jhnavi
Topic Starter
Hi all,
Recently my computer is running slow and my internet browser is opening unknown sites.
I am posting Hackthis, combofix logs along with startup list
pls help me in fixing my computer issue..
hijackthis.log
—————————————
Logfile of HijackThis v1.99.1
Scan saved at 11:01:38 PM, on 12/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\lxbmcoms.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Lexmark 4200 Series\lxbmmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Free Download Manager\fum\fum.exe
C:\Program Files\Free Download Manager\FUM\fumoei.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [lxbmmon.exe] "C:\Program Files\Lexmark 4200 Series\lxbmmon.exe"
O4 - HKLM\..\Run: [Lexmark 4200 Series Fax Server] "C:\Program Files\Lexmark 4200 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCPitstop Disk MD Registration Reminder] C:\Program Files\PCPitstop\Disk MD\Reminder.exe
O4 - HKLM\..\Run: [b04f65fd] rundll32.exe "C:\WINDOWS\system32\vrlxeobx.dll",b
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Free Upload Manager] "C:\Program Files\Free Download Manager\fum\fum.exe" -autorun
O4 - HKCU\..\Run: [Free Uploader Oe Integration] C:\Program Files\Free Download Manager\FUM\fumoei.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Upload - {FD4E2FF8-973C-4A19-89BD-8E86B3CFCFE1} - C:\Program Files\Free Download Manager\FUM\fumiebtn.dll
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.andhrajyothy.com/wfplayer/tdserver.cab
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://my-remote.johnsoncontrols.com/https…om/iNotes6W.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinner.com/games/v41/freecell/freecell.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v53/h2hpool/h2hpool.cab
O16 - DPF: {FDD6CEF8-3C6E-42E0-BC7B-D730085CFABC} (Jaxtr Outlook Importer) - http://www.jaxtr.com/user/activex/JaxtrOutlookImporter.CAB
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxbm_device - - C:\WINDOWS\system32\lxbmcoms.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
COMBO FIC LOG FILE
ComboFix 07-12-02.6 - Supraja 2007-12-07 23:08:35.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.784 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\gjjjl.ini
C:\WINDOWS\system32\gjjjl.ini2
C:\WINDOWS\system32\ueyxgrtj.dll
C:\WINDOWS\system32\vrlxeobx.dll
C:\WINDOWS\system32\xboexlrv.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-11-08 to 2007-12-08 )))))))))))))))))))))))))))))))
.
2007-12-07 23:13 . 2007-12-07 23:14 371 –ahs—- C:\WINDOWS\system32\gjjjl.ini
2007-12-05 20:47 . 2007-12-05 20:47 143 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-12-04 23:16 . 2007-12-04 23:16 d——– C:\Program Files\SkanerOnline
2007-12-04 23:05 . 2007-12-06 20:39 349 –a—— C:\WINDOWS\gmer.ini
2007-12-04 22:44 . 2007-12-04 22:44 d——– C:\Program Files\PCPitstop
2007-12-03 22:31 . 2007-12-06 20:28 d——– C:\Program Files\XoftSpySE
2007-12-03 22:18 . 2007-12-03 22:18 d——– C:\Documents and Settings\Supraja\DoctorWeb
2007-12-03 21:44 . 2007-12-03 21:44 d——– C:\Program Files\Lavasoft
2007-12-03 21:44 . 2007-12-03 21:44 d——– C:\Documents and Settings\Supraja\Application Data\Lavasoft
2007-12-03 21:40 . 2007-12-03 21:40 d——– C:\Documents and Settings\Supraja\Application Data\AdwareAlert
2007-12-03 21:31 . 2007-12-03 21:31 d——– C:\Program Files\Common Files\Scanner
2007-12-03 21:15 . 2007-12-03 21:15 d——– C:\WINDOWS\Registry Repair 5
2007-12-03 21:15 . 2007-12-03 21:15 d——– C:\Program Files\Migo Software
2007-12-03 20:48 . 2007-12-03 22:11 794,169 –ahs—- C:\WINDOWS\system32\lhaqkyku.ini
2007-12-02 20:47 . 2007-12-02 20:47 336,480 –a—— C:\WINDOWS\system32\ljjjg.dll
2007-12-02 19:47 . 2007-12-02 19:47 d——– C:\Documents and Settings\Supraja\Application Data\Apple Computer
2007-12-02 19:13 . 2007-12-02 19:14 d——– C:\Program Files\QuickTime
2007-12-02 19:13 . 2007-12-02 19:13 d——– C:\Program Files\Apple Software Update
2007-12-02 19:13 . 2007-12-02 19:13 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-02 19:13 . 2007-12-02 19:13 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-02 19:08 . 2007-12-02 19:33 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-02 19:08 . 2007-12-02 19:08 356,352 –a—— C:\WINDOWS\eSellerateEngine.dll
2007-12-02 19:08 . 2004-12-07 10:11 258,352 –a—— C:\WINDOWS\system32\Unicows.dll
2007-12-02 18:55 . 2007-12-02 18:55 d——– C:\Documents and Settings\Supraja\Application Data\STOIK
2007-12-02 18:54 . 2007-12-02 18:54 d——– C:\Program Files\STOIK Imaging
2007-12-02 18:38 . 2004-08-04 00:56 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-12-02 18:38 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-11-29 16:50 . 2007-11-29 16:50 38,567 –a—— C:\WINDOWS\system32\pcpbios.exe
2007-11-29 16:50 . 2007-11-29 16:50 4,096 –a—— C:\WINDOWS\system32\sysres.dll
2007-11-09 22:54 . 2007-11-09 22:55 d——– C:\Downloads
2007-11-09 22:53 . 2007-11-09 22:53 d——– C:\Program Files\Free Download Manager
2007-11-09 22:53 . 2007-12-07 23:10 d——– C:\Documents and Settings\Supraja\Application Data\Free Download Manager
2007-11-09 22:53 . 2007-11-09 22:53 d——– C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2007-11-09 22:49 . 2007-11-09 22:49 d——– C:\Program Files\UnzipThemAll
2007-11-09 22:49 . 2000-12-05 23:00 209,608 –a—— C:\WINDOWS\system32\TABCTL32.ocx
2007-11-09 22:49 . 2005-02-28 23:52 102,400 –a—— C:\WINDOWS\system32\unzip32.dll
2007-11-09 22:49 . 2005-08-26 02:50 77,312 –a—— C:\WINDOWS\system32\UNACEV2.DLL
2007-11-08 17:07 . 2007-11-08 17:07 47 –a—— C:\WINDOWS\NeroDigital.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-08 06:47 ——— d—–w C:\Documents and Settings\Supraja\Application Data\Skype
2007-12-07 19:31 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-04 05:31 ——— d—–w C:\Program Files\Yahoo!
2007-12-03 02:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-30 23:00 ——— d—–w C:\Program Files\Norton Security Scan
2007-11-27 15:45 ——— d—–w C:\Documents and Settings\Supraja\Application Data\4200Series
2007-11-26 02:41 ——— d—–w C:\Program Files\Google
2007-11-22 20:06 ——— d—–w C:\Program Files\Lexmark 4200 Series
2007-11-11 07:26 ——— d—–w C:\Program Files\SopCast
2007-11-06 06:36 ——— d—–w C:\Program Files\Common Files\xing shared
2007-11-06 06:36 ——— d—–w C:\Program Files\Common Files\Real
2007-11-06 00:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\QuickTime
2007-11-02 21:48 ——— d—–w C:\Documents and Settings\Supraja\Application Data\ArcSoft
2007-11-01 03:06 ——— d—–w C:\Program Files\DivX
2007-10-29 23:03 8,864 —-a-w C:\WINDOWS\system32\drivers\CDAC15BA.SYS
2007-10-29 23:03 39,936 —-a-w C:\WINDOWS\system32\drivers\CDAC11BA.EXE
2007-10-29 23:03 30,720 —h–r C:\WINDOWS\CdaC13BA.EXE
2007-10-29 23:03 112,128 —h–r C:\WINDOWS\CdaC14BA.DLL
2007-10-29 00:40 ——— d—–w C:\Documents and Settings\Supraja\Application Data\Creative
2007-10-29 00:38 ——— d—–w C:\Program Files\Creative
2007-10-29 00:35 ——— d—–w C:\Program Files\ArcSoft
2007-10-29 00:26 8,552 —-a-w C:\WINDOWS\system32\drivers\asctrm.sys
2007-10-24 02:47 ——— d—–w C:\Documents and Settings\Supraja\Application Data\AdobeUM
2007-10-21 04:40 ——— d—–w C:\Program Files\Eusing Free Registry Cleaner
2007-10-21 04:27 ——— d—–w C:\Documents and Settings\Supraja\Application Data\DivX
2007-10-21 03:53 ——— d—–w C:\Program Files\Messer
2007-10-21 03:06 ——— d—–w C:\Program Files\Java
2007-10-21 02:56 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-10-20 02:37 ——— d—–w C:\Program Files\Skype
2007-10-20 02:37 ——— d—–w C:\Program Files\Common Files\Skype
2007-10-20 02:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-10-16 21:34 ——— d—–w C:\Documents and Settings\Supraja\Application Data\Media Player Classic
2007-10-16 03:45 ——— d—–w C:\Program Files\K-Lite Codec Pack
2007-10-15 02:21 ——— d—–w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-10-15 02:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\4200Series
2007-10-15 02:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\4200 Series
2007-10-15 00:52 ——— d—–w C:\Documents and Settings\Supraja\Application Data\Yahoo!
2007-10-15 00:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-10-15 00:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-14 20:28 ——— d—–w C:\Program Files\MSXML 4.0
2007-10-14 03:39 ——— d—–w C:\Documents and Settings\Supraja\Application Data\SopCast
2007-10-14 02:01 ——— d—–w C:\Program Files\Pure Networks
2007-10-14 02:01 ——— d—–w C:\Program Files\Common Files\AOL
2007-10-14 02:00 ——— d—–w C:\Program Files\Toshiba
2007-10-14 01:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-14 01:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-14 01:47 ——— d—–w C:\Program Files\Symantec Client Security
2007-10-14 01:47 ——— d—–w C:\Program Files\Symantec
2007-10-14 01:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
.
((((((((((((((((((((((((((((( snapshot@2007-12-03_22.43.48.94 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-02 00:13:04 345,816 —-a-w C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
+ 2007-12-05 07:05:25 585,791 —-a-w C:\WINDOWS\gmer.dll
+ 2007-06-29 17:38:18 581,632 —-a-r C:\WINDOWS\gmer.exe
- 2007-10-14 00:39:55 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-07 04:39:15 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-10-14 00:39:55 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-07 04:39:15 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-14 00:39:55 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-07 04:39:15 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-05 07:05:25 70,001 —-a-w C:\WINDOWS\system32\drivers\gmer.sys
+ 2007-03-15 20:00:36 466,432 —-a-w C:\WINDOWS\system32\SkanerOnline.dll
+ 2007-01-19 17:40:42 89,088 —-a-w C:\WINDOWS\system32\SkanerOnlineUninstall.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{245A6CD4-5EA9-B9EB-791A-06F67243094D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B17709EF-4A5E-48B4-9D3C-B43BCC0B1FC4}]
2007-12-02 20:47 336480 –a—— C:\WINDOWS\system32\ljjjg.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 02:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 16:43]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 06:59]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 12:31]
"Free Upload Manager"="C:\Program Files\Free Download Manager\fum\fum.exe" [2007-07-29 19:13]
"Free Uploader Oe Integration"="C:\Program Files\Free Download Manager\FUM\fumoei.exe" [2007-06-10 18:02]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-08 07:31]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-08 07:27]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 12:48]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-08-06 07:27]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-09-05 16:16]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-28 13:37 C:\WINDOWS\agrsmmsg.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 14:28]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 14:26]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2004-12-14 18:12]
"TPSMain"="TPSMain.exe" [2004-08-27 08:34 C:\WINDOWS\system32\TPSMain.exe]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2004-11-12 16:57]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 13:03]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-09-15 14:03]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 04:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 10:27]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 10:31]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 16:37]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 15:44]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" [2004-03-12 14:18]
"lxbmmon.exe"="C:\Program Files\Lexmark 4200 Series\lxbmmon.exe" [2007-01-30 07:38]
"Lexmark 4200 Series Fax Server"="C:\Program Files\Lexmark 4200 Series\fm3032.exe" [2007-01-30 07:42]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 06:59]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" [2004-07-30 10:04]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-05 22:36]
"PCPitstop Disk MD Registration Reminder"="C:\Program Files\PCPitstop\Disk MD\Reminder.exe" [2007-08-22 22:49]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-09-28 14:08:20]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 10:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\ljjjg.dll
R0 KR10N;KR10N;C:\WINDOWS\system32\drivers\KR10N.sys
S3 P0630VID;Creative WebCam Live!;C:\WINDOWS\system32\DRIVERS\P0630Vid.sys
S4 lxbm_device;lxbm_device;C:\WINDOWS\system32\lxbmcoms.exe -service
.
Contents of the 'Scheduled Tasks' folder
"2007-12-04 05:40:09 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2007-12-03 16:48:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-30 23:00:08 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-12-04 05:16:09 C:\WINDOWS\Tasks\Registry Repair 5.job"
- C:\Program Files\Migo Software\RegistryRepair5\Registry Repair.exe
"2007-10-14 01:55:03 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-07 23:13:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-07 23:15:18 - machine was rebooted
C:\ComboFix2.txt … 2007-12-06 20:14
C:\ComboFix3.txt … 2007-12-04 23:01
.
— E O F —
AND STARTUP LIST REPORT
StartupList report, 12/7/2007, 11:02:41 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16544)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Lexmark 4200 Series\lxbmmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Free Download Manager\fum\fum.exe
C:\Program Files\Free Download Manager\FUM\fumoei.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\lxbmcoms.exe
————————————————–
Listing of startup folders:
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
IgfxTray = C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds = C:\WINDOWS\system32\hkcmd.exe
SoundMAXPnP = C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
SoundMAX = C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
LtMoh = C:\Program Files\ltmoh\Ltmoh.exe
AGRSMMSG = AGRSMMSG.exe
SynTPLpr = C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
THotkey = C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
TPSMain = TPSMain.exe
Tvs = C:\Program Files\Toshiba\Tvs\TvsTray.exe
PadTouch = C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
SmoothView = C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
dla = C:\WINDOWS\system32\dla\tfswctrl.exe
IntelWireless = C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
EOUApp = C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
Pinger = c:\toshiba\ivp\ism\pinger.exe /run
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
vptray = C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
lxbmmon.exe = "C:\Program Files\Lexmark 4200 Series\lxbmmon.exe"
Lexmark 4200 Series Fax Server = "C:\Program Files\Lexmark 4200 Series\fm3032.exe" /s
YSearchProtection = "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
QuickTime Task = "C:\Program Files\QuickTime\QTTask.exe" -atboottime
SunJavaUpdateSched = "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
Creative WebCam Tray = C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
PCPitstop Disk MD Registration Reminder = C:\Program Files\PCPitstop\Disk MD\Reminder.exe
b04f65fd = rundll32.exe "C:\WINDOWS\system32\vrlxeobx.dll",b
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
Yahoo! Pager = "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
YSearchProtection = C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
Skype = "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
Free Upload Manager = "C:\Program Files\Free Download Manager\fum\fum.exe" -autorun
Free Uploader Oe Integration = C:\Program Files\Free Download Manager\FUM\fumoei.exe
————————————————–
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Task Scheduler jobs:
AdwareAlert Scheduled Scan.job
AppleSoftwareUpdate.job
Norton Security Scan.job
Registry Repair 5.job
Symantec NetDetect.job
————————————————–
Enumerating Download Program Files:
[TDServer Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\tdserver.ocx
CODEBASE = http://www.andhrajyothy.com/wfplayer/tdserver.cab
[ScrabbleCubes Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\SCRABB~1.OCX
CODEBASE = http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock…director/sw.cab
[Installation Support]
InProcServer32 = C:\Program Files\Yahoo!\Common\Yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\Yinsthelper.dll
[iNotes6 Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\inotes6W.dll
CODEBASE = https://my-remote.johnsoncontrols.com/https…om/iNotes6W.cab
[DivXBrowserPlugin Object]
InProcServer32 = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CODEBASE = http://download.divx.com/player/DivXBrowserPlugin.cab
[MksSkanerOnline Class]
InProcServer32 = C:\WINDOWS\system32\SkanerOnline.dll
CODEBASE = http://www.mks.com.pl/skaner/SkanerOnline.cab
[FreeCell Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\freecell.ocx
CODEBASE = http://www.worldwinner.com/games/v41/freecell/freecell.cab
[Wwlaunch Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\wwlaunch.ocx
CODEBASE = http://www.worldwinner.com/games/shared/wwlaunch.cab
[SopCore Control]
InProcServer32 = C:\PROGRA~1\SopCast\ActiveX\SopCore.ocx
CODEBASE = http://download.sopcast.com/download/SOPCORE.CAB
[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab
[H2hPool Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\h2hpool.ocx
CODEBASE = http://www.worldwinner.com/games/v53/h2hpool/h2hpool.cab
[Jaxtr Outlook Importer]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\JaxtrOutlookImporter.dll
CODEBASE = http://www.jaxtr.com/user/activex/JaxtrOutlookImporter.CAB
————————————————–
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\WINDOWS\system32\jhklquhb.exe => C:\DOCUME~1\Supraja\LOCALS~1\Temp\temp.fr1974|||
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll
————————————————–
End of report, 10,643 bytes
Report generated in 0.020 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Appreciate your help
Recently my computer is running slow and my internet browser is opening unknown sites.
I am posting Hackthis, combofix logs along with startup list
pls help me in fixing my computer issue..
hijackthis.log
—————————————
Logfile of HijackThis v1.99.1
Scan saved at 11:01:38 PM, on 12/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\WINDOWS\system32\lxbmcoms.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Lexmark 4200 Series\lxbmmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Free Download Manager\fum\fum.exe
C:\Program Files\Free Download Manager\FUM\fumoei.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [lxbmmon.exe] "C:\Program Files\Lexmark 4200 Series\lxbmmon.exe"
O4 - HKLM\..\Run: [Lexmark 4200 Series Fax Server] "C:\Program Files\Lexmark 4200 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PCPitstop Disk MD Registration Reminder] C:\Program Files\PCPitstop\Disk MD\Reminder.exe
O4 - HKLM\..\Run: [b04f65fd] rundll32.exe "C:\WINDOWS\system32\vrlxeobx.dll",b
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Free Upload Manager] "C:\Program Files\Free Download Manager\fum\fum.exe" -autorun
O4 - HKCU\..\Run: [Free Uploader Oe Integration] C:\Program Files\Free Download Manager\FUM\fumoei.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Upload - {FD4E2FF8-973C-4A19-89BD-8E86B3CFCFE1} - C:\Program Files\Free Download Manager\FUM\fumiebtn.dll
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.andhrajyothy.com/wfplayer/tdserver.cab
O16 - DPF: {02A2D714-433E-46E4-B217-7C3B3FAF8EAE} (ScrabbleCubes Control) - http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://my-remote.johnsoncontrols.com/https…om/iNotes6W.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {68282C51-9459-467B-95BF-3C0E89627E55} (MksSkanerOnline Class) - http://www.mks.com.pl/skaner/SkanerOnline.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinner.com/games/v41/freecell/freecell.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) - http://download.sopcast.com/download/SOPCORE.CAB
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) - http://www.worldwinner.com/games/v53/h2hpool/h2hpool.cab
O16 - DPF: {FDD6CEF8-3C6E-42E0-BC7B-D730085CFABC} (Jaxtr Outlook Importer) - http://www.jaxtr.com/user/activex/JaxtrOutlookImporter.CAB
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxbm_device - - C:\WINDOWS\system32\lxbmcoms.exe
O23 - Service: OwnershipProtocol - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
COMBO FIC LOG FILE
ComboFix 07-12-02.6 - Supraja 2007-12-07 23:08:35.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.784 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\gjjjl.ini
C:\WINDOWS\system32\gjjjl.ini2
C:\WINDOWS\system32\ueyxgrtj.dll
C:\WINDOWS\system32\vrlxeobx.dll
C:\WINDOWS\system32\xboexlrv.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((( Files Created from 2007-11-08 to 2007-12-08 )))))))))))))))))))))))))))))))
.
2007-12-07 23:13 . 2007-12-07 23:14 371 –ahs—- C:\WINDOWS\system32\gjjjl.ini
2007-12-05 20:47 . 2007-12-05 20:47 143 –a—— C:\WINDOWS\system32\mcrh.tmp
2007-12-04 23:16 . 2007-12-04 23:16 d——– C:\Program Files\SkanerOnline
2007-12-04 23:05 . 2007-12-06 20:39 349 –a—— C:\WINDOWS\gmer.ini
2007-12-04 22:44 . 2007-12-04 22:44 d——– C:\Program Files\PCPitstop
2007-12-03 22:31 . 2007-12-06 20:28 d——– C:\Program Files\XoftSpySE
2007-12-03 22:18 . 2007-12-03 22:18 d——– C:\Documents and Settings\Supraja\DoctorWeb
2007-12-03 21:44 . 2007-12-03 21:44 d——– C:\Program Files\Lavasoft
2007-12-03 21:44 . 2007-12-03 21:44 d——– C:\Documents and Settings\Supraja\Application Data\Lavasoft
2007-12-03 21:40 . 2007-12-03 21:40 d——– C:\Documents and Settings\Supraja\Application Data\AdwareAlert
2007-12-03 21:31 . 2007-12-03 21:31 d——– C:\Program Files\Common Files\Scanner
2007-12-03 21:15 . 2007-12-03 21:15 d——– C:\WINDOWS\Registry Repair 5
2007-12-03 21:15 . 2007-12-03 21:15 d——– C:\Program Files\Migo Software
2007-12-03 20:48 . 2007-12-03 22:11 794,169 –ahs—- C:\WINDOWS\system32\lhaqkyku.ini
2007-12-02 20:47 . 2007-12-02 20:47 336,480 –a—— C:\WINDOWS\system32\ljjjg.dll
2007-12-02 19:47 . 2007-12-02 19:47 d——– C:\Documents and Settings\Supraja\Application Data\Apple Computer
2007-12-02 19:13 . 2007-12-02 19:14 d——– C:\Program Files\QuickTime
2007-12-02 19:13 . 2007-12-02 19:13 d——– C:\Program Files\Apple Software Update
2007-12-02 19:13 . 2007-12-02 19:13 d——– C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-12-02 19:13 . 2007-12-02 19:13 d——– C:\Documents and Settings\All Users\Application Data\Apple
2007-12-02 19:08 . 2007-12-02 19:33 d-a—— C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-02 19:08 . 2007-12-02 19:08 356,352 –a—— C:\WINDOWS\eSellerateEngine.dll
2007-12-02 19:08 . 2004-12-07 10:11 258,352 –a—— C:\WINDOWS\system32\Unicows.dll
2007-12-02 18:55 . 2007-12-02 18:55 d——– C:\Documents and Settings\Supraja\Application Data\STOIK
2007-12-02 18:54 . 2007-12-02 18:54 d——– C:\Program Files\STOIK Imaging
2007-12-02 18:38 . 2004-08-04 00:56 159,232 –a—— C:\WINDOWS\system32\ptpusd.dll
2007-12-02 18:38 . 2001-08-17 22:36 5,632 –a—— C:\WINDOWS\system32\ptpusb.dll
2007-11-29 16:50 . 2007-11-29 16:50 38,567 –a—— C:\WINDOWS\system32\pcpbios.exe
2007-11-29 16:50 . 2007-11-29 16:50 4,096 –a—— C:\WINDOWS\system32\sysres.dll
2007-11-09 22:54 . 2007-11-09 22:55 d——– C:\Downloads
2007-11-09 22:53 . 2007-11-09 22:53 d——– C:\Program Files\Free Download Manager
2007-11-09 22:53 . 2007-12-07 23:10 d——– C:\Documents and Settings\Supraja\Application Data\Free Download Manager
2007-11-09 22:53 . 2007-11-09 22:53 d——– C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2007-11-09 22:49 . 2007-11-09 22:49 d——– C:\Program Files\UnzipThemAll
2007-11-09 22:49 . 2000-12-05 23:00 209,608 –a—— C:\WINDOWS\system32\TABCTL32.ocx
2007-11-09 22:49 . 2005-02-28 23:52 102,400 –a—— C:\WINDOWS\system32\unzip32.dll
2007-11-09 22:49 . 2005-08-26 02:50 77,312 –a—— C:\WINDOWS\system32\UNACEV2.DLL
2007-11-08 17:07 . 2007-11-08 17:07 47 –a—— C:\WINDOWS\NeroDigital.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-08 06:47 ——— d—–w C:\Documents and Settings\Supraja\Application Data\Skype
2007-12-07 19:31 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-04 05:31 ——— d—–w C:\Program Files\Yahoo!
2007-12-03 02:54 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-30 23:00 ——— d—–w C:\Program Files\Norton Security Scan
2007-11-27 15:45 ——— d—–w C:\Documents and Settings\Supraja\Application Data\4200Series
2007-11-26 02:41 ——— d—–w C:\Program Files\Google
2007-11-22 20:06 ——— d—–w C:\Program Files\Lexmark 4200 Series
2007-11-11 07:26 ——— d—–w C:\Program Files\SopCast
2007-11-06 06:36 ——— d—–w C:\Program Files\Common Files\xing shared
2007-11-06 06:36 ——— d—–w C:\Program Files\Common Files\Real
2007-11-06 00:09 ——— d—–w C:\Documents and Settings\All Users\Application Data\QuickTime
2007-11-02 21:48 ——— d—–w C:\Documents and Settings\Supraja\Application Data\ArcSoft
2007-11-01 03:06 ——— d—–w C:\Program Files\DivX
2007-10-29 23:03 8,864 —-a-w C:\WINDOWS\system32\drivers\CDAC15BA.SYS
2007-10-29 23:03 39,936 —-a-w C:\WINDOWS\system32\drivers\CDAC11BA.EXE
2007-10-29 23:03 30,720 —h–r C:\WINDOWS\CdaC13BA.EXE
2007-10-29 23:03 112,128 —h–r C:\WINDOWS\CdaC14BA.DLL
2007-10-29 00:40 ——— d—–w C:\Documents and Settings\Supraja\Application Data\Creative
2007-10-29 00:38 ——— d—–w C:\Program Files\Creative
2007-10-29 00:35 ——— d—–w C:\Program Files\ArcSoft
2007-10-29 00:26 8,552 —-a-w C:\WINDOWS\system32\drivers\asctrm.sys
2007-10-24 02:47 ——— d—–w C:\Documents and Settings\Supraja\Application Data\AdobeUM
2007-10-21 04:40 ——— d—–w C:\Program Files\Eusing Free Registry Cleaner
2007-10-21 04:27 ——— d—–w C:\Documents and Settings\Supraja\Application Data\DivX
2007-10-21 03:53 ——— d—–w C:\Program Files\Messer
2007-10-21 03:06 ——— d—–w C:\Program Files\Java
2007-10-21 02:56 ——— d—–w C:\Program Files\Windows Media Connect 2
2007-10-20 02:37 ——— d—–w C:\Program Files\Skype
2007-10-20 02:37 ——— d—–w C:\Program Files\Common Files\Skype
2007-10-20 02:37 ——— d—–w C:\Documents and Settings\All Users\Application Data\Skype
2007-10-16 21:34 ——— d—–w C:\Documents and Settings\Supraja\Application Data\Media Player Classic
2007-10-16 03:45 ——— d—–w C:\Program Files\K-Lite Codec Pack
2007-10-15 02:21 ——— d—–w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-10-15 02:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\4200Series
2007-10-15 02:20 ——— d—–w C:\Documents and Settings\All Users\Application Data\4200 Series
2007-10-15 00:52 ——— d—–w C:\Documents and Settings\Supraja\Application Data\Yahoo!
2007-10-15 00:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-10-15 00:15 ——— d—–w C:\Documents and Settings\All Users\Application Data\Yahoo!
2007-10-14 20:28 ——— d—–w C:\Program Files\MSXML 4.0
2007-10-14 03:39 ——— d—–w C:\Documents and Settings\Supraja\Application Data\SopCast
2007-10-14 02:01 ——— d—–w C:\Program Files\Pure Networks
2007-10-14 02:01 ——— d—–w C:\Program Files\Common Files\AOL
2007-10-14 02:00 ——— d—–w C:\Program Files\Toshiba
2007-10-14 01:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-14 01:59 ——— d—–w C:\Documents and Settings\All Users\Application Data\AOL
2007-10-14 01:47 ——— d—–w C:\Program Files\Symantec Client Security
2007-10-14 01:47 ——— d—–w C:\Program Files\Symantec
2007-10-14 01:47 ——— d—–w C:\Documents and Settings\All Users\Application Data\Symantec
.
((((((((((((((((((((((((((((( snapshot@2007-12-03_22.43.48.94 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-02 00:13:04 345,816 —-a-w C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
+ 2007-12-05 07:05:25 585,791 —-a-w C:\WINDOWS\gmer.dll
+ 2007-06-29 17:38:18 581,632 —-a-r C:\WINDOWS\gmer.exe
- 2007-10-14 00:39:55 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2007-12-07 04:39:15 16,384 —-a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2007-10-14 00:39:55 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2007-12-07 04:39:15 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2007-10-14 00:39:55 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-07 04:39:15 32,768 —-a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-05 07:05:25 70,001 —-a-w C:\WINDOWS\system32\drivers\gmer.sys
+ 2007-03-15 20:00:36 466,432 —-a-w C:\WINDOWS\system32\SkanerOnline.dll
+ 2007-01-19 17:40:42 89,088 —-a-w C:\WINDOWS\system32\SkanerOnlineUninstall.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{245A6CD4-5EA9-B9EB-791A-06F67243094D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B17709EF-4A5E-48B4-9D3C-B43BCC0B1FC4}]
2007-12-02 20:47 336480 –a—— C:\WINDOWS\system32\ljjjg.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 02:24]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [2007-08-30 16:43]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 06:59]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 12:31]
"Free Upload Manager"="C:\Program Files\Free Download Manager\fum\fum.exe" [2007-07-29 19:13]
"Free Uploader Oe Integration"="C:\Program Files\Free Download Manager\FUM\fumoei.exe" [2007-06-10 18:02]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-10-08 07:31]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-10-08 07:27]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-07-27 12:48]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2004-08-06 07:27]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-09-05 16:16]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-28 13:37 C:\WINDOWS\agrsmmsg.exe]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 14:28]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 14:26]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2004-12-14 18:12]
"TPSMain"="TPSMain.exe" [2004-08-27 08:34 C:\WINDOWS\system32\TPSMain.exe]
"Tvs"="C:\Program Files\Toshiba\Tvs\TvsTray.exe" [2004-11-12 16:57]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-09-07 13:03]
"SmoothView"="C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-09-15 14:03]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 04:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 10:27]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 10:31]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 16:37]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2004-02-29 15:44]
"vptray"="C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe" [2004-03-12 14:18]
"lxbmmon.exe"="C:\Program Files\Lexmark 4200 Series\lxbmmon.exe" [2007-01-30 07:38]
"Lexmark 4200 Series Fax Server"="C:\Program Files\Lexmark 4200 Series\fm3032.exe" [2007-01-30 07:42]
"YSearchProtection"="C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe" [2007-06-08 06:59]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-10-19 20:16]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" [2004-07-30 10:04]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-11-05 22:36]
"PCPitstop Disk MD Registration Reminder"="C:\Program Files\PCPitstop\Disk MD\Reminder.exe" [2007-08-22 22:49]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
RAMASST.lnk - C:\WINDOWS\system32\RAMASST.exe [2005-09-28 14:08:20]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-10-15 10:27 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\ljjjg.dll
R0 KR10N;KR10N;C:\WINDOWS\system32\drivers\KR10N.sys
S3 P0630VID;Creative WebCam Live!;C:\WINDOWS\system32\DRIVERS\P0630Vid.sys
S4 lxbm_device;lxbm_device;C:\WINDOWS\system32\lxbmcoms.exe -service
.
Contents of the 'Scheduled Tasks' folder
"2007-12-04 05:40:09 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.ex
- C:\Program Files\AdwareAlert
"2007-12-03 16:48:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-30 23:00:08 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2007-12-04 05:16:09 C:\WINDOWS\Tasks\Registry Repair 5.job"
- C:\Program Files\Migo Software\RegistryRepair5\Registry Repair.exe
"2007-10-14 01:55:03 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-07 23:13:39
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-07 23:15:18 - machine was rebooted
C:\ComboFix2.txt … 2007-12-06 20:14
C:\ComboFix3.txt … 2007-12-04 23:01
.
— E O F —
AND STARTUP LIST REPORT
StartupList report, 12/7/2007, 11:02:41 PM
StartupList version: 1.52.2
Started from : C:\Program Files\Hijackthis\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16544)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Intel\Wireless\Bin\OProtSvc.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\toshiba\ivp\ism\pinger.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Lexmark 4200 Series\lxbmmon.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Free Download Manager\fum\fum.exe
C:\Program Files\Free Download Manager\FUM\fumoei.exe
C:\WINDOWS\system32\RAMASST.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\lxbmcoms.exe
————————————————–
Listing of startup folders:
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
IgfxTray = C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds = C:\WINDOWS\system32\hkcmd.exe
SoundMAXPnP = C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
SoundMAX = C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
LtMoh = C:\Program Files\ltmoh\Ltmoh.exe
AGRSMMSG = AGRSMMSG.exe
SynTPLpr = C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh = C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
THotkey = C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
TPSMain = TPSMain.exe
Tvs = C:\Program Files\Toshiba\Tvs\TvsTray.exe
PadTouch = C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
SmoothView = C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
dla = C:\WINDOWS\system32\dla\tfswctrl.exe
IntelWireless = C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
EOUApp = C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
Pinger = c:\toshiba\ivp\ism\pinger.exe /run
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
vptray = C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
lxbmmon.exe = "C:\Program Files\Lexmark 4200 Series\lxbmmon.exe"
Lexmark 4200 Series Fax Server = "C:\Program Files\Lexmark 4200 Series\fm3032.exe" /s
YSearchProtection = "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
QuickTime Task = "C:\Program Files\QuickTime\QTTask.exe" -atboottime
SunJavaUpdateSched = "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
Creative WebCam Tray = C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
TkBellExe = "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
PCPitstop Disk MD Registration Reminder = C:\Program Files\PCPitstop\Disk MD\Reminder.exe
b04f65fd = rundll32.exe "C:\WINDOWS\system32\vrlxeobx.dll",b
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
TOSCDSPD = C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
Yahoo! Pager = "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
YSearchProtection = C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
Skype = "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
Free Upload Manager = "C:\Program Files\Free Download Manager\fum\fum.exe" -autorun
Free Uploader Oe Integration = C:\Program Files\Free Download Manager\FUM\fumoei.exe
————————————————–
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Task Scheduler jobs:
AdwareAlert Scheduled Scan.job
AppleSoftwareUpdate.job
Norton Security Scan.job
Registry Repair 5.job
Symantec NetDetect.job
————————————————–
Enumerating Download Program Files:
[TDServer Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\tdserver.ocx
CODEBASE = http://www.andhrajyothy.com/wfplayer/tdserver.cab
[ScrabbleCubes Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\SCRABB~1.OCX
CODEBASE = http://www.worldwinner.com/games/v46/scrab…rabblecubes.cab
[PCPitstop Utility]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\PCPitstop.dll
CODEBASE = http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\Director\SwDir.dll
CODEBASE = http://fpdownload.macromedia.com/get/shock…director/sw.cab
[Installation Support]
InProcServer32 = C:\Program Files\Yahoo!\Common\Yinsthelper.dll
CODEBASE = C:\Program Files\Yahoo!\Common\Yinsthelper.dll
[iNotes6 Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\inotes6W.dll
CODEBASE = https://my-remote.johnsoncontrols.com/https…om/iNotes6W.cab
[DivXBrowserPlugin Object]
InProcServer32 = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CODEBASE = http://download.divx.com/player/DivXBrowserPlugin.cab
[MksSkanerOnline Class]
InProcServer32 = C:\WINDOWS\system32\SkanerOnline.dll
CODEBASE = http://www.mks.com.pl/skaner/SkanerOnline.cab
[FreeCell Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\freecell.ocx
CODEBASE = http://www.worldwinner.com/games/v41/freecell/freecell.cab
[Wwlaunch Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\wwlaunch.ocx
CODEBASE = http://www.worldwinner.com/games/shared/wwlaunch.cab
[SopCore Control]
InProcServer32 = C:\PROGRA~1\SopCast\ActiveX\SopCore.ocx
CODEBASE = http://download.sopcast.com/download/SOPCORE.CAB
[{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}]
CODEBASE = http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9d.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab
[H2hPool Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\h2hpool.ocx
CODEBASE = http://www.worldwinner.com/games/v53/h2hpool/h2hpool.cab
[Jaxtr Outlook Importer]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\JaxtrOutlookImporter.dll
CODEBASE = http://www.jaxtr.com/user/activex/JaxtrOutlookImporter.CAB
————————————————–
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\WINDOWS\system32\jhklquhb.exe => C:\DOCUME~1\Supraja\LOCALS~1\Temp\temp.fr1974|||
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll
WPDShServiceObj: C:\WINDOWS\system32\WPDShServiceObj.dll
————————————————–
End of report, 10,643 bytes
Report generated in 0.020 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Appreciate your help