This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Homepage Hijacked :(

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear WTT,

It seems my homepage has been hijacked by http://ahomepcsafety.com/

I am worried that it has done some damage to my computer.

I downloaded SpyBot yesterday but that does not seem to remove it.

I have just downloaded Hijackthis and immediately did a scan which is included below.

Many thanks for your help in advance.


Logfile of HijackThis v1.99.1
Scan saved at 21:02:16, on 08/01/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\T-Mobile\web'n'walk USB manager\web'n'walk USB manager.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.boston.com/ae/music/gallery/world_music_awards/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: (no name) - {2012F73E-7427-4AD8-9E9D-6CBA6E0053D4} - C:\Program Files\Video Add-on\isfmdl.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{02E5C13B-B702-4963-AEF4-D4B3BD67065A}: NameServer = 149.254.192.126 149.254.201.126
O17 - HKLM\System\CS1\Services\Tcpip\..\{02E5C13B-B702-4963-AEF4-D4B3BD67065A}: NameServer = 149.254.192.126 149.254.201.126
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
Hello and welcome to the forum. Sorry about the delay in responding :( If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread. Also please describe how your computer behaves at the moment.
Hiya,

No problem with the delay, I appreciate your help. Sorry it has taken a few days to reply to your response, I was away for a while.

I used SpyBot just before I left and it seemed to remove the hijacked homepage, but I'm not sure if my computer is okay. Following your message I have just tried to do another HiJackThis scan and save log, but a message comes up that says:

"For some reason your system denied write access to the Hosts file. If any hijacked domains are in this file HiJackThis may NOT be able to fix this. If that happens, you need to edit the file yourself. To do this, click Start, Run and type: notepad "C:\Windows\System32\drivers\etc\hosts" and press Enter. Find the line(s) HiJackThis reports and delete them. Save this file as "hosts," (with quotes), and reboot"

My computer seems to be fine, but it's very new and I'm not sure if it is fixed, sorry if I'm sounding vague.

Here is a scan I have just taken.


Logfile of HijackThis v1.99.1
Scan saved at 18:13:11, on 15/01/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\T-Mobile\web'n'walk USB manager\web'n'walk USB manager.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: WlanUtility.lnk = C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
That error about the host file is normal using Vista.

Just a little cleanup

Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O13 - Gopher Prefix:

Close ALL windows and browsers except HijackThis and click "Fix checked"

Reboot
Also please describe how your computer behaves at the moment.
Hello,

Thank you for your reply.

Well I rang a HiJackThis, System Scan Only and was going to click on the boxes you mentioned but noticed that the first 2 lines were different to what you had written, is this a problem or should I check the boxes anyway? Maybe they are there but I just can't see them, please tell me if that's the case.

The last 2 lines seem to be there. I was just going to check these two but thought I would check with you first.

My computer seems to be working fine I think. I say think only because I've had the computer for just 3 weeks and have mainly been on the internet.

I have included the scan I have just taken.

Many thanks,

elbaroni



Logfile of HijackThis v1.99.1
Scan saved at 23:50:42, on 16/01/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\T-Mobile\web'n'walk USB manager\web'n'walk USB manager.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: WlanUtility.lnk = C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{02E5C13B-B702-4963-AEF4-D4B3BD67065A}: NameServer = 149.254.192.126 149.254.201.126
O17 - HKLM\System\CS1\Services\Tcpip\..\{02E5C13B-B702-4963-AEF4-D4B3BD67065A}: NameServer = 149.254.192.126 149.254.201.126
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
You want to remove the ones that show ie.redirect


You need To disable TeaTimer, it can stop our fix.

1) Run Spybot-S&D
2) Go to the Mode menu, and make sure "Advanced Mode" is selected
3) On the left hand side, choose Tools -> Resident
4) Uncheck "Resident TeaTimer" and OK any prompts

The best way is to do both, Right click the system tray icon and shut down. This will reset TT's registry snapshot. Then, open spybot in advanced mode and turn it off. When cleaning is done, open Spybot in advanced mode to turn back on.

Once fix is completed in the all clear post!!

Enable Teatimer

Open Spybot
Click on Tools in bottom left hand corner.
Click on Resident.
Check Resident "TeaTimer" box.
Click on Allow change ONLY to popup box with:
Entry: SpybotSD Teatimer
Click on Mode, select Default mode
Close Spybot




Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O13 - Gopher Prefix:

Close ALL windows and browsers except HijackThis and click "Fix checked"


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hello again,

Apologies, please ignore my previous email. When I looked at my reply I realised my error. I checked the boxes and clicked fix now.

I think my computer is fine. I was worried that when my homepage was hijacked they had somehow found a way in to my computer.

I have included a scan.

Thank you,

elbaroni



Logfile of HijackThis v1.99.1
Scan saved at 00:35:19, on 17/01/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Napster\napster.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\T-Mobile\web'n'walk USB manager\web'n'walk USB manager.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: WlanUtility.lnk = C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{02E5C13B-B702-4963-AEF4-D4B3BD67065A}: NameServer = 149.254.192.126 149.254.201.126
O17 - HKLM\System\CS1\Services\Tcpip\..\{02E5C13B-B702-4963-AEF4-D4B3BD67065A}: NameServer = 149.254.192.126 149.254.201.126
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Hi, Thank you for this. I have to go away for the weekend and will not have access to my computer. I will download and follow your instructions when I return on Monday evening. Have a good weekend. elbaroni
Hiya,

Hope u had a good wkend :) I downloaded ComboFix and followed the prompts. I have included the report and also save the latest log from HijackThis.

My computer seems to be running fine also.

Below is the ComboFix report:



ComboFix 08-01-20.1 - Andy 2008-01-21 18:00:24.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1163 [GMT 0:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Helper
C:\Windows\system32\x64

.
((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-21 17:59 . 2000-08-31 08:00 51,200 –a—— C:\Windows\NirCmd.exe
2008-01-15 20:09 . 2008-01-15 20:09 d——– C:\Users\Andy\AppData\Roaming\HP
2008-01-15 20:09 . 2008-01-15 20:09 d——– C:\Users\Andy\AppData\Roaming\CyberLink
2008-01-10 21:32 . 2008-01-10 21:32 d——– C:\Users\Andy\AppData\Roaming\Leadertech
2008-01-10 20:57 . 2008-01-17 02:42 d——– C:\Users\Andy\AppData\Roaming\Azureus
2008-01-10 20:57 . 2008-01-10 20:57 d——– C:\Users\All Users\Azureus
2008-01-10 20:57 . 2008-01-10 20:57 d——– C:\ProgramData\Azureus
2008-01-10 20:54 . 2008-01-10 20:57 d——– C:\Program Files\Azureus
2008-01-10 20:26 . 2008-01-10 20:26 246,294,913 –a—— C:\Windows\MEMORY.DMP
2008-01-10 19:41 . 2003-09-15 14:10 68,408 –a—— C:\Windows\System32\drivers\ws01uph.bin
2008-01-10 19:41 . 2003-09-15 14:10 40,832 –a—— C:\Windows\System32\drivers\ms6823.sys
2008-01-10 19:39 . 2008-01-10 19:39 d——– C:\Program Files\WLAN
2008-01-09 03:03 . 2008-01-09 03:03 802,816 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-01-09 03:03 . 2008-01-09 03:03 216,760 –a—— C:\Windows\System32\drivers\netio.sys
2008-01-09 03:03 . 2008-01-09 03:03 167,424 –a—— C:\Windows\System32\tcpipcfg.dll
2008-01-09 03:03 . 2008-01-09 03:03 24,064 –a—— C:\Windows\System32\netcfg.exe
2008-01-09 03:03 . 2008-01-09 03:03 22,016 –a—— C:\Windows\System32\netiougc.exe
2008-01-09 03:02 . 2008-01-09 03:02 4,247,552 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-09 03:02 . 2008-01-09 03:02 1,686,016 –a—— C:\Windows\System32\gameux.dll
2008-01-09 03:02 . 2008-01-09 03:02 1,060,920 –a—— C:\Windows\System32\drivers\ntfs.sys
2008-01-09 03:02 . 2008-01-09 03:02 211,000 –a—— C:\Windows\System32\drivers\volsnap.sys
2008-01-09 03:02 . 2008-01-09 03:02 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-01-09 03:02 . 2008-01-09 03:02 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-01-09 03:02 . 2008-01-09 03:02 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-01-09 03:02 . 2008-01-09 03:02 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-01-09 03:02 . 2008-01-09 03:02 15,928 –a—— C:\Windows\System32\drivers\pciide.sys
2008-01-09 03:01 . 2008-01-09 03:01 11,776 –a—— C:\Windows\System32\sbunattend.exe
2008-01-07 01:49 . 2008-01-07 02:28 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-01-07 01:49 . 2008-01-07 02:28 d——– C:\ProgramData\Spybot - Search & Destroy
2008-01-06 19:38 . 2008-01-06 19:38 d——– C:\Users\All Users\LightScribe
2008-01-06 19:38 . 2008-01-06 19:38 d——– C:\ProgramData\LightScribe
2008-01-03 19:21 . 2008-01-03 19:21 d——– C:\Users\Andy\AppData\Roaming\AdobeUM
2008-01-03 19:16 . 2008-01-03 19:16 d——– C:\Users\Andy\AppData\Roaming\Nokia Multimedia Player
2008-01-01 14:26 . 2008-01-01 14:26 d——– C:\Users\Andy\AppData\Roaming\NSeries
2008-01-01 14:03 . 2008-01-01 14:03 d——– C:\Users\All Users\Nokia
2008-01-01 14:03 . 2008-01-01 14:03 d——– C:\ProgramData\Nokia
2008-01-01 14:03 . 2008-01-01 14:03 d——– C:\Program Files\Common Files\Nokia
2008-01-01 14:01 . 2008-01-03 19:08 d——– C:\Users\Andy\AppData\Roaming\Nokia
2008-01-01 14:01 . 2008-01-01 14:25 d——– C:\Users\All Users\PC Suite
2008-01-01 14:01 . 2008-01-01 14:25 d——– C:\ProgramData\PC Suite
2008-01-01 14:00 . 2008-01-01 14:00 d——– C:\Program Files\Common Files\PCSuite
2008-01-01 13:57 . 2008-01-01 14:01 d——– C:\Users\Andy\AppData\Roaming\PC Suite
2008-01-01 13:57 . 2008-01-01 13:57 d——– C:\Program Files\PC Connectivity Solution
2008-01-01 13:55 . 2008-01-01 14:03 d——– C:\Program Files\Nokia
2008-01-01 13:55 . 2007-02-22 10:15 90,624 –a—— C:\Windows\System32\nmwcdcls.dll
2007-12-29 13:59 . 2007-12-29 13:59 d——– C:\Users\Andy\AppData\Roaming\Template
2007-12-29 13:59 . 2008-01-08 23:50 294 –a—— C:\Users\Andy\AppData\Roaming\wklnhst.dat
2007-12-29 03:51 . 2008-01-21 17:52 d——– C:\Users\Andy\AppData\Roaming\Skype
2007-12-29 03:51 . 2007-12-29 03:51 d——– C:\Users\All Users\Skype
2007-12-29 03:51 . 2007-12-29 03:51 d——– C:\ProgramData\Skype
2007-12-29 03:51 . 2007-12-29 03:51 d——– C:\Program Files\Skype
2007-12-26 18:56 . 2007-12-26 18:56 d——– C:\Program Files\eMule
2007-12-26 17:38 . 2007-12-26 17:38 1,327,104 –a—— C:\Windows\System32\quartz.dll
2007-12-26 17:38 . 2007-12-26 17:38 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2007-12-26 17:38 . 2007-12-26 17:38 223,232 –a—— C:\Windows\System32\WMASF.DLL
2007-12-26 17:38 . 2007-12-26 17:38 9,728 –a—— C:\Windows\System32\LAPRXY.DLL
2007-12-26 17:38 . 2007-12-26 17:38 2,048 –a—— C:\Windows\System32\asferror.dll
2007-12-26 17:37 . 2007-12-26 17:37 737,792 –a—— C:\Windows\System32\inetcomm.dll
2007-12-26 17:37 . 2007-12-26 17:37 84,480 –a—— C:\Windows\System32\INETRES.dll
2007-12-26 17:35 . 2007-12-26 17:35 788,992 –a—— C:\Windows\System32\rpcrt4.dll
2007-12-26 17:34 . 2007-12-26 17:34 d——– C:\Program Files\MSXML 4.0
2007-12-26 17:34 . 2007-12-26 17:34 3,504,824 –a—— C:\Windows\System32\ntkrnlpa.exe
2007-12-26 17:34 . 2007-12-26 17:34 3,470,520 –a—— C:\Windows\System32\ntoskrnl.exe
2007-12-26 17:34 . 2007-12-26 17:34 2,048 –a—— C:\Windows\System32\tzres.dll
2007-12-26 17:15 . 2007-12-26 17:15 1,712,984 –a—— C:\Windows\System32\wuaueng.dll
2007-12-26 17:15 . 2007-12-26 17:15 1,524,224 –a—— C:\Windows\System32\wucltux.dll
2007-12-26 17:15 . 2007-12-26 17:15 549,720 –a—— C:\Windows\System32\wuapi.dll
2007-12-26 17:15 . 2007-12-26 17:15 163,000 –a—— C:\Windows\System32\wuwebv.dll
2007-12-26 17:15 . 2007-12-26 17:15 80,896 –a—— C:\Windows\System32\wudriver.dll
2007-12-26 17:15 . 2007-12-26 17:15 53,080 –a—— C:\Windows\System32\wuauclt.exe
2007-12-26 17:15 . 2007-12-26 17:15 43,352 –a—— C:\Windows\System32\wups2.dll
2007-12-26 17:15 . 2007-12-26 17:15 33,624 –a—— C:\Windows\System32\wups.dll
2007-12-26 17:15 . 2007-12-26 17:15 31,232 –a—— C:\Windows\System32\wuapp.exe
2007-12-26 17:11 . 2007-03-05 07:53 92,032 –a—— C:\Windows\System32\drivers\ewusbmdm.sys
2007-12-26 17:11 . 2007-03-05 07:52 23,424 –a—— C:\Windows\System32\drivers\ewdcsc.sys
2007-12-26 17:10 . 2007-12-26 17:10 d——– C:\Program Files\T-Mobile
2007-12-26 16:15 . 2007-12-26 17:28 16 –a—— C:\Windows\System32\coh.cache
2007-12-26 15:58 . 2007-12-26 15:58 dr——- C:\Users\Andy\Searches
2007-12-26 15:58 . 2007-12-26 15:58 dr——- C:\Users\Andy\Contacts
2007-12-26 15:56 . 2007-12-26 15:56 44 –a—— C:\Windows\system\hpsysdrv.dat
2007-12-26 15:56 . 2007-12-26 15:56 0 -rahs—- C:\Windows\System32\drivers\103C_HP_cNB_G7000 Notebook PC_Y5335KV_0U_QCND7461K1L_E447154-032_4A_I30D9_SHP_V83.19_F.08_T070913_WV3-0_L409_M2038_J160_7Intel_86FD_91.47_#071226_N10EC8139_(GZ902EA#ABU)_XMOBILE_CN10
_Z_2F.08_G80862A02;80862A03.MRK
2007-12-26 15:52 . 2007-12-26 15:52 d——– C:\Users\Andy\AppData\Roaming\Hewlett-Packard
2007-12-26 15:49 . 2008-01-05 23:04 dr——- C:\Users\Andy\Videos
2007-12-26 15:49 . 2007-12-26 15:58 dr——- C:\Users\Andy\Saved Games
2007-12-26 15:49 . 2008-01-09 00:00 dr——- C:\Users\Andy\Pictures
2007-12-26 15:49 . 2008-01-17 01:05 dr——- C:\Users\Andy\Music
2007-12-26 15:49 . 2007-12-26 15:58 dr——- C:\Users\Andy\Links
2007-12-26 15:49 . 2008-01-21 17:50 dr——- C:\Users\Andy\Downloads
2007-12-26 15:49 . 2008-01-17 00:35 dr——- C:\Users\Andy\Documents
2007-12-26 15:49 . 2006-11-02 12:37 d——– C:\Users\Andy\AppData\Roaming\Media Center Programs
2007-12-26 15:49 . 2007-12-26 15:58 d–h—– C:\Users\Andy\AppData
2007-12-26 15:49 . 2007-12-26 15:49 81 –a—— C:\Windows\System32\LOG
2007-12-26 15:42 . 2007-12-26 15:42 dr——- C:\Windows\System32\config\systemprofile\Contacts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 20:09 ——— d—–w C:\ProgramData\HP
2008-01-09 03:20 ——— d—–w C:\Program Files\Windows Sidebar
2008-01-09 03:20 ——— d—–w C:\Program Files\Windows Mail
2008-01-09 03:02 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-09 03:02 449,024 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-09 03:02 2,143,744 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-09 03:02 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-06 19:05 ——— d—–w C:\ProgramData\Symantec
2007-12-26 23:50 ——— d—–w C:\ProgramData\Microsoft Help
2007-12-26 18:33 ——— d—–w C:\Program Files\Norton Internet Security
2007-12-26 18:33 ——— d—–w C:\Program Files\Google
2007-12-26 18:29 805 —-a-w C:\Windows\system32\drivers\SYMEVENT.INF
2007-12-26 18:29 123,952 —-a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2007-12-26 18:29 10,740 —-a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2007-12-26 18:29 ——— d—–w C:\Program Files\Symantec
2007-12-26 18:28 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-26 17:40 704,000 —-a-w C:\Windows\System32\PhotoScreensaver.scr
2007-12-26 17:40 67,584 —-a-w C:\Windows\System32\wlanhlp.dll
2007-12-26 17:40 542,720 —-a-w C:\Windows\System32\sysmain.dll
2007-12-26 17:40 502,784 —-a-w C:\Windows\System32\wlansvc.dll
2007-12-26 17:40 47,104 —-a-w C:\Windows\System32\wlanapi.dll
2007-12-26 17:40 299,008 —-a-w C:\Windows\System32\wlansec.dll
2007-12-26 17:40 289,280 —-a-w C:\Windows\System32\wlanmsm.dll
2007-12-26 17:40 28,344 —-a-w C:\Windows\system32\drivers\battc.sys
2007-12-26 17:40 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2007-12-26 17:40 24,064 —-a-w C:\Windows\System32\wtsapi32.dll
2007-12-26 17:40 20,920 —-a-w C:\Windows\system32\drivers\compbatt.sys
2007-12-26 17:40 2,923,520 —-a-w C:\Windows\explorer.exe
2007-12-26 17:40 2,027,008 —-a-w C:\Windows\System32\win32k.sys
2007-12-26 17:40 14,208 —-a-w C:\Windows\system32\drivers\CmBatt.sys
2007-12-26 17:40 11,264 —-a-w C:\Windows\system32\drivers\wmiacpi.sys
2007-12-26 17:39 86,016 —-a-w C:\Windows\System32\icfupgd.dll
2007-12-26 17:39 8,147,968 —-a-w C:\Windows\System32\wmploc.DLL
2007-12-26 17:39 7,680 —-a-w C:\Windows\System32\spwmp.dll
2007-12-26 17:39 63,488 —-a-w C:\Windows\system32\drivers\mpsdrv.sys
2007-12-26 17:39 61,952 —-a-w C:\Windows\System32\cmifw.dll
2007-12-26 17:39 4,096 —-a-w C:\Windows\System32\dxmasf.dll
2007-12-26 17:39 396,800 —-a-w C:\Windows\System32\MPSSVC.dll
2007-12-26 17:39 392,192 —-a-w C:\Windows\System32\FirewallAPI.dll
2007-12-26 17:39 356,864 —-a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-12-26 17:39 23,040 —-a-w C:\Windows\system32\drivers\tunnel.sys
2007-12-26 17:39 178,688 —-a-w C:\Windows\System32\iphlpsvc.dll
2007-12-26 17:39 16,896 —-a-w C:\Windows\System32\wfapigp.dll
2007-12-26 17:39 15,360 —-a-w C:\Windows\system32\drivers\TUNMP.SYS
2007-12-26 17:36 84,992 —-a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-26 17:36 824,832 —-a-w C:\Windows\System32\wininet.dll
2007-12-26 17:36 58,368 —-a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-26 17:36 56,320 —-a-w C:\Windows\System32\iesetup.dll
2007-12-26 17:36 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-26 17:36 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2007-12-26 17:36 130,048 —-a-w C:\Windows\system32\drivers\srv2.sys
2007-12-26 17:36 101,888 —-a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Templates
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Start Menu
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Favorites
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Documents
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Desktop
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Application Data
2007-11-30 23:57 43,696 —-a-w C:\Windows\system32\drivers\srtspx.sys
2007-11-30 23:57 317,616 —-a-w C:\Windows\system32\drivers\srtspl.sys
2007-11-30 23:57 279,088 —-a-w C:\Windows\system32\drivers\srtsp.sys
2007-11-30 23:57 10,549 —-a-w C:\Windows\system32\drivers\srtspx.cat
2007-11-30 23:57 10,549 —-a-w C:\Windows\system32\drivers\srtspl.cat
2007-11-30 23:57 10,545 —-a-w C:\Windows\system32\drivers\srtsp.cat
2007-11-30 23:57 1,430 —-a-w C:\Windows\system32\drivers\srtspl.inf
2007-11-30 23:57 1,421 —-a-w C:\Windows\system32\drivers\srtspx.inf
2007-11-30 23:57 1,415 —-a-w C:\Windows\system32\drivers\srtsp.inf
2007-11-01 19:34 8,704 —-a-w C:\Windows\System32\hccoin.dll
2007-11-01 19:34 39,936 —-a-w C:\Windows\System32\dwmapi.dll
2007-11-01 19:34 2,016,256 —-a-w C:\Windows\System32\milcore.dll
2007-11-01 19:33 22,632 —-a-w C:\Windows\System32\streamci.dll
2007-11-01 18:53 174 –sha-w C:\Program Files\desktop.ini
2007-11-01 18:21 750,080 —-a-w C:\Windows\System32\qmgr.dll
2007-11-01 18:19 88,576 —-a-w C:\Windows\System32\avifil32.dll
2007-11-01 18:19 82,944 —-a-w C:\Windows\System32\mciavi32.dll
2007-11-01 18:19 8,138,240 —-a-w C:\Windows\System32\ssBranded.scr
2007-11-01 18:19 712,192 —-a-w C:\Windows\System32\WindowsCodecs.dll
2007-11-01 18:19 69,632 —-a-w C:\Windows\System32\sendmail.dll
2007-11-01 18:19 65,024 —-a-w C:\Windows\System32\avicap32.dll
2007-11-01 18:19 61,440 —-a-w C:\Windows\System32\ntprint.exe
2007-11-01 18:19 31,232 —-a-w C:\Windows\System32\msvidc32.dll
2007-11-01 18:19 269,824 —-a-w C:\Windows\System32\schannel.dll
2007-11-01 18:19 220,160 —-a-w C:\Windows\System32\ntprint.dll
2007-11-01 18:19 123,904 —-a-w C:\Windows\System32\msvfw32.dll
2007-11-01 18:19 120,320 —-a-w C:\Windows\System32\dhcpcsvc6.dll
2007-11-01 18:19 12,800 —-a-w C:\Windows\System32\msrle32.dll
2007-11-01 18:19 10,240 —-a-w C:\Windows\System32\dhcpcmonitor.dll
2007-11-01 18:19 1,984,512 —-a-w C:\Windows\System32\authui.dll
2007-11-01 18:18 25,600 —-a-w C:\Windows\System32\LangCleanupSysprepAction.dll
2007-11-01 18:18 23,552 —-a-w C:\Windows\System32\lpremove.exe
2007-11-01 18:18 166,912 —-a-w C:\Windows\System32\lpksetup.exe
2007-11-01 18:18 10,240 —-a-w C:\Windows\System32\MUILanguageCleanup.dll
2007-11-01 18:17 8,192 —-a-w C:\Windows\System32\riched32.dll
2007-11-01 18:17 77,824 —-a-w C:\Windows\System32\rascfg.dll
2007-11-01 18:17 694,784 —-a-w C:\Windows\System32\localspl.dll
2007-11-01 18:17 52,736 —-a-w C:\Windows\System32\rasdiag.dll
2007-11-01 18:17 384,000 —-a-w C:\Windows\System32\netcfgx.dll
2007-11-01 18:17 36,864 —-a-w C:\Windows\System32\cdd.dll
2007-11-01 18:17 33,280 —-a-w C:\Windows\System32\traffic.dll
2007-11-01 18:17 32,768 —-a-w C:\Windows\System32\rasmxs.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 03:01 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 12:34 2159104 C:\Windows\System32\oobefldr.dll]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 20:26 484904]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 12:35 125440]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-07-14 00:41 20034600]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 12:36 201728]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-11-01 18:00 1006264]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2006-11-07 20:57 159744]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 11:59 115816]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-06-06 11:52 142104]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-06-06 11:52 154392]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-06-06 11:52 138008]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-03-29 00:45 176128]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2007-01-13 02:36 323216]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-06-11 15:57 184320]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 18:54 50696]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 20:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 23:12 317128]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 06:11 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-11-01 19:47 77824]
"NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 14:44 3100672]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 08:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 07:01:50 734872]
WlanUtility.lnk - C:\Program Files\WLAN\WLANUtility\WlanUtility.exe [2003-10-28 18:09:42 70656]

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080116.003\IDSvix86.sys [2007-12-04 17:51]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot []
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-01-29 22:23]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-05-31 10:51]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-10-30 19:55]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-01-03 15:43]
S3 ms6823;IEEE802.11b Wireless USB Adapter;C:\Windows\system32\DRIVERS\ms6823.sys [2003-09-15 14:10]
S3 NETw3v32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 07:30]
S3 NETw4v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-05-04 14:11]
S3 RTSTOR;USB Mass Storage Device;C:\Windows\system32\drivers\RTSTOR.SYS [2007-05-12 03:09]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{111fd7b2-b3e1-11dc-b057-001b388ebf06}]
\shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{111fd7b3-b3e1-11dc-b057-001b388ebf06}]
\shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42975d1-b3c9-11dc-87c8-001b388ebf06}]
\shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42975fc-b3c9-11dc-87c8-001b388ebf06}]
\shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42975fe-b3c9-11dc-87c8-001b388ebf06}]
\shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4297613-b3c9-11dc-87c8-001b388ebf06}]
\shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42980af-b3c9-11dc-87c8-001b388ebf06}]
\shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42980b0-b3c9-11dc-87c8-001b388ebf06}]
\shell\AutoRun\command - F:\AutoRun.exe

*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-01-14 20:08:46 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Andy.job"
- c:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-01-21 01:00:20 C:\Windows\Tasks\User_Feed_Synchronization-{D0E902B5-6EE6-4251-9584-7789EFA8150B}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-21 18:03:10
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-21 18:04:15
.
2008-01-21 00:59:29 — E O F —



Here is the HijackThis log:


Logfile of HijackThis v1.99.1
Scan saved at 18:06:17, on 21/01/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\Explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Windows\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: WlanUtility.lnk = C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
Download & run this file
http://www.techsupportforum.com/sectools/s…Disinfector.exe

Be sure to insert any flash drives or USB devices that you use.

Next:

Open notepad and copy/paste the text in the quotebox below into it:

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{111fd7b2-b3e1-11dc-b057-001b388ebf06}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{111fd7b3-b3e1-11dc-b057-001b388ebf06}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42975d1-b3c9-11dc-87c8-001b388ebf06}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42975fc-b3c9-11dc-87c8-001b388ebf06}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42975fe-b3c9-11dc-87c8-001b388ebf06}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f4297613-b3c9-11dc-87c8-001b388ebf06}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42980af-b3c9-11dc-87c8-001b388ebf06}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f42980b0-b3c9-11dc-87c8-001b388ebf06}]


Save this as Save this as "CFScript"


[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Hi,

Thanks for the mail. I've done as requested and include the logs below:


My computer seems to be running well from what I can tell.

Thanx,

e



ComboFix 08-01-20.1 - Andy 2008-01-21 23:00:21.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.984 [GMT 0:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\Andy\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2007-12-21 to 2008-01-21 )))))))))))))))))))))))))))))))
.

2008-01-21 17:59 . 2000-08-31 08:00 51,200 –a—— C:\Windows\NirCmd.exe
2008-01-15 20:09 . 2008-01-15 20:09 d——– C:\Users\Andy\AppData\Roaming\HP
2008-01-15 20:09 . 2008-01-15 20:09 d——– C:\Users\Andy\AppData\Roaming\CyberLink
2008-01-10 21:32 . 2008-01-10 21:32 d——– C:\Users\Andy\AppData\Roaming\Leadertech
2008-01-10 20:57 . 2008-01-21 23:03 d——– C:\Users\Andy\AppData\Roaming\Azureus
2008-01-10 20:57 . 2008-01-10 20:57 d——– C:\Users\All Users\Azureus
2008-01-10 20:57 . 2008-01-10 20:57 d——– C:\ProgramData\Azureus
2008-01-10 20:54 . 2008-01-10 20:57 d——– C:\Program Files\Azureus
2008-01-10 20:26 . 2008-01-10 20:26 246,294,913 –a—— C:\Windows\MEMORY.DMP
2008-01-10 19:41 . 2003-09-15 14:10 68,408 –a—— C:\Windows\System32\drivers\ws01uph.bin
2008-01-10 19:41 . 2003-09-15 14:10 40,832 –a—— C:\Windows\System32\drivers\ms6823.sys
2008-01-10 19:39 . 2008-01-10 19:39 d——– C:\Program Files\WLAN
2008-01-09 03:03 . 2008-01-09 03:03 802,816 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-01-09 03:03 . 2008-01-09 03:03 216,760 –a—— C:\Windows\System32\drivers\netio.sys
2008-01-09 03:03 . 2008-01-09 03:03 167,424 –a—— C:\Windows\System32\tcpipcfg.dll
2008-01-09 03:03 . 2008-01-09 03:03 24,064 –a—— C:\Windows\System32\netcfg.exe
2008-01-09 03:03 . 2008-01-09 03:03 22,016 –a—— C:\Windows\System32\netiougc.exe
2008-01-09 03:02 . 2008-01-09 03:02 4,247,552 –a—— C:\Windows\System32\GameUXLegacyGDFs.dll
2008-01-09 03:02 . 2008-01-09 03:02 1,686,016 –a—— C:\Windows\System32\gameux.dll
2008-01-09 03:02 . 2008-01-09 03:02 1,060,920 –a—— C:\Windows\System32\drivers\ntfs.sys
2008-01-09 03:02 . 2008-01-09 03:02 211,000 –a—— C:\Windows\System32\drivers\volsnap.sys
2008-01-09 03:02 . 2008-01-09 03:02 154,624 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-01-09 03:02 . 2008-01-09 03:02 109,624 –a—— C:\Windows\System32\drivers\ataport.sys
2008-01-09 03:02 . 2008-01-09 03:02 45,112 –a—— C:\Windows\System32\drivers\pciidex.sys
2008-01-09 03:02 . 2008-01-09 03:02 21,560 –a—— C:\Windows\System32\drivers\atapi.sys
2008-01-09 03:02 . 2008-01-09 03:02 15,928 –a—— C:\Windows\System32\drivers\pciide.sys
2008-01-09 03:01 . 2008-01-09 03:01 11,776 –a—— C:\Windows\System32\sbunattend.exe
2008-01-07 01:49 . 2008-01-07 02:28 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-01-07 01:49 . 2008-01-07 02:28 d——– C:\ProgramData\Spybot - Search & Destroy
2008-01-06 19:38 . 2008-01-06 19:38 d——– C:\Users\All Users\LightScribe
2008-01-06 19:38 . 2008-01-06 19:38 d——– C:\ProgramData\LightScribe
2008-01-03 19:21 . 2008-01-03 19:21 d——– C:\Users\Andy\AppData\Roaming\AdobeUM
2008-01-03 19:16 . 2008-01-03 19:16 d——– C:\Users\Andy\AppData\Roaming\Nokia Multimedia Player
2008-01-01 14:26 . 2008-01-01 14:26 d——– C:\Users\Andy\AppData\Roaming\NSeries
2008-01-01 14:03 . 2008-01-01 14:03 d——– C:\Users\All Users\Nokia
2008-01-01 14:03 . 2008-01-01 14:03 d——– C:\ProgramData\Nokia
2008-01-01 14:03 . 2008-01-01 14:03 d——– C:\Program Files\Common Files\Nokia
2008-01-01 14:01 . 2008-01-03 19:08 d——– C:\Users\Andy\AppData\Roaming\Nokia
2008-01-01 14:01 . 2008-01-01 14:25 d——– C:\Users\All Users\PC Suite
2008-01-01 14:01 . 2008-01-01 14:25 d——– C:\ProgramData\PC Suite
2008-01-01 14:00 . 2008-01-01 14:00 d——– C:\Program Files\Common Files\PCSuite
2008-01-01 13:57 . 2008-01-01 14:01 d——– C:\Users\Andy\AppData\Roaming\PC Suite
2008-01-01 13:57 . 2008-01-01 13:57 d——– C:\Program Files\PC Connectivity Solution
2008-01-01 13:55 . 2008-01-01 14:03 d——– C:\Program Files\Nokia
2008-01-01 13:55 . 2007-02-22 10:15 90,624 –a—— C:\Windows\System32\nmwcdcls.dll
2007-12-29 13:59 . 2007-12-29 13:59 d——– C:\Users\Andy\AppData\Roaming\Template
2007-12-29 13:59 . 2008-01-08 23:50 294 –a—— C:\Users\Andy\AppData\Roaming\wklnhst.dat
2007-12-29 03:51 . 2008-01-21 22:50 d——– C:\Users\Andy\AppData\Roaming\Skype
2007-12-29 03:51 . 2007-12-29 03:51 d——– C:\Users\All Users\Skype
2007-12-29 03:51 . 2007-12-29 03:51 d——– C:\ProgramData\Skype
2007-12-29 03:51 . 2007-12-29 03:51 d——– C:\Program Files\Skype
2007-12-26 18:56 . 2007-12-26 18:56 d——– C:\Program Files\eMule
2007-12-26 17:38 . 2007-12-26 17:38 1,327,104 –a—— C:\Windows\System32\quartz.dll
2007-12-26 17:38 . 2007-12-26 17:38 1,244,672 –a—— C:\Windows\System32\mcmde.dll
2007-12-26 17:38 . 2007-12-26 17:38 223,232 –a—— C:\Windows\System32\WMASF.DLL
2007-12-26 17:38 . 2007-12-26 17:38 9,728 –a—— C:\Windows\System32\LAPRXY.DLL
2007-12-26 17:38 . 2007-12-26 17:38 2,048 –a—— C:\Windows\System32\asferror.dll
2007-12-26 17:37 . 2007-12-26 17:37 737,792 –a—— C:\Windows\System32\inetcomm.dll
2007-12-26 17:37 . 2007-12-26 17:37 84,480 –a—— C:\Windows\System32\INETRES.dll
2007-12-26 17:35 . 2007-12-26 17:35 788,992 –a—— C:\Windows\System32\rpcrt4.dll
2007-12-26 17:34 . 2007-12-26 17:34 d——– C:\Program Files\MSXML 4.0
2007-12-26 17:34 . 2007-12-26 17:34 3,504,824 –a—— C:\Windows\System32\ntkrnlpa.exe
2007-12-26 17:34 . 2007-12-26 17:34 3,470,520 –a—— C:\Windows\System32\ntoskrnl.exe
2007-12-26 17:34 . 2007-12-26 17:34 2,048 –a—— C:\Windows\System32\tzres.dll
2007-12-26 17:15 . 2007-12-26 17:15 1,712,984 –a—— C:\Windows\System32\wuaueng.dll
2007-12-26 17:15 . 2007-12-26 17:15 1,524,224 –a—— C:\Windows\System32\wucltux.dll
2007-12-26 17:15 . 2007-12-26 17:15 549,720 –a—— C:\Windows\System32\wuapi.dll
2007-12-26 17:15 . 2007-12-26 17:15 163,000 –a—— C:\Windows\System32\wuwebv.dll
2007-12-26 17:15 . 2007-12-26 17:15 80,896 –a—— C:\Windows\System32\wudriver.dll
2007-12-26 17:15 . 2007-12-26 17:15 53,080 –a—— C:\Windows\System32\wuauclt.exe
2007-12-26 17:15 . 2007-12-26 17:15 43,352 –a—— C:\Windows\System32\wups2.dll
2007-12-26 17:15 . 2007-12-26 17:15 33,624 –a—— C:\Windows\System32\wups.dll
2007-12-26 17:15 . 2007-12-26 17:15 31,232 –a—— C:\Windows\System32\wuapp.exe
2007-12-26 17:11 . 2007-03-05 07:53 92,032 –a—— C:\Windows\System32\drivers\ewusbmdm.sys
2007-12-26 17:11 . 2007-03-05 07:52 23,424 –a—— C:\Windows\System32\drivers\ewdcsc.sys
2007-12-26 17:10 . 2007-12-26 17:10 d——– C:\Program Files\T-Mobile
2007-12-26 16:15 . 2007-12-26 17:28 16 –a—— C:\Windows\System32\coh.cache
2007-12-26 15:58 . 2007-12-26 15:58 dr——- C:\Users\Andy\Searches
2007-12-26 15:58 . 2007-12-26 15:58 dr——- C:\Users\Andy\Contacts
2007-12-26 15:56 . 2007-12-26 15:56 44 –a—— C:\Windows\system\hpsysdrv.dat
2007-12-26 15:56 . 2007-12-26 15:56 0 -rahs—- C:\Windows\System32\drivers\103C_HP_cNB_G7000 Notebook PC_Y5335KV_0U_QCND7461K1L_E447154-032_4A_I30D9_SHP_V83.19_F.08_T070913_WV3-0_L409_M2038_J160_7Intel_86FD_91.47_#071226_N10EC8139_(GZ902EA#ABU)_XMOBILE_CN10
_Z_2F.08_G80862A02;80862A03.MRK
2007-12-26 15:52 . 2007-12-26 15:52 d——– C:\Users\Andy\AppData\Roaming\Hewlett-Packard
2007-12-26 15:49 . 2008-01-05 23:04 dr——- C:\Users\Andy\Videos
2007-12-26 15:49 . 2007-12-26 15:58 dr——- C:\Users\Andy\Saved Games
2007-12-26 15:49 . 2008-01-09 00:00 dr——- C:\Users\Andy\Pictures
2007-12-26 15:49 . 2008-01-17 01:05 dr——- C:\Users\Andy\Music
2007-12-26 15:49 . 2007-12-26 15:58 dr——- C:\Users\Andy\Links
2007-12-26 15:49 . 2008-01-21 18:19 dr——- C:\Users\Andy\Downloads
2007-12-26 15:49 . 2008-01-21 18:06 dr——- C:\Users\Andy\Documents
2007-12-26 15:49 . 2006-11-02 12:37 d——– C:\Users\Andy\AppData\Roaming\Media Center Programs
2007-12-26 15:49 . 2007-12-26 15:58 d–h—– C:\Users\Andy\AppData
2007-12-26 15:49 . 2007-12-26 15:49 81 –a—— C:\Windows\System32\LOG
2007-12-26 15:42 . 2007-12-26 15:42 dr——- C:\Windows\System32\config\systemprofile\Contacts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-15 20:09 ——— d—–w C:\ProgramData\HP
2008-01-09 03:20 ——— d—–w C:\Program Files\Windows Sidebar
2008-01-09 03:20 ——— d—–w C:\Program Files\Windows Mail
2008-01-09 03:02 537,600 —-a-w C:\Windows\AppPatch\AcLayers.dll
2008-01-09 03:02 449,024 —-a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-01-09 03:02 2,143,744 —-a-w C:\Windows\AppPatch\AcGenral.dll
2008-01-09 03:02 173,056 —-a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-01-06 19:05 ——— d—–w C:\ProgramData\Symantec
2007-12-26 23:50 ——— d—–w C:\ProgramData\Microsoft Help
2007-12-26 18:33 ——— d—–w C:\Program Files\Norton Internet Security
2007-12-26 18:33 ——— d—–w C:\Program Files\Google
2007-12-26 18:29 805 —-a-w C:\Windows\system32\drivers\SYMEVENT.INF
2007-12-26 18:29 123,952 —-a-w C:\Windows\system32\drivers\SYMEVENT.SYS
2007-12-26 18:29 10,740 —-a-w C:\Windows\system32\drivers\SYMEVENT.CAT
2007-12-26 18:29 ——— d—–w C:\Program Files\Symantec
2007-12-26 18:28 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2007-12-26 17:40 704,000 —-a-w C:\Windows\System32\PhotoScreensaver.scr
2007-12-26 17:40 67,584 —-a-w C:\Windows\System32\wlanhlp.dll
2007-12-26 17:40 542,720 —-a-w C:\Windows\System32\sysmain.dll
2007-12-26 17:40 502,784 —-a-w C:\Windows\System32\wlansvc.dll
2007-12-26 17:40 47,104 —-a-w C:\Windows\System32\wlanapi.dll
2007-12-26 17:40 299,008 —-a-w C:\Windows\System32\wlansec.dll
2007-12-26 17:40 289,280 —-a-w C:\Windows\System32\wlanmsm.dll
2007-12-26 17:40 28,344 —-a-w C:\Windows\system32\drivers\battc.sys
2007-12-26 17:40 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2007-12-26 17:40 24,064 —-a-w C:\Windows\System32\wtsapi32.dll
2007-12-26 17:40 20,920 —-a-w C:\Windows\system32\drivers\compbatt.sys
2007-12-26 17:40 2,923,520 —-a-w C:\Windows\explorer.exe
2007-12-26 17:40 2,027,008 —-a-w C:\Windows\System32\win32k.sys
2007-12-26 17:40 14,208 —-a-w C:\Windows\system32\drivers\CmBatt.sys
2007-12-26 17:40 11,264 —-a-w C:\Windows\system32\drivers\wmiacpi.sys
2007-12-26 17:39 86,016 —-a-w C:\Windows\System32\icfupgd.dll
2007-12-26 17:39 8,147,968 —-a-w C:\Windows\System32\wmploc.DLL
2007-12-26 17:39 7,680 —-a-w C:\Windows\System32\spwmp.dll
2007-12-26 17:39 63,488 —-a-w C:\Windows\system32\drivers\mpsdrv.sys
2007-12-26 17:39 61,952 —-a-w C:\Windows\System32\cmifw.dll
2007-12-26 17:39 4,096 —-a-w C:\Windows\System32\dxmasf.dll
2007-12-26 17:39 396,800 —-a-w C:\Windows\System32\MPSSVC.dll
2007-12-26 17:39 392,192 —-a-w C:\Windows\System32\FirewallAPI.dll
2007-12-26 17:39 356,864 —-a-w C:\Windows\System32\MediaMetadataHandler.dll
2007-12-26 17:39 23,040 —-a-w C:\Windows\system32\drivers\tunnel.sys
2007-12-26 17:39 178,688 —-a-w C:\Windows\System32\iphlpsvc.dll
2007-12-26 17:39 16,896 —-a-w C:\Windows\System32\wfapigp.dll
2007-12-26 17:39 15,360 —-a-w C:\Windows\system32\drivers\TUNMP.SYS
2007-12-26 17:36 84,992 —-a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-26 17:36 824,832 —-a-w C:\Windows\System32\wininet.dll
2007-12-26 17:36 58,368 —-a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-26 17:36 56,320 —-a-w C:\Windows\System32\iesetup.dll
2007-12-26 17:36 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-26 17:36 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2007-12-26 17:36 130,048 —-a-w C:\Windows\system32\drivers\srv2.sys
2007-12-26 17:36 101,888 —-a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Templates
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Start Menu
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Favorites
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Documents
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Desktop
2007-12-26 15:42 ——— d-sh–w C:\ProgramData\Application Data
2007-11-30 23:57 43,696 —-a-w C:\Windows\system32\drivers\srtspx.sys
2007-11-30 23:57 317,616 —-a-w C:\Windows\system32\drivers\srtspl.sys
2007-11-30 23:57 279,088 —-a-w C:\Windows\system32\drivers\srtsp.sys
2007-11-30 23:57 10,549 —-a-w C:\Windows\system32\drivers\srtspx.cat
2007-11-30 23:57 10,549 —-a-w C:\Windows\system32\drivers\srtspl.cat
2007-11-30 23:57 10,545 —-a-w C:\Windows\system32\drivers\srtsp.cat
2007-11-30 23:57 1,430 —-a-w C:\Windows\system32\drivers\srtspl.inf
2007-11-30 23:57 1,421 —-a-w C:\Windows\system32\drivers\srtspx.inf
2007-11-30 23:57 1,415 —-a-w C:\Windows\system32\drivers\srtsp.inf
2007-11-01 19:34 8,704 —-a-w C:\Windows\System32\hccoin.dll
2007-11-01 19:34 39,936 —-a-w C:\Windows\System32\dwmapi.dll
2007-11-01 19:34 2,016,256 —-a-w C:\Windows\System32\milcore.dll
2007-11-01 19:33 22,632 —-a-w C:\Windows\System32\streamci.dll
2007-11-01 18:53 174 –sha-w C:\Program Files\desktop.ini
2007-11-01 18:21 750,080 —-a-w C:\Windows\System32\qmgr.dll
2007-11-01 18:19 88,576 —-a-w C:\Windows\System32\avifil32.dll
2007-11-01 18:19 82,944 —-a-w C:\Windows\System32\mciavi32.dll
2007-11-01 18:19 8,138,240 —-a-w C:\Windows\System32\ssBranded.scr
2007-11-01 18:19 712,192 —-a-w C:\Windows\System32\WindowsCodecs.dll
2007-11-01 18:19 69,632 —-a-w C:\Windows\System32\sendmail.dll
2007-11-01 18:19 65,024 —-a-w C:\Windows\System32\avicap32.dll
2007-11-01 18:19 61,440 —-a-w C:\Windows\System32\ntprint.exe
2007-11-01 18:19 31,232 —-a-w C:\Windows\System32\msvidc32.dll
2007-11-01 18:19 269,824 —-a-w C:\Windows\System32\schannel.dll
2007-11-01 18:19 220,160 —-a-w C:\Windows\System32\ntprint.dll
2007-11-01 18:19 123,904 —-a-w C:\Windows\System32\msvfw32.dll
2007-11-01 18:19 120,320 —-a-w C:\Windows\System32\dhcpcsvc6.dll
2007-11-01 18:19 12,800 —-a-w C:\Windows\System32\msrle32.dll
2007-11-01 18:19 10,240 —-a-w C:\Windows\System32\dhcpcmonitor.dll
2007-11-01 18:19 1,984,512 —-a-w C:\Windows\System32\authui.dll
2007-11-01 18:18 25,600 —-a-w C:\Windows\System32\LangCleanupSysprepAction.dll
2007-11-01 18:18 23,552 —-a-w C:\Windows\System32\lpremove.exe
2007-11-01 18:18 166,912 —-a-w C:\Windows\System32\lpksetup.exe
2007-11-01 18:18 10,240 —-a-w C:\Windows\System32\MUILanguageCleanup.dll
2007-11-01 18:17 8,192 —-a-w C:\Windows\System32\riched32.dll
2007-11-01 18:17 77,824 —-a-w C:\Windows\System32\rascfg.dll
2007-11-01 18:17 694,784 —-a-w C:\Windows\System32\localspl.dll
2007-11-01 18:17 52,736 —-a-w C:\Windows\System32\rasdiag.dll
2007-11-01 18:17 384,000 —-a-w C:\Windows\System32\netcfgx.dll
2007-11-01 18:17 36,864 —-a-w C:\Windows\System32\cdd.dll
2007-11-01 18:17 33,280 —-a-w C:\Windows\System32\traffic.dll
2007-11-01 18:17 32,768 —-a-w C:\Windows\System32\rasmxs.dll
.

((((((((((((((((((((((((((((( snapshot@2008-01-21_18.03.46.10 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-21 17:46:46 67,584 –s-a-w C:\Windows\bootstat.dat
+ 2008-01-21 20:19:03 67,584 –s-a-w C:\Windows\bootstat.dat
- 2008-01-21 17:59:54 217,088 —-a-w C:\Windows\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-21 23:00:09 217,088 —-a-w C:\Windows\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-21 17:59:55 212,992 —-a-w C:\Windows\erdnt\Hiv-backup\Users\00000002\NTUSER.DAT
+ 2008-01-21 23:00:09 212,992 —-a-w C:\Windows\erdnt\Hiv-backup\Users\00000002\NTUSER.DAT
- 2008-01-21 17:59:55 1,134,592 —-a-w C:\Windows\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-21 23:00:09 1,155,072 —-a-w C:\Windows\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-21 17:59:56 2,224,128 —-a-w C:\Windows\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-21 23:00:09 2,224,128 —-a-w C:\Windows\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-21 17:48:18 262,144 —-a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-21 22:34:14 262,144 —-a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-01-21 17:48:57 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-01-21 20:21:13 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-01-21 20:21:13 262,144 —ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-01-21 17:56:59 262,144 —-a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-21 22:52:11 262,144 —-a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-01-21 17:48:52 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-01-21 20:21:08 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-01-21 20:21:08 262,144 —ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-01-21 18:02:37 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-01-21 22:49:10 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-01-21 18:02:37 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-21 22:49:10 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-01-21 18:02:37 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-01-21 22:49:10 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-01-21 17:55:10 108,526 —-a-w C:\Windows\System32\perfc009.dat
+ 2008-01-21 20:31:33 108,526 —-a-w C:\Windows\System32\perfc009.dat
- 2008-01-21 17:55:10 623,342 —-a-w C:\Windows\System32\perfh009.dat
+ 2008-01-21 20:31:33 623,342 —-a-w C:\Windows\System32\perfh009.dat
- 2008-01-21 17:49:12 5,530 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1356316909-1956569011-1238113177-1000_UserData.bin
+ 2008-01-21 20:21:34 5,690 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1356316909-1956569011-1238113177-1000_UserData.bin
- 2008-01-21 17:49:12 63,740 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-01-21 20:21:34 63,740 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-01-21 17:49:10 35,278 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-01-21 20:21:32 35,334 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 03:01 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 12:34 2159104 C:\Windows\System32\oobefldr.dll]
"LightScribe Control Panel"="C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-04-19 20:26 484904]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 12:35 125440]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-07-14 00:41 20034600]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 12:36 201728]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-11-01 18:00 1006264]
"Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2006-11-07 20:57 159744]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 11:59 115816]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2007-06-06 11:52 142104]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2007-06-06 11:52 154392]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2007-06-06 11:52 138008]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-03-29 00:45 176128]
"NapsterShell"="C:\Program Files\Napster\napster.exe" [2007-01-13 02:36 323216]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-06-11 15:57 184320]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 18:54 50696]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 20:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 23:12 317128]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 06:11 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-11-01 19:47 77824]
"NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 14:44 3100672]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 23:46 57344]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 08:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 07:01:50 734872]
WlanUtility.lnk - C:\Program Files\WLAN\WLANUtility\WlanUtility.exe [2003-10-28 18:09:42 70656]

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080116.003\IDSvix86.sys [2007-12-04 17:51]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot []
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-01-29 22:23]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2007-05-31 10:51]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-10-30 19:55]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-01-03 15:43]
S3 ms6823;IEEE802.11b Wireless USB Adapter;C:\Windows\system32\DRIVERS\ms6823.sys [2003-09-15 14:10]
S3 NETw3v32;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw3v32.sys [2006-11-02 07:30]
S3 NETw4v32;Intel® Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit;C:\Windows\system32\DRIVERS\NETw4v32.sys [2007-05-04 14:11]
S3 RTSTOR;USB Mass Storage Device;C:\Windows\system32\drivers\RTSTOR.SYS [2007-05-12 03:09]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

*Newly Created Service* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder
"2008-01-21 20:00:15 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Andy.job"
- c:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK:
"2008-01-21 01:00:20 C:\Windows\Tasks\User_Feed_Synchronization-{D0E902B5-6EE6-4251-9584-7789EFA8150B}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-21 23:03:57
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-21 23:05:10
ComboFix2.txt 2008-01-21 18:04:16
.
2008-01-21 00:59:29 — E O F —


Here is the Hijack this log:



Logfile of HijackThis v1.99.1
Scan saved at 23:06:36, on 21/01/2008
Platform: Unknown Windows (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\T-Mobile\web'n'walk USB manager\web'n'walk USB manager.exe
C:\Program Files\Azureus\Azureus.exe
C:\Windows\Explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [HP Health Check Scheduler] C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: WlanUtility.lnk = C:\Program Files\WLAN\WLANUtility\WlanUtility.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.updatesgate.com/redirect.php (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{02E5C13B-B702-4963-AEF4-D4B3BD67065A}: NameServer = 149.254.192.126 149.254.201.126
O17 - HKLM\System\CS1\Services\Tcpip\..\{02E5C13B-B702-4963-AEF4-D4B3BD67065A}: NameServer = 149.254.192.126 149.254.201.126
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: igfxcui - C:\Windows\SYSTEM32\igfxdev.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h cltCommon (file missing)
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]

    Log looks good :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI