Please help...please...
Here is my Virtumondebegone log and** Hackthis log. **note** i had to rename in order to even locate files and they will not delete when checked.
[11/26/2007, 16:20:54] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Compaq_Owner\Desktop\VirtumundoBeGone.exe" )
[11/26/2007, 16:21:03] - Detected System Information:
[11/26/2007, 16:21:03] - Windows Version: 5.1.2600, Service Pack 2
[11/26/2007, 16:21:03] - Current Username: Compaq_Owner (Admin)
[11/26/2007, 16:21:03] - Windows is in NORMAL mode.
[11/26/2007, 16:21:03] - Searching for Browser Helper Objects:
[11/26/2007, 16:21:03] - BHO 1: {044250FC-36C5-48B8-AB5C-692419D03883} ()
[11/26/2007, 16:21:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:04] - No filename found. Continuing.
[11/26/2007, 16:21:04] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[11/26/2007, 16:21:04] - BHO 3: {0D39A900-0F3A-4C29-A254-3E65244FDC34} (ContextHelper)
[11/26/2007, 16:21:04] - BHO 4: {1a67b0dc-03ca-42e4-9bef-a30a132dafcd} ()
[11/26/2007, 16:21:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:04] - Checking for HKLM\...\Winlogon\Notify\tojnmlyg
[11/26/2007, 16:21:04] - Key not found: HKLM\...\Winlogon\Notify\tojnmlyg, continuing.
[11/26/2007, 16:21:04] - BHO 5: {1C1DD717-53B2-485E-A17B-C9977C205E10} ()
[11/26/2007, 16:21:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:04] - No filename found. Continuing.
[11/26/2007, 16:21:05] - BHO 6: {1CCAE7CC-7709-43F2-A578-4D8B3D445186} ()
[11/26/2007, 16:21:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:05] - No filename found. Continuing.
[11/26/2007, 16:21:05] - BHO 7: {1E57D3CF-F804-47B5-893B-774A50534055} ()
[11/26/2007, 16:21:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:05] - No filename found. Continuing.
[11/26/2007, 16:21:05] - BHO 8: {24A59DCD-3E8F-43EA-83E3-F40234949A19} ()
[11/26/2007, 16:21:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:05] - Checking for HKLM\...\Winlogon\Notify\mlljk
[11/26/2007, 16:21:05] - Key not found: HKLM\...\Winlogon\Notify\mlljk, continuing.
[11/26/2007, 16:21:05] - BHO 9: {33628043-A4B2-4A2D-9840-D322BD02183E} ()
[11/26/2007, 16:21:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:06] - No filename found. Continuing.
[11/26/2007, 16:21:06] - BHO 10: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[11/26/2007, 16:21:06] - BHO 11: {695FB7DE-B99A-493A-8661-347029E3685C} ()
[11/26/2007, 16:21:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:06] - No filename found. Continuing.
[11/26/2007, 16:21:06] - BHO 12: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/26/2007, 16:21:06] - BHO 13: {8A0CDDD6-D1AD-423B-BCB1-BF51502D42D5} ()
[11/26/2007, 16:21:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:06] - No filename found. Continuing.
[11/26/2007, 16:21:06] - BHO 14: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[11/26/2007, 16:21:06] - BHO 15: {A20BD310-872B-4D97-B35C-3DD4AD01362C} ()
[11/26/2007, 16:21:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:07] - No filename found. Continuing.
[11/26/2007, 16:21:07] - BHO 16: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[11/26/2007, 16:21:07] - BHO 17: {A96B3405-748E-4E4C-A6E8-492B47D7639B} ()
[11/26/2007, 16:21:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/26/2007, 16:21:07] - No filename found. Continuing.
[11/26/2007, 16:21:07] - BHO 18: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/26/2007, 16:21:07] - Finished Searching Browser Helper Objects
[11/26/2007, 16:21:07] - Finishing up...
[11/26/2007, 16:21:07] - Nothing found! Exiting...
[11/27/2007, 22:15:35] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Compaq_Owner\Desktop\VirtumundoBeGone.exe" )
[11/27/2007, 22:15:38] - Detected System Information:
[11/27/2007, 22:15:38] - Windows Version: 5.1.2600, Service Pack 2
[11/27/2007, 22:15:38] - Current Username: Compaq_Owner (Admin)
[11/27/2007, 22:15:38] - Windows is in SAFE mode with Networking.
[11/27/2007, 22:15:38] - Searching for Browser Helper Objects:
[11/27/2007, 22:15:38] - BHO 1: {044250FC-36C5-48B8-AB5C-692419D03883} ()
[11/27/2007, 22:15:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:38] - No filename found. Continuing.
[11/27/2007, 22:15:38] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[11/27/2007, 22:15:38] - BHO 3: {0D39A900-0F3A-4C29-A254-3E65244FDC34} (ContextHelper)
[11/27/2007, 22:15:38] - BHO 4: {1C1DD717-53B2-485E-A17B-C9977C205E10} ()
[11/27/2007, 22:15:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:38] - No filename found. Continuing.
[11/27/2007, 22:15:38] - BHO 5: {1CCAE7CC-7709-43F2-A578-4D8B3D445186} ()
[11/27/2007, 22:15:38] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:38] - No filename found. Continuing.
[11/27/2007, 22:15:38] - BHO 6: {1E57D3CF-F804-47B5-893B-774A50534055} ()
[11/27/2007, 22:15:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:39] - No filename found. Continuing.
[11/27/2007, 22:15:39] - BHO 7: {24A59DCD-3E8F-43EA-83E3-F40234949A19} ()
[11/27/2007, 22:15:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:39] - No filename found. Continuing.
[11/27/2007, 22:15:39] - BHO 8: {33628043-A4B2-4A2D-9840-D322BD02183E} ()
[11/27/2007, 22:15:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:39] - No filename found. Continuing.
[11/27/2007, 22:15:39] - BHO 9: {492e663e-a116-4edb-9be9-833c850405a7} ()
[11/27/2007, 22:15:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:39] - Checking for HKLM\...\Winlogon\Notify\xcsqqgoy
[11/27/2007, 22:15:39] - Key not found: HKLM\...\Winlogon\Notify\xcsqqgoy, continuing.
[11/27/2007, 22:15:39] - BHO 10: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[11/27/2007, 22:15:39] - BHO 11: {56BBB2A8-01F4-4178-B539-D7C17C86D4C6} ()
[11/27/2007, 22:15:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:39] - Checking for HKLM\...\Winlogon\Notify\mlljk
[11/27/2007, 22:15:39] - Key not found: HKLM\...\Winlogon\Notify\mlljk, continuing.
[11/27/2007, 22:15:39] - BHO 12: {695FB7DE-B99A-493A-8661-347029E3685C} ()
[11/27/2007, 22:15:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:39] - No filename found. Continuing.
[11/27/2007, 22:15:39] - BHO 13: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/27/2007, 22:15:39] - BHO 14: {8A0CDDD6-D1AD-423B-BCB1-BF51502D42D5} ()
[11/27/2007, 22:15:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:39] - No filename found. Continuing.
[11/27/2007, 22:15:39] - BHO 15: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[11/27/2007, 22:15:39] - BHO 16: {A20BD310-872B-4D97-B35C-3DD4AD01362C} ()
[11/27/2007, 22:15:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:39] - No filename found. Continuing.
[11/27/2007, 22:15:39] - BHO 17: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[11/27/2007, 22:15:39] - BHO 18: {A96B3405-748E-4E4C-A6E8-492B47D7639B} ()
[11/27/2007, 22:15:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/27/2007, 22:15:39] - No filename found. Continuing.
[11/27/2007, 22:15:39] - BHO 19: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/27/2007, 22:15:39] - Finished Searching Browser Helper Objects
[11/27/2007, 22:15:39] - Finishing up...
[11/27/2007, 22:15:39] - Nothing found! Exiting...
[11/28/2007, 0:13:32] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Compaq_Owner\Desktop\bunny.exe" )
[11/28/2007, 0:13:41] - Detected System Information:
[11/28/2007, 0:13:41] - Windows Version: 5.1.2600, Service Pack 2
[11/28/2007, 0:13:41] - Current Username: Compaq_Owner (Admin)
[11/28/2007, 0:13:41] - Windows is in NORMAL mode.
[11/28/2007, 0:13:41] - Searching for Browser Helper Objects:
[11/28/2007, 0:13:41] - BHO 1: {044250FC-36C5-48B8-AB5C-692419D03883} ()
[11/28/2007, 0:13:41] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:41] - No filename found. Continuing.
[11/28/2007, 0:13:42] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[11/28/2007, 0:13:42] - BHO 3: {0D39A900-0F3A-4C29-A254-3E65244FDC34} (ContextHelper)
[11/28/2007, 0:13:42] - BHO 4: {1CCAE7CC-7709-43F2-A578-4D8B3D445186} ()
[11/28/2007, 0:13:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:42] - No filename found. Continuing.
[11/28/2007, 0:13:42] - BHO 5: {1E57D3CF-F804-47B5-893B-774A50534055} ()
[11/28/2007, 0:13:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:42] - No filename found. Continuing.
[11/28/2007, 0:13:42] - BHO 6: {24A59DCD-3E8F-43EA-83E3-F40234949A19} ()
[11/28/2007, 0:13:42] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:42] - No filename found. Continuing.
[11/28/2007, 0:13:43] - BHO 7: {33628043-A4B2-4A2D-9840-D322BD02183E} ()
[11/28/2007, 0:13:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:43] - No filename found. Continuing.
[11/28/2007, 0:13:43] - BHO 8: {492e663e-a116-4edb-9be9-833c850405a7} ()
[11/28/2007, 0:13:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:43] - Checking for HKLM\...\Winlogon\Notify\xcsqqgoy
[11/28/2007, 0:13:43] - Key not found: HKLM\...\Winlogon\Notify\xcsqqgoy, continuing.
[11/28/2007, 0:13:43] - BHO 9: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[11/28/2007, 0:13:44] - BHO 10: {695FB7DE-B99A-493A-8661-347029E3685C} ()
[11/28/2007, 0:13:44] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:44] - No filename found. Continuing.
[11/28/2007, 0:13:44] - BHO 11: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/28/2007, 0:13:44] - BHO 12: {7EDA3C14-705C-44B1-B3B9-646C9DA9377A} ()
[11/28/2007, 0:13:44] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:44] - Checking for HKLM\...\Winlogon\Notify\mlljk
[11/28/2007, 0:13:44] - Key not found: HKLM\...\Winlogon\Notify\mlljk, continuing.
[11/28/2007, 0:13:44] - BHO 13: {8A0CDDD6-D1AD-423B-BCB1-BF51502D42D5} ()
[11/28/2007, 0:13:44] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:44] - No filename found. Continuing.
[11/28/2007, 0:13:44] - BHO 14: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[11/28/2007, 0:13:44] - BHO 15: {A20BD310-872B-4D97-B35C-3DD4AD01362C} ()
[11/28/2007, 0:13:45] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:45] - No filename found. Continuing.
[11/28/2007, 0:13:45] - BHO 16: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[11/28/2007, 0:13:45] - BHO 17: {A96B3405-748E-4E4C-A6E8-492B47D7639B} ()
[11/28/2007, 0:13:45] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 0:13:45] - No filename found. Continuing.
[11/28/2007, 0:13:45] - BHO 18: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/28/2007, 0:13:45] - Finished Searching Browser Helper Objects
[11/28/2007, 0:13:45] - Finishing up...
[11/28/2007, 0:13:45] - Nothing found! Exiting...
[11/28/2007, 10:25:09] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Compaq_Owner\Desktop\bunny.exe" )
[11/28/2007, 10:25:13] - Detected System Information:
[11/28/2007, 10:25:13] - Windows Version: 5.1.2600, Service Pack 2
[11/28/2007, 10:25:13] - Current Username: Compaq_Owner (Admin)
[11/28/2007, 10:25:13] - Windows is in NORMAL mode.
[11/28/2007, 10:25:13] - Searching for Browser Helper Objects:
[11/28/2007, 10:25:13] - BHO 1: {044250FC-36C5-48B8-AB5C-692419D03883} ()
[11/28/2007, 10:25:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:14] - No filename found. Continuing.
[11/28/2007, 10:25:14] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[11/28/2007, 10:25:14] - BHO 3: {0D39A900-0F3A-4C29-A254-3E65244FDC34} (ContextHelper)
[11/28/2007, 10:25:14] - BHO 4: {1CCAE7CC-7709-43F2-A578-4D8B3D445186} ()
[11/28/2007, 10:25:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:14] - No filename found. Continuing.
[11/28/2007, 10:25:14] - BHO 5: {1E57D3CF-F804-47B5-893B-774A50534055} ()
[11/28/2007, 10:25:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:14] - No filename found. Continuing.
[11/28/2007, 10:25:14] - BHO 6: {24A59DCD-3E8F-43EA-83E3-F40234949A19} ()
[11/28/2007, 10:25:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:14] - No filename found. Continuing.
[11/28/2007, 10:25:14] - BHO 7: {2CB22A05-79D4-4758-B343-2E7E0666AFF8} ()
[11/28/2007, 10:25:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:15] - Checking for HKLM\...\Winlogon\Notify\mlljk
[11/28/2007, 10:25:15] - Key not found: HKLM\...\Winlogon\Notify\mlljk, continuing.
[11/28/2007, 10:25:15] - BHO 8: {33628043-A4B2-4A2D-9840-D322BD02183E} ()
[11/28/2007, 10:25:15] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:15] - No filename found. Continuing.
[11/28/2007, 10:25:15] - BHO 9: {492e663e-a116-4edb-9be9-833c850405a7} ()
[11/28/2007, 10:25:15] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:15] - Checking for HKLM\...\Winlogon\Notify\xcsqqgoy
[11/28/2007, 10:25:15] - Key not found: HKLM\...\Winlogon\Notify\xcsqqgoy, continuing.
[11/28/2007, 10:25:15] - BHO 10: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[11/28/2007, 10:25:15] - BHO 11: {695FB7DE-B99A-493A-8661-347029E3685C} ()
[11/28/2007, 10:25:15] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:15] - No filename found. Continuing.
[11/28/2007, 10:25:15] - BHO 12: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[11/28/2007, 10:25:15] - BHO 13: {7EDA3C14-705C-44B1-B3B9-646C9DA9377A} ()
[11/28/2007, 10:25:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:16] - No filename found. Continuing.
[11/28/2007, 10:25:16] - BHO 14: {8A0CDDD6-D1AD-423B-BCB1-BF51502D42D5} ()
[11/28/2007, 10:25:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:16] - No filename found. Continuing.
[11/28/2007, 10:25:16] - BHO 15: {9ECB9560-04F9-4bbc-943D-298DDF1699E1} (CNisExtBho Class)
[11/28/2007, 10:25:16] - BHO 16: {A20BD310-872B-4D97-B35C-3DD4AD01362C} ()
[11/28/2007, 10:25:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:16] - No filename found. Continuing.
[11/28/2007, 10:25:16] - BHO 17: {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (CNavExtBho Class)
[11/28/2007, 10:25:16] - BHO 18: {A96B3405-748E-4E4C-A6E8-492B47D7639B} ()
[11/28/2007, 10:25:16] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/28/2007, 10:25:16] - No filename found. Continuing.
[11/28/2007, 10:25:16] - BHO 19: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[11/28/2007, 10:25:16] - Finished Searching Browser Helper Objects
[11/28/2007, 10:25:17] - Finishing up...
[11/28/2007, 10:25:17] - Nothing found! Exiting...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:29:27 AM, on 11/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Documents and Settings\Compaq_Owner\Desktop\fuzzybunny.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.h...a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
O2 - BHO: (no name) - {044250FC-36C5-48B8-AB5C-692419D03883} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Program Files\ContextTool\ContextTool-2.dll (file missing)
O2 - BHO: (no name) - {1CCAE7CC-7709-43F2-A578-4D8B3D445186} - (no file)
O2 - BHO: (no name) - {1E57D3CF-F804-47B5-893B-774A50534055} - (no file)
O2 - BHO: (no name) - {24A59DCD-3E8F-43EA-83E3-F40234949A19} - (no file)
O2 - BHO: (no name) - {2CB22A05-79D4-4758-B343-2E7E0666AFF8} - C:\WINDOWS\system32\mlljk.dll
O2 - BHO: (no name) - {33628043-A4B2-4A2D-9840-D322BD02183E} - (no file)
O2 - BHO: {7a504058-c338-9eb9-bde4-611ae366e294} - {492e663e-a116-4edb-9be9-833c850405a7} - C:\WINDOWS\system32\xcsqqgoy.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {695FB7DE-B99A-493A-8661-347029E3685C} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7EDA3C14-705C-44B1-B3B9-646C9DA9377A} - (no file)
O2 - BHO: (no name) - {8A0CDDD6-D1AD-423B-BCB1-BF51502D42D5} - (no file)
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {A20BD310-872B-4D97-B35C-3DD4AD01362C} - (no file)
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {A96B3405-748E-4E4C-A6E8-492B47D7639B} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [WordPerfect Office 1215] "C:\Program Files\WordPerfect Office 12\Programs\Registration.exe" /title="WordPerfect Office 12" /date=121107 serial=<serial number removed>
O4 - HKLM\..\Run: [dvd43] "C:\Program Files\dvd43\dvd43_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
O8 - Extra context menu item: &Search - ?p=ZNxdm117KLUS
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn...ro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...ploader_v10.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 12762 bytes
**UPDATE*** 11/29/07 10am
I know you guys here are super busy with these logs so I figured I'd do a lil self help. I have done a lot of reading and I think I managed to get MLLJK.dll out of my computer. Here is my Combofix log and my updated Hijackthis log file...Please let me know what you see
ComboFix 07-11-29.3 - Compaq_Owner 2007-11-29 0:58:58.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.614 [GMT -6:00]
Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Start Menu\Live Safety Center.lnk
C:\Documents and Settings\Compaq_Owner\Desktop\Live Safety Center.lnk
C:\Documents and Settings\Compaq_Owner\Desktop\Online Security Guide.lnk
C:\Documents and Settings\Compaq_Owner\Favorites\Online Security Guide.lnk
C:\setup.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ahlpnmuj.dll
C:\WINDOWS\system32\chupwgeb.dll
C:\WINDOWS\system32\gdyadeli.dll
C:\WINDOWS\system32\gjdhmihv.dll
C:\WINDOWS\system32\jbpuvjbc.dll
C:\WINDOWS\system32\kjllm.ini
C:\WINDOWS\system32\kjllm.ini2
C:\WINDOWS\system32\mlljk.dll
C:\WINDOWS\system32\mtxrmhmm.dll
C:\WINDOWS\system32\owgwhptn.dll
C:\WINDOWS\system32\tmpqmksq.dll
C:\WINDOWS\system32\vpbkkjbg.dll
C:\WINDOWS\system32\xdhinwxl.ini
C:\WINDOWS\system32\xdhinwxl.ini2
C:\WINDOWS\system32\xdhinwxl.tmp
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-29 )))))))))))))))))))))))))))))))
.
2007-11-27 21:36 . 2007-11-27 21:36 <DIR> d-------- C:\Program Files\Lavasoft
2007-11-27 21:36 . 2007-11-27 21:36 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2007-11-27 21:36 . 2007-11-27 21:36 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-11-26 17:30 . 2007-11-26 17:30 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-11-26 14:11 . 2007-11-26 14:11 <DIR> d-------- C:\Program Files\Webroot
2007-11-26 14:11 . 2007-11-26 14:11 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2007-11-26 14:11 . 2007-11-26 14:11 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Webroot
2007-11-26 14:11 . 2007-11-26 14:11 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2007-11-26 14:11 . 2007-10-01 16:40 1,526,072 --a------ C:\WINDOWS\WRSetup.dll
2007-11-26 14:08 . 2007-11-26 14:08 164 --a------ C:\install.dat
2007-11-26 13:31 . 2007-11-26 13:31 <DIR> d-------- C:\VundoFix Backups
2007-11-26 11:33 . 2007-08-08 20:02 235,008 --a------ C:\WINDOWS\UNBOC.EXE
2007-11-26 11:32 . 2007-11-26 11:32 <DIR> d-------- C:\Program Files\Comodo
2007-11-26 10:57 . 2007-11-26 11:45 <DIR> d-------- C:\Program Files\Spyware Doctor
2007-11-26 10:57 . 2007-11-26 10:57 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\PC Tools
2007-11-26 10:57 . 2007-10-18 00:16 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-11-26 10:57 . 2007-10-18 00:15 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-11-26 10:57 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-11-17 18:56 . 2007-11-17 20:04 428 --a------ C:\WINDOWS\wininit.ini
2007-11-16 23:34 . 2007-11-27 22:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-14 20:39 . 2007-11-14 20:39 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PopCap
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-29 06:09 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-28 07:04 --------- d-----w C:\Program Files\Java
2007-11-17 06:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-17 06:28 --------- d-----w C:\Program Files\Microsoft ActiveSync
2007-11-17 06:27 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\Move Networks
2007-10-26 02:22 --------- d-----w C:\Documents and Settings\Compaq_Owner\Application Data\Audacity
2007-10-18 06:16 29,000 ----a-w C:\WINDOWS\system32\drivers\kcom.sys
2007-10-01 22:24 23,864 ----a-w C:\WINDOWS\system32\drivers\sskbfd.sys
2007-10-01 22:24 21,816 ----a-w C:\WINDOWS\system32\drivers\sshrmd.sys
2007-10-01 22:24 20,280 ----a-w C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2007-10-01 22:24 163,640 ----a-w C:\WINDOWS\system32\drivers\ssidrv.sys
2006-04-28 02:20 24,192 ----a-w C:\Documents and Settings\Compaq_Owner\usbsermptxp.sys
2006-04-28 02:20 22,768 ----a-w C:\Documents and Settings\Compaq_Owner\usbsermpt.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{044250FC-36C5-48B8-AB5C-692419D03883}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0D39A900-0F3A-4C29-A254-3E65244FDC34}]
C:\Program Files\ContextTool\ContextTool-2.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1CCAE7CC-7709-43F2-A578-4D8B3D445186}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E57D3CF-F804-47B5-893B-774A50534055}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{24A59DCD-3E8F-43EA-83E3-F40234949A19}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{33628043-A4B2-4A2D-9840-D322BD02183E}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{492e663e-a116-4edb-9be9-833c850405a7}]
C:\WINDOWS\system32\xcsqqgoy.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{695FB7DE-B99A-493A-8661-347029E3685C}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7EDA3C14-705C-44B1-B3B9-646C9DA9377A}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8A0CDDD6-D1AD-423B-BCB1-BF51502D42D5}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A20BD310-872B-4D97-B35C-3DD4AD01362C}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A96B3405-748E-4E4C-A6E8-492B47D7639B}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-01-24 20:46]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2005-07-27 00:58]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-03-23 14:43]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 12:47 C:\WINDOWS\ALCXMNTR.EXE]
"WordPerfect Office 1215"="C:\Program Files\WordPerfect Office 12\Programs\Registration.exe" [2004-03-08 07:36]
"dvd43"="C:\Program Files\dvd43\dvd43_tray.exe" [2006-05-22 12:26]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2004-08-11 21:23]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-10-01 16:40]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\mlljk.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Compaq Connections.lnk
backup=C:\WINDOWS\pss\Compaq Connections.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NewShortcut1.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NewShortcut1.lnk
backup=C:\WINDOWS\pss\NewShortcut1.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Compaq_Owner^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Compaq_Owner\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 02:06 40048 --a------ C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd]
ALCWZRD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ANIWZCSService]
2003-08-21 14:12 32768 --a------ C:\Program Files\Alpha Networks\ANIWZCS Service\WZCSLDR.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Creative Detector]
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 06:00 15360 --a------ C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\D-Link Air Utility]
2003-09-03 15:49 3358720 --a------ C:\Program Files\D-Link\Air Utility\AirCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2005-07-27 00:58 405583 --a------ C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-12-22 06:38 241664 --a--c--- C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-08-04 15:28 49152 --a--c--- C:\Program Files\HP\HP Software Update\HPWuSchd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 17:04 52736 --a------ c:\windows\system\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IcoSet]
c:\hp\bin\cloaker.exe c:\hp\bin\IcoSet\adjust.bat seticon
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2007-09-07 15:55 267064 --a------ C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-11 21:02 61440 --a------ C:\HP\KBD\KBD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar Search Scope Monitor]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe /m=0
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MyWebSearch Email Plugin]
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\outlook]
C:\Program Files\outlook\outlook.exe /auto
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2003-09-12 21:13 98304 --a------ C:\WINDOWS\system32\ps2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2004-04-14 21:43 233472 --a------ C:\WINDOWS\SMINST\RECGUARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
2006-05-08 03:17 81920 --a------ C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-01-24 20:46 171448 --a------ C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winlog]
winlog.exe
R0 SSFS0BB9;Spy Sweeper File System Filer Driver: 0BB9;C:\WINDOWS\system32\Drivers\SSFS0BB9.SYS
R3 HidMouse;HidMouse;C:\WINDOWS\system32\Drivers\HidMouse.sys
S3 BOCDRIVE;BOClean Kernel Monitor.;\??\C:\Program Files\Comodo\CBOClean\BOCDRIVE.sys
S3 PRISM;D-Link Air Wireless Prism3 Adapter Driver;C:\WINDOWS\system32\DRIVERS\PRISMNDS.sys
S3 RimSerPort;RIM Virtual Serial Port;C:\WINDOWS\system32\DRIVERS\RimSerial.sys
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys
S3 USBAAPL;Apple Mobile USB Driver;C:\WINDOWS\system32\Drivers\usbaapl.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setupSNK.exe
.
Contents of the 'Scheduled Tasks' folder
"2007-11-29 04:49:26 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-17 02:00:23 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Compaq_Owner.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
"2007-11-29 07:04:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
"2007-11-26 20:11:34 C:\WINDOWS\Tasks\wrSpySweeperTrialSweep.job"
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
- C:\
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-29 01:10:03
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-29 1:13:18 - machine was rebooted
.
--- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:38:47 AM, on 11/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Compaq_Owner\Desktop\fuzzybunny.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.h...a...&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.h...a...&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...a...&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.h...a...&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {044250FC-36C5-48B8-AB5C-692419D03883} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Media Holding Enterprises, LLC - {0D39A900-0F3A-4C29-A254-3E65244FDC34} - C:\Program Files\ContextTool\ContextTool-2.dll (file missing)
O2 - BHO: (no name) - {1CCAE7CC-7709-43F2-A578-4D8B3D445186} - (no file)
O2 - BHO: (no name) - {1E57D3CF-F804-47B5-893B-774A50534055} - (no file)
O2 - BHO: (no name) - {24A59DCD-3E8F-43EA-83E3-F40234949A19} - (no file)
O2 - BHO: (no name) - {33628043-A4B2-4A2D-9840-D322BD02183E} - (no file)
O2 - BHO: {7a504058-c338-9eb9-bde4-611ae366e294} - {492e663e-a116-4edb-9be9-833c850405a7} - C:\WINDOWS\system32\xcsqqgoy.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {695FB7DE-B99A-493A-8661-347029E3685C} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7EDA3C14-705C-44B1-B3B9-646C9DA9377A} - (no file)
O2 - BHO: (no name) - {8A0CDDD6-D1AD-423B-BCB1-BF51502D42D5} - (no file)
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - c:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: (no name) - {A20BD310-872B-4D97-B35C-3DD4AD01362C} - (no file)
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {A96B3405-748E-4E4C-A6E8-492B47D7639B} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [WordPerfect Office 1215] "C:\Program Files\WordPerfect Office 12\Programs\Registration.exe" /title="WordPerfect Office 12" /date=121107 serial=<serial number removed>
O4 - HKLM\..\Run: [dvd43] "C:\Program Files\dvd43\dvd43_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNOTIFY.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O8 - Extra context menu item: &Search - ?p=ZNxdm117KLUS
O8 - Extra context menu item: Add To Compaq Organize... - C:\PROGRA~1\HEWLET~1\COMPAQ~1\bin\core.hp.main\SendTo.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx...owserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn...ro.cab56649.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...ploader_v10.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
--
End of file - 12380 bytes
Thanks for your time,
Manolo
Edited by silver, 01 December 2007 - 02:34 AM.
removed software serial numbers