This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] DDABC.DLL

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Spyware Doctor is blocking it but can't get rid of it!

Logfile of HijackThis v1.99.1
Scan saved at 10:48:53 PM, on 1/26/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\McAfee.com\Agent\mcagent .exe
C:\Program Files\Spyware Doctor\SDTrayApp .exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\SiteAdvisor\6145\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\McAfee\MSC\mcregist.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\explorer.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bestbuy.msn.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6145\SiteAdv.dll
O2 - BHO: (no name) - {121889D2-0D3B-4DC2-8C90-E315028AAC3A} - C:\WINDOWS\system32\ddabc.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {8062EB4B-904F-4E1B-BB20-A90FE2F3B7EF} - (no file)
O2 - BHO: (no name) - {981f8aed-ed54-486e-9eb5-7037dd4d98ee} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {C01F97A0-644C-4176-B852-B0212D859DA2} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6145\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [EPSON Stylus C88 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIABA.EXE /P23 "EPSON Stylus C88 Series" /O5 "LPT1:" /M "Stylus C88"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1185169693545
O17 - HKLM\System\CCS\Services\Tcpip\..\{082AF019-14A7-479F-95A3-F6D47D929E66}: NameServer = 64.246.130.9 64.246.131.9
O17 - HKLM\System\CS1\Services\Tcpip\..\{082AF019-14A7-479F-95A3-F6D47D929E66}: NameServer = 64.246.130.9 64.246.131.9
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6145\SiteAdv.dll
O20 - Winlogon Notify: dtvjqsab - dtvjqsab.dll (file missing)
O20 - Winlogon Notify: vtuuttt - vtuuttt.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6145\SAService.exe

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.


Unless informed of in advance, failure to post replies within 5 days will result in this thread being closed.


Hi BubbaBucko

I'm Gary R, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
If you can do these things, everything should go smoothly.
  • Please note you'll need to have Administrator privileges to perform the fixes. (XP accounts are Administrator by default)
  • Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.

It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.


Before we go any further, I need you to install Recovery Console to your computer.

This is purely a precautionary procedure, but it is essential.

There are some new infections going round that damage your ability to boot if they are removed. Whilst I don't see signs of them on your computer, it's always easier to be cautious now than sorry later.

Recovery Console gives us the ability to recover your computer if such a thing happens.

Nothing is going to change on your computer other than we're going to install Recovery Console.

  • Download combofix.exe by sUBs to your Desktop (it must be in this location).
  • Alternate Download
  • If you already have a previous version, delete it and download a new version.
  • Do not attempt to run Combofix other than in the method described below.
  • Go to Microsoft's website
  • Select the download that's appropriate for your Operating System

[external image: Posted Image]

  • Download the file & save it as it's originally named, to your Desktop.

[external image: Posted Image]

  • Now close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it.
  • Follow the prompts to start ComboFix.
  • When prompted, agree to the End-User License Agreement to install Microsoft Recovery Console.
  • When complete, a log named CF_RC.txt will open.
  • Please post the contents of that log.

Please do not shutdown or reboot your machine until we have reviewed the log.
Hi Gary, I tried to download both versions of combofix.exe. In both instances I had a box come up saying "nircmd.com not a valid Win32 application. Then the command boc came up saying access was denied. John
Did the box come up when you tried to download Combofix, or when you tried to run it?

If the latter, try this.

Please run ComboFix using these instructions:
  • Click Start > Run
  • Copy/Paste "%userprofile%\desktop\combofix.exe" /killall into the Run box.
  • Click OK
  • Combofix will now run.
  • When finished, it'll produce a log for you.
  • Post that log in your next reply please.

IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


If your problem is with downloading a copy, try downloading on another computer and transferring it to your computer using a USB keydrive or CD.
Gary, I tried all of your suggestions and I can't get Combofix to run. I downloaded both versions, I tried the run command – neither would work. I downloaded it on another computer and loaded it from the CD – it wouldn't run. I tried the run command with this and it still won't run. I keep getting popups of different versions of Combofix is not a valid WIN32 application or combofix\nircmd.com is not a valid WIN 32 application. Any other ideas?
Please disregard this post


Gonna have to contact the guy who wrote Combofix on this one, I've not seen this kind of problem before, he's usually pretty prompt with his replies, get back to you as soon as possible.

In the meantime, can you try running Combofix in Safe Mode and see if that enables you to run it.

Reboot your computer in Safe Mode
  • If your computer is running, shut down Windows, then turn the power off.
  • Wait 30 seconds, then turn the computer on, and begin tapping the F8 key.
  • The Windows Advanced Options Menu appears. (If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again).
  • Select Safe Mode using the up/down arrow keys.
  • Press Enter.
  • Log on with an account that has administrator priviledges, usually your own account will be administrator by default (Do NOT use the account named Administrator).
Hi Bubbabucko.

Please disregard my last post and follow the instructions below.


sUBs has written a new version of Combofix for situations like yours.

Download Combo-Fix.exe to your Desktop.

Next

Rename it to FixCombo.exe

Run a scan with FixCombo

  • Double click FixCombo.exe & follow the prompts.
  • Note: Combofix will automatically disconnect your Internet connection when it runs, do not reconnect it.
  • When finished, it will
    • Produce a log for you. (it can also be found at C:\Combofix.txt)
    • Restore your Internet connection.
  • Post the log in your next reply please.
  • Now run a new HJT scan and send me the log from that as well please.
IMPORTANT
  • Do not use your computer while Combofix is running.
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • If you've lost your Internet connection when Combofix has completely finished, re-start your computer to restore it.

If you have any problems with these instructions, a detailed Tutorial for how to use Combofix is available here.
Hi Gary,
It appears to have worked this time!

Logs:

ComboFix 08-01-30.1 - 2008-01-29 23:43:13.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.224 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\FixCombo.exe.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\ddabc.dll
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\aesdrrvs.ini
C:\WINDOWS\system32\blsnewun.dll
C:\WINDOWS\system32\cbadd.ini
C:\WINDOWS\system32\cbadd.ini2
C:\WINDOWS\system32\ddabc.dll
C:\WINDOWS\system32\ddabc.exe
C:\WINDOWS\system32\eqefstvy.ini
C:\WINDOWS\system32\fbncqjmi.ini
C:\WINDOWS\system32\fjdtnqbh.ini
C:\WINDOWS\system32\gkbqnuti.dll
C:\WINDOWS\system32\gnurgtji.ini
C:\WINDOWS\system32\gvwjmvnj.ini
C:\WINDOWS\system32\gxalmdtn.ini
C:\WINDOWS\system32\hjkxalyl.ini
C:\WINDOWS\system32\hsjujori.ini
C:\WINDOWS\system32\jkpkcdol.ini
C:\WINDOWS\system32\jxbtrebb.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mreyxwmj.ini
C:\WINDOWS\system32\muiargrq.dll
C:\WINDOWS\system32\nlclucck.dll
C:\WINDOWS\system32\nnjtqxak.ini
C:\WINDOWS\system32\pbpdsxig.ini
C:\WINDOWS\system32\rffvcswk.ini
C:\WINDOWS\system32\rjycxxqy.ini
C:\WINDOWS\system32\rpvragjs.ini
C:\WINDOWS\system32\vynjnyci.ini
C:\WINDOWS\system32\wabtdini.ini
C:\WINDOWS\system32\wmloicbq.ini
C:\WINDOWS\system32\yjoqtaxm.ini

—– BITS: Possible infected sites —–

hxxp://gpdl.google.com

.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-30 )))))))))))))))))))))))))))))))
.

2008-01-27 21:03 . 2008-01-27 21:03 d–h—– C:\WINDOWS\PIF
2008-01-26 23:09 . 2008-01-26 23:09 d——– C:\Program Files\Trend Micro
2008-01-26 00:24 . 2008-01-26 00:24 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-26 00:23 . 2008-01-26 00:23 d——– C:\Program Files\Spyware Doctor
2008-01-26 00:23 . 2008-01-26 00:23 d——– C:\Documents and Settings\John \Application Data\PC Tools
2008-01-26 00:23 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2008-01-26 00:23 . 2007-10-04 17:10 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-26 00:23 . 2007-10-04 17:10 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-26 00:23 . 2007-10-04 17:10 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-26 00:23 . 2007-10-04 17:11 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-01-25 22:57 . 2008-01-25 22:57 d——– C:\Program Files\Norton Security Scan
2008-01-25 20:33 . 2008-01-25 20:33 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-25 20:09 . 2008-01-25 20:09 d——– C:\Program Files\Google
2008-01-22 23:15 . 2008-01-22 23:15 d——– C:\Program Files\SiteAdvisor
2008-01-22 23:15 . 2008-01-22 23:15 d——– C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-01-22 23:15 . 2008-01-22 23:15 d——– C:\Documents and Settings\John \Application Data\SiteAdvisor
2008-01-22 23:15 . 2008-01-22 23:15 d——– C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-01-21 16:35 . 2008-01-23 02:01 584 –a—— C:\WINDOWS\wininit.ini
2008-01-21 09:41 . 2008-01-21 09:41 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-21 03:24 . 2008-01-21 03:24 163,904 ——— C:\WINDOWS\system32\ntfzqpvf.dll_old
2007-12-27 12:36 . 2008-01-21 20:37 90,112 –a—— C:\WINDOWS\Updreg .exe
2007-12-27 12:36 . 2008-01-21 20:37 40,960 –a—— C:\WINDOWS\GWMDMpi .exe
2007-12-25 14:18 . 2007-12-25 14:18 d——– C:\Program Files\AviSynth 2.5
2007-12-25 14:18 . 2007-12-25 14:18 43,698 –a—— C:\WINDOWS\system32\xvid-uninstall.exe
2007-12-25 14:17 . 2007-12-25 14:17 d——– C:\Program Files\AutoGK
2007-12-25 13:14 . 2007-12-25 13:14 d——– C:\Program Files\iriverter
2007-12-25 10:56 . 2007-12-25 10:56 d——– C:\Program Files\Daniusoft
2007-12-22 02:31 . 2007-12-22 02:31 d——– C:\Program Files\ffdshow
2007-12-16 14:35 . 2007-12-16 14:35 d——– C:\Temp
2007-12-16 10:58 . 2007-12-16 10:58 d——– C:\Program Files\Xilisoft
2007-12-16 10:58 . 2005-11-20 23:48 45,056 –a—— C:\WINDOWS\system32\WNASPI32.DLL
2007-12-16 10:58 . 2005-11-20 23:48 16,512 –a—— C:\WINDOWS\system32\drivers\ASPI32.SYS
2007-12-13 21:13 . 2007-12-13 21:13 d——– C:\Program Files\Sierra On-Line
2007-12-13 21:13 . 1998-06-30 16:13 1,045,776 –a—— C:\WINDOWS\system32\msjet35.dll
2007-12-13 21:13 . 1998-06-30 16:13 407,312 –a—— C:\WINDOWS\system32\msrepl35.dll
2007-12-13 21:13 . 1998-06-30 16:13 368,912 –a—— C:\WINDOWS\system32\vbar332.dll
2007-12-13 21:13 . 1998-06-30 16:13 252,176 –a—— C:\WINDOWS\system32\msrd2x35.dll
2007-12-13 21:13 . 1998-06-30 16:12 123,664 –a—— C:\WINDOWS\system32\Msjint35.dll
2007-12-13 21:13 . 1998-06-30 16:12 24,848 –a—— C:\WINDOWS\system32\msjter35.dll
2007-12-13 21:13 . 2007-12-13 21:14 301 –a—— C:\WINDOWS\Sierra.ini
2007-12-13 21:12 . 2007-12-13 21:12 d——– C:\Sierra
2007-12-07 21:40 . 2007-12-07 21:40 d——– C:\Program Files\illiminable
2007-12-02 23:43 . 2007-12-02 23:46 104 –a—— C:\WINDOWS\entpack.ini
2007-12-02 16:26 . 1993-08-18 00:00 286,768 –a—— C:\WINDOWS\HELPHLPR.DLL
2007-12-02 16:26 . 1993-08-18 00:00 3,083 –a—— C:\WINDOWS\ARCADE.INI
2007-12-02 16:26 . 1993-08-18 00:00 2,333 –a—— C:\WINDOWS\WAVEMIX.INI
2007-12-02 16:25 . 2007-12-02 16:25 d——– C:\ARCADE
2007-12-02 16:24 . 1991-09-12 00:00 271,264 –a—— C:\WINDOWS\VBRUN100.DLL
2007-12-02 16:24 . 1991-09-12 00:00 19,200 –a—— C:\WINDOWS\WEPUTIL.DLL
2007-12-02 16:23 . 2007-12-02 16:23 d——– C:\Documents and Settings\John \WINDOWS
2007-12-02 16:23 . 2007-12-02 16:23 d——– C:\BOWEP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 07:26 450,560 ——w C:\WINDOWS\system32\dllcache\jscript.dll
2007-10-30 10:16 3,058,688 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 23:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 06:13 96,256 ——w C:\WINDOWS\system32\dllcache\inseng.dll
2007-10-11 06:13 659,456 —-a-w C:\WINDOWS\system32\wininet.dll
2007-10-11 06:13 659,456 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-11 06:13 615,424 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-11 06:13 55,808 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-11 06:13 532,480 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-11 06:13 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-10-11 06:13 449,024 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-11 06:13 39,424 ——w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-10-11 06:13 357,888 ——w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-10-11 06:13 251,392 ——w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-10-11 06:13 205,312 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-11 06:13 16,384 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-11 06:13 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-10-11 06:13 146,432 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-11 06:13 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-10-11 06:13 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-10-11 06:13 1,023,488 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-10-10 11:16 18,432 ——w C:\WINDOWS\system32\dllcache\iedw.exe
.
—-a-w			40,960 2008-01-22 02:37:24  C:\WINDOWS\GWMDMpi .exe
—-a-w			90,112 2008-01-22 02:37:24  C:\WINDOWS\Updreg .exe
—-a-w			98,304 2008-01-22 02:37:30  C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIABA .EXE
—-a-w		 1,694,208 2008-01-24 14:27:32  C:\Program Files\Messenger\msmsgs .exe
—-a-w		   200,704 2008-01-22 02:37:28  C:\Program Files\Logitech\iTouch\iTouch .exe
—-a-w			35,328 2008-01-22 02:37:24  C:\Program Files\Logitech\MouseWare\system\EM_EXEC .EXE
—-a-w		   582,992 2008-01-27 17:43:16  C:\Program Files\McAfee.com\Agent\mcagent .exe
—-a-w			39,792 2008-01-22 02:37:24  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
—-a-w		 1,460,560 2008-01-23 12:11:16  C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
—-a-w		 1,065,288 2008-01-30 06:15:32  C:\Program Files\Spyware Doctor\SDTrayApp .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7ed2196c-bb13-4d79-bbbd-a9449a87fdc6}]
C:\WINDOWS\system32\wckuupfr.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [ ]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [ ]
"GWMDMMSG"="GWMDMMSG.exe" [2001-10-31 19:10 101615 C:\WINDOWS\GWMDMMSG.exe]
"nwiz"="nwiz.exe" [2002-02-01 17:46 303104 C:\WINDOWS\system32\nwiz.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [ ]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [ ]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [ ]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-01-25 20:33:45 124400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuuttt]
vtuuttt.dll


.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 07:00:22 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe.4158 0
"2008-01-15 07:08:56 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2008-01-26 04:57:14 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-29 23:51:08
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
.
**************************************************************************
.
Completion time: 2008-01-29 23:53:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-30 05:53:02
.
2007-12-27 22:22:37 — E O F —


Logfile of HijackThis v1.99.1
Scan saved at 12:26:02 AM, on 1/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bestbuy.msn.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: {6cdf78a9-449a-dbbb-97d4-31bbc6912de7} - {7ed2196c-bb13-4d79-bbbd-a9449a87fdc6} - C:\WINDOWS\system32\wckuupfr.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1185169693545
O17 - HKLM\System\CCS\Services\Tcpip\..\{082AF019-14A7-479F-95A3-F6D47D929E66}: NameServer = 64.246.130.9 64.246.131.9
O17 - HKLM\System\CS1\Services\Tcpip\..\{082AF019-14A7-479F-95A3-F6D47D929E66}: NameServer = 64.246.130.9 64.246.131.9
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O20 - Winlogon Notify: vtuuttt - vtuuttt.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: McAfee Application Installer Cleanup (0286281201673627) (0286281201673627mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP\028628~1.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe

–John
Hi John,

Looking better, but still some work to do.

  • Click Start > Run type Notepad click OK.
  • This will open an empty Notepad file.
  • Copy/Paste the contents of the box below into Notepad.
File::
C:\WINDOWS\system32\ntfzqpvf.dll_old
C:\WINDOWS\system32\wckuupfr.dll

RenV::
C:\WINDOWS\GWMDMpi .exe
C:\WINDOWS\Updreg .exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\E_FATIABA .EXE
C:\Program Files\Messenger\msmsgs .exe
C:\Program Files\Logitech\iTouch\iTouch .exe
C:\Program Files\Logitech\MouseWare\system\EM_EXEC .EXE
C:\Program Files\McAfee.com\Agent\mcagent .exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer .exe
C:\Program Files\Spyware Doctor\SDTrayApp .exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7ed2196c-bb13-4d79-bbbd-a9449a87fdc6}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtuuttt]
  • Click Format and ensure Wordwrap is unchecked.
  • Save as CFScript.txt to your Desktop.
[external image: Posted Image]

Refering to the picture above, drag CFScript.txt into ComboFix.exe

Combofix will now process that file.

When finished, it will produce a log for you. Post that log in your next reply please. (it can also be found at C:\Combofix.txt)

Next

Run a scan with HJT and when finished check the following items (if found, some probably won't be).

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bestbuy.msn.com

O2 - BHO: {6cdf78a9-449a-dbbb-97d4-31bbc6912de7} - {7ed2196c-bb13-4d79-bbbd-a9449a87fdc6} - C:\WINDOWS\system32\wckuupfr.dll (file missing)

O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com

O20 - Winlogon Notify: vtuuttt - vtuuttt.dll (file missing)



Now close all open windows and click Fix Checked to remove them.

Reboot your computer

Next

  • Click Start > Run and type cleanmgr then click OK.
  • This will bring up the Disk Cleanup window.
  • Check the following entries.
    • Downloaded Program Files.
    • Temporary Internet Files.
    • Recycle Bin.
    • Temporary Files.
  • Click OK.
  • When a prompt pops up click Yes.

Then

Please do an online scan with Kaspersky Online Scanner

Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.

Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings.
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK.
  • Now under select a target to scan select My Computer.
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Note: The Kaspersky online scanner is not yet fully compatible with IE7. You may get returned to a window without the Accept/Decline buttons after allowing the ActiveX control. The buttons are there - you just can't see them! Click on the zoom button (bottom, right of the window) and change it from 100% to 75%. You should now see the buttons. Reset to 100% once the license has been accepted.

Now

Run a new scan with HJT and send me the log please.

Summary of the logs I need from you in your next post:
  • New Combofix log
  • Kaspersky log
  • New HJT log


Please post each log separately to prevent them being cut off by the forum post size limiter.
Gary, When I try to do the first step, I get these 2 messages: 327882R2FWJFW\nircmd.com is not a valid WIN32 application Windows cannot find Kmd.exe John
Did you use the latest edition of Combofix, the one we re-named to FixCombo? Sorry I forgot to say that was the edition that needed to be used. If you have any other editions please delete them. If this was not the cause of the problem let me know.
Please Disregard this post Gary, Yes I used the one we renamed FixCombo. Again, messages: 327882R2FWJFW\nircmd.com is not a valid WIN 32 application and Windows cannot find Kmd.exe –John
Gary,
I uninstalled ComboFix and then followed the installation steps to reinstall. It worked.
Here is the ComboFix log.

C:\WINDOWS\system32\ntfzqpvf.dll_old

.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.

2008-01-27 21:03 . 2008-01-27 21:03 d–h—– C:\WINDOWS\PIF
2008-01-26 23:09 . 2008-01-26 23:09 d——– C:\Program Files\Trend Micro
2008-01-26 00:24 . 2008-01-26 00:24 d——– C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-26 00:23 . 2008-01-26 00:23 d——– C:\Program Files\Spyware Doctor
2008-01-26 00:23 . 2008-01-26 00:23 d——– C:\Documents and Settings\John Kozlowski\Application Data\PC Tools
2008-01-26 00:23 . 2005-09-23 07:29 626,688 –a—— C:\WINDOWS\system32\msvcr80.dll
2008-01-26 00:23 . 2007-10-04 17:10 79,688 –a—— C:\WINDOWS\system32\drivers\iksyssec.sys
2008-01-26 00:23 . 2007-10-04 17:10 62,280 –a—— C:\WINDOWS\system32\drivers\iksysflt.sys
2008-01-26 00:23 . 2007-10-04 17:10 41,288 –a—— C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-01-26 00:23 . 2007-10-04 17:11 29,000 –a—— C:\WINDOWS\system32\drivers\kcom.sys
2008-01-25 22:57 . 2008-01-25 22:57 d——– C:\Program Files\Norton Security Scan
2008-01-25 20:33 . 2008-01-25 20:33 d——– C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-25 20:09 . 2008-01-25 20:09 d——– C:\Program Files\Google
2008-01-22 23:15 . 2008-01-22 23:15 d——– C:\Program Files\SiteAdvisor
2008-01-22 23:15 . 2008-01-22 23:15 d——– C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2008-01-22 23:15 . 2008-01-22 23:15 d——– C:\Documents and Settings\John Kozlowski\Application Data\SiteAdvisor
2008-01-22 23:15 . 2008-01-22 23:15 d——– C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-01-21 16:35 . 2008-01-23 02:01 584 –a—— C:\WINDOWS\wininit.ini
2008-01-21 09:41 . 2008-01-21 09:41 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-27 12:36 . 2008-01-21 20:37 90,112 –a—— C:\WINDOWS\Updreg.exe
2007-12-27 12:36 . 2008-01-21 20:37 40,960 –a—— C:\WINDOWS\GWMDMpi.exe
2007-12-25 14:18 . 2007-12-25 14:18 d——– C:\Program Files\AviSynth 2.5
2007-12-25 14:18 . 2007-12-25 14:18 43,698 –a—— C:\WINDOWS\system32\xvid-uninstall.exe
2007-12-25 14:17 . 2007-12-25 14:17 d——– C:\Program Files\AutoGK
2007-12-25 13:14 . 2007-12-25 13:14 d——– C:\Program Files\iriverter
2007-12-25 10:56 . 2007-12-25 10:56 d——– C:\Program Files\Daniusoft
2007-12-22 02:31 . 2007-12-22 02:31 d——– C:\Program Files\ffdshow
2007-12-16 14:35 . 2007-12-16 14:35 d——– C:\Temp
2007-12-16 10:58 . 2007-12-16 10:58 d——– C:\Program Files\Xilisoft
2007-12-16 10:58 . 2005-11-20 23:48 45,056 –a—— C:\WINDOWS\system32\WNASPI32.DLL
2007-12-16 10:58 . 2005-11-20 23:48 16,512 –a—— C:\WINDOWS\system32\drivers\ASPI32.SYS
2007-12-13 21:13 . 2007-12-13 21:13 d——– C:\Program Files\Sierra On-Line
2007-12-13 21:13 . 1998-06-30 16:13 1,045,776 –a—— C:\WINDOWS\system32\msjet35.dll
2007-12-13 21:13 . 1998-06-30 16:13 407,312 –a—— C:\WINDOWS\system32\msrepl35.dll
2007-12-13 21:13 . 1998-06-30 16:13 368,912 –a—— C:\WINDOWS\system32\vbar332.dll
2007-12-13 21:13 . 1998-06-30 16:13 252,176 –a—— C:\WINDOWS\system32\msrd2x35.dll
2007-12-13 21:13 . 1998-06-30 16:12 123,664 –a—— C:\WINDOWS\system32\Msjint35.dll
2007-12-13 21:13 . 1998-06-30 16:12 24,848 –a—— C:\WINDOWS\system32\msjter35.dll
2007-12-13 21:13 . 2007-12-13 21:14 301 –a—— C:\WINDOWS\Sierra.ini
2007-12-13 21:12 . 2007-12-13 21:12 d——– C:\Sierra
2007-12-07 21:40 . 2007-12-07 21:40 d——– C:\Program Files\illiminable
2007-12-02 23:43 . 2007-12-02 23:46 104 –a—— C:\WINDOWS\entpack.ini
2007-12-02 16:26 . 1993-08-18 00:00 286,768 –a—— C:\WINDOWS\HELPHLPR.DLL
2007-12-02 16:26 . 1993-08-18 00:00 3,083 –a—— C:\WINDOWS\ARCADE.INI
2007-12-02 16:26 . 1993-08-18 00:00 2,333 –a—— C:\WINDOWS\WAVEMIX.INI
2007-12-02 16:25 . 2007-12-02 16:25 d——– C:\ARCADE
2007-12-02 16:24 . 1991-09-12 00:00 271,264 –a—— C:\WINDOWS\VBRUN100.DLL
2007-12-02 16:24 . 1991-09-12 00:00 19,200 –a—— C:\WINDOWS\WEPUTIL.DLL
2007-12-02 16:23 . 2007-12-02 16:23 d——– C:\Documents and Settings\John Kozlowski\WINDOWS
2007-12-02 16:23 . 2007-12-02 16:23 d——– C:\BOWEP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 07:26 450,560 ——w C:\WINDOWS\system32\dllcache\jscript.dll
2007-10-30 10:16 3,058,688 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-27 23:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-27 23:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-11 06:13 96,256 ——w C:\WINDOWS\system32\dllcache\inseng.dll
2007-10-11 06:13 659,456 —-a-w C:\WINDOWS\system32\wininet.dll
2007-10-11 06:13 659,456 ——w C:\WINDOWS\system32\dllcache\wininet.dll
2007-10-11 06:13 615,424 ——w C:\WINDOWS\system32\dllcache\urlmon.dll
2007-10-11 06:13 55,808 ——w C:\WINDOWS\system32\dllcache\extmgr.dll
2007-10-11 06:13 532,480 ——w C:\WINDOWS\system32\dllcache\mstime.dll
2007-10-11 06:13 474,112 ——w C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-10-11 06:13 449,024 ——w C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-10-11 06:13 39,424 ——w C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-10-11 06:13 357,888 ——w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-10-11 06:13 251,392 ——w C:\WINDOWS\system32\dllcache\iepeers.dll
2007-10-11 06:13 205,312 ——w C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-10-11 06:13 16,384 ——w C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-10-11 06:13 151,040 ——w C:\WINDOWS\system32\dllcache\cdfview.dll
2007-10-11 06:13 146,432 ——w C:\WINDOWS\system32\dllcache\msrating.dll
2007-10-11 06:13 1,494,528 ——w C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-10-11 06:13 1,054,208 ——w C:\WINDOWS\system32\dllcache\danim.dll
2007-10-11 06:13 1,023,488 ——w C:\WINDOWS\system32\dllcache\browseui.dll
2007-10-10 11:16 18,432 ——w C:\WINDOWS\system32\dllcache\iedw.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-01-24 08:27 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" []
"zBrowser Launcher"="C:\Program Files\Logitech\iTouch\iTouch.exe" [2008-01-21 20:37 200704]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2008-01-21 20:37 35328]
"GWMDMMSG"="GWMDMMSG.exe" [2001-10-31 19:10 101615 C:\WINDOWS\GWMDMMSG.exe]
"nwiz"="nwiz.exe" [2002-02-01 17:46 303104 C:\WINDOWS\system32\nwiz.exe]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-21 20:37 39792]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2008-01-27 11:43 582992]
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2008-01-30 00:15 1065288]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6253\SiteAdv.exe" [ ]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 03:15:54 65588]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-01-25 20:33:45 124400]


.
Contents of the 'Scheduled Tasks' folder
"2008-01-01 07:00:22 C:\WINDOWS\Tasks\McQcTask.job"
- c:\program files\mcafee\mqc\QcConsol.exe.4158 0
"2008-01-15 07:08:56 C:\WINDOWS\Tasks\McDefragTask.job"
- C:\WINDOWS\system32\defrag.exe
"2008-01-26 04:57:14 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-30 22:51:34
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
.
**************************************************************************
.
Completion time: 2008-01-30 22:53:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-31 04:53:16
ComboFix2.txt 2008-01-30 05:53:10
.
2007-12-27 22:22:37 — E O F —



–John
Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 37297 Number of viruses found: 3 Number of infected objects: 7 Number of suspicious objects: 0 Duration of the scan process: 01:13:53 Infected Object Name / Virus Name / Last Action C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\Temp\mcmsc_0pVoQ5PHIuxAI45 Object is locked skipped C:\WINDOWS\Temp\mcafee_Yl4AObs0LCkG3IZ Object is locked skipped C:\WINDOWS\Temp\mcmsc_rVRZdJtVvipzGcy Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\ModemLog_GTW V.92 Voice Modem.txt Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\Logs\{2A5B4629-A808-4E64-B03A-89A348744534}.log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MSC\McUsers.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Logs\OAS.Log Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MPF\data\log.edb Object is locked skipped C:\Documents and Settings\All Users\Application Data\McAfee\MNA\NAData Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped C:\Documents and Settings\John Kozlowski\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\John Kozlowski\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\John Kozlowski\Local Settings\History\History.IE5\MSHist012008013020080131\index.dat Object is locked skipped C:\Documents and Settings\John Kozlowski\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\John Kozlowski\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\John Kozlowski\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\John Kozlowski\Local Settings\Temp\~DF5C39.tmp Object is locked skipped C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080126-221713-819.dll Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\John Kozlowski\Desktop\backups\backup-20080127-094727-308.dll Infected: Virus.Win32.Trats.d skipped C:\Documents and Settings\John Kozlowski\Cookies\index.dat Object is locked skipped C:\Documents and Settings\John Kozlowski\ntuser.dat Object is locked skipped C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP2\A0000030.exe Infected: Trojan-Dropper.Win32.Agent.dgo skipped C:\System Volume Information\_restore{C4187BA9-7563-4EFE-B482-C14A20ABCB6F}\RP3\change.log Object is locked skipped C:\QooBox\Quarantine\C\WINDOWS\system32\ntfzqpvf.dll_old.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.dnn skipped C:\QooBox\Quarantine\C\Program Files\Spyware Doctor\SDTrayApp.exe.vir Infected: Trojan-Dropper.Win32.Agent.dgo skipped C:\QooBox\Quarantine\catchme2008-01-29_235018.85.zip/ddabc.dll Infected: Virus.Win32.Trats.d skipped C:\QooBox\Quarantine\catchme2008-01-29_235018.85.zip ZIP: infected - 1 skipped Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 1:55:27 AM, on 1/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\McAfee\MSC\mcuimgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1185169693545
O17 - HKLM\System\CCS\Services\Tcpip\..\{082AF019-14A7-479F-95A3-F6D47D929E66}: NameServer = 64.246.130.9 64.246.131.9
O17 - HKLM\System\CS1\Services\Tcpip\..\{082AF019-14A7-479F-95A3-F6D47D929E66}: NameServer = 64.246.130.9 64.246.131.9
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI