This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan nebuler

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My experience on the Web always told me to never run an .exe from a download but for some reason I had a brainfart and am now paying for it. I have had several trojans pop up blocked by my Symantec firewall and antivirus. I have ran ATF Cleaner. I have run AVG in Safemode but for some reason it didnt save me a log file. I downloaded SUPERantispyware. Ran this and saved a log file. but as soon as I rebooted it took like an hour to start after several restarts by holding the shutoff on my tower. Then to get it to boot fully I had to set from latest good configuration. All in all the bugs are still here as the computer is slow as hell and I dont dare restart do to the fact that it may not restart. Maybe there is a problem whith my BIOS but I am not sure how to check or repair. I have done defrag last night no luck. heres some logs from SUPERantispyware AND HJT V.2



Super antispyware log.
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 10/21/2007 at 00:49 AM

Application Version : 3.9.1008

Core Rules Database Version : 3328
Trace Rules Database Version: 1329

Scan type : Complete Scan
Total Scan Time : 02:31:47

Memory items scanned : 428
Memory threats detected : 1
Registry items scanned : 7127
Registry threats detected : 10
File items scanned : 145059
File threats detected : 1

Trojan.Unknown Origin/System
C:\WINDOWS\SYSTEM32\WINCQT32.DLL
C:\WINDOWS\SYSTEM32\WINCQT32.DLL

Trojan.Unknown Origin
HKLM\SOFTWARE\Microsoft\MSSMGR
HKLM\SOFTWARE\Microsoft\MSSMGR#Data
HKLM\SOFTWARE\Microsoft\MSSMGR#LSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#Brnd
HKLM\SOFTWARE\Microsoft\MSSMGR#MSLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#BSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#SSTV
HKLM\SOFTWARE\Microsoft\MSSMGR#SCLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#SSLIST
HKLM\SOFTWARE\Microsoft\MSSMGR#PSTV


HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:37:46 PM, on 10/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\GEEKSTOGO\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = LOVE YOU LUCY - YO HUBBY
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://zone.msn.com/bingame/pppp/default/P…rs.1.0.0.39.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169715065435
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\GEEKSTOGO\SASWINLO.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\GEEKSTOGO\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

–
End of file - 12680 bytes
Hello and Welcome to the forum. I suggest you do this: You could try System Restore. 1. Click Start. 2. Point to All Programs. 3. Point to Accessories. 4. Point to System Tools. 5. Click System Restore. 6. Follow the instructions on the wizard. See if you can find a date the the PC worked.
Unable to due so. When running AVG in safe mode I was told to delete all prior restore points. I am still getting dialers from within and slow reboot if at all. In my event viewer I have several Tcpip Warnings from what I see as dialers over loading my Security protocalls. I need help to get rid of these if you can . Thank you.
I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
Ok thank you for trying to help me with this. I ran the Combofix.exe. Here is the log with new Hijackthis log.



COMBOFIX LOG

ComboFix 07-10-26.4 - LUCY 2007-10-25 21:30:49.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1221 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\LUCY\Application Data\inst.exe
C:\Documents and Settings\LUCY\Application Data\macromedia\Flash Player\#SharedObjects\UQGANKNN\www.broadcaster.com
C:\Documents and Settings\LUCY\Application Data\macromedia\Flash Player\#SharedObjects\UQGANKNN\www.broadcaster.com\played_list.sol
C:\Documents and Settings\LUCY\Application Data\macromedia\Flash Player\#SharedObjects\UQGANKNN\www.broadcaster.com\video_queue.sol
C:\Documents and Settings\LUCY\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
C:\Documents and Settings\LUCY\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\winsys.exe

.
((((((((((((((((((((((((( Files Created from 2007-09-26 to 2007-10-26 )))))))))))))))))))))))))))))))
.

2007-10-25 21:29 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-24 20:52 d——– C:\WINDOWS\LastGood
2007-10-23 15:38 d——– C:\Documents and Settings\LUCY\Application Data\MagicBall3
2007-10-22 18:52 110 –a—— C:\Documents and Settings\All Users\Application Data\MostFunGameId.bin
2007-10-21 20:36 d——– C:\Documents and Settings\LUCY\Application Data\Sandlot Games
2007-10-21 20:36 d——– C:\Documents and Settings\All Users\Application Data\Trymedia
2007-10-21 20:29 d——– C:\Program Files\MostFun
2007-10-21 20:29 d——– C:\Documents and Settings\All Users\Application Data\MostFun
2007-10-21 04:04 d——– C:\Program Files\Trend Micro
2007-10-20 22:14 d——– C:\Documents and Settings\LUCY\Application Data\SUPERAntiSpyware.com
2007-10-20 22:14 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-20 14:36 d——– C:\Documents and Settings\Administrator.RITTERBY-1VCO1Z\Application Data\Grisoft
2007-10-20 14:16 d——– C:\Documents and Settings\LUCY\Application Data\Grisoft
2007-10-20 14:11 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-20 14:11 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-17 22:12 d——– C:\Program Files\Microsoft Bootvis
2007-10-17 16:25 d——– C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-10-16 20:52 d——– C:\Program Files\SystemRequirementsLab
2007-10-16 20:25 66,048 –a–c— C:\WINDOWS\system32\dllcache\s3legacy.dll
2007-10-14 23:12 2,320,000 –a—— C:\WINDOWS\system32\TUKernel.exe
2007-10-14 19:57 d–h—– C:\WINDOWS\Icons
2007-10-14 19:46 25,160 –a—— C:\WINDOWS\system32\drivers\ElbyCDIO.sys
2007-10-13 12:16 d——– C:\Program Files\Real
2007-10-13 12:16 d——– C:\Program Files\Common Files\xing shared
2007-10-13 12:15 d——– C:\Program Files\Common Files\Real
2007-10-11 23:51 d——– C:\Program Files\Activision
2007-10-11 09:27 96,832 –a—— C:\WINDOWS\system32\drivers\AnyDVD.sys
2007-10-10 20:00 d——– C:\WINDOWS\system32\PhotoImpression Slideshow
2007-10-09 22:26 d——– C:\Documents and Settings\LUCY\Application Data\iScreensaver
2007-10-08 01:00 28,672 –a—— C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-10-08 00:12 d——– C:\Program Files\TuneUp Utilities 2007
2007-10-08 00:12 29,704 –a—— C:\WINDOWS\system32\uxtuneup.dll
2007-10-07 18:42 d——– C:\EPSONREG
2007-10-07 18:42 d——– C:\Documents and Settings\LUCY\Application Data\Leadertech
2007-10-07 18:38 d——– C:\Documents and Settings\LUCY\Application Data\ArcSoft
2007-10-07 18:38 11,776 –a—— C:\WINDOWS\system32\drivers\afc.sys
2007-10-07 18:37 d——– C:\Program Files\EPSON Print CD
2007-10-07 18:37 d——– C:\Program Files\Common Files\ArcSoft
2007-10-07 18:37 d——– C:\Program Files\ArcSoft
2007-10-07 18:37 258,352 –a—— C:\WINDOWS\system32\unicows.dll
2007-10-07 18:37 212,480 –a—— C:\WINDOWS\PCDLIB32.DLL
2007-10-07 18:37 126,976 –a—— C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2007-10-07 18:36 d——– C:\Documents and Settings\All Users\Application Data\EPSON
2007-10-07 18:34 d——– C:\Documents and Settings\LUCY\Application Data\InstallShield
2007-10-07 18:33 d——– C:\Program Files\epson
2007-10-07 18:33 67,072 –a—— C:\WINDOWS\system32\escwiad.dll
2007-10-06 12:28 d——– C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-10-03 15:04 d——– C:\Program Files\iTunes
2007-10-03 15:04 d——– C:\Program Files\iPod
2007-09-30 19:44 d——– C:\Presets
2007-09-30 19:29 d——– C:\Program Files\Trapcode
2007-09-29 23:03 59,264 –a—— C:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-09-29 23:03 59,264 –a–c— C:\WINDOWS\system32\dllcache\usbaudio.sys
2007-09-29 18:40 d——– C:\Documents and Settings\LUCY\Application Data\PlayFirst

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-22 03:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2007-10-21 05:13 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-20 18:59 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Skype
2007-10-18 23:44 ——— d—–w C:\Program Files\Easy CD-DA Extractor 10
2007-10-18 23:40 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-18 22:47 ——— d—–w C:\Documents and Settings\LUCY\Application Data\LimeWire
2007-10-18 02:45 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-10-18 00:34 ——— d—–w C:\Documents and Settings\LUCY\Application Data\VersionTracker Pro
2007-10-17 23:37 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-10-17 23:37 103,736 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-10-17 23:33 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Xfire
2007-10-17 23:23 ——— d—–w C:\Program Files\Java
2007-10-17 23:09 ——— d—–w C:\Program Files\Microsoft Silverlight
2007-10-15 06:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-10-12 06:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-12 06:16 ——— d—–w C:\Documents and Settings\LUCY\Application Data\teamspeak2
2007-10-08 05:32 ——— d—–w C:\Program Files\Google
2007-10-07 18:31 ——— d—–w C:\Program Files\MSN Games
2007-09-26 05:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-09-23 09:46 ——— d—–w C:\Program Files\Pinnacle
2007-09-19 16:53 ——— d—–w C:\Program Files\QuickTime
2007-09-19 16:51 ——— d—–w C:\Program Files\Common Files\Apple
2007-09-19 16:50 ——— d—–w C:\Program Files\Apple Software Update
2007-09-19 16:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-17 08:07 81,920 —-a-w C:\WINDOWS\system32\nvwddi.dll
2007-09-17 08:07 81,920 —-a-w C:\WINDOWS\system32\nvmctray.dll
2007-09-17 08:07 8,491,008 —-a-w C:\WINDOWS\system32\nvcpl.dll
2007-09-17 08:07 753,664 —-a-w C:\WINDOWS\system32\nvcplui.exe
2007-09-17 08:07 6,853,088 —-a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-09-17 08:07 6,746,112 —-a-w C:\WINDOWS\system32\nvoglnt.dll
2007-09-17 08:07 6,344,704 —-a-w C:\WINDOWS\system32\nvdisps.dll
2007-09-17 08:07 5,783,040 —-a-w C:\WINDOWS\system32\nv4_disp.dll
2007-09-17 08:07 466,944 —-a-w C:\WINDOWS\system32\nvshell.dll
2007-09-17 08:07 45,056 —-a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-09-17 08:07 442,368 —-a-w C:\WINDOWS\system32\nvappbar.exe
2007-09-17 08:07 425,984 —-a-w C:\WINDOWS\system32\keystone.exe
2007-09-17 08:07 364,544 —-a-w C:\WINDOWS\system32\nvapi.dll
2007-09-17 08:07 36,864 —-a-w C:\WINDOWS\system32\nvcodins.dll
2007-09-17 08:07 36,864 —-a-w C:\WINDOWS\system32\nvcod.dll
2007-09-17 08:07 307,200 —-a-w C:\WINDOWS\system32\nvexpbar.dll
2007-09-17 08:07 3,551,232 —-a-w C:\WINDOWS\system32\nvvitvs.dll
2007-09-17 08:07 3,334,144 —-a-w C:\WINDOWS\system32\nvgames.dll
2007-09-17 08:07 286,720 —-a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-09-17 08:07 229,376 —-a-w C:\WINDOWS\system32\nvmccs.dll
2007-09-17 08:07 2,371,584 —-a-w C:\WINDOWS\system32\nvwss.dll
2007-09-17 08:07 188,416 —-a-w C:\WINDOWS\system32\nvmccss.dll
2007-09-17 08:07 155,716 —-a-w C:\WINDOWS\system32\nvsvc32.exe
2007-09-17 08:07 147,456 —-a-w C:\WINDOWS\system32\nvcolor.exe
2007-09-17 08:07 1,703,936 —-a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-09-17 08:07 1,626,112 —-a-w C:\WINDOWS\system32\nwiz.exe
2007-09-17 08:07 1,478,656 —-a-w C:\WINDOWS\system32\nview.dll
2007-09-17 08:07 1,339,392 —-a-w C:\WINDOWS\system32\nvdspsch.exe
2007-09-17 08:07 1,150,976 —-a-w C:\WINDOWS\system32\nvmobls.dll
2007-09-17 08:07 1,019,904 —-a-w C:\WINDOWS\system32\nvwimg.dll
2007-09-14 13:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-09-14 13:34 ——— d—–w C:\Program Files\Common Files\Adobe
2007-09-14 13:32 ——— d—–w C:\Program Files\Common Files\Control Panels
2007-09-14 13:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\ALM
2007-09-14 12:49 ——— d—–w C:\Program Files\Bonjour
2007-09-14 12:42 ——— d—–w C:\Program Files\Common Files\Macrovision Shared
2007-09-14 07:43 ——— d—–w C:\Documents and Settings\LUCY\Application Data\GetRightToGo
2007-09-14 06:49 ——— d—–w C:\Program Files\VSO
2007-09-14 06:49 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Vso
2007-09-12 06:27 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Xfire
2007-09-09 13:24 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-09-09 07:06 ——— d—–w C:\Program Files\Windows Live
2007-09-09 07:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
2007-09-09 01:22 ——— d—–w C:\Program Files\TechTracker
2007-09-08 06:20 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Sony
2007-09-08 00:57 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Publish Providers
2007-09-08 00:52 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-09-04 17:46 ——— d—–w C:\Program Files\MTV Networks
2007-08-30 13:33 9,464 ——w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-08-30 13:33 9,336 ——w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-08-30 13:33 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-08-30 13:33 129,784 ——w C:\WINDOWS\system32\pxafs.dll
2007-08-30 13:33 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-08-30 13:33 118,056 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-16 23:17 51,568 —-a-w C:\WINDOWS\system32\sirenacm.dll
2007-08-10 19:56 93,128 —-a-w C:\WINDOWS\system32\ElbyCDIO.dll
2007-07-31 02:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 02:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 02:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 02:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 02:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 02:19 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-07-31 02:19 207,736 —-a-w C:\WINDOWS\system32\muweb.dll
2007-07-31 02:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 02:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 02:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-06-03 19:27 87,608 -c–a-w C:\Documents and Settings\LUCY\Application Data\ezpinst.exe
2007-06-03 19:27 47,360 -c–a-w C:\Documents and Settings\LUCY\Application Data\pcouffin.sys
2007-05-08 06:05 35,352 -c–a-w C:\Documents and Settings\LUCY\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" [2006-06-15 01:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 17:14]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-10-13 12:15]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

C:\Documents and Settings\LUCY\Start Menu\Programs\Startup\
MostFun.lnk - C:\Program Files\MostFun\Bin\MostFun.exe [2007-08-28 17:47:20]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\GEEKSTOGO\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\GEEKSTOGO\SASWINLO.dll 2007-04-19 13:41 294912 D:\GEEKSTOGO\SASWINLO.dll


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AnyDVD"=C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"EPSON Stylus Photo RX595 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICLA.EXE /FU "C:\WINDOWS\TEMP\E_SCB.tmp" /EF "HKCU"
"SUPERAntiSpyware"=D:\GEEKSTOGO\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"nwiz"=nwiz.exe /install
"SoundMan"=SOUNDMAN.EXE
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"Adobe_ID0EYTHM"=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"Adobe Photo Downloader"="C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"!AVG Anti-Spyware"="D:\GEEKSTOGO\AVG Anti-Spyware 7.5\avgas.exe" /minimized

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 Intels51;Creatix V.9X DSP Data Fax Modem;C:\WINDOWS\system32\DRIVERS\ctxs51.sys
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - CATCHME
*Newly Created Service* - WMIAPSRV
.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 03:41:12 C:\WINDOWS\Tasks\1-Click Maintenance.job"
"2007-10-24 16:02:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-25 21:34:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-25 21:35:37
.



HIJACKTHIS LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:41:55 PM, on 10/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\GEEKSTOGO\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kodak\Kodak Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MostFun\bin\MostFun.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - Startup: MostFun.lnk = C:\Program Files\MostFun\Bin\MostFun.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://zone.msn.com/bingame/pppp/default/P…rs.1.0.0.39.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169715065435
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\GEEKSTOGO\SASWINLO.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\GEEKSTOGO\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

–
End of file - 12884 bytes
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\WINDOWS\system32\TUKernel.exe


Save this as CFScript.txt


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log.
Also please "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
OK. Here are the logs you needed. I will now attempt to reboot and see if it does. hopefully I will be back on. Havent shut this thing off in a week. Since it took almost an hour to reboot the last time. I had to go to last good config. to get it to work before. I will post a reply to this as soon as I get it rebooted. Thank you . I will be here all day to work on this . Thanks again dude.

COMBOFIX

ComboFix 07-10-26.4 - LUCY 2007-10-26 10:08:10.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1371 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\LUCY\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-09-26 to 2007-10-26 )))))))))))))))))))))))))))))))
.

2007-10-26 01:06 d——– C:\Program Files\Easy CD-DA Extractor 10
2007-10-26 00:04 d——– C:\Program Files\TuneUp Utilities 2007
2007-10-26 00:04 29,704 –a—— C:\WINDOWS\system32\uxtuneup.dll
2007-10-25 21:29 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-24 20:52 d——– C:\WINDOWS\LastGood
2007-10-23 15:38 d——– C:\Documents and Settings\LUCY\Application Data\MagicBall3
2007-10-22 18:52 110 –a—— C:\Documents and Settings\All Users\Application Data\MostFunGameId.bin
2007-10-21 20:36 d——– C:\Documents and Settings\LUCY\Application Data\Sandlot Games
2007-10-21 20:36 d——– C:\Documents and Settings\All Users\Application Data\Trymedia
2007-10-21 20:29 d——– C:\Program Files\MostFun
2007-10-21 20:29 d——– C:\Documents and Settings\All Users\Application Data\MostFun
2007-10-21 04:04 d——– C:\Program Files\Trend Micro
2007-10-20 22:14 d——– C:\Documents and Settings\LUCY\Application Data\SUPERAntiSpyware.com
2007-10-20 22:14 d——– C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-10-20 14:36 d——– C:\Documents and Settings\Administrator.RITTERBY-1VCO1Z\Application Data\Grisoft
2007-10-20 14:16 d——– C:\Documents and Settings\LUCY\Application Data\Grisoft
2007-10-20 14:11 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-20 14:11 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-17 22:12 d——– C:\Program Files\Microsoft Bootvis
2007-10-17 16:25 d——– C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-10-16 20:52 d——– C:\Program Files\SystemRequirementsLab
2007-10-16 20:25 66,048 –a–c— C:\WINDOWS\system32\dllcache\s3legacy.dll
2007-10-14 23:12 2,320,000 –a—— C:\WINDOWS\system32\TUKernel.exe
2007-10-14 19:57 d–h—– C:\WINDOWS\Icons
2007-10-14 19:46 25,160 –a—— C:\WINDOWS\system32\drivers\ElbyCDIO.sys
2007-10-13 12:16 d——– C:\Program Files\Real
2007-10-13 12:16 d——– C:\Program Files\Common Files\xing shared
2007-10-13 12:15 d——– C:\Program Files\Common Files\Real
2007-10-11 23:51 d——– C:\Program Files\Activision
2007-10-11 09:27 96,832 –a—— C:\WINDOWS\system32\drivers\AnyDVD.sys
2007-10-10 20:00 d——– C:\WINDOWS\system32\PhotoImpression Slideshow
2007-10-09 22:26 d——– C:\Documents and Settings\LUCY\Application Data\iScreensaver
2007-10-08 01:00 28,672 –a—— C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-10-07 18:42 d——– C:\EPSONREG
2007-10-07 18:42 d——– C:\Documents and Settings\LUCY\Application Data\Leadertech
2007-10-07 18:38 d——– C:\Documents and Settings\LUCY\Application Data\ArcSoft
2007-10-07 18:38 11,776 –a—— C:\WINDOWS\system32\drivers\afc.sys
2007-10-07 18:37 d——– C:\Program Files\EPSON Print CD
2007-10-07 18:37 d——– C:\Program Files\Common Files\ArcSoft
2007-10-07 18:37 d——– C:\Program Files\ArcSoft
2007-10-07 18:37 258,352 –a—— C:\WINDOWS\system32\unicows.dll
2007-10-07 18:37 212,480 –a—— C:\WINDOWS\PCDLIB32.DLL
2007-10-07 18:37 126,976 –a—— C:\WINDOWS\system32\PhotoImpression Slideshow.scr
2007-10-07 18:36 d——– C:\Documents and Settings\All Users\Application Data\EPSON
2007-10-07 18:34 d——– C:\Documents and Settings\LUCY\Application Data\InstallShield
2007-10-07 18:33 d——– C:\Program Files\epson
2007-10-07 18:33 67,072 –a—— C:\WINDOWS\system32\escwiad.dll
2007-10-06 12:28 d——– C:\Documents and Settings\All Users\Application Data\PlayFirst
2007-10-03 15:04 d——– C:\Program Files\iTunes
2007-10-03 15:04 d——– C:\Program Files\iPod
2007-09-30 19:44 d——– C:\Presets
2007-09-30 19:29 d——– C:\Program Files\Trapcode
2007-09-29 23:03 59,264 –a—— C:\WINDOWS\system32\drivers\USBAUDIO.sys
2007-09-29 23:03 59,264 –a–c— C:\WINDOWS\system32\dllcache\usbaudio.sys
2007-09-29 18:40 d——– C:\Documents and Settings\LUCY\Application Data\PlayFirst

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-26 08:09 ——— d—a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-26 07:56 ——— d—–w C:\Documents and Settings\LUCY\Application Data\LimeWire
2007-10-26 07:04 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2007-10-26 07:03 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Xfire
2007-10-22 03:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2007-10-20 18:59 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Skype
2007-10-18 02:45 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-10-18 00:34 ——— d—–w C:\Documents and Settings\LUCY\Application Data\VersionTracker Pro
2007-10-17 23:37 22,328 —-a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2007-10-17 23:37 103,736 —-a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-10-17 23:23 ——— d—–w C:\Program Files\Java
2007-10-17 23:09 ——— d—–w C:\Program Files\Microsoft Silverlight
2007-10-15 06:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\1Click DVD Copy
2007-10-12 06:53 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-12 06:16 ——— d—–w C:\Documents and Settings\LUCY\Application Data\teamspeak2
2007-10-08 05:32 ——— d—–w C:\Program Files\Google
2007-10-07 18:31 ——— d—–w C:\Program Files\MSN Games
2007-09-26 05:30 ——— d—–w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-09-23 09:46 ——— d—–w C:\Program Files\Pinnacle
2007-09-19 16:53 ——— d—–w C:\Program Files\QuickTime
2007-09-19 16:51 ——— d—–w C:\Program Files\Common Files\Apple
2007-09-19 16:50 ——— d—–w C:\Program Files\Apple Software Update
2007-09-19 16:50 ——— d—–w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-17 08:07 81,920 —-a-w C:\WINDOWS\system32\nvwddi.dll
2007-09-17 08:07 81,920 —-a-w C:\WINDOWS\system32\nvmctray.dll
2007-09-17 08:07 8,491,008 —-a-w C:\WINDOWS\system32\nvcpl.dll
2007-09-17 08:07 753,664 —-a-w C:\WINDOWS\system32\nvcplui.exe
2007-09-17 08:07 6,853,088 —-a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-09-17 08:07 6,746,112 —-a-w C:\WINDOWS\system32\nvoglnt.dll
2007-09-17 08:07 6,344,704 —-a-w C:\WINDOWS\system32\nvdisps.dll
2007-09-17 08:07 5,783,040 —-a-w C:\WINDOWS\system32\nv4_disp.dll
2007-09-17 08:07 466,944 —-a-w C:\WINDOWS\system32\nvshell.dll
2007-09-17 08:07 45,056 —-a-w C:\WINDOWS\system32\nvmccsrs.dll
2007-09-17 08:07 442,368 —-a-w C:\WINDOWS\system32\nvappbar.exe
2007-09-17 08:07 425,984 —-a-w C:\WINDOWS\system32\keystone.exe
2007-09-17 08:07 364,544 —-a-w C:\WINDOWS\system32\nvapi.dll
2007-09-17 08:07 36,864 —-a-w C:\WINDOWS\system32\nvcodins.dll
2007-09-17 08:07 36,864 —-a-w C:\WINDOWS\system32\nvcod.dll
2007-09-17 08:07 307,200 —-a-w C:\WINDOWS\system32\nvexpbar.dll
2007-09-17 08:07 3,551,232 —-a-w C:\WINDOWS\system32\nvvitvs.dll
2007-09-17 08:07 3,334,144 —-a-w C:\WINDOWS\system32\nvgames.dll
2007-09-17 08:07 286,720 —-a-w C:\WINDOWS\system32\nvnt4cpl.dll
2007-09-17 08:07 229,376 —-a-w C:\WINDOWS\system32\nvmccs.dll
2007-09-17 08:07 2,371,584 —-a-w C:\WINDOWS\system32\nvwss.dll
2007-09-17 08:07 188,416 —-a-w C:\WINDOWS\system32\nvmccss.dll
2007-09-17 08:07 155,716 —-a-w C:\WINDOWS\system32\nvsvc32.exe
2007-09-17 08:07 147,456 —-a-w C:\WINDOWS\system32\nvcolor.exe
2007-09-17 08:07 1,703,936 —-a-w C:\WINDOWS\system32\nvwdmcpl.dll
2007-09-17 08:07 1,626,112 —-a-w C:\WINDOWS\system32\nwiz.exe
2007-09-17 08:07 1,478,656 —-a-w C:\WINDOWS\system32\nview.dll
2007-09-17 08:07 1,339,392 —-a-w C:\WINDOWS\system32\nvdspsch.exe
2007-09-17 08:07 1,150,976 —-a-w C:\WINDOWS\system32\nvmobls.dll
2007-09-17 08:07 1,019,904 —-a-w C:\WINDOWS\system32\nvwimg.dll
2007-09-14 13:35 ——— d—–w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-09-14 13:34 ——— d—–w C:\Program Files\Common Files\Adobe
2007-09-14 13:32 ——— d—–w C:\Program Files\Common Files\Control Panels
2007-09-14 13:29 ——— d—–w C:\Documents and Settings\All Users\Application Data\ALM
2007-09-14 12:49 ——— d—–w C:\Program Files\Bonjour
2007-09-14 12:42 ——— d—–w C:\Program Files\Common Files\Macrovision Shared
2007-09-14 07:43 ——— d—–w C:\Documents and Settings\LUCY\Application Data\GetRightToGo
2007-09-14 06:49 ——— d—–w C:\Program Files\VSO
2007-09-14 06:49 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Vso
2007-09-12 06:27 ——— d—–w C:\Documents and Settings\LocalService\Application Data\Xfire
2007-09-09 13:24 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-09-09 07:06 ——— d—–w C:\Program Files\Windows Live
2007-09-09 07:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\WindowsLiveInstaller
2007-09-09 01:22 ——— d—–w C:\Program Files\TechTracker
2007-09-08 06:20 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Sony
2007-09-08 00:57 ——— d—–w C:\Documents and Settings\LUCY\Application Data\Publish Providers
2007-09-08 00:52 ——— d—–w C:\Program Files\Microsoft SQL Server
2007-09-04 17:46 ——— d—–w C:\Program Files\MTV Networks
2007-08-30 13:33 9,464 ——w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-08-30 13:33 9,336 ——w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-08-30 13:33 43,528 ——w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-08-30 13:33 129,784 ——w C:\WINDOWS\system32\pxafs.dll
2007-08-30 13:33 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-08-30 13:33 118,056 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-16 23:17 51,568 —-a-w C:\WINDOWS\system32\sirenacm.dll
2007-08-10 19:56 93,128 —-a-w C:\WINDOWS\system32\ElbyCDIO.dll
2007-07-31 02:19 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-07-31 02:19 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-07-31 02:19 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-31 02:19 43,352 —-a-w C:\WINDOWS\system32\wups2.dll
2007-07-31 02:19 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-07-31 02:19 271,224 —-a-w C:\WINDOWS\system32\mucltui.dll
2007-07-31 02:19 207,736 —-a-w C:\WINDOWS\system32\muweb.dll
2007-07-31 02:19 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-07-31 02:19 1,712,984 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-31 02:18 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-06-03 19:27 87,608 -c–a-w C:\Documents and Settings\LUCY\Application Data\ezpinst.exe
2007-06-03 19:27 47,360 -c–a-w C:\Documents and Settings\LUCY\Application Data\pcouffin.sys
2007-05-08 06:05 35,352 -c–a-w C:\Documents and Settings\LUCY\Application Data\GDIPFONTCACHEV1.DAT
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" [2006-06-15 01:40]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 06:24]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-24 17:14]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"=1 (0x1)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= D:\GEEKSTOGO\SASSEH.DLL [2006-12-20 13:55 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
D:\GEEKSTOGO\SASWINLO.dll 2007-04-19 13:41 294912 D:\GEEKSTOGO\SASWINLO.dll


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"AnyDVD"=C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"MySpaceIM"=C:\Program Files\MySpace\IM\MySpaceIM.exe
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"EPSON Stylus Photo RX595 Series"=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICLA.EXE /FU "C:\WINDOWS\TEMP\E_SCB.tmp" /EF "HKCU"
"SUPERAntiSpyware"=D:\GEEKSTOGO\SUPERAntiSpyware.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"nwiz"=nwiz.exe /install
"SoundMan"=SOUNDMAN.EXE
"IntelliPoint"="c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"NvMediaCenter"=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
"NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
"Adobe_ID0EYTHM"=C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
"Adobe Photo Downloader"="C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.2\apdproxy.exe"
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
"!AVG Anti-Spyware"="D:\GEEKSTOGO\AVG Anti-Spyware 7.5\avgas.exe" /minimized

R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 Intels51;Creatix V.9X DSP Data Fax Modem;C:\WINDOWS\system32\DRIVERS\ctxs51.sys
R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp

*Newly Created Service* - CATCHME
*Newly Created Service* - UXTUNEUP
*Newly Created Service* - WMIAPSRV
.
Contents of the 'Scheduled Tasks' folder
"2007-10-26 07:04:49 C:\WINDOWS\Tasks\1-Click Maintenance.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-10-24 16:02:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************

catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-26 10:12:02
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-26 10:13:33
C:\ComboFix2.txt … 2007-10-25 21:35
.
— E O F —

HJT LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:19:46 AM, on 10/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\GEEKSTOGO\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kodak\Kodak Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://zone.msn.com/bingame/pppp/default/P…rs.1.0.0.39.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1169715065435
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - D:\GEEKSTOGO\SASWINLO.dll
O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\GEEKSTOGO\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSSQL$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SQLAgent$SONY_MEDIAMGR - Unknown owner - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (file missing)
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

–
End of file - 12554 bytes
WOW That was a long reboot. OK just as before my computer hangs at shut down for about 1 minute . Then at screen that says pentium 4 inside. (splashscreen I think) it hangs then stops. So I have to hold restart button for 10 sec. then try again. Same thing hangs then nothing. I do it again. Then I get past that screen and then it stalls at a black screen with cursor bottom left. Do it again then hit F8 and it gets to screen where I select start windows with last good config.. then it goes to load bar screen. Then hangs at black screen for several minutes. before loading up Windows. Very very slow process. takes me about 15 to 20 min. to get it all done. SCARY. it used to be so fast. I am lost. Any ideas. Thank you for your help thus far. Geoff
I have seen other posts with reboot problems but within them is says the settings are case sensitive do not attempt these or something like that until a TEAM member says to do so. so I havent.
1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
AVG Anti-Spyware 7.5

Lets get some of the ones that don't need to run at startup.
The 016's will come back if you ever visit that site again.

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…p1.0.0.15-3.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {49E67060-2C0D-415E-94C7-52A49F73B2F1} (CPlayFirstPiratePoppersControl Object) - http://zone.msn.com/bingame/pppp/default/P…rs.1.0.0.39.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://www.maricopa.gov/assessor/gis/plugin/mgaxctrl.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab

Close ALL windows and browsers except HijackThis and click "Fix checked"

Reboot and see how it goes.
Well I did what you said this time I let it run through without stalling total time to reboot was at 15 min. Also I think the problem started when I moved my pc and added the new printer. if this helps at all. I read that a bios problem might be at fault to reset to default settings. in these forums. but cannot access BIOS for some reason there is a password protecteing them. I have never set a password so I have no clue. sorry to see ya go but I will be waiting

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI