MikeyG63
Topic Starter
Hi LDTate, continuation of a cold thread here
http://forums.whatthetech.com/index.php?sh…st&p=426759
sorry about the lack of activity, I was in a Cornish Vale with no internet access (barely analog TV!)
Problem still remains - a couple of crashes of explorer per day, when switching application that may or may not include explorer. I have run many cleaners, spyware & virus checkers now: Symmantec AV, AVG, Kaspersky, Windows live, Ccleaner, Lavasoft, Spybot S&D, none reporting malicious stuff. Fairly sure it's not an infection, but may be the legacy of one because my main AV (Symmantec Corporate) has contained the exact file but not cleaned up on a previous occasion. AVG did not have real time enabled because SAV did. SAV is paid/licensed so I'll take AVG off now it's expired.
As per your last advice, I now include ATF and Combofix, logs as below. Combofix went straight for instsrv.exe, which I imagine is installed for use by my company's IT dept since I understand this to be a windows file.
ComboFix 08-01-10.2 - r49961 2008-01-10 12:38:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.415 [GMT 0:00]
Running from: E:\Applications\ComboFix\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\instsrv.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-10 to 2008-01-10 )))))))))))))))))))))))))))))))
.
2008-01-10 12:34 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-06 23:48 . 2007-07-30 19:19 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2008-01-06 23:48 . 2007-07-30 19:18 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2008-01-06 23:48 . 2007-07-30 19:19 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2008-01-06 23:48 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-01-06 23:48 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2008-01-06 23:48 . 2007-07-30 19:18 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2007-12-28 19:46 . 2007-12-28 19:46 d——– C:\Program Files\GetDataBack
2007-12-21 15:08 . 2007-12-21 15:08 d——– C:\Program Files\Canon
2007-12-21 15:07 . 2000-03-24 16:10 271,872 –a—— C:\WINDOWS\system32\UCS32P.DLL
2007-12-21 15:07 . 2000-03-24 16:08 155,648 –a—— C:\WINDOWS\system32\MG600.DLL
2007-12-21 15:07 . 2000-03-24 16:08 98,816 –a—— C:\WINDOWS\system32\FB63UUSD.dll
2007-12-21 15:07 . 2000-03-24 16:18 13,824 –a—— C:\WINDOWS\system32\FB63UCPL.DLL
2007-12-12 09:00 . 2004-08-03 23:08 31,744 –a—— C:\WINDOWS\system32\drivers\wceusbsh.sys
2007-12-12 09:00 . 2004-08-03 23:08 31,744 –a–c— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2007-12-11 10:12 . 2007-12-11 10:12 d——– D:\Profiles\r49961\Application Data\Grisoft
2007-12-11 10:09 . 2007-12-11 10:09 d——– D:\Profiles\All Users\Application Data\Grisoft
2007-12-11 10:09 . 2007-05-30 12:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-11 09:03 . 2008-01-09 21:54 d——– D:\Profiles\All Users\Application Data\Spybot - Search & Destroy
2007-12-10 15:48 . 2004-08-04 00:56 116,224 –a–c— C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2007-12-10 15:48 . 2001-08-17 22:37 99,865 –a–c— C:\WINDOWS\system32\dllcache\xlog.exe
2007-12-10 15:48 . 2001-08-17 22:37 27,648 –a–c— C:\WINDOWS\system32\dllcache\xrxftplt.exe
2007-12-10 15:48 . 2001-08-17 22:36 23,040 –a–c— C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2007-12-10 15:48 . 2001-08-17 22:36 17,408 –a–c— C:\WINDOWS\system32\dllcache\xrxscnui.dll
2007-12-10 15:48 . 2001-08-17 12:11 16,970 –a–c— C:\WINDOWS\system32\dllcache\xem336n5.sys
2007-12-10 15:48 . 2001-08-17 22:37 4,608 –a–c— C:\WINDOWS\system32\dllcache\xrxflnch.exe
2007-12-10 15:46 . 2004-08-03 21:32 571,392 –a–c— C:\WINDOWS\system32\dllcache\tintlgnt.ime
2007-12-10 15:45 . 2001-08-17 22:36 495,616 –a–c— C:\WINDOWS\system32\dllcache\sblfx.dll
2007-12-10 15:44 . 2001-08-17 13:28 899,146 –a–c— C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2007-12-10 15:43 . 2001-08-17 14:05 351,616 –a–c— C:\WINDOWS\system32\dllcache\ovcodek2.sys
2007-12-10 15:42 . 2001-08-23 13:00 1,875,968 –a–c— C:\WINDOWS\system32\dllcache\msir3jp.lex
2007-12-10 15:41 . 2001-08-17 13:28 802,683 –a–c— C:\WINDOWS\system32\dllcache\ltsm.sys
2007-12-10 15:40 . 2001-08-23 13:00 1,158,818 –a–c— C:\WINDOWS\system32\dllcache\korwbrkr.lex
2007-12-10 15:40 . 2001-08-17 22:36 242,176 –a–c— C:\WINDOWS\system32\dllcache\kdsusd.dll
2007-12-10 15:40 . 2004-08-03 23:00 87,424 –a–c— C:\WINDOWS\system32\dllcache\irda.sys
2007-12-10 15:40 . 2001-08-23 13:00 70,656 –a–c— C:\WINDOWS\system32\dllcache\korwbrkr.dll
2007-12-10 15:40 . 2001-08-17 22:36 45,568 –a–c— C:\WINDOWS\system32\dllcache\kdsui.dll
2007-12-10 15:40 . 2001-08-17 22:36 37,376 –a–c— C:\WINDOWS\system32\dllcache\kousd.dll
2007-12-10 15:40 . 2001-08-17 13:49 26,624 –a–c— C:\WINDOWS\system32\dllcache\irstusb.sys
2007-12-10 15:40 . 2001-08-17 13:49 23,552 –a–c— C:\WINDOWS\system32\dllcache\irmk7.sys
2007-12-10 15:40 . 2001-08-17 13:51 18,688 –a–c— C:\WINDOWS\system32\dllcache\irsir.sys
2007-12-10 15:38 . 2001-08-23 13:00 13,463,552 –a–c— C:\WINDOWS\system32\dllcache\hwxjpn.dll
2007-12-10 15:37 . 2001-08-17 14:56 1,733,120 –a–c— C:\WINDOWS\system32\dllcache\g400d.dll
2007-12-10 15:36 . 2001-08-17 12:14 952,007 –a–c— C:\WINDOWS\system32\dllcache\diwan.sys
2007-12-10 15:35 . 2001-08-23 13:00 1,677,824 –a–c— C:\WINDOWS\system32\dllcache\chsbrkr.dll
2007-12-10 15:34 . 2001-08-17 13:28 762,780 –a–c— C:\WINDOWS\system32\dllcache\3cwmcru.sys
2007-12-10 15:33 . 2001-08-17 14:56 66,048 –a–c— C:\WINDOWS\system32\dllcache\s3legacy.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 12:42 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-01-07 23:12 ——— d—–w C:\Program Files\CCleaner
2008-01-06 17:12 ——— d—–w C:\Program Files\lx_cats
2007-12-27 16:16 ——— d—–w C:\Program Files\Paint Shop Pro 5
2007-12-17 21:29 ——— d—–w D:\Profiles\r49961\Application Data\Skype
2007-12-01 10:23 ——— d—–w C:\Program Files\DC++
2007-11-28 12:21 ——— d—–w C:\Program Files\Lexmark
2007-11-28 11:33 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-28 11:28 ——— d—–w C:\Program Files\patches
2007-11-27 14:05 ——— d—–w D:\Profiles\All Users\Application Data\Kaspersky Lab
2007-11-18 16:57 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-11-18 16:57 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2007-11-18 16:31 ——— d—–w C:\Program Files\Motorola Phone Tools
2007-11-18 16:30 ——— d—–w C:\Program Files\Common Files\Motorola Shared
2007-11-18 16:29 92,064 —-a-w D:\Profiles\r49961\mqdmmdm.sys
2007-11-18 16:29 9,232 —-a-w D:\Profiles\r49961\mqdmmdfl.sys
2007-11-18 16:29 79,328 —-a-w D:\Profiles\r49961\mqdmserd.sys
2007-11-18 16:29 66,656 —-a-w D:\Profiles\r49961\mqdmbus.sys
2007-11-18 16:29 6,208 —-a-w D:\Profiles\r49961\mqdmcmnt.sys
2007-11-18 16:29 5,936 —-a-w D:\Profiles\r49961\mqdmwhnt.sys
2007-11-18 16:29 4,048 —-a-w D:\Profiles\r49961\mqdmcr.sys
2007-11-18 16:29 25,600 —-a-w D:\Profiles\r49961\usbsermptxp.sys
2007-11-18 16:29 22,768 —-a-w D:\Profiles\r49961\usbsermpt.sys
2007-11-18 10:41 ——— d—–w D:\Profiles\All Users\Application Data\BVRP Software
2007-11-18 10:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-18 10:39 22,768 —-a-w C:\WINDOWS\system32\drivers\usbsermpt.sys
2007-11-18 10:12 ——— d—–w C:\Program Files\LiveUpdate
2007-11-17 16:20 ——— d—–w D:\Profiles\r49961\Application Data\Acronis
2007-11-12 20:34 ——— d—–w D:\Profiles\All Users\Application Data\DVD Shrink
2007-11-12 00:16 ——— d—–w C:\Program Files\illiminable
2007-10-23 04:12 121,038 —-a-w C:\WINDOWS\Clean_Messenger.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-10-24 18:05 4687352]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-04-10 17:35 3900776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Blocker"="C:\Program Files\Internet Explorer\Iereg.exe" [2005-06-14 13:29 111218]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-26 20:30 282624]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-12-21 17:33 48800]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2006-05-27 03:51 85744]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 22:44 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 22:41 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 22:45 118784]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-04-06 14:58 1032192]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2006-04-14 11:56 569413]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 19:13 176128]
"HRHCM"="C:\Program Files\Internet Explorer\PLUGINS\iemod.exe" [2005-12-20 15:31 111107]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-16 21:12 1164912]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-16 21:17 1941784]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-10-16 21:13 87584]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"LXCYCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2005-12-01 18:38 65536]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:56 15360]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-04-10 17:35 3900776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Btn_Back"= 0 (0x0)
"Btn_Forward"= 0 (0x0)
"Btn_Stop"= 0 (0x0)
"Btn_Refresh"= 0 (0x0)
"Btn_Home"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"Btn_History"= 0 (0x0)
"Btn_Favorites"= 0 (0x0)
"Btn_Media"= 0 (0x0)
"Btn_Folders"= 0 (0x0)
"Btn_Fullscreen"= 0 (0x0)
"Btn_Tools"= 0 (0x0)
"Btn_MailNews"= 0 (0x0)
"Btn_Size"= 0 (0x0)
"Btn_Print"= 0 (0x0)
"Btn_Edit"= 0 (0x0)
"Btn_Discussions"= 0 (0x0)
"Btn_Cut"= 0 (0x0)
"Btn_Copy"= 0 (0x0)
"Btn_Paste"= 0 (0x0)
"Btn_Encoding"= 0 (0x0)
"Btn_PrintPreview"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoSetActiveDesktop"= 0 (0x0)
"NoLogoff"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"NoTrayContextMenu"= 0 (0x0)
"EnforceShellExtensionSecurity"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
R2 AMBroker;Access Manager Configuration Service;"C:\Program Files\AccessManager\Client\AMBroker.exe" [2004-11-03 08:45]
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2006-02-09 02:50]
R2 Sygman;SSA Integration Manager;"C:\Program Files\AccessManager\Client\sygman.exe" [2004-11-03 08:48]
R3 lxcy_device;lxcy_device;C:\WINDOWS\system32\lxcycoms.exe [2006-02-20 19:23]
R3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2006-02-09 02:50]
S0 black;black;C:\WINDOWS\system32\drivers\BlackDrv.sys []
S3 DAPlugin;Visual Insight DA Plugin;C:\Program Files\AccessManager\Client\DAPlugin.exe [2004-11-03 08:56]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-02-27 14:31]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-19 22:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-19 22:40]
S3 sp_spi_da;Visual Insight Dial Analysis;C:\Program Files\AccessManager\SMOC\spi_da.exe [2004-10-15 16:40]
S4 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2004-05-07 21:11]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##msiadmin.freescale.net#MSIADMIN#SMSPKG#Office2003#source]
\Shell\AutoRun\command - Y:\setuppro.EXE /AUTORUN
\Shell\configure\command - Y:\setuppro.EXE
\Shell\install\command - Y:\setuppro.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999-999-99-FSL-OfficeCommunicator-ENG-manual}]
"C:\Program Files\Microsoft Office Communicator\CurrentKeys.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-FSL-2K3}]
C:\WINDOWS\SAFE_Sender_FSL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-FSL-IMRemoval}]
"C:\WINDOWS\Clean_Messenger.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-FSL-NETMEETING}]
C:\WINDOWS\FSLnetmeeting.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-2K3}]
C:\WINDOWS\2k3_USR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-EZCD52}]
C:\WINNT\System32\REGEZCD5.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-IE6SP1}]
C:\WINDOWS\MotIESet6_SP1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0-0-0-0-MOT-IE6FreeScale}]
C:\WINDOWS\ieproxy.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0-0-0-0-MOT-IE6PRE}]
C:\WINDOWS\MotIESet6_pre.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9D467580-AF3D-4e3c-8893-4F29CB100EB2}]
"C:\WINDOWS\SAVasetup.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BAFC1927-A731-4c34-829B-47EE05ADD199}]
"C:\WINDOWS\regedit.exe" /s "C:\WINDOWS\mot-wmp9.reg"
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-10 12:42:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-10 12:46:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-10 12:46:04
.
2008-01-09 08:22:31 — E O F —
Logfile of HijackThis v1.99.1
Scan saved at 13:09:50, on 10/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\lxcycoms.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.my.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.freescale.net:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.freescale.net;freescale.net;*.mot.com;
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Blocker] "C:\Program Files\Internet Explorer\Iereg.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [HRHCM] "C:\Program Files\Internet Explorer\PLUGINS\iemod.exe" /s
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1126394220883
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163431684203
O16 - DPF: {9A04E3F0-3BB2-11D2-91E2-00C04FAEC46B} (NMClient Class) - http://meet-emea.freescale.net/ConferencingBin/xcliacc.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = emea.freescale.net,sps.mot.com,am.freescale.net,ap.freescale.net,fsl.freescale.n
et,freescale.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = emea.freescale.net,sps.mot.com,am.freescale.net,ap.freescale.net,fsl.freescale.n
et,freescale.net
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Thanks for looking,
Mike
http://forums.whatthetech.com/index.php?sh…st&p=426759
sorry about the lack of activity, I was in a Cornish Vale with no internet access (barely analog TV!)
Problem still remains - a couple of crashes of explorer per day, when switching application that may or may not include explorer. I have run many cleaners, spyware & virus checkers now: Symmantec AV, AVG, Kaspersky, Windows live, Ccleaner, Lavasoft, Spybot S&D, none reporting malicious stuff. Fairly sure it's not an infection, but may be the legacy of one because my main AV (Symmantec Corporate) has contained the exact file but not cleaned up on a previous occasion. AVG did not have real time enabled because SAV did. SAV is paid/licensed so I'll take AVG off now it's expired.
As per your last advice, I now include ATF and Combofix, logs as below. Combofix went straight for instsrv.exe, which I imagine is installed for use by my company's IT dept since I understand this to be a windows file.
ComboFix 08-01-10.2 - r49961 2008-01-10 12:38:02.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.415 [GMT 0:00]
Running from: E:\Applications\ComboFix\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\instsrv.exe
.
((((((((((((((((((((((((( Files Created from 2007-12-10 to 2008-01-10 )))))))))))))))))))))))))))))))
.
2008-01-10 12:34 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\NirCmd.exe
2008-01-06 23:48 . 2007-07-30 19:19 271,224 –a—— C:\WINDOWS\system32\mucltui.dll
2008-01-06 23:48 . 2007-07-30 19:18 34,136 –a—— C:\WINDOWS\system32\wucltui.dll.mui
2008-01-06 23:48 . 2007-07-30 19:19 30,072 –a—— C:\WINDOWS\system32\mucltui.dll.mui
2008-01-06 23:48 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-01-06 23:48 . 2007-07-30 19:19 25,944 –a—— C:\WINDOWS\system32\wuapi.dll.mui
2008-01-06 23:48 . 2007-07-30 19:18 20,312 –a—— C:\WINDOWS\system32\wuaueng.dll.mui
2007-12-28 19:46 . 2007-12-28 19:46 d——– C:\Program Files\GetDataBack
2007-12-21 15:08 . 2007-12-21 15:08 d——– C:\Program Files\Canon
2007-12-21 15:07 . 2000-03-24 16:10 271,872 –a—— C:\WINDOWS\system32\UCS32P.DLL
2007-12-21 15:07 . 2000-03-24 16:08 155,648 –a—— C:\WINDOWS\system32\MG600.DLL
2007-12-21 15:07 . 2000-03-24 16:08 98,816 –a—— C:\WINDOWS\system32\FB63UUSD.dll
2007-12-21 15:07 . 2000-03-24 16:18 13,824 –a—— C:\WINDOWS\system32\FB63UCPL.DLL
2007-12-12 09:00 . 2004-08-03 23:08 31,744 –a—— C:\WINDOWS\system32\drivers\wceusbsh.sys
2007-12-12 09:00 . 2004-08-03 23:08 31,744 –a–c— C:\WINDOWS\system32\dllcache\wceusbsh.sys
2007-12-11 10:12 . 2007-12-11 10:12 d——– D:\Profiles\r49961\Application Data\Grisoft
2007-12-11 10:09 . 2007-12-11 10:09 d——– D:\Profiles\All Users\Application Data\Grisoft
2007-12-11 10:09 . 2007-05-30 12:10 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-11 09:03 . 2008-01-09 21:54 d——– D:\Profiles\All Users\Application Data\Spybot - Search & Destroy
2007-12-10 15:48 . 2004-08-04 00:56 116,224 –a–c— C:\WINDOWS\system32\dllcache\xrxwiadr.dll
2007-12-10 15:48 . 2001-08-17 22:37 99,865 –a–c— C:\WINDOWS\system32\dllcache\xlog.exe
2007-12-10 15:48 . 2001-08-17 22:37 27,648 –a–c— C:\WINDOWS\system32\dllcache\xrxftplt.exe
2007-12-10 15:48 . 2001-08-17 22:36 23,040 –a–c— C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
2007-12-10 15:48 . 2001-08-17 22:36 17,408 –a–c— C:\WINDOWS\system32\dllcache\xrxscnui.dll
2007-12-10 15:48 . 2001-08-17 12:11 16,970 –a–c— C:\WINDOWS\system32\dllcache\xem336n5.sys
2007-12-10 15:48 . 2001-08-17 22:37 4,608 –a–c— C:\WINDOWS\system32\dllcache\xrxflnch.exe
2007-12-10 15:46 . 2004-08-03 21:32 571,392 –a–c— C:\WINDOWS\system32\dllcache\tintlgnt.ime
2007-12-10 15:45 . 2001-08-17 22:36 495,616 –a–c— C:\WINDOWS\system32\dllcache\sblfx.dll
2007-12-10 15:44 . 2001-08-17 13:28 899,146 –a–c— C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2007-12-10 15:43 . 2001-08-17 14:05 351,616 –a–c— C:\WINDOWS\system32\dllcache\ovcodek2.sys
2007-12-10 15:42 . 2001-08-23 13:00 1,875,968 –a–c— C:\WINDOWS\system32\dllcache\msir3jp.lex
2007-12-10 15:41 . 2001-08-17 13:28 802,683 –a–c— C:\WINDOWS\system32\dllcache\ltsm.sys
2007-12-10 15:40 . 2001-08-23 13:00 1,158,818 –a–c— C:\WINDOWS\system32\dllcache\korwbrkr.lex
2007-12-10 15:40 . 2001-08-17 22:36 242,176 –a–c— C:\WINDOWS\system32\dllcache\kdsusd.dll
2007-12-10 15:40 . 2004-08-03 23:00 87,424 –a–c— C:\WINDOWS\system32\dllcache\irda.sys
2007-12-10 15:40 . 2001-08-23 13:00 70,656 –a–c— C:\WINDOWS\system32\dllcache\korwbrkr.dll
2007-12-10 15:40 . 2001-08-17 22:36 45,568 –a–c— C:\WINDOWS\system32\dllcache\kdsui.dll
2007-12-10 15:40 . 2001-08-17 22:36 37,376 –a–c— C:\WINDOWS\system32\dllcache\kousd.dll
2007-12-10 15:40 . 2001-08-17 13:49 26,624 –a–c— C:\WINDOWS\system32\dllcache\irstusb.sys
2007-12-10 15:40 . 2001-08-17 13:49 23,552 –a–c— C:\WINDOWS\system32\dllcache\irmk7.sys
2007-12-10 15:40 . 2001-08-17 13:51 18,688 –a–c— C:\WINDOWS\system32\dllcache\irsir.sys
2007-12-10 15:38 . 2001-08-23 13:00 13,463,552 –a–c— C:\WINDOWS\system32\dllcache\hwxjpn.dll
2007-12-10 15:37 . 2001-08-17 14:56 1,733,120 –a–c— C:\WINDOWS\system32\dllcache\g400d.dll
2007-12-10 15:36 . 2001-08-17 12:14 952,007 –a–c— C:\WINDOWS\system32\dllcache\diwan.sys
2007-12-10 15:35 . 2001-08-23 13:00 1,677,824 –a–c— C:\WINDOWS\system32\dllcache\chsbrkr.dll
2007-12-10 15:34 . 2001-08-17 13:28 762,780 –a–c— C:\WINDOWS\system32\dllcache\3cwmcru.sys
2007-12-10 15:33 . 2001-08-17 14:56 66,048 –a–c— C:\WINDOWS\system32\dllcache\s3legacy.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-10 12:42 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-01-07 23:12 ——— d—–w C:\Program Files\CCleaner
2008-01-06 17:12 ——— d—–w C:\Program Files\lx_cats
2007-12-27 16:16 ——— d—–w C:\Program Files\Paint Shop Pro 5
2007-12-17 21:29 ——— d—–w D:\Profiles\r49961\Application Data\Skype
2007-12-01 10:23 ——— d—–w C:\Program Files\DC++
2007-11-28 12:21 ——— d—–w C:\Program Files\Lexmark
2007-11-28 11:33 ——— d—–w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-28 11:28 ——— d—–w C:\Program Files\patches
2007-11-27 14:05 ——— d—–w D:\Profiles\All Users\Application Data\Kaspersky Lab
2007-11-18 16:57 0 —ha-w C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2007-11-18 16:57 0 —ha-w C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2007-11-18 16:31 ——— d—–w C:\Program Files\Motorola Phone Tools
2007-11-18 16:30 ——— d—–w C:\Program Files\Common Files\Motorola Shared
2007-11-18 16:29 92,064 —-a-w D:\Profiles\r49961\mqdmmdm.sys
2007-11-18 16:29 9,232 —-a-w D:\Profiles\r49961\mqdmmdfl.sys
2007-11-18 16:29 79,328 —-a-w D:\Profiles\r49961\mqdmserd.sys
2007-11-18 16:29 66,656 —-a-w D:\Profiles\r49961\mqdmbus.sys
2007-11-18 16:29 6,208 —-a-w D:\Profiles\r49961\mqdmcmnt.sys
2007-11-18 16:29 5,936 —-a-w D:\Profiles\r49961\mqdmwhnt.sys
2007-11-18 16:29 4,048 —-a-w D:\Profiles\r49961\mqdmcr.sys
2007-11-18 16:29 25,600 —-a-w D:\Profiles\r49961\usbsermptxp.sys
2007-11-18 16:29 22,768 —-a-w D:\Profiles\r49961\usbsermpt.sys
2007-11-18 10:41 ——— d—–w D:\Profiles\All Users\Application Data\BVRP Software
2007-11-18 10:40 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-11-18 10:39 22,768 —-a-w C:\WINDOWS\system32\drivers\usbsermpt.sys
2007-11-18 10:12 ——— d—–w C:\Program Files\LiveUpdate
2007-11-17 16:20 ——— d—–w D:\Profiles\r49961\Application Data\Acronis
2007-11-12 20:34 ——— d—–w D:\Profiles\All Users\Application Data\DVD Shrink
2007-11-12 00:16 ——— d—–w C:\Program Files\illiminable
2007-10-23 04:12 121,038 —-a-w C:\WINDOWS\Clean_Messenger.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2006-10-24 18:05 4687352]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-04-10 17:35 3900776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Blocker"="C:\Program Files\Internet Explorer\Iereg.exe" [2005-06-14 13:29 111218]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-06-26 20:30 282624]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2005-12-21 17:33 48800]
"vptray"="C:\PROGRA~1\SYMANT~2\VPTray.exe" [2006-05-27 03:51 85744]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-12-13 22:44 98304]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-12-13 22:41 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-12-13 22:45 118784]
"Dell QuickSet"="C:\Program Files\Dell\QuickSet\quickset.exe" [2006-04-06 14:58 1032192]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-04-14 11:51 667718]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-04-14 11:52 602182]
"EOUApp"="C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe" [2006-04-14 11:56 569413]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2005-10-07 19:13 176128]
"HRHCM"="C:\Program Files\Internet Explorer\PLUGINS\iemod.exe" [2005-12-20 15:31 111107]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 05:56 110592 C:\WINDOWS\system32\bthprops.cpl]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2006-10-16 21:12 1164912]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2006-10-16 21:17 1941784]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2006-10-16 21:13 87584]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 17:30 282624 C:\WINDOWS\stsystra.exe]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"LXCYCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [2005-12-01 18:38 65536]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 05:56 15360]
"Communicator"="C:\Program Files\Microsoft Office Communicator\Communicator.exe" [2007-04-10 17:35 3900776]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"disablecad"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoMSAppLogo5ChannelNotify"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"Btn_Back"= 0 (0x0)
"Btn_Forward"= 0 (0x0)
"Btn_Stop"= 0 (0x0)
"Btn_Refresh"= 0 (0x0)
"Btn_Home"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"Btn_History"= 0 (0x0)
"Btn_Favorites"= 0 (0x0)
"Btn_Media"= 0 (0x0)
"Btn_Folders"= 0 (0x0)
"Btn_Fullscreen"= 0 (0x0)
"Btn_Tools"= 0 (0x0)
"Btn_MailNews"= 0 (0x0)
"Btn_Size"= 0 (0x0)
"Btn_Print"= 0 (0x0)
"Btn_Edit"= 0 (0x0)
"Btn_Discussions"= 0 (0x0)
"Btn_Cut"= 0 (0x0)
"Btn_Copy"= 0 (0x0)
"Btn_Paste"= 0 (0x0)
"Btn_Encoding"= 0 (0x0)
"Btn_PrintPreview"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoSetActiveDesktop"= 0 (0x0)
"NoLogoff"= 0 (0x0)
"NoSetFolders"= 0 (0x0)
"NoTrayContextMenu"= 0 (0x0)
"EnforceShellExtensionSecurity"= 0 (0x0)
"NoDeletePrinter"= 0 (0x0)
"NoAddPrinter"= 0 (0x0)
"NoPrinterTabs"= 0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
R2 AMBroker;Access Manager Configuration Service;"C:\Program Files\AccessManager\Client\AMBroker.exe" [2004-11-03 08:45]
R2 CcmExec;SMS Agent Host;C:\WINDOWS\system32\CCM\CcmExec.exe [2006-02-09 02:50]
R2 Sygman;SSA Integration Manager;"C:\Program Files\AccessManager\Client\sygman.exe" [2004-11-03 08:48]
R3 lxcy_device;lxcy_device;C:\WINDOWS\system32\lxcycoms.exe [2006-02-20 19:23]
R3 prepdrvr;SMS Process Event Driver;C:\WINDOWS\system32\CCM\prepdrv.sys [2006-02-09 02:50]
S0 black;black;C:\WINDOWS\system32\drivers\BlackDrv.sys []
S3 DAPlugin;Visual Insight DA Plugin;C:\Program Files\AccessManager\Client\DAPlugin.exe [2004-11-03 08:56]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-02-27 14:31]
S3 RapFile;RapFile;C:\WINDOWS\system32\drivers\RapFile.sys [2003-06-19 22:40]
S3 RapNet;RapNet;C:\WINDOWS\system32\drivers\RapNet.sys [2003-06-19 22:40]
S3 sp_spi_da;Visual Insight Dial Analysis;C:\Program Files\AccessManager\SMOC\spi_da.exe [2004-10-15 16:40]
S4 a320raid;a320raid;C:\WINDOWS\system32\DRIVERS\a320raid.sys [2004-05-07 21:11]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\##msiadmin.freescale.net#MSIADMIN#SMSPKG#Office2003#source]
\Shell\AutoRun\command - Y:\setuppro.EXE /AUTORUN
\Shell\configure\command - Y:\setuppro.EXE
\Shell\install\command - Y:\setuppro.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999-999-99-FSL-OfficeCommunicator-ENG-manual}]
"C:\Program Files\Microsoft Office Communicator\CurrentKeys.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-FSL-2K3}]
C:\WINDOWS\SAFE_Sender_FSL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-FSL-IMRemoval}]
"C:\WINDOWS\Clean_Messenger.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-FSL-NETMEETING}]
C:\WINDOWS\FSLnetmeeting.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-2K3}]
C:\WINDOWS\2k3_USR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-EZCD52}]
C:\WINNT\System32\REGEZCD5.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{Z99999999-999-9999-9999-MOT-IE6SP1}]
C:\WINDOWS\MotIESet6_SP1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0-0-0-0-MOT-IE6FreeScale}]
C:\WINDOWS\ieproxy.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0-0-0-0-MOT-IE6PRE}]
C:\WINDOWS\MotIESet6_pre.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9D467580-AF3D-4e3c-8893-4F29CB100EB2}]
"C:\WINDOWS\SAVasetup.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{BAFC1927-A731-4c34-829B-47EE05ADD199}]
"C:\WINDOWS\regedit.exe" /s "C:\WINDOWS\mot-wmp9.reg"
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-10 12:42:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-10 12:46:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-10 12:46:04
.
2008-01-09 08:22:31 — E O F —
Logfile of HijackThis v1.99.1
Scan saved at 13:09:50, on 10/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\AccessManager\Client\AMBroker.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AccessManager\Client\sygman.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CCM\CLICOMP\RemCtrl\Wuser32.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~2\VPTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\lxcycoms.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.my.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ie/defaul…earch.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwgate0.freescale.net:1080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.freescale.net;freescale.net;*.mot.com;
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Blocker] "C:\Program Files\Internet Explorer\Iereg.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [EOUApp] "C:\Program Files\Intel\Wireless\Bin\EOUWiz.exe"
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [HRHCM] "C:\Program Files\Internet Explorer\PLUGINS\iemod.exe" /s
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1126394220883
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163431684203
O16 - DPF: {9A04E3F0-3BB2-11D2-91E2-00C04FAEC46B} (NMClient Class) - http://meet-emea.freescale.net/ConferencingBin/xcliacc.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = emea.freescale.net,sps.mot.com,am.freescale.net,ap.freescale.net,fsl.freescale.n
et,freescale.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = emea.freescale.net,sps.mot.com,am.freescale.net,ap.freescale.net,fsl.freescale.n
et,freescale.net
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Access Manager Configuration Service (AMBroker) - MCI, Inc. - C:\Program Files\AccessManager\Client\AMBroker.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Visual Insight DA Plugin (DAPlugin) - MCI, Inc. - C:\Program Files\AccessManager\Client\DAPlugin.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcycoms.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SP Software Installer - Smartpipes, Inc. - C:\Program Files\AccessManager\PMAC\sp_SWIns.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Visual Insight Dial Analysis (sp_spi_da) - Smartpipes, Inc. - C:\Program Files\AccessManager\SMOC\spi_da.exe
O23 - Service: SSA Integration Manager (Sygman) - MCI, Inc. - C:\Program Files\AccessManager\Client\sygman.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Thanks for looking,
Mike