:13:38 C:\WINNT\system32\ActiveScan\pfdnnt.exe
—-a-w 49,152 2004-02-04 19:08:42 C:\WINNT\system32\ActiveScan\port32.dll
—-a-w 69,632 2006-08-01 18:23:10 C:\WINNT\system32\ActiveScan\pscpu.dll
—-a-w 1,388,544 2006-08-23 18:06:08 C:\WINNT\system32\ActiveScan\pskahk.dll
—-a-w 10,752 2006-08-17 16:38:14 C:\WINNT\system32\ActiveScan\pskalloc.dll
—-a-w 61,440 2006-09-04 16:49:54 C:\WINNT\system32\ActiveScan\pskas.dll
—-a-w 779,264 2006-08-18 13:46:18 C:\WINNT\system32\ActiveScan\pskavs.dll
—-a-w 417,792 2007-03-26 19:25:34 C:\WINNT\system32\ActiveScan\pskcmp.dll
—-a-w 90,112 2006-08-09 15:42:24 C:\WINNT\system32\ActiveScan\pskfss.dll
—-a-w 208,896 2006-07-19 15:55:58 C:\WINNT\system32\ActiveScan\pskhtml.dll
—-a-w 9,728 2006-01-20 21:57:00 C:\WINNT\system32\ActiveScan\pskmas.dll
—-a-w 14,336 2006-05-17 14:50:12 C:\WINNT\system32\ActiveScan\pskmdfs.dll
—-a-w 33,280 2006-08-16 15:58:12 C:\WINNT\system32\ActiveScan\pskpack.dll
—-a-w 266,240 2006-06-30 19:42:36 C:\WINNT\system32\ActiveScan\pskscs.dll
—-a-w 62,976 2006-08-17 19:33:14 C:\WINNT\system32\ActiveScan\pskutil.dll
—-a-w 13,312 2006-08-08 18:13:10 C:\WINNT\system32\ActiveScan\pskvfile.dll
—-a-w 69,632 2006-08-18 13:53:08 C:\WINNT\system32\ActiveScan\pskvfs.dll
—-a-w 167,936 2006-08-18 13:49:50 C:\WINNT\system32\ActiveScan\pskvm.dll
—-a-w 353,840 2007-04-18 22:16:04 C:\WINNT\system32\ActiveScan\psscan.dll
—-a-w 35,328 2007-01-22 19:42:48 C:\WINNT\system32\ActiveScan\rawvfile.dll
—-a-w 9,488 1997-09-18 11:12:32 C:\WINNT\system32\ActiveScan\sporder.dll
—-a-w 69,632 2006-02-28 22:23:40 C:\WINNT\system32\ActiveScan\tcpvfile.dll
—-a-w 262,144 2007-09-06 22:10:30 C:\WINNT\system32\config\systemprofile\ntuser.dat
—-a-w 16,384 2007-09-06 22:14:33 C:\WINNT\system32\config\systemprofile\Cookies\index.dat
—-a-w 32,768 2007-09-06 22:14:33 C:\WINNT\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

—-a-w 262,144 2007-09-05 15:06:01 C:\WINNT\system32\config\systemprofile\ntuser.dat
—-a-w 16,384 2007-08-18 20:00:00 C:\WINNT\system32\config\systemprofile\Cookies\index.dat
—-a-w 32,768 2007-08-18 20:00:00 C:\WINNT\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINNT\System32\NvCpl.dll" [2004-03-03 11:29]
"Keyboard Preload Check"="C:\OEMDRVRS\KEYB\Preload.exe" []
"PROMon.exe"="PROMon.exe" [2002-04-18 18:32 C:\WINNT\system32\PROMon.exe]
"CTHelper"="CTHELPER.EXE" [2002-07-02 17:56 C:\WINNT\system32\cthelper.exe]
"UpdReg"="C:\WINNT\UpdReg.EXE" []
"Jet Detection"="C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2007-09-05 22:48]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2006-11-18 14:19]
"2wSysTray"="C:\Program Files\2Wire\2PortalMon.exe" [2007-09-05 22:46]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 14:50 C:\WINNT\system32\SK9910DM.EXE]
"NAV Agent"="C:\PROGRA~1\NORTON~1\navapw32.exe" [2007-09-05 22:53]
"iamapp"="C:\Program Files\Norton Internet Security\IAMAPP.EXE" [2007-09-05 22:53]
"NvMediaCenter"="C:\WINNT\System32\NvMcTray.dll" [2004-03-03 11:29]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" []
"ctfmon.exe"="C:\WINNT\System32\ctfmon.exe" [2002-08-29 05:41]
"Uniblue SpyEraser"="C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" [2007-07-24 13:21]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"DriverLoad"=
"DriverCheck"=
"SystemDriverLoad"=
"SystemDriver"=
"FDriver"=
"ADriver"=
"CDriver"=
"DDriver"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ADriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverCheck]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DriverLoad]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriver]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemDriverLoad]


[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"mnmsrvcAudioSrv"=2 (0x2)
"mnmsrvc"=3 (0x3)

R1 cdudf_xp;cdudf_xp;C:\WINNT\System32\drivers\cdudf_xp.sys
R1 pwd_2k;pwd_2k;C:\WINNT\System32\drivers\pwd_2k.sys
R1 Sk9920nt;PS/2 Keyboard Filter Driver for NT 4.0;C:\WINNT\System32\DRIVERS\Sk9920nt.sys
R1 UdfReadr_xp;UdfReadr_xp;C:\WINNT\System32\drivers\UdfReadr_xp.sys
R2 NISSERV;Norton Internet Security Service;C:\Program Files\Norton Internet Security\NISSERV.EXE
R2 NMSSvc;Intel® NMS;C:\WINNT\System32\NMSSvc.exe
R2 RioPNP;RioPNP;C:\WINNT\System32\drivers\RioPNP.sys
R3 2WIREPCP;2Wire USB;C:\WINNT\System32\DRIVERS\2WirePCP.sys
R3 GTWModem;GTW V.92 Voicemodem;C:\WINNT\System32\DRIVERS\GWMDM.sys
R3 NMSCFG;NIC Management Service Configuration Driver;\??\C:\WINNT\System32\drivers\NMSCFG.SYS
R3 Sk99202k;PS/2 Keyboard Filter Driver for Win2000;C:\WINNT\System32\DRIVERS\Sk99202k.sys
S3 BCMModem;BCM V.90 56K Modem;C:\WINNT\System32\DRIVERS\BCMDM.sys
S3 dvd_2K;dvd_2K;C:\WINNT\System32\drivers\dvd_2K.sys
S3 mmc_2K;mmc_2K;C:\WINNT\System32\drivers\mmc_2K.sys
S3 PCDRDRV;Pcdr Helper Driver;\??\C:\Atf\Qctest\PCDoc\PCDRDRV.sys
S4 mnmsrvcAudioSrv;NetMeeting Remote Desktop Sharing mnmsrvcAudioSrv;C:\WINNT\System32\2052b.exe srv

*Newly Created Service* - NMSCFG
*Newly Created Service* - NMSSVC
*Newly Created Service* - SYMTDI

Contents of the 'Scheduled Tasks' folder
"2007-09-06 22:15:33 C:\WINNT\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2007-09-05 03:45:23 C:\WINNT\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-09-06 18:35:22
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-09-06 18:36:05
C:\ComboFix-quarantined-files.txt … 2007-09-06 18:35
C:\ComboFix2.txt … 2007-09-06 17:16
C:\ComboFix3.txt … 2007-09-05 13:11

— E O F —
========================================================================

Logfile of HijackThis v1.99.1
Scan saved at 6:43:47 PM, on 9/6/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINNT\System32\RUNDLL32.EXE
C:\WINNT\System32\ctfmon.exe
C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\WINNT\System32\NMSSvc.exe
C:\WINNT\explorer.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\HJT\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsl.sbc.yahoo.com/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Internet Security\IAMAPP.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\System32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O12 - Plugin for .edf: C:\Program Files\Internet Explorer\PLUGINS\NPInfotl.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB5C5554-2B89-4D18-9938-D7EFEDDB2346} (ebcardatl Class) - http://fast.ebrary.com/support/plugins/ebraryReader.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe
Okay looks good from here…how's she running? I can see you've done some cleaning up too.

If it's running well then that means were at the moment of truth as they say (whoever "they" are).

You need to update to Service Pack 2. I didn't recommend this until now because SP2 does not like to take if there is malware present. But SP2 has many critical security updates, here's my "canned speech" on that.

It is crucial to update to Service Pack 2, it is probably the most important update the Microsoft has ever put out for WinXP and you are extremely vulnerable without it, Service Pack 2 significantly increases the security on your computer. I recommend that you do this update as soon as possible.

Link to Windows Update: http://v5.windowsupdate.microsoft.com

Please update your computer then post back with how it went. If you have any problems please post back with as much detail as you can. This is needed because any problems updating to SP2 could indicate that there is still some infection on your system that we need to address.
Grinding grinding on Windows Update, I had to install 4 updates by hand before it would run on its own. It wanted BITS 2.0 and WinHTTP 5.1 (KB842773), MS Windows Installer 3.1, Windows Genuine Validation Tool (KB892130) and Windows update KB89846 first. However it would tell me it was going to download and isntall them, but that failed over and over, so I ended up downloading them individually from the download site and installing them myself. Now it's cranking through 63 other updates on its own, but I don't know if those are actually SP2, or if they are just other updates I'm missing, and I have to do SP2 after that, or what.
They are probably part of SP2. Just curious, when was the last time you did an update here? When we're done I will remind you in my "prevention" speech to make sure Windows is updated. The easiest way is to set it to run automatically or at least notify you there are updates and then you can look first then initiate them.
Like 4 years since I did an update. After doing those 63, it did 11 more, then 1 more, and now it's ready to do SP2. I need to free up some disk space though, I think it said I need 1.8 gig free, and I don't have it. It's kind of odd, it did SP2 hotfixes without SP2 installed, very wierd, but hey, it's Microsoft, they can do no wrong. Well, tomorrow is another day!
Yay, SP2 is now installed, I have 300 meg of disk space left. I'm going to try to clean up restore points now.

=====================================================================
Logfile of HijackThis v1.99.1
Scan saved at 11:15:39 AM, on 9/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINNT\System32\nvsvc32.exe
C:\Program Files\Norton Internet Security\NISSERV.EXE
C:\Program Files\Norton Internet Security\SymProxySvc.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dsl.sbc.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [Uniblue SpyEraser] "C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" -m
O4 - HKCU\..\RunOnce: [CF1DelUnicows] cmd /C del C:\DOCUME~1\Owner\LOCALS~1\Temp\unicows.dll
O4 - HKCU\..\RunOnce: [CF1DelEXE] cmd /C del C:\DOCUME~1\Owner\LOCALS~1\Temp\Customer-5.3.2.8.exe
O4 - HKCU\..\RunOnce: [CF1DelMsvcr] cmd /C del C:\DOCUME~1\Owner\LOCALS~1\Temp\msvcr71.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .edf: C:\Program Files\Internet Explorer\PLUGINS\NPInfotl.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/wind…b?1189130737875
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1189141398968
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB5C5554-2B89-4D18-9938-D7EFEDDB2346} (ebcardatl Class) - http://fast.ebrary.com/support/plugins/ebraryReader.exe
O20 - Winlogon Notify: WgaLogon - C:\WINNT\SYSTEM32\WgaLogon.dll
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISSERV.EXE
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINNT\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Norton Internet Security Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\SymProxySvc.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI