This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Nasty Trojan-New Hijack This

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

New Combofix log

ComboFix 07-11-08.1 - Rich 2007-11-17 14:51:59.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.203 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2007-10-17 to 2007-11-17 )))))))))))))))))))))))))))))))
.

2007-11-17 11:05 6,058,496 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2007-11-17 11:05 2,455,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dat
2007-11-17 11:05 459,264 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2007-11-17 11:05 383,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2007-11-17 11:05 267,776 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2007-11-17 11:05 63,488 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2007-11-17 11:05 52,224 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2007-11-17 11:05 13,824 ——— C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-11-17 10:44 452,640 –ahs—- C:\WINDOWS\SYSTEM32\DRIVERS\fidbox.dat
2007-11-17 10:41 d——– C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-11-17 10:40 d——– C:\WINDOWS\Internet Logs
2007-11-17 08:45 d——– C:\WINDOWS\SYSTEM32\Kaspersky Lab
2007-11-17 08:45 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-11-15 07:31 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-11-14 17:49 d——– C:\Program Files\Trend Micro
2007-11-04 20:00 d——– C:\Documents and Settings\Rich\Application Data\ArcSoft
2007-11-04 19:48 d——– C:\Program Files\Common Files\ArcSoft
2007-11-04 19:48 d——– C:\Program Files\ArcSoft
2007-11-04 19:48 245,408 –a—— C:\WINDOWS\SYSTEM32\unicows.dll
2007-11-04 19:47 d——– C:\Program Files\Common Files\snpstd3
2007-11-04 19:47 d——– C:\Documents and Settings\Rich\Application Data\InstallShield
2007-11-04 19:47 10,180,096 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\snpstd3.sys
2007-11-04 19:47 843,776 –a—— C:\WINDOWS\vsnpstd3.exe
2007-11-04 19:47 262,144 –a—— C:\WINDOWS\tsnpstd3.exe
2007-11-04 19:47 147,456 –a—— C:\WINDOWS\SYSTEM32\rsnpstd3.dll
2007-11-04 19:47 94,208 –a—— C:\WINDOWS\amcap.exe
2007-11-04 19:47 53,248 –a—— C:\WINDOWS\SYSTEM32\csnpstd3.dll
2007-11-04 19:47 53,248 –a—— C:\WINDOWS\csnpstd3.dll
2007-11-04 19:18 85,376 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\NABTSFEC.sys
2007-11-04 19:18 85,376 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\nabtsfec.sys
2007-11-04 19:18 53,760 –a—— C:\WINDOWS\SYSTEM32\vfwwdm32.dll
2007-11-04 19:18 53,760 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\vfwwdm32.dll
2007-11-04 19:18 17,024 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\CCDECODE.sys
2007-11-04 19:18 17,024 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\ccdecode.sys
2007-11-04 19:13 59,264 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\USBAUDIO.sys
2007-11-04 19:13 59,264 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usbaudio.sys
2007-11-04 19:13 31,616 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\usbccgp.sys
2007-11-04 19:13 31,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usbccgp.sys
2007-11-02 18:59 d——– C:\WINDOWS\SYSTEM32\NtmsData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 19:44 5,996 –sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-17 19:11 ——— d—–w C:\Program Files\Java
2007-11-05 06:16 ——— d—–w C:\Documents and Settings\Rich\Application Data\Skype
2007-11-05 03:48 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-25 17:05 94,416 —-a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-25 17:05 93,264 —-a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-10-25 17:03 23,152 —-a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-10-25 17:01 42,912 —-a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-10-25 16:58 26,624 —-a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-10-25 16:24 815,480 —-a-w C:\WINDOWS\SYSTEM32\aswBoot.exe
2007-10-25 16:14 95,608 —-a-w C:\WINDOWS\SYSTEM32\AVASTSS.scr
2007-09-30 06:02 ——— d—–w C:\Program Files\Allied General
2007-09-07 00:14 75,248 —-a-w C:\WINDOWS\zllsputility.exe
2007-09-07 00:14 1,086,952 —-a-w C:\WINDOWS\SYSTEM32\zpeng24.dll
2007-08-22 13:12 474,112 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shlwapi.dll
2007-08-22 13:12 151,040 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\cdfview.dll
2007-08-22 13:12 1,494,528 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shdocvw.dll
2007-08-22 13:12 1,054,208 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\danim.dll
2007-08-22 13:12 1,022,976 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\browseui.dll
2007-08-21 06:15 683,520 —-a-w C:\WINDOWS\SYSTEM32\inetcomm.dll
2007-08-21 06:15 683,520 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\inetcomm.dll
2007-08-20 23:34 3,584,512 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-08-20 10:04 824,832 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-08-20 10:04 671,232 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-08-20 10:04 477,696 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-08-20 10:04 44,544 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
2007-08-20 10:04 384,512 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
2007-08-20 10:04 27,648 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-08-20 10:04 232,960 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
2007-08-20 10:04 230,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
2007-08-20 10:04 214,528 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-08-20 10:04 193,024 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-08-20 10:04 153,088 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
2007-08-20 10:04 132,608 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-08-20 10:04 124,928 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
2007-08-20 10:04 105,984 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
2007-08-20 10:04 102,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
2007-08-20 10:04 1,152,000 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-08-17 10:21 625,152 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2007-08-17 10:20 63,488 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2007-08-17 07:34 161,792 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
1998-08-24 19:09 10,000 ——w C:\WINDOWS\INF\unregpn.exe
2005-09-08 20:14:17 176,422 –sha-w C:\WINDOWS\SYSTEM32\prqss.bak1
2005-09-24 17:47:41 423,822 –sha-w C:\WINDOWS\SYSTEM32\prqss.bak2
2005-09-24 20:11:22 423,583 –sha-w C:\WINDOWS\SYSTEM32\prqss.ini2
.

((((((((((((((((((((((((((((( snapshot@2007-11-15_ 7.54.38.68 )))))))))))))))))))))))))))))))))))))))))
.
- 2006-12-19 21:52:18 8,453,632 -c—-w C:\WINDOWS\$NtUninstallKB943460$\shell32.dll
- 2007-08-21 10:20:02 115,712 -c—-w C:\WINDOWS\$NtUninstallKB943460$\xpsp3res.dll
+ 2004-08-04 11:00:00 61,440 -c–a-w C:\WINDOWS\ie7\admparse.dll
+ 2004-08-04 11:00:00 99,840 -c–a-w C:\WINDOWS\ie7\advpack.dll
+ 2004-08-04 11:00:00 35,328 -c–a-w C:\WINDOWS\ie7\corpol.dll
+ 2006-06-03 11:40:49 33,792 -c–a-w C:\WINDOWS\ie7\custsat.dll
+ 2007-08-22 13:12:16 357,888 -c–a-w C:\WINDOWS\ie7\dxtmsft.dll
+ 2007-08-22 13:12:16 205,312 -c–a-w C:\WINDOWS\ie7\dxtrans.dll
+ 2007-08-22 13:12:16 55,808 -c–a-w C:\WINDOWS\ie7\extmgr.dll
+ 2004-08-04 11:00:00 38,912 -c–a-w C:\WINDOWS\ie7\hmmapi.dll
+ 2004-08-04 11:00:00 34,304 -c–a-w C:\WINDOWS\ie7\ie4uinit.exe
+ 2004-08-04 11:00:00 139,264 -c–a-w C:\WINDOWS\ie7\ieakeng.dll
+ 2004-08-04 11:00:00 216,576 -c–a-w C:\WINDOWS\ie7\ieaksie.dll
+ 2004-08-04 11:00:00 221,184 -c–a-w C:\WINDOWS\ie7\ieakui.dll
+ 2004-08-04 11:00:00 323,584 -c–a-w C:\WINDOWS\ie7\iedkcs32.dll
+ 2007-08-21 10:30:45 18,432 -c–a-w C:\WINDOWS\ie7\iedw.exe
+ 2004-08-04 11:00:00 81,920 -c–a-w C:\WINDOWS\ie7\ieencode.dll
+ 2007-08-22 13:12:16 251,392 -c–a-w C:\WINDOWS\ie7\iepeers.dll
+ 2004-08-04 11:00:00 48,640 -c–a-w C:\WINDOWS\ie7\iernonce.dll
+ 2004-08-04 11:00:00 62,976 -c–a-w C:\WINDOWS\ie7\iesetup.dll
+ 2004-08-04 11:00:00 93,184 -c–a-w C:\WINDOWS\ie7\iexplore.exe
+ 2004-08-04 11:00:00 35,840 -c–a-w C:\WINDOWS\ie7\imgutil.dll
+ 2007-08-22 13:12:16 96,256 -c–a-w C:\WINDOWS\ie7\inseng.dll
+ 2006-05-18 05:24:25 450,560 -c–a-w C:\WINDOWS\ie7\jscript.dll
+ 2007-08-22 13:12:16 16,384 -c–a-w C:\WINDOWS\ie7\jsproxy.dll
+ 2004-08-04 11:00:00 22,016 -c–a-w C:\WINDOWS\ie7\licmgr10.dll
+ 2004-08-04 11:00:00 29,184 -c–a-w C:\WINDOWS\ie7\mshta.exe
+ 2007-08-22 13:12:17 3,058,176 -c–a-w C:\WINDOWS\ie7\mshtml.dll
+ 2007-08-22 13:12:17 449,024 -c–a-w C:\WINDOWS\ie7\mshtmled.dll
+ 2004-08-04 11:00:00 56,832 -c–a-w C:\WINDOWS\ie7\mshtmler.dll
+ 2004-08-04 11:00:00 146,432 -c–a-w C:\WINDOWS\ie7\msls31.dll
+ 2007-08-22 13:12:17 146,432 -c–a-w C:\WINDOWS\ie7\msrating.dll
+ 2007-08-22 13:12:17 532,480 -c–a-w C:\WINDOWS\ie7\mstime.dll
+ 2004-08-04 11:00:00 96,256 -c–a-w C:\WINDOWS\ie7\occache.dll
+ 2007-08-22 13:12:17 39,424 -c–a-w C:\WINDOWS\ie7\pngfilt.dll
+ 2007-08-14 02:54:42 32,960 -c–a-w C:\WINDOWS\ie7\spuninst\iecustom.dll
+ 2007-08-14 02:52:06 66,048 -c–a-w C:\WINDOWS\ie7\spuninst\ieResetIcons.exe
+ 2006-09-07 01:43:16 213,216 -c–a-w C:\WINDOWS\ie7\spuninst\spuninst.exe
+ 2006-09-07 01:43:18 371,424 -c–a-w C:\WINDOWS\ie7\spuninst\updspapi.dll
+ 2004-08-04 11:00:00 37,888 -c–a-w C:\WINDOWS\ie7\url.dll
+ 2007-08-22 13:12:18 615,424 -c–a-w C:\WINDOWS\ie7\urlmon.dll
+ 2004-08-04 11:00:00 417,792 -c–a-w C:\WINDOWS\ie7\vbscript.dll
+ 2007-06-26 15:13:22 851,968 -c–a-w C:\WINDOWS\ie7\vgx.dll
+ 2004-08-04 11:00:00 276,480 -c–a-w C:\WINDOWS\ie7\webcheck.dll
+ 2007-08-22 13:12:18 658,944 -c–a-w C:\WINDOWS\ie7\wininet.dll
+ 2007-08-14 02:39:00 123,904 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\advpack.dll
+ 2007-08-14 02:35:38 214,528 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\dxtrans.dll
+ 2007-08-14 02:54:10 131,584 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\extmgr.dll
+ 2007-08-14 02:36:26 61,952 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\icardie.dll
+ 2007-08-14 02:39:06 54,784 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ie4uinit.exe
+ 2007-08-14 02:39:26 152,064 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakeng.dll
+ 2007-08-14 02:39:54 229,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieaksie.dll
+ 2007-08-14 01:56:54 161,792 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieakui.dll
+ 2007-02-13 00:10:12 2,451,312 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dat
+ 2007-07-11 20:27:48 383,488 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieapfltr.dll
+ 2007-08-14 02:39:50 382,976 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iedkcs32.dll
+ 2007-08-14 02:54:10 6,049,280 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieframe.dll
+ 2007-08-14 02:39:10 43,008 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iernonce.dll
+ 2007-08-14 02:34:04 266,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iertutil.dll
+ 2007-08-14 02:39:10 13,312 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\ieudinit.exe
+ 2007-08-14 02:43:56 622,080 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\iexplore.exe
+ 2007-08-14 02:54:10 27,136 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\jsproxy.dll
+ 2007-08-14 02:54:10 458,752 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeeds.dll
+ 2007-08-14 02:54:10 50,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msfeedsbs.dll
+ 2007-08-14 02:54:12 3,578,368 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtml.dll
+ 2007-08-14 02:54:10 475,648 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mshtmled.dll
+ 2007-08-14 02:44:26 192,000 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\msrating.dll
+ 2007-08-14 02:54:10 670,720 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\mstime.dll
+ 2007-08-14 02:44:06 101,376 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\occache.dll
+ 2007-03-06 01:22:39 213,216 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\updspapi.dll
+ 2007-08-14 02:44:30 105,984 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\url.dll
+ 2007-08-14 02:54:10 1,162,240 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\urlmon.dll
+ 2007-08-14 02:54:10 231,424 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\webcheck.dll
+ 2007-08-14 02:54:10 818,688 -c—-w C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll
+ 2006-06-03 11:40:49 33,792 ——w C:\WINDOWS\network diagnostic\custsat.dll
+ 2006-10-10 12:44:50 557,568 ——w C:\WINDOWS\network diagnostic\xpnetdiag.exe
- 2004-08-04 11:00:00 61,440 —-a-w C:\WINDOWS\SYSTEM32\admparse.dll
+ 2007-08-14 02:39:20 71,680 —-a-w C:\WINDOWS\SYSTEM32\admparse.dll
- 2004-08-04 11:00:00 99,840 —-a-w C:\WINDOWS\SYSTEM32\advpack.dll
+ 2007-08-20 10:04:34 124,928 —-a-w C:\WINDOWS\SYSTEM32\advpack.dll
- 2004-08-04 11:00:00 61,440 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\admparse.dll
+ 2007-08-14 02:39:20 71,680 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\admparse.dll
- 2005-01-28 21:44:28 28,672 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
+ 2007-08-14 02:54:10 33,792 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\custsat.dll
- 2007-08-22 13:12:16 357,888 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
+ 2007-08-14 02:35:46 346,624 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtmsft.dll
- 2004-08-04 11:00:00 38,912 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\hmmapi.dll
+ 2007-08-14 02:18:02 60,416 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\hmmapi.dll
- 2007-08-21 10:30:45 18,432 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
+ 2007-08-14 02:44:02 69,120 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iedw.exe
- 2004-08-04 11:00:00 81,920 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\ieencode.dll
+ 2007-08-14 02:45:18 78,336 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\ieencode.dll
- 2007-08-22 13:12:16 251,392 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iepeers.dll
+ 2007-08-14 02:54:10 191,488 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iepeers.dll
- 2004-08-04 11:00:00 62,976 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iesetup.dll
+ 2007-08-14 02:39:12 55,296 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\iesetup.dll
- 2004-08-04 11:00:00 35,840 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\imgutil.dll
+ 2007-08-14 02:36:06 36,352 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\imgutil.dll
- 2007-08-22 13:12:16 96,256 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\inseng.dll
+ 2007-08-14 02:39:02 92,672 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\inseng.dll
- 2006-05-18 05:24:25 450,560 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll
+ 2007-08-14 02:38:04 491,520 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jscript.dll
- 2004-08-04 11:00:00 22,016 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\licmgr10.dll
+ 2007-08-14 02:44:18 40,960 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\licmgr10.dll
- 2004-08-04 11:00:00 29,184 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshta.exe
+ 2007-08-14 02:32:30 45,568 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshta.exe
- 2004-08-04 11:00:00 56,832 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmler.dll
+ 2007-08-14 02:01:12 48,128 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmler.dll
- 2004-08-04 11:00:00 146,432 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msls31.dll
+ 2007-08-14 02:54:10 156,160 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msls31.dll
- 2007-08-22 13:12:17 39,424 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
+ 2007-08-14 02:36:12 44,544 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\pngfilt.dll
- 2004-08-04 11:00:00 417,792 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\vbscript.dll
+ 2007-08-14 02:54:10 413,696 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\vbscript.dll
- 2007-06-26 15:13:22 851,968 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\vgx.dll
+ 2007-08-14 02:54:10 765,952 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\VGX.dll
+ 2007-07-19 23:10:28 127,768 —-a-w C:\WINDOWS\SYSTEM32\DRIVERS\klif.sys
- 2007-08-22 13:12:16 357,888 —-a-w C:\WINDOWS\SYSTEM32\dxtmsft.dll
+ 2007-08-14 02:35:46 346,624 —-a-w C:\WINDOWS\SYSTEM32\dxtmsft.dll
- 2007-08-22 13:12:16 205,312 —-a-w C:\WINDOWS\SYSTEM32\dxtrans.dll
+ 2007-08-20 10:04:34 214,528 ——w C:\WINDOWS\SYSTEM32\dxtrans.dll
- 2007-08-22 13:12:16 55,808 —-a-w C:\WINDOWS\SYSTEM32\extmgr.dll
+ 2007-08-20 10:04:34 132,608 ——w C:\WINDOWS\SYSTEM32\extmgr.dll
+ 2007-08-20 10:04:34 63,488 —-a-w C:\WINDOWS\SYSTEM32\icardie.dll
+ 2006-06-29 16:05:44 26,112 ——w C:\WINDOWS\SYSTEM32\idndl.dll
- 2004-08-04 11:00:00 34,304 —-a-w C:\WINDOWS\SYSTEM32\ie4uinit.exe
+ 2007-08-17 10:20:54 63,488 ——w C:\WINDOWS\SYSTEM32\ie4uinit.exe
- 2004-08-04 11:00:00 139,264 —-a-w C:\WINDOWS\SYSTEM32\ieakeng.dll
+ 2007-08-20 10:04:34 153,088 ——w C:\WINDOWS\SYSTEM32\ieakeng.dll
- 2004-08-04 11:00:00 216,576 —-a-w C:\WINDOWS\SYSTEM32\ieaksie.dll
+ 2007-08-20 10:04:35 230,400 ——w C:\WINDOWS\SYSTEM32\ieaksie.dll
- 2004-08-04 11:00:00 221,184 —-a-w C:\WINDOWS\SYSTEM32\ieakui.dll
+ 2007-08-17 07:34:25 161,792 ——w C:\WINDOWS\SYSTEM32\ieakui.dll
+ 2007-04-17 09:32:38 2,455,488 —-a-w C:\WINDOWS\SYSTEM32\ieapfltr.dat
+ 2007-08-20 10:04:35 383,488 —-a-w C:\WINDOWS\SYSTEM32\ieapfltr.dll
- 2004-08-04 11:00:00 323,584 —-a-w C:\WINDOWS\SYSTEM32\iedkcs32.dll
+ 2007-08-20 10:04:35 384,512 ——w C:\WINDOWS\SYSTEM32\iedkcs32.dll
- 2004-08-04 11:00:00 81,920 —-a-w C:\WINDOWS\SYSTEM32\ieencode.dll
+ 2007-08-14 02:45:18 78,336 —-a-w C:\WINDOWS\SYSTEM32\ieencode.dll
+ 2007-08-20 10:04:37 6,058,496 —-a-w C:\WINDOWS\SYSTEM32\ieframe.dll
- 2007-08-22 13:12:16 251,392 —-a-w C:\WINDOWS\SYSTEM32\iepeers.dll
+ 2007-08-14 02:54:10 191,488 —-a-w C:\WINDOWS\SYSTEM32\iepeers.dll
- 2004-08-04 11:00:00 48,640 —-a-w C:\WINDOWS\SYSTEM32\iernonce.dll
+ 2007-08-20 10:04:38 44,544 ——w C:\WINDOWS\SYSTEM32\iernonce.dll
+ 2007-08-20 10:04:38 267,776 —-a-w C:\WINDOWS\SYSTEM32\iertutil.dll
- 2004-08-04 11:00:00 62,976 —-a-w C:\WINDOWS\SYSTEM32\iesetup.dll
+ 2007-08-14 02:39:12 55,296 —-a-w C:\WINDOWS\SYSTEM32\iesetup.dll
+ 2007-08-17 10:20:54 13,824 —-a-w C:\WINDOWS\SYSTEM32\ieudinit.exe
+ 2007-08-14 02:54:10 180,736 ——w C:\WINDOWS\SYSTEM32\ieui.dll
- 2004-08-04 11:00:00 35,840 —-a-w C:\WINDOWS\SYSTEM32\imgutil.dll
+ 2007-08-14 02:36:06 36,352 —-a-w C:\WINDOWS\SYSTEM32\imgutil.dll
- 2007-08-22 13:12:16 96,256 —-a-w C:\WINDOWS\SYSTEM32\inseng.dll
+ 2007-08-14 02:39:02 92,672 —-a-w C:\WINDOWS\SYSTEM32\inseng.dll
- 2003-11-19 22:36:26 24,681 —-a-w C:\WINDOWS\SYSTEM32\java.exe
+ 2007-09-25 06:30:28 135,168 —-a-w C:\WINDOWS\SYSTEM32\java.exe
- 2003-11-19 22:36:30 28,779 —-a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2007-09-25 06:30:30 135,168 —-a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2007-09-25 07:31:42 139,264 —-a-w C:\WINDOWS\SYSTEM32\javaws.exe
- 2006-05-18 05:24:25 450,560 —-a-w C:\WINDOWS\SYSTEM32\jscript.dll
+ 2007-08-14 02:38:04 491,520 —-a-w C:\WINDOWS\SYSTEM32\jscript.dll
- 2007-08-22 13:12:16 16,384 —-a-w C:\WINDOWS\SYSTEM32\jsproxy.dll
+ 2007-08-20 10:04:39 27,648 ——w C:\WINDOWS\SYSTEM32\jsproxy.dll
+ 2005-05-24 20:27:16 213,048 —-a-w C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 23:47:20 94,208 —-a-w C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 23:49:54 950,272 —-a-w C:\WINDOWS\SYSTEM32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
+ 2007-09-07 00:13:58 796,048 —-a-w C:\WINDOWS\SYSTEM32\libeay32_0.9.6l.dll
- 2004-08-04 11:00:00 22,016 —-a-w C:\WINDOWS\SYSTEM32\licmgr10.dll
+ 2007-08-14 02:44:18 40,960 —-a-w C:\WINDOWS\SYSTEM32\licmgr10.dll
+ 2007-08-20 10:04:39 459,264 —-a-w C:\WINDOWS\SYSTEM32\msfeeds.dll
+ 2007-08-20 10:04:39 52,224 —-a-w C:\WINDOWS\SYSTEM32\msfeedsbs.dll
+ 2007-08-14 02:36:40 12,288 ——w C:\WINDOWS\SYSTEM32\msfeedssync.exe
- 2004-08-04 11:00:00 29,184 —-a-w C:\WINDOWS\SYSTEM32\mshta.exe
+ 2007-08-14 02:32:30 45,568 —-a-w C:\WINDOWS\SYSTEM32\mshta.exe
- 2007-08-22 13:12:17 3,058,176 —-a-w C:\WINDOWS\SYSTEM32\mshtml.dll
+ 2007-08-20 23:34:42 3,584,512 —-a-w C:\WINDOWS\SYSTEM32\mshtml.dll
- 2007-08-22 13:12:17 449,024 —-a-w C:\WINDOWS\SYSTEM32\mshtmled.dll
+ 2007-08-20 10:04:41 477,696 ——w C:\WINDOWS\SYSTEM32\mshtmled.dll
- 2004-08-04 11:00:00 56,832 —-a-w C:\WINDOWS\SYSTEM32\mshtmler.dll
+ 2007-08-14 02:01:12 48,128 —-a-w C:\WINDOWS\SYSTEM32\mshtmler.dll
- 2004-08-04 11:00:00 146,432 —-a-w C:\WINDOWS\SYSTEM32\msls31.dll
+ 2007-08-14 02:54:10 156,160 —-a-w C:\WINDOWS\SYSTEM32\msls31.dll
- 2007-08-22 13:12:17 146,432 —-a-w C:\WINDOWS\SYSTEM32\msrating.dll
+ 2007-08-20 10:04:41 193,024 ——w C:\WINDOWS\SYSTEM32\msrating.dll
- 2007-08-22 13:12:17 532,480 —-a-w C:\WINDOWS\SYSTEM32\mstime.dll
+ 2007-08-20 10:04:42 671,232 ——w C:\WINDOWS\SYSTEM32\mstime.dll
+ 2006-06-29 01:59:26 24,576 ——w C:\WINDOWS\SYSTEM32\nlsdl.dll
+ 2006-06-29 16:05:44 23,552 ——w C:\WINDOWS\SYSTEM32\normaliz.dll
- 2004-08-04 11:00:00 96,256 —-a-w C:\WINDOWS\SYSTEM32\occache.dll
+ 2007-08-20 10:04:42 102,400 —-a-w C:\WINDOWS\SYSTEM32\occache.dll
- 2007-08-22 13:12:17 39,424 —-a-w C:\WINDOWS\SYSTEM32\pngfilt.dll
+ 2007-08-14 02:36:12 44,544 —-a-w C:\WINDOWS\SYSTEM32\pngfilt.dll
- 2007-10-26 03:36:51 8,454,656 —-a-w C:\WINDOWS\SYSTEM32\shell32.dll
+ 2007-10-26 03:34:01 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\shell32.dll
- 2005-06-28 17:21:34 22,752 —-a-w C:\WINDOWS\SYSTEM32\spupdsvc.exe
+ 2006-09-07 01:43:16 22,752 —-a-w C:\WINDOWS\SYSTEM32\spupdsvc.exe
- 2004-08-04 11:00:00 37,888 —-a-w C:\WINDOWS\SYSTEM32\url.dll
+ 2007-08-20 10:04:42 105,984 —-a-w C:\WINDOWS\SYSTEM32\url.dll
- 2007-08-22 13:12:18 615,424 —-a-w C:\WINDOWS\SYSTEM32\urlmon.dll
+ 2007-08-20 10:04:42 1,152,000 —-a-w C:\WINDOWS\SYSTEM32\urlmon.dll
- 2004-08-04 11:00:00 417,792 —-a-w C:\WINDOWS\SYSTEM32\vbscript.dll
+ 2007-08-14 02:54:10 413,696 —-a-w C:\WINDOWS\SYSTEM32\vbscript.dll
+ 2007-09-07 00:14:04 83,432 —-a-w C:\WINDOWS\SYSTEM32\vsdata.dll
+ 2007-09-07 00:14:28 395,080 —-a-w C:\WINDOWS\SYSTEM32\vsdatant.sys
+ 2007-09-07 00:14:04 157,160 —-a-w C:\WINDOWS\SYSTEM32\vsinit.dll
+ 2007-09-07 00:14:04 103,912 —-a-w C:\WINDOWS\SYSTEM32\vsmonapi.dll
+ 2007-09-07 00:14:04 275,944 —-a-w C:\WINDOWS\SYSTEM32\vspubapi.dll
+ 2007-09-07 00:14:04 71,144 —-a-w C:\WINDOWS\SYSTEM32\vsregexp.dll
+ 2007-09-07 00:14:06 472,552 —-a-w C:\WINDOWS\SYSTEM32\vsutil.dll
+ 2007-09-07 00:14:06 46,568 —-a-w C:\WINDOWS\SYSTEM32\vswmi.dll
+ 2007-09-07 00:14:06 99,816 —-a-w C:\WINDOWS\SYSTEM32\vsxml.dll
- 2004-08-04 11:00:00 276,480 —-a-w C:\WINDOWS\SYSTEM32\webcheck.dll
+ 2007-08-20 10:04:42 232,960 —-a-w C:\WINDOWS\SYSTEM32\webcheck.dll
+ 2007-08-14 02:45:16 206,336 ——w C:\WINDOWS\SYSTEM32\WinFXDocObj.exe
- 2007-08-22 13:12:18 658,944 —-a-w C:\WINDOWS\SYSTEM32\wininet.dll
+ 2007-08-20 10:04:43 824,832 —-a-w C:\WINDOWS\SYSTEM32\wininet.dll
- 2006-03-28 03:27:56 117,760 —-a-w C:\WINDOWS\SYSTEM32\xmllite.dll
+ 2006-07-14 15:52:22 121,856 —-a-w C:\WINDOWS\SYSTEM32\xmllite.dll
- 2007-10-29 10:26:53 115,712 —-a-w C:\WINDOWS\SYSTEM32\xpsp3res.dll
+ 2007-10-29 10:04:03 350,720 —-a-w C:\WINDOWS\SYSTEM32\xpsp3res.dll
+ 2007-09-07 00:14:06 83,432 —-a-w C:\WINDOWS\SYSTEM32\zlcomm.dll
+ 2007-09-07 00:14:08 71,144 —-a-w C:\WINDOWS\SYSTEM32\zlcommdb.dll
+ 2007-11-17 18:43:06 4,212 —h–w C:\WINDOWS\SYSTEM32\zllictbl.dat
+ 2007-09-07 00:13:56 370,208 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\av.dll
+ 2007-05-31 08:03:30 65,248 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\bases\aphish.dat
+ 2006-06-30 22:47:36 21,568 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\bases\avcmhk4.dll
+ 2007-05-31 08:03:16 77,824 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\CKAHComm.dll
+ 2007-05-31 08:03:16 110,592 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\CKAHrule.dll
+ 2007-05-31 08:03:16 331,776 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\CKAHUM.dll
+ 2007-05-31 08:03:16 38,400 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\FSSync.dll
+ 2007-07-19 23:10:32 110,360 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\instdrivers\w2kxp32\kl1.sys
+ 2007-07-19 23:10:32 186,128 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\instdrivers\w2kxp32\klif.sys
+ 2007-05-31 08:03:48 110,360 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\instdrivers\x32\kl1.sys
+ 2007-07-19 23:10:28 127,768 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\instdrivers\x32\klif.sys
+ 2007-05-31 08:03:50 45,056 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\instdrivers\x32\regcat.exe
+ 2006-09-20 07:12:14 208,960 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\inv.dll
+ 2007-08-25 03:31:48 274,432 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\kave.dll
+ 2006-12-20 02:13:52 1,093,632 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\libeay32.dll
+ 2007-05-31 08:03:20 548,864 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\msvcp80.dll
+ 2007-05-31 08:03:20 626,688 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\msvcr80.dll
+ 2007-05-31 08:03:18 184,320 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\prloader.dll
+ 2007-05-31 08:03:22 90,112 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\prremote.dll
+ 2007-08-25 03:31:48 135,168 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\ScanningProcess.exe
+ 2006-12-20 02:13:52 200,704 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\avsys\ssleay32.dll
+ 2007-09-07 00:13:56 99,816 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\camupd.dll
+ 2004-01-30 20:35:08 813,568 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\dbghelp.dll
+ 2007-09-07 00:13:58 128,480 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\fbl.dll
+ 2007-09-07 00:13:58 38,376 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\featuremap.dll
+ 2007-09-07 00:13:58 321,016 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\imsecure.dll
+ 2007-09-07 00:14:30 288,144 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\ConfigWizard.zip.dll
+ 2007-09-07 00:14:30 152,976 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\licenseui.zip.dll
+ 2007-09-07 00:14:30 26,000 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\zlsvc.zip.dll
+ 2007-09-07 00:14:32 1,361,296 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\zpy.zip.dll
+ 2007-09-07 00:14:32 71,056 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\lib\zui.zip.dll
+ 2007-09-07 00:15:50 30,184 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\plugins\rpc_server\rpc_server.dll
+ 2007-09-07 00:15:52 30,216 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\plugins\vsmon_plugin\vsmon_plugin.dll
+ 2007-08-15 23:45:42 714,208 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\qrbase.dll
+ 2007-08-15 23:45:44 787,936 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\qrsrecl.dll
+ 2007-09-07 00:14:00 173,544 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\scheduler.dll
+ 2007-01-11 19:12:08 2,432,259 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\spyware.dat
+ 2007-08-15 23:45:44 1,500,640 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\srescan.dll
+ 2007-06-11 20:44:10 50,416 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\srescan.sys
+ 2007-09-07 00:14:02 456,168 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\ssleay32.dll
+ 2007-09-07 00:15:52 214,528 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\streamapi\httpblocker\httpblocker.dll
+ 2007-09-07 00:15:54 3,266,040 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\streamapi\imslsp\imslsp.dll
+ 2006-09-05 04:59:14 503,875 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\upd_core.dll
+ 2007-08-01 14:30:04 833,248 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\updating.dll
+ 2007-09-07 00:14:18 149,032 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\updclient.exe
+ 2007-01-12 01:31:06 286,787 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\updtrsdk.dll
+ 2007-09-07 00:14:04 108,008 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsavpro.dll
+ 2007-09-07 00:14:04 79,336 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsdb.dll
+ 2007-09-07 00:14:18 75,304 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
+ 2007-09-07 00:14:04 2,024,936 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsmondll.dll
+ 2007-09-07 00:14:06 1,345,000 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsruledb.dll
+ 2007-09-07 00:14:06 239,080 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\vsvault.dll
+ 2007-01-11 19:12:08 2,432,259 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlasdbup.dat
+ 2007-09-07 00:14:08 177,640 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlparser.dll
+ 2007-09-07 00:14:08 79,344 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlquarantine.dll
+ 2007-09-07 00:14:08 382,440 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlsre.dll
+ 2007-09-07 00:14:08 120,296 —-a-w C:\WINDOWS\SYSTEM32\ZoneLabs\zlupdate.dll
+ 2007-11-17 19:45:21 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_77c.dat
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-28 23:43]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 18:12]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 14:54]
"UpdateManager"="C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" [2004-01-06 23:01]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-05 23:05]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2005-04-10 15:51]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-10-25 08:20]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 17:44]
"nwiz"="nwiz.exe" [2007-06-28 23:43 C:\WINDOWS\SYSTEM32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-28 23:43]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-09-06 16:14]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 08:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-09 08:00]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 04:05:56]


.
Contents of the 'Scheduled Tasks' folder
"2007-11-08 00:26:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-11-03 03:16:30 C:\WINDOWS\Tasks\Weekly Backupset.job"
- C:\WINDOWS\system32\ntbackup.exe
.
**************************************************************************

catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 14:54:53
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-11-17 14:56:04
C:\ComboFix2.txt … 2007-11-16 07:57
C:\ComboFix3.txt … 2007-11-15 07:56
.
— E O F —
latest HJT log

Logfile of HijackThis v1.99.1
Scan saved at 3:06:48 PM, on 11/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\FredFlintstone.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…99/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1110436232357
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…576/mcfscan.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

Thanks!

Rich
OK, latest logs look good. How's your computer behaving now?

I'd like you to do a little something for me.

I'm still not exactly sure what caused you to have the Password problem, so I'd like to have a look at one of your Registry keys.
  • Click Start > Run type Notepad click OK.
  • This will open an empty Notepad file.
  • Copy/Paste the contents of the box below into Notepad.
@ echo off

reg query "HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa" >> "%userprofile%"\Desktop\look.txt

Notepad.exe %userprofile%\Desktop\look.txt
  • Click Format and ensure Wordwrap is unchecked.
  • Save as RegExp.bat
  • Save as file type All Files or it won't work.
  • Now double click on RegExp.bat to run it.
  • A file look.txt will open on your Desktop, please post the contents in your next reply.
Hi Gary, the PC is functioning normally now. I think I finally understand why people buy Macs or use Linux after going through all this. ! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages REG_MULTI_SZ msv1_0\ Bounds REG_BINARY 0030000000200000 Security Packages REG_MULTI_SZ kerberosmsv1_0schannelwdigest\ ImpersonatePrivilegeUpgradeToolHasRun REG_DWORD 0x1 LsaPid REG_DWORD 0x2e0 SecureBoot REG_DWORD 0x1 auditbaseobjects REG_DWORD 0x0 crashonauditfail REG_DWORD 0x0 disabledomaincreds REG_DWORD 0x0 everyoneincludesanonymous REG_DWORD 0x0 fipsalgorithmpolicy REG_DWORD 0x0 forceguest REG_DWORD 0x1 fullprivilegeauditing REG_BINARY 00 limitblankpassworduse REG_DWORD 0x1 lmcompatibilitylevel REG_DWORD 0x0 nodefaultadminowner REG_DWORD 0x1 nolmhash REG_DWORD 0x0 restrictanonymous REG_DWORD 0x0 restrictanonymoussam REG_DWORD 0x1 Notification Packages REG_MULTI_SZ scecli\ enabledcom REG_SZ y HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\AccessProviders HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Audit HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Data HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\GBG HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\JD HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Kerberos HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\msv1_0 HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\Skew1 HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SSO HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\SspiCache Thanks, Rich
Hi Rich,

OK, the key looks good.

Let's clear out the programmes we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately. Besides they're updated regularly so won't be of any use against future infections
  • Double click OTMoveIt.exe to launch the programme.
  • Click on the CleanUp! button.
  • OTMoveIt will download a list from the Internet, if your firewall or other defensive programmes alerts you, allow it access.
  • You will be prompted to allow the clean up procedure, click Yes
  • When finished exit out of OTMoveIt
  • Now delete OTMoveIt.exe (if present).
Delete CFScript.txt please.

You can delete or keep FileFind as you wish, it's a handy little utility at times.

As far as I can see, your computer looks clear of infection now.

Are you still noticing any problems ?
  • If you are let me know about them.
  • If not it's time to make your computer more secure.
Below are a series of recommendations which will help you keep more secure online.

Obviously you have already taken care of some of the issues mentioned, but it is important that you read through them, and address any that you may have missed.

THESE STEPS ARE VERY IMPORTANT

Lets reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which according to your Kaspesky scan are infected (they can't re-infect you unless you do a restore, but best clean them out now). Please note you need Administrator Access to clean the restore points.
  • Turn off System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Check Turn off System Restore.
    • Click Apply, and then click OK.
  • Reboot.
  • Turn ON System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • UN-Check *Turn off System Restore*.
    • Click Apply, and then click OK.
  • NOTE: only do this once, NOT on a regular basis.
Update your Java.
Older versions have vulnerabilities that malware can and are using to infect systems.

Please follow these steps to remove older version Java components. This is important as it's still possible to get infected through an old install even if you're using the latest version of Java.
  • Close any programmes you may have running, ESPECIALLY your web browser
  • Click Start > Control Panel.
  • Click Add/Remove Programs.
  • Check any item with Java Runtime Environment (JRE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove all versions of Java.
  • Reboot your computer once all Java components are removed.
Download the latest version of Java Runtime Environment (JRE) 6u3, and install it to your computer.

Updating Windows and Internet Explorer
It is essential you keep your Operating System up to date with all the latest patches. The bad guys watch for the latest exploits, as soon as Microsoft brings out a patch, the bad guys will bring out an infection to exploit that vulnerability. If you don't have all the latest patches your computer is vulnerable. Please go to the windows update site and get the critical updates.

Use a "secure" browser
Install Internet Explorer 7 or an alternative browser like Firefox or Opera for more secure surfing.
Please remember that there is no such thing as a totally secure browser. Your browsing habits will be the major factor in determining just how safe you are online. If you visit, Crack/Warez sites, Porn sites, or other sites of a questionable nature, you still run a severe risk of getting infected.

The following are free programs that are designed to keep your computer clean. A brief description is included with each item, click on name to go to download site.
  • Adaware SE Personal
    Adaware is a free program. It scans for known spyware on your computer. These scans should be run at least once every two weeks. For more information, see this tutorial
  • Spybot S & D
    Spybot is a scanner like Adaware. It scans for spyware and other malicious programs. It is important to have both Adaware and Spybot on your computer because each program provides unique detection and protection measures. Spybot has preventitive tools that stop programs from even installing on your computer.
    To see how to set this up as well as more spybot features, see here
  • SpywareBlaster
    Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes "kill bits" in the registry, so that certain activex controls can't install.
    If you don't know what activex controls are, see here
  • IE Spyad
    It puts many bad webpages on your restricted zones LIST. This means that you can still view the "bad" webpages, but the webpages can't do certain things (such as use javascripts and cookies). Use IE Spyad for single account computers, and IE Spyad 2 for multi account computers.
  • Hosts file:
  • Make sure you read the instructions on how to install the hosts file, here.
    • Every version of windows has a hosts file as part of them.
    • In a very basic sense, they are used to locate webpages.
    • We can customize a hosts file so that it blocks certain webpages.
    • However, it can slow down certain computers.
  • If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
    • Click the start button (at the lower left hand corner of your screen)
    • Click run
    • In the dialog box, type services.msc
    • hit enter, then locate dns client
    • Highlight it, then double-click it.
    • On the dropdown box, change the setting from automatic to manual.
    • Click ok
  • Use an Anti Virus Software - It's very important that your computer has an anti-virus software running. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - LIST of free Anti virus programs
  • Use a Firewall - I cannot stress enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
    See here to choose one.
  • Site Advisor This is a utility that can be downloaded and installed. It loads an icon to the taskbar of your browser (versions for IE and Firefox), indicating the trustworthiness of the site you are on. Green for safe, Red for suspicious. Click on the icon to access details that SiteAdvisor has about the site.
Here's links to a few articles which are well worth reading Finally

NOW is the time you can start to hit back at the people who infected you.
[external image: Posted Image]
Please take the time to go and complain - that forum has a topic for your infection which is Vundo…….. (if not, post in the Is your infection not listed here? topic). Please post as a reply, you do not need to register to do so (but you can if you wish). It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to government or government agencies that something will get done.

Hi Gary, I followed your instructions and the computer is running fine.

I could not find CFScript.txt to delete.

I followed all the steps you suggested.

I really appreciate all the time you and the other volunteers on this forum take to help with these problems.

I've attached a final hjt log just in case you wanted to see it.

Logfile of HijackThis v1.99.1
Scan saved at 11:12:34 AM, on 11/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Hijackthis\FredFlintstone.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…99/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1110436232357
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.mcafee.com/products/protected/mvt/mvt.cab
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/…576/mcfscan.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Thanks again

Rich
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI