This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Problems are getting worse

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry, I bumped my last topic before I read not too. Things are getting progressively worse, now explorer.exe will not start when Windows boots. I use task manager to start explorer.exe.
Latest Hijackthis log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:58:02 PM, on 01/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.47.6.3:8887
F3 - REG:win.ini: load=C:\WINDOWS\system32\ssqpm.exe
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: {40a2e884-678e-794b-42b4-6fbf165ff9e3} - {3e9ff561-fbf6-4b24-b497-e876488e2a04} - C:\WINDOWS\system32\lkskmkre.dll (file missing)
O2 - BHO: (no name) - {78116C7D-EE2D-4F2B-BF44-6E6F95CCE6CC} - C:\WINDOWS\system32\ssqpm.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A051B1FF-8D7E-418B-AABE-4FF82F4280A2} - C:\WINDOWS\system32\gebcbbc.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [a82176dc] rundll32.exe "C:\WINDOWS\system32\pnmsdckn.dll",b
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [PrintServer Diagnostic] C:\Program Files\Print Server\PTP\PSDiagnostic.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
O4 - Startup: Hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
O4 - Global Startup: SEL Update Manager.lnk = C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180326421187
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TPS
O17 - HKLM\Software\..\Telephony: DomainName = TPS
O17 - HKLM\System\CCS\Services\Tcpip\..\{06DED577-FDB1-4CD0-9491-D956C6614714}: NameServer = 5.35.153.15
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: incsfxct - incsfxct.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Inc. - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SEL-5860 Time Service - Schweitzer Engineering Laboratories, Inc. - C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 11636 bytes
Hello singleshot and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem. It appears likely that your system has been infected with a Vundo trojan file infector. This trojan renames legitimate startup executables and replaces them with malware. We will attempt to reverse the process but please be advised that most often, there are programs that can not be salvaged and will need to be reinstalled.

Delete any existing version of ComboFix you have sitting on your desktop

Download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
——————————————————————–
1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results"
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net
——————————————————————–
2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review


****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

ComboFix 08-01-31.4 - Todd Baker 2008-01-31 6:16:37.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.398 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\ssqpm.dll
C:\Documents and Settings\Todd Baker\Application Data\inst.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ekloqwpk.dll
C:\WINDOWS\system32\fvhmrfqw.ini
C:\WINDOWS\system32\gebcbbc.dll
C:\WINDOWS\system32\hikejhhe.dll
C:\WINDOWS\system32\hjtgnoxw.ini
C:\WINDOWS\system32\incsfxct.dllbox
C:\WINDOWS\system32\kpwqolke.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\micr0st.dll
C:\WINDOWS\system32\mpqss.ini
C:\WINDOWS\system32\mpqss.ini2
C:\WINDOWS\system32\MSDLF.DLL
C:\WINDOWS\system32\nkcdsmnp.ini
C:\WINDOWS\system32\pnmsdckn.dll
C:\WINDOWS\system32\ssqpm.dll
C:\WINDOWS\system32\unrar.dll
C:\WINDOWS\system32\wkffojhg.ini

.
((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.

2008-01-30 22:10 . 2008-01-30 22:10 d——– C:\Program Files\Sun
2008-01-30 22:10 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-30 22:07 . 2008-01-30 22:10 d——– C:\Program Files\Java
2008-01-30 22:05 . 2008-01-30 22:05 d——– C:\Program Files\Common Files\Java
2008-01-29 14:10 . 2008-01-29 14:10 d——– C:\Program Files\Trend Micro
2008-01-28 22:27 . 2008-01-28 22:27 d——– C:\Program Files\Lavasoft
2008-01-27 12:05 . 2008-01-30 08:28 321 –a—— C:\BOOT.INI
2008-01-27 07:42 . 2008-01-27 07:42 d——– C:\Program Files\Microsoft Silverlight
2008-01-26 19:06 . 2008-01-29 11:46 d——– C:\VundoFix Backups
2008-01-23 04:15 . 2008-01-23 04:15 67 –a—— C:\WINDOWS\URPC.INI
2008-01-19 00:04 . 2008-01-19 00:04 d——– C:\Program Files\DVDFab Platinum 4
2008-01-18 17:02 . 2008-01-18 17:02 d——– C:\Program Files\LG Software Innovations
2008-01-18 17:02 . 2008-01-27 08:54 d——– C:\Documents and Settings\Todd Baker\Application Data\Vso
2008-01-18 17:02 . 2008-01-18 17:02 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-18 17:02 . 2008-01-27 06:58 47,360 –a—— C:\Documents and Settings\Todd Baker\Application Data\pcouffin.sys
2008-01-18 16:25 . 2008-01-18 16:26 d——– C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-18 15:34 . 2008-01-18 15:34 d——– C:\Program Files\XviD
2008-01-18 15:34 . 2008-01-18 15:36 67 –a—— C:\WINDOWS\#1 DVD Ripper.INI
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\Todd Baker\Application Data\PCTV4Me
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\All Users\Application Data\PCTV4Me
2008-01-07 13:31 . 2008-01-07 12:42 359,808 –a—— C:\WINDOWS\system32\drivers\tcpip.sys.old
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Program Files\Common Files\Synacast
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Documents and Settings\Todd Baker\Application Data\PPMate
2008-01-07 12:42 . 2008-01-07 12:42 359,808 –a—— C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-01-05 10:35 . 2008-01-05 10:35 0 –a—— C:\WINDOWS\iplayer.INI
2008-01-05 10:33 . 2008-01-05 10:34 d——– C:\Program Files\InterActual
2008-01-04 13:50 . 2008-01-27 13:09 0 –a—— C:\WINDOWS\system32\tdlsoui.flag
2008-01-04 13:48 . 2008-01-05 07:08 d——– C:\Documents and Settings\Todd Baker\Application Data\dvdcss
2008-01-02 11:39 . 2008-01-02 11:39 d——– C:\Documents and Settings\Todd Baker\Application Data\Simple Star
2008-01-02 11:38 . 2008-01-02 11:38 d——– C:\Program Files\Common Files\Simple Star Shared
2008-01-02 11:36 . 2008-01-02 11:45 d——– C:\Documents and Settings\Todd Baker\Application Data\Walgreens
2007-12-21 15:18 . 2007-09-05 15:56 101,632 -ra—— C:\WINDOWS\system32\drivers\swnc8u51.sys
2007-12-21 15:18 . 2007-09-05 15:56 73,600 -ra—— C:\WINDOWS\system32\drivers\swumx51.sys
2007-12-14 11:32 . 2007-12-14 11:32 12,632 –a—— C:\WINDOWS\system32\lsdelete.exe
2007-12-11 16:02 . 2007-12-11 16:11 24 —hs—- C:\WINDOWS\S22D02DB5.tmp
2007-12-09 12:43 . 2007-12-09 12:43 d——– C:\Documents and Settings\Todd Baker\Application Data\SlySoft
2007-12-09 12:40 . 2007-12-09 12:40 d——– C:\Documents and Settings\All Users\Application Data\SlySoft
2007-12-09 12:35 . 2007-12-12 22:55 d——– C:\Program Files\SlySoft
2007-12-09 07:15 . 2007-12-09 07:15 d——– C:\Documents and Settings\Todd Baker\Application Data\CyberLink
2007-12-09 04:19 . 2007-12-10 04:45 67 –a—— C:\WINDOWS\DVDRegionFree.INI
2007-12-08 16:25 . 2007-12-08 16:25 d——– C:\Program Files\GE Industrial Systems
2007-12-05 04:09 . 2007-12-05 04:09 d–h—– C:\WINDOWS\PIF
2007-12-01 14:27 . 2007-12-01 14:27 d——– C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-12-01 14:22 . 2007-12-01 14:22 d——– C:\Documents and Settings\Todd Baker\Application Data\Songbird1
2007-12-01 13:31 . 2007-12-01 13:31 d——– C:\Program Files\PCPitstop

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 04:00 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-30 16:42 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\U3
2008-01-30 14:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-30 14:31 ——— d—–w C:\Program Files\Eraser
2008-01-29 04:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-29 04:18 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 19:43 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-01-27 19:23 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-27 19:23 ——— d—–w C:\Program Files\Apoint
2008-01-27 19:10 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Skype
2008-01-27 19:01 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Hamachi
2008-01-27 17:47 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\skypePM
2008-01-27 15:06 ——— d—–w C:\Program Files\Password Safe
2008-01-27 12:59 ——— d—–w C:\Program Files\MagicDVDRipper
2008-01-23 05:04 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Azureus
2008-01-22 18:42 80 ——w C:\Documents and Settings\Todd Baker\Application Data\TIF.DAT
2008-01-07 21:03 ——— d—–w C:\Program Files\Azureus
2007-12-09 18:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-05 07:37 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\GoodSync
2007-11-29 16:55 ——— d—–w C:\Program Files\Siber Systems
2007-11-28 00:22 ——— d—–w C:\Program Files\DV6
2007-11-25 21:29 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-25 21:08 21,361 —-a-w C:\WINDOWS\AegisP.sys
2007-10-09 13:39 724,992 —-a-w C:\WINDOWS\iun6002.exe
2003-08-27 19:19 36,963 —-a-r C:\Program Files\Common Files\SM1updtr.dll
.
—-a-w		   176,128 2008-01-27 18:59:24  C:\Program Files\Apoint\Apoint .exe
—-a-w			33,280 2008-01-27 18:59:24  C:\Program Files\AT&T\Communication Manager\ATTCM .exe
—-a-w			52,896 2008-01-27 18:59:14  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			68,856 2008-01-27 18:59:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		 1,101,824 2008-01-27 18:59:37  C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
—-a-w		   995,328 2008-01-27 18:59:33  C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
—-a-w		21,686,568 2008-01-27 18:59:59  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		   125,168 2008-01-27 18:59:17  C:\Program Files\Symantec AntiVirus\VPTray .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"Walgreens PhotoShow Media Manager"="C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [ ]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [ ]
"Eraser"="C:\Program Files\Eraser\eraser.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-28 18:05 8429568]
"SigmatelSysTrayApp"="stsystra.exe" []
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 04:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"NvMediaCenter"="NvMCTray.dll" [2007-04-28 18:05 81920 C:\WINDOWS\system32\nvmctray.dll]
"AT&T Communication Manager"="C:\Program Files\AT&T\Communication Manager\ATTCM.exe" [ ]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"PrintServer Diagnostic"="C:\Program Files\Print Server\PTP\PSDiagnostic.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [ ]

C:\Documents and Settings\TPS\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]

C:\Documents and Settings\Todd Baker\Start Menu\Programs\Startup\
Hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 16:46:00 1724416]
SEL Update Manager.lnk - C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe [2007-04-09 14:29:44 303104]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 01000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\incsfxct]
incsfxct.dll

R1 tcpipBM;Bytemobile Kernel Network Provider;C:\WINDOWS\system32\drivers\tcpipBM.sys [2007-09-08 20:17]
R2 CBN;CBN;C:\WINDOWS\System32\Drivers\CBN.SYS [2007-11-08 20:09]
R3 guardian2;guardian2;C:\WINDOWS\system32\Drivers\oz776.sys [2007-02-23 14:47]
S3 CSRBC;CSRBC.Sys CSR test driver;C:\WINDOWS\system32\Drivers\csrbcxp.sys [2007-01-16 10:22]
S3 DN2AKNET;Dualnet IM Driver;C:\Program Files\Common Files\Deterministic Networks\Dnet2\bin\DN2AKNET.sys [2006-02-20 11:18]
S3 DniVad;Kongsberg Maritime virtual Network Adapter;C:\WINDOWS\system32\DRIVERS\dnvad.sys [2006-02-20 11:18]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-05-04 15:54]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\PCTINDIS5.SYS [2007-09-08 20:13]
S3 SE2Cbus;Sony Ericsson Device 044 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cbus.sys [2006-11-10 08:54]
S3 SE2Cmdfl;Sony Ericsson Device 044 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Cmdfl.sys [2006-11-10 08:54]
S3 SE2Cmdm;Sony Ericsson Device 044 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Cmdm.sys [2006-11-10 08:54]
S3 SE2Cmgmt;Sony Ericsson Device 044 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cmgmt.sys [2006-11-10 08:54]
S3 se2Cnd5;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se2Cnd5.sys [2006-11-10 08:54]
S3 SE2Cobex;Sony Ericsson Device 044 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Cobex.sys [2006-11-10 08:54]
S3 se2Cunic;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se2Cunic.sys [2006-11-10 08:54]
S3 SEL-5860 Time Service;SEL-5860 Time Service;"C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe" [2006-06-30 07:50]
S3 SMNDIS5;SMNDIS5 NDIS Protocol Driver;C:\PROGRA~1\VERIZO~1\VZACCE~1\SMNDIS5.SYS []
S3 SWMX00;Sierra Wireless USB MUX Driver (#00);C:\WINDOWS\system32\DRIVERS\swmx00.sys []
S3 SWNC5E00;Sierra Wireless MUX NDIS Driver (#00);C:\WINDOWS\system32\DRIVERS\SWNC5E00.sys []
S3 SWNC8U20;Sierra Wireless MUX NDIS Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swnc8u20.sys [2007-09-05 15:56]
S3 SWNC8U51;Sierra Wireless MUX NDIS Driver (UMTS51);C:\WINDOWS\system32\DRIVERS\swnc8u51.sys [2007-09-05 15:56]
S3 SWUMX20;Sierra Wireless USB MUX Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swumx20.sys [2007-09-05 15:56]
S3 SWUMX51;Sierra Wireless USB MUX Driver (UMTS51);C:\WINDOWS\system32\DRIVERS\swumx51.sys [2007-09-05 15:56]
S3 USBDongle;USBDongle;C:\WINDOWS\system32\DRIVERS\USBKey.sys [2002-12-27 01:09]
S3 V0070VID;Creative WebCam Notebook Ultra;C:\WINDOWS\system32\DRIVERS\V0070Vid.sys [2005-02-18 00:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{286a2e99-0a18-11dc-b0f5-cb21c15f200b}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{87cd5e04-1306-11dc-b108-0019b9694767}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bdaf34f0-5737-11dc-b65f-00164148b3dc}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f90b679c-84c6-11dc-b6b6-00a0d5ffff85}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe

.
**************************************************************************

disk not found C:\

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

disk not found C:\

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
.
**************************************************************************
.
Completion time: 2008-01-31 6:29:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-31 12:28:19
.
2008-01-08 20:38:25 — E O F —

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:36, on 2008-01-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.47.6.3:8887
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [PrintServer Diagnostic] C:\Program Files\Print Server\PTP\PSDiagnostic.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [Eraser] C:\Program Files\Eraser\eraser.exe -hide
O4 - Startup: Hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
O4 - Global Startup: SEL Update Manager.lnk = C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180326421187
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TPS
O17 - HKLM\Software\..\Telephony: DomainName = TPS
O17 - HKLM\System\CCS\Services\Tcpip\..\{06DED577-FDB1-4CD0-9491-D956C6614714}: NameServer = 5.35.153.15
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: incsfxct - incsfxct.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Inc. - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SEL-5860 Time Service - Schweitzer Engineering Laboratories, Inc. - C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 11660 bytes
Several of your programs have been damaged or ruined and will require reinstallation. We will first concentrate on replacing the good files that are available on your system and proceed with the remaining chores after all is clean:


A. 1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
File::
C:\WINDOWS\system32\drivers\tcpip.sys.old
C:\WINDOWS\system32\drivers\swnc8u51.sys
C:\WINDOWS\system32\drivers\swumx51.sys
C:\WINDOWS\S22D02DB5.tmp

RenV::
—-a-w		   176,128 2008-01-27 18:59:24  C:\Program Files\Apoint\Apoint .exe
—-a-w			33,280 2008-01-27 18:59:24  C:\Program Files\AT&T\Communication Manager\ATTCM .exe
—-a-w			52,896 2008-01-27 18:59:14  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			68,856 2008-01-27 18:59:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		 1,101,824 2008-01-27 18:59:37  C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
—-a-w		   995,328 2008-01-27 18:59:33  C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
—-a-w		21,686,568 2008-01-27 18:59:59  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		   125,168 2008-01-27 18:59:17  C:\Program Files\Symantec AntiVirus\VPTray .exe


Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\incsfxct]


Driver::
SMNDIS5
SWMX00
SWNC5E00

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


6. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply after you re-enable all the programs that were disabled during the running of ComboFix:
  • Combofix.txt
  • A new HijackThis log.
Please take note:

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.


B. I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
I still have an exception error that comes up before the desktop shows up on bootup. It is for Defwatch.exe. I also get a request to send a error report to Microsoft for Virus Definition Daemon ensoutering a problem.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:39, on 2008-01-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.47.6.3:8887
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Startup: Hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
O4 - Global Startup: SEL Update Manager.lnk = C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180326421187
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TPS
O17 - HKLM\Software\..\Telephony: DomainName = TPS
O17 - HKLM\System\CCS\Services\Tcpip\..\{06DED577-FDB1-4CD0-9491-D956C6614714}: NameServer = 5.35.153.15
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Inc. - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SEL-5860 Time Service - Schweitzer Engineering Laboratories, Inc. - C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 11826 bytes


ComboFix 08-01-31.4 - Todd Baker 2008-01-31 12:28:54.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.530 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Todd Baker\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\WINDOWS\S22D02DB5.tmp
C:\WINDOWS\system32\drivers\swnc8u51.sys
C:\WINDOWS\system32\drivers\swumx51.sys
C:\WINDOWS\system32\drivers\tcpip.sys.old
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\S22D02DB5.tmp
C:\WINDOWS\system32\drivers\swnc8u51.sys
C:\WINDOWS\system32\drivers\swumx51.sys
C:\WINDOWS\system32\drivers\tcpip.sys.old

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_SMNDIS5
——-\SMNDIS5
——-\SWMX00
——-\SWNC5E00


((((((((((((((((((((((((( Files Created from 2007-12-28 to 2008-01-31 )))))))))))))))))))))))))))))))
.

2008-01-30 22:10 . 2008-01-30 22:10 d——– C:\Program Files\Sun
2008-01-30 22:10 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-30 22:07 . 2008-01-30 22:10 d——– C:\Program Files\Java
2008-01-30 22:05 . 2008-01-30 22:05 d——– C:\Program Files\Common Files\Java
2008-01-29 14:10 . 2008-01-29 14:10 d——– C:\Program Files\Trend Micro
2008-01-28 22:27 . 2008-01-28 22:27 d——– C:\Program Files\Lavasoft
2008-01-27 12:05 . 2008-01-31 12:21 321 –a—— C:\BOOT.INI
2008-01-27 07:42 . 2008-01-27 07:42 d——– C:\Program Files\Microsoft Silverlight
2008-01-26 19:06 . 2008-01-29 11:46 d——– C:\VundoFix Backups
2008-01-23 04:15 . 2008-01-23 04:15 67 –a—— C:\WINDOWS\URPC.INI
2008-01-19 00:04 . 2008-01-19 00:04 d——– C:\Program Files\DVDFab Platinum 4
2008-01-18 17:02 . 2008-01-18 17:02 d——– C:\Program Files\LG Software Innovations
2008-01-18 17:02 . 2008-01-27 08:54 d——– C:\Documents and Settings\Todd Baker\Application Data\Vso
2008-01-18 17:02 . 2008-01-18 17:02 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-18 17:02 . 2008-01-27 06:58 47,360 –a—— C:\Documents and Settings\Todd Baker\Application Data\pcouffin.sys
2008-01-18 16:25 . 2008-01-18 16:26 d——– C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-18 15:34 . 2008-01-18 15:34 d——– C:\Program Files\XviD
2008-01-18 15:34 . 2008-01-18 15:36 67 –a—— C:\WINDOWS\#1 DVD Ripper.INI
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\Todd Baker\Application Data\PCTV4Me
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\All Users\Application Data\PCTV4Me
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Program Files\Common Files\Synacast
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Documents and Settings\Todd Baker\Application Data\PPMate
2008-01-07 12:42 . 2008-01-07 12:42 359,808 –a—— C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-01-05 10:35 . 2008-01-05 10:35 0 –a—— C:\WINDOWS\iplayer.INI
2008-01-05 10:33 . 2008-01-05 10:34 d——– C:\Program Files\InterActual
2008-01-04 13:50 . 2008-01-27 13:09 0 –a—— C:\WINDOWS\system32\tdlsoui.flag
2008-01-04 13:48 . 2008-01-05 07:08 d——– C:\Documents and Settings\Todd Baker\Application Data\dvdcss
2008-01-02 11:39 . 2008-01-02 11:39 d——– C:\Documents and Settings\Todd Baker\Application Data\Simple Star
2008-01-02 11:38 . 2008-01-02 11:38 d——– C:\Program Files\Common Files\Simple Star Shared
2008-01-02 11:36 . 2008-01-02 11:45 d——– C:\Documents and Settings\Todd Baker\Application Data\Walgreens
2007-12-14 11:32 . 2007-12-14 11:32 12,632 –a—— C:\WINDOWS\system32\lsdelete.exe
2007-12-09 12:43 . 2007-12-09 12:43 d——– C:\Documents and Settings\Todd Baker\Application Data\SlySoft
2007-12-09 12:40 . 2007-12-09 12:40 d——– C:\Documents and Settings\All Users\Application Data\SlySoft
2007-12-09 12:35 . 2007-12-12 22:55 d——– C:\Program Files\SlySoft
2007-12-09 07:15 . 2007-12-09 07:15 d——– C:\Documents and Settings\Todd Baker\Application Data\CyberLink
2007-12-09 04:19 . 2007-12-10 04:45 67 –a—— C:\WINDOWS\DVDRegionFree.INI
2007-12-08 16:25 . 2007-12-08 16:25 d——– C:\Program Files\GE Industrial Systems
2007-12-05 04:09 . 2007-12-05 04:09 d–h—– C:\WINDOWS\PIF
2007-12-01 14:27 . 2007-12-01 14:27 d——– C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-12-01 14:22 . 2007-12-01 14:22 d——– C:\Documents and Settings\Todd Baker\Application Data\Songbird1
2007-12-01 13:31 . 2007-12-01 13:31 d——– C:\Program Files\PCPitstop

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 04:00 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-30 16:42 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\U3
2008-01-30 14:51 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-30 14:31 ——— d—–w C:\Program Files\Eraser
2008-01-29 04:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-29 04:18 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 19:43 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-01-27 19:23 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-27 19:23 ——— d—–w C:\Program Files\Apoint
2008-01-27 19:10 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Skype
2008-01-27 19:01 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Hamachi
2008-01-27 17:47 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\skypePM
2008-01-27 15:06 ——— d—–w C:\Program Files\Password Safe
2008-01-27 12:59 ——— d—–w C:\Program Files\MagicDVDRipper
2008-01-23 05:04 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Azureus
2008-01-22 18:42 80 ——w C:\Documents and Settings\Todd Baker\Application Data\TIF.DAT
2008-01-07 21:03 ——— d—–w C:\Program Files\Azureus
2007-12-09 18:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-05 07:37 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\GoodSync
2007-11-29 16:55 ——— d—–w C:\Program Files\Siber Systems
2007-11-28 00:22 ——— d—–w C:\Program Files\DV6
2007-11-25 21:29 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-25 21:08 21,361 —-a-w C:\WINDOWS\AegisP.sys
2007-10-09 13:39 724,992 —-a-w C:\WINDOWS\iun6002.exe
2003-08-27 19:19 36,963 —-a-r C:\Program Files\Common Files\SM1updtr.dll
.
—-a-w		   176,128 2008-01-27 18:59:24  C:\Program Files\Apoint\Apoint .exe
—-a-w			33,280 2008-01-27 18:59:24  C:\Program Files\AT&T\Communication Manager\ATTCM .exe
—-a-w			52,896 2008-01-27 18:59:14  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			68,856 2008-01-27 18:59:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		 1,101,824 2008-01-27 18:59:37  C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
—-a-w		   995,328 2008-01-27 18:59:33  C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
—-a-w		21,686,568 2008-01-27 18:59:59  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		   125,168 2008-01-27 18:59:17  C:\Program Files\Symantec AntiVirus\VPTray .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"Walgreens PhotoShow Media Manager"="C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [ ]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-28 18:05 8429568]
"SigmatelSysTrayApp"="stsystra.exe" []
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 04:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"NvMediaCenter"="NvMCTray.dll" [2007-04-28 18:05 81920 C:\WINDOWS\system32\nvmctray.dll]
"AT&T Communication Manager"="C:\Program Files\AT&T\Communication Manager\ATTCM.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [ ]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 04:00 158208]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]

C:\Documents and Settings\TPS\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]

C:\Documents and Settings\Todd Baker\Start Menu\Programs\Startup\
Hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 16:46:00 1724416]
SEL Update Manager.lnk - C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe [2007-04-09 14:29:44 303104]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 01000000

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\Program Files\Eraser\eraser.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrintServer Diagnostic]
C:\Program Files\Print Server\PTP\PSDiagnostic.exe

R1 tcpipBM;Bytemobile Kernel Network Provider;C:\WINDOWS\system32\drivers\tcpipBM.sys [2007-09-08 20:17]
R2 CBN;CBN;C:\WINDOWS\System32\Drivers\CBN.SYS [2007-11-08 20:09]
R3 guardian2;guardian2;C:\WINDOWS\system32\Drivers\oz776.sys [2007-02-23 14:47]
S3 CSRBC;CSRBC.Sys CSR test driver;C:\WINDOWS\system32\Drivers\csrbcxp.sys [2007-01-16 10:22]
S3 DN2AKNET;Dualnet IM Driver;C:\Program Files\Common Files\Deterministic Networks\Dnet2\bin\DN2AKNET.sys [2006-02-20 11:18]
S3 DniVad;Kongsberg Maritime virtual Network Adapter;C:\WINDOWS\system32\DRIVERS\dnvad.sys [2006-02-20 11:18]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-05-04 15:54]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\PCTINDIS5.SYS [2007-09-08 20:13]
S3 SE2Cbus;Sony Ericsson Device 044 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cbus.sys [2006-11-10 08:54]
S3 SE2Cmdfl;Sony Ericsson Device 044 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Cmdfl.sys [2006-11-10 08:54]
S3 SE2Cmdm;Sony Ericsson Device 044 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Cmdm.sys [2006-11-10 08:54]
S3 SE2Cmgmt;Sony Ericsson Device 044 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cmgmt.sys [2006-11-10 08:54]
S3 se2Cnd5;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se2Cnd5.sys [2006-11-10 08:54]
S3 SE2Cobex;Sony Ericsson Device 044 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Cobex.sys [2006-11-10 08:54]
S3 se2Cunic;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se2Cunic.sys [2006-11-10 08:54]
S3 SEL-5860 Time Service;SEL-5860 Time Service;"C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe" [2006-06-30 07:50]
S3 SWNC8U20;Sierra Wireless MUX NDIS Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swnc8u20.sys [2007-09-05 15:56]
S3 SWNC8U51;Sierra Wireless MUX NDIS Driver (UMTS51);C:\WINDOWS\system32\DRIVERS\swnc8u51.sys []
S3 SWUMX20;Sierra Wireless USB MUX Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swumx20.sys [2007-09-05 15:56]
S3 SWUMX51;Sierra Wireless USB MUX Driver (UMTS51);C:\WINDOWS\system32\DRIVERS\swumx51.sys []
S3 USBDongle;USBDongle;C:\WINDOWS\system32\DRIVERS\USBKey.sys [2002-12-27 01:09]
S3 V0070VID;Creative WebCam Notebook Ultra;C:\WINDOWS\system32\DRIVERS\V0070Vid.sys [2005-02-18 00:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{286a2e99-0a18-11dc-b0f5-cb21c15f200b}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{87cd5e04-1306-11dc-b108-0019b9694767}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bdaf34f0-5737-11dc-b65f-00164148b3dc}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f90b679c-84c6-11dc-b6b6-00a0d5ffff85}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe

.
**************************************************************************

disk not found C:\

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

disk not found C:\

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\WINDOWS\system32\dumprep.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
.
**************************************************************************
.
Completion time: 2008-01-31 12:39:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-31 18:38:14
ComboFix2.txt 2008-01-31 12:29:12
.
2008-01-08 20:38:25 — E O F —


# version=4
# OnlineScanner.ocx=[removed]
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=2840 (20080131)
# vers_arch_module=1.063 (20080117)
# vers_adv_heur_module=1.060 (20070601)
# EOSSerial=04fd7aef087e304cab794f67c8f0f10f
# end=finished
# remove_checked=false
# unwanted_checked=false
# utc_time=2008-01-31 07:49:14
# local_time=2008-01-31 01:49:14 (-0600, Central Standard Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=347184
# found=5
# scan_time=3213
C:\Documents and Settings\Todd Baker\My Documents\My Downloads\AVICodecPackPlus2.exe Win32/Adware.Webdir application 57DD3EAC8F5BC33A0027D6928F230693
C:\Documents and Settings\Todd Baker\My Documents\My Downloads\AVICodecPackPlus2.exe »NSIS »pxwma.dll Win32/Adware.Webdir application 00000000000000000000000000000000
C:\QooBox\Quarantine\C\WINDOWS\system32\gebcbbc.dll.vir Win32/Adware.Virtumonde application EBF8A5698FDDCE62DC9BA0C3EFF4042B
C:\QooBox\Quarantine\C\WINDOWS\system32\ssqpm.dll.vir Win32/Adware.Virtumonde.FP application 3B1480B4775E1C05AB5842F9D947D875
C:\VundoFix Backups\gebcbbc.dll.bad Win32/Adware.Virtumonde application EBF8A5698FDDCE62DC9BA0C3EFF4042B


I also have a big red X in windows explorer next to C:/ drive where the hard drive icon should be.

Thanks for all you help
Let us see if we can get rid of the bad X first. This next procedure will only identify registry entries and will NOT change anything:

1. Launch Notepad, and copy/paste the contents of the quote box below into a new Notepad file. Save it with file name options.txt and save as file type: all files to your desktop.

RegSearch Options File

[Search]
DriveIcons

[Exclude]

[Options]
Filter=KVDLUI


2. Download Registry Search to your desktop.
  • Right click on the compressed RegSearch folder, and choose "Extract All". In the box that pops open, click "Next", then "Next" again, and then "Finish". You now have another RegSearch folder on your desktop.
  • Open the new folder, and double click on regsearch.exe
  • Click "Import" in the lower left corner and browse to the options.txt file that you just saved on your desktop. Do not choose the one in the RegSearch folder itself.
  • Click OK and Registry Search will scan your registry for the file(s), and a Notepad box will open with a report.
  • Please reply here with the entire contents of the Notepad file from RegSearch.
Windows Registry Editor Version 5.00 ; Registry Search 2.0 by Bobbi Flekman © 2005 ; Version: 2.0.5.0 ; Results at 2008-01-31 19:17:23 for strings: ; 'driveicons' ; Strings excluded from search: ; (None) ; Search in: ; Registry Keys Registry Values Registry Data ; HKEY_LOCAL_MACHINE HKEY_USERS [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c\DefaultIcon] ; End Of The Log…
1. Go to Start->Run and type in notepad and hit OK.

2. Then copy and paste the content of the following codebox into Notepad:

@ECHO OFF
If exist Query.txt Del Query.txt
@ECHO Working…….
Reg query "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons" /s >> Query.txt
Reg Delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons" /f
start notepad Query.txt
del icon.bat

3. Save the file to your DESKTOP as "icon.bat". Make sure to save it with the quotes.

4. Double click icon.bat.

5. Post the content of Query.txt into your reply and tell me if the "X" is gone and your "C: Drive icon" is back
! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\DriveIcons\c\DefaultIcon REG_SZ %SystemRoot%\system32\shell32.dll,131 The x is gone and the drive icon is back, Thank you
Let's try this again:


1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\Documents and Settings\Todd Baker\My Documents\My Downloads\AVICodecPackPlus2.exe

RenV::
C:\Program Files\Apoint\Apoint .exe
C:\Program Files\AT&T\Communication Manager\ATTCM .exe
C:\Program Files\Common Files\Symantec Shared\ccApp .exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
C:\Program Files\Skype\Phone\Skype .exe
C:\Program Files\Symantec AntiVirus\VPTray .exe

KillAll::
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Save the above as CFScript.txt

4. Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.

5. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

6. ComboFix will automatically REBOOT your machine when the KillAll:: switch is used..

7. Next, re-enable all the programs that you disabled prior to running ComboFix.

8. Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix 08-01-31.4 - Todd Baker 2008-01-31 21:53:46.3 - NTFSx86

Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Todd Baker\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE
C:\Documents and Settings\Todd Baker\My Documents\My Downloads\AVICodecPackPlus2.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Todd Baker\My Documents\My Downloads\AVICodecPackPlus2.exe

.
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.

2008-01-31 12:51 . 2008-01-31 13:49 d——– C:\Program Files\EsetOnlineScanner
2008-01-30 22:10 . 2008-01-30 22:10 d——– C:\Program Files\Sun
2008-01-30 22:10 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-30 22:07 . 2008-01-30 22:10 d——– C:\Program Files\Java
2008-01-30 22:05 . 2008-01-30 22:05 d——– C:\Program Files\Common Files\Java
2008-01-29 14:10 . 2008-01-29 14:10 d——– C:\Program Files\Trend Micro
2008-01-28 22:27 . 2008-01-28 22:27 d——– C:\Program Files\Lavasoft
2008-01-27 12:05 . 2008-01-31 12:21 321 –a—— C:\BOOT.INI
2008-01-27 07:42 . 2008-01-27 07:42 d——– C:\Program Files\Microsoft Silverlight
2008-01-26 19:06 . 2008-01-29 11:46 d——– C:\VundoFix Backups
2008-01-23 04:15 . 2008-01-23 04:15 67 –a—— C:\WINDOWS\URPC.INI
2008-01-19 00:04 . 2008-01-19 00:04 d——– C:\Program Files\DVDFab Platinum 4
2008-01-18 17:02 . 2008-01-18 17:02 d——– C:\Program Files\LG Software Innovations
2008-01-18 17:02 . 2008-01-27 08:54 d——– C:\Documents and Settings\Todd Baker\Application Data\Vso
2008-01-18 17:02 . 2008-01-18 17:02 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-18 17:02 . 2008-01-27 06:58 47,360 –a—— C:\Documents and Settings\Todd Baker\Application Data\pcouffin.sys
2008-01-18 16:25 . 2008-01-18 16:26 d——– C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-18 15:34 . 2008-01-18 15:34 d——– C:\Program Files\XviD
2008-01-18 15:34 . 2008-01-18 15:36 67 –a—— C:\WINDOWS\#1 DVD Ripper.INI
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\Todd Baker\Application Data\PCTV4Me
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\All Users\Application Data\PCTV4Me
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Program Files\Common Files\Synacast
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Documents and Settings\Todd Baker\Application Data\PPMate
2008-01-07 12:42 . 2008-01-07 12:42 359,808 –a—— C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-01-05 10:35 . 2008-01-05 10:35 0 –a—— C:\WINDOWS\iplayer.INI
2008-01-05 10:33 . 2008-01-05 10:34 d——– C:\Program Files\InterActual
2008-01-04 13:50 . 2008-01-27 13:09 0 –a—— C:\WINDOWS\system32\tdlsoui.flag
2008-01-04 13:48 . 2008-01-05 07:08 d——– C:\Documents and Settings\Todd Baker\Application Data\dvdcss
2008-01-02 11:39 . 2008-01-02 11:39 d——– C:\Documents and Settings\Todd Baker\Application Data\Simple Star
2008-01-02 11:38 . 2008-01-02 11:38 d——– C:\Program Files\Common Files\Simple Star Shared
2008-01-02 11:36 . 2008-01-02 11:45 d——– C:\Documents and Settings\Todd Baker\Application Data\Walgreens

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 18:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-31 04:00 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-30 16:42 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\U3
2008-01-30 14:31 ——— d—–w C:\Program Files\Eraser
2008-01-29 04:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-29 04:18 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 19:43 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-01-27 19:23 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-27 19:23 ——— d—–w C:\Program Files\Apoint
2008-01-27 19:10 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Skype
2008-01-27 19:01 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Hamachi
2008-01-27 17:47 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\skypePM
2008-01-27 15:06 ——— d—–w C:\Program Files\Password Safe
2008-01-27 12:59 ——— d—–w C:\Program Files\MagicDVDRipper
2008-01-23 05:04 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Azureus
2008-01-22 18:42 80 ——w C:\Documents and Settings\Todd Baker\Application Data\TIF.DAT
2008-01-07 21:03 ——— d—–w C:\Program Files\Azureus
2007-12-13 04:55 ——— d—–w C:\Program Files\SlySoft
2007-12-09 18:43 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\SlySoft
2007-12-09 18:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-12-09 18:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-09 13:15 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\CyberLink
2007-12-08 22:25 ——— d—–w C:\Program Files\GE Industrial Systems
2007-12-05 07:37 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\GoodSync
2007-12-01 20:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-12-01 20:22 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Songbird1
2007-12-01 19:31 ——— d—–w C:\Program Files\PCPitstop
2007-11-25 21:29 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-25 21:08 21,361 —-a-w C:\WINDOWS\AegisP.sys
2003-08-27 19:19 36,963 —-a-r C:\Program Files\Common Files\SM1updtr.dll
.
—-a-w		   176,128 2008-01-27 18:59:24  C:\Program Files\Apoint\Apoint .exe
—-a-w			33,280 2008-01-27 18:59:24  C:\Program Files\AT&T\Communication Manager\ATTCM .exe
—-a-w			52,896 2008-01-27 18:59:14  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			68,856 2008-01-27 18:59:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		 1,101,824 2008-01-27 18:59:37  C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
—-a-w		   995,328 2008-01-27 18:59:33  C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
—-a-w		21,686,568 2008-01-27 18:59:59  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		   125,168 2008-01-27 18:59:17  C:\Program Files\Symantec AntiVirus\VPTray .exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"Walgreens PhotoShow Media Manager"="C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [ ]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-28 18:05 8429568]
"SigmatelSysTrayApp"="stsystra.exe" []
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 04:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"NvMediaCenter"="NvMCTray.dll" [2007-04-28 18:05 81920 C:\WINDOWS\system32\nvmctray.dll]
"AT&T Communication Manager"="C:\Program Files\AT&T\Communication Manager\ATTCM.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [ ]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]
"PrintServer Diagnostic"="C:\Program Files\Print Server\PTP\PSDiagnostic.exe" [ ]

C:\Documents and Settings\TPS\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]

C:\Documents and Settings\Todd Baker\Start Menu\Programs\Startup\
Hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 16:46:00 1724416]
SEL Update Manager.lnk - C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe [2007-04-09 14:29:44 303104]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 01000000

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\Program Files\Eraser\eraser.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrintServer Diagnostic]
C:\Program Files\Print Server\PTP\PSDiagnostic.exe

R1 tcpipBM;Bytemobile Kernel Network Provider;C:\WINDOWS\system32\drivers\tcpipBM.sys [2007-09-08 20:17]
R2 CBN;CBN;C:\WINDOWS\System32\Drivers\CBN.SYS [2007-11-08 20:09]
R3 guardian2;guardian2;C:\WINDOWS\system32\Drivers\oz776.sys [2007-02-23 14:47]
S3 CSRBC;CSRBC.Sys CSR test driver;C:\WINDOWS\system32\Drivers\csrbcxp.sys [2007-01-16 10:22]
S3 DN2AKNET;Dualnet IM Driver;C:\Program Files\Common Files\Deterministic Networks\Dnet2\bin\DN2AKNET.sys [2006-02-20 11:18]
S3 DniVad;Kongsberg Maritime virtual Network Adapter;C:\WINDOWS\system32\DRIVERS\dnvad.sys [2006-02-20 11:18]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-05-04 15:54]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\PCTINDIS5.SYS [2007-09-08 20:13]
S3 SE2Cbus;Sony Ericsson Device 044 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cbus.sys [2006-11-10 08:54]
S3 SE2Cmdfl;Sony Ericsson Device 044 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Cmdfl.sys [2006-11-10 08:54]
S3 SE2Cmdm;Sony Ericsson Device 044 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Cmdm.sys [2006-11-10 08:54]
S3 SE2Cmgmt;Sony Ericsson Device 044 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cmgmt.sys [2006-11-10 08:54]
S3 se2Cnd5;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se2Cnd5.sys [2006-11-10 08:54]
S3 SE2Cobex;Sony Ericsson Device 044 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Cobex.sys [2006-11-10 08:54]
S3 se2Cunic;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se2Cunic.sys [2006-11-10 08:54]
S3 SEL-5860 Time Service;SEL-5860 Time Service;"C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe" [2006-06-30 07:50]
S3 SWNC8U20;Sierra Wireless MUX NDIS Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swnc8u20.sys [2007-09-05 15:56]
S3 SWNC8U51;Sierra Wireless MUX NDIS Driver (UMTS51);C:\WINDOWS\system32\DRIVERS\swnc8u51.sys []
S3 SWUMX20;Sierra Wireless USB MUX Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swumx20.sys [2007-09-05 15:56]
S3 SWUMX51;Sierra Wireless USB MUX Driver (UMTS51);C:\WINDOWS\system32\DRIVERS\swumx51.sys []
S3 USBDongle;USBDongle;C:\WINDOWS\system32\DRIVERS\USBKey.sys [2002-12-27 01:09]
S3 V0070VID;Creative WebCam Notebook Ultra;C:\WINDOWS\system32\DRIVERS\V0070Vid.sys [2005-02-18 00:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{286a2e99-0a18-11dc-b0f5-cb21c15f200b}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{87cd5e04-1306-11dc-b108-0019b9694767}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bdaf34f0-5737-11dc-b65f-00164148b3dc}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f90b679c-84c6-11dc-b6b6-00a0d5ffff85}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe

.
**************************************************************************

disk not found C:\

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

disk not found C:\

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
.
**************************************************************************
.
Completion time: 2008-01-31 22:04:53 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-01 04:04:01
ComboFix2.txt 2008-01-31 18:39:07
ComboFix3.txt 2008-01-31 12:29:12
.
2008-01-08 20:38:25 — E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:07, on 2008-01-31
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.47.6.3:8887
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [PrintServer Diagnostic] C:\Program Files\Print Server\PTP\PSDiagnostic.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe
O4 - Startup: Hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
O4 - Global Startup: SEL Update Manager.lnk = C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180326421187
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TPS
O17 - HKLM\Software\..\Telephony: DomainName = TPS
O17 - HKLM\System\CCS\Services\Tcpip\..\{06DED577-FDB1-4CD0-9491-D956C6614714}: NameServer = 5.35.153.15
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Inc. - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SEL-5860 Time Service - Schweitzer Engineering Laboratories, Inc. - C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 11917 bytes
I have not abandoned you. I am just waiting for another pair of eyes to help me find out why those files do not appear to be replaced by ComboFix.
When you have run ComboFix both by itself or using the CFScript feature did you receive any error messages. If in the affirmative, please post them if you are able to remember what they said. Thanks
Sorry for interrupting but there's a bug with the current copy of ComboFix. Please delete your existing copy & grab an updated copy from http://download.bleepingcomputer.com/sUBs/ComboFix.exe.

Run this CFScript with it & post the resultant log:

RENV::
—-a-w		   176,128 2008-01-27 18:59:24  C:\Program Files\Apoint\Apoint .exe
—-a-w			33,280 2008-01-27 18:59:24  C:\Program Files\AT&T\Communication Manager\ATTCM .exe
—-a-w			52,896 2008-01-27 18:59:14  C:\Program Files\Common Files\Symantec Shared\ccApp .exe
—-a-w			68,856 2008-01-27 18:59:50  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier .exe
—-a-w		 1,101,824 2008-01-27 18:59:37  C:\Program Files\Intel\Wireless\Bin\ifrmewrk .exe
—-a-w		   995,328 2008-01-27 18:59:33  C:\Program Files\Intel\Wireless\Bin\ZCfgSvc .exe
—-a-w		21,686,568 2008-01-27 18:59:59  C:\Program Files\Skype\Phone\Skype .exe
—-a-w		   125,168 2008-01-27 18:59:17  C:\Program Files\Symantec AntiVirus\VPTray .exe
The only error that comes up when combofix finishes is an "SED" error it can't find raw_data file. Also this time a flashplayer update poped up and every time I right click on any file Symantec starts a install program. The other thing that I have found is the Intel PCset Wireless program that controls my wireless modem does not load in the tray anymore and the at&t connection program for my wireless card never works after a reboot, I always have to reinstall it.

ComboFix 08-02.01.5 - Todd Baker 2008-02-01 6:31:19.4 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.442 [GMT -6:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Todd Baker\Desktop\CFScript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat

—– BITS: Possible infected sites —–

hxxp://au.download.windowsupdate.com
hxxp://www.download.windowsupdate.com
.
((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.

2008-01-31 12:51 . 2008-01-31 13:49 d——– C:\Program Files\EsetOnlineScanner
2008-01-30 22:10 . 2008-01-30 22:10 d——– C:\Program Files\Sun
2008-01-30 22:10 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-01-30 22:07 . 2008-01-30 22:10 d——– C:\Program Files\Java
2008-01-30 22:05 . 2008-01-30 22:05 d——– C:\Program Files\Common Files\Java
2008-01-29 14:10 . 2008-01-29 14:10 d——– C:\Program Files\Trend Micro
2008-01-28 22:27 . 2008-01-28 22:27 d——– C:\Program Files\Lavasoft
2008-01-27 12:05 . 2008-01-31 12:21 321 –a—— C:\BOOT.INI
2008-01-27 07:42 . 2008-01-27 07:42 d——– C:\Program Files\Microsoft Silverlight
2008-01-26 19:06 . 2008-01-29 11:46 d——– C:\VundoFix Backups
2008-01-23 04:15 . 2008-01-23 04:15 67 –a—— C:\WINDOWS\URPC.INI
2008-01-19 00:04 . 2008-01-19 00:04 d——– C:\Program Files\DVDFab Platinum 4
2008-01-18 17:02 . 2008-01-18 17:02 d——– C:\Program Files\LG Software Innovations
2008-01-18 17:02 . 2008-01-27 08:54 d——– C:\Documents and Settings\Todd Baker\Application Data\Vso
2008-01-18 17:02 . 2008-01-18 17:02 47,360 –a—— C:\WINDOWS\system32\drivers\pcouffin.sys
2008-01-18 17:02 . 2008-01-27 06:58 47,360 –a—— C:\Documents and Settings\Todd Baker\Application Data\pcouffin.sys
2008-01-18 16:25 . 2008-01-18 16:26 d——– C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-01-18 15:34 . 2008-01-18 15:34 d——– C:\Program Files\XviD
2008-01-18 15:34 . 2008-01-18 15:36 67 –a—— C:\WINDOWS\#1 DVD Ripper.INI
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\Todd Baker\Application Data\PCTV4Me
2008-01-07 13:36 . 2008-01-07 13:37 d——– C:\Documents and Settings\All Users\Application Data\PCTV4Me
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Program Files\Common Files\Synacast
2008-01-07 13:23 . 2008-01-07 13:23 d——– C:\Documents and Settings\Todd Baker\Application Data\PPMate
2008-01-07 12:42 . 2008-01-07 12:42 359,808 –a—— C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-01-05 10:35 . 2008-01-05 10:35 0 –a—— C:\WINDOWS\iplayer.INI
2008-01-05 10:33 . 2008-01-05 10:34 d——– C:\Program Files\InterActual
2008-01-04 13:50 . 2008-01-27 13:09 0 –a—— C:\WINDOWS\system32\tdlsoui.flag
2008-01-04 13:48 . 2008-01-05 07:08 d——– C:\Documents and Settings\Todd Baker\Application Data\dvdcss
2008-01-02 11:39 . 2008-01-02 11:39 d——– C:\Documents and Settings\Todd Baker\Application Data\Simple Star
2008-01-02 11:38 . 2008-01-02 11:38 d——– C:\Program Files\Common Files\Simple Star Shared
2008-01-02 11:36 . 2008-01-02 11:45 d——– C:\Documents and Settings\Todd Baker\Application Data\Walgreens

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 12:31 ——— d—–w C:\Program Files\Symantec AntiVirus
2008-02-01 12:31 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-02-01 12:31 ——— d—–w C:\Program Files\Apoint
2008-01-31 18:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-01-31 04:00 ——— d—–w C:\Program Files\Microsoft ActiveSync
2008-01-30 16:42 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\U3
2008-01-30 14:31 ——— d—–w C:\Program Files\Eraser
2008-01-29 04:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-29 04:18 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-01-27 19:10 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Skype
2008-01-27 19:01 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Hamachi
2008-01-27 17:47 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\skypePM
2008-01-27 15:06 ——— d—–w C:\Program Files\Password Safe
2008-01-27 12:59 ——— d—–w C:\Program Files\MagicDVDRipper
2008-01-23 05:04 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Azureus
2008-01-22 18:42 80 ——w C:\Documents and Settings\Todd Baker\Application Data\TIF.DAT
2008-01-07 21:03 ——— d—–w C:\Program Files\Azureus
2007-12-14 17:32 12,632 —-a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-13 04:55 ——— d—–w C:\Program Files\SlySoft
2007-12-09 18:43 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\SlySoft
2007-12-09 18:40 ——— d—–w C:\Documents and Settings\All Users\Application Data\SlySoft
2007-12-09 18:37 ——— d–h–w C:\Program Files\InstallShield Installation Information
2007-12-09 13:15 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\CyberLink
2007-12-08 22:25 ——— d—–w C:\Program Files\GE Industrial Systems
2007-12-05 07:37 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\GoodSync
2007-12-01 20:27 ——— d—–w C:\Documents and Settings\All Users\Application Data\SongbirdVLC
2007-12-01 20:22 ——— d—–w C:\Documents and Settings\Todd Baker\Application Data\Songbird1
2007-12-01 19:31 ——— d—–w C:\Program Files\PCPitstop
2007-11-25 21:29 32 —-a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-11-25 21:08 376,832 —-a-w C:\WINDOWS\system32\AegisI5Installer.exe
2007-11-25 21:08 21,361 —-a-w C:\WINDOWS\AegisP.sys
2007-11-09 02:09 43,520 —-a-w C:\WINDOWS\system32\CBNDLL.DLL
2007-11-09 02:09 376,832 —-a-w C:\WINDOWS\system32\MPIWIN32.DLL
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2003-08-27 19:19 36,963 —-a-r C:\Program Files\Common Files\SM1updtr.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00 15360]
"Walgreens PhotoShow Media Manager"="C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe" [ ]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-28 18:05 8429568]
"SigmatelSysTrayApp"="stsystra.exe" []
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 04:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"NvMediaCenter"="NvMCTray.dll" [2007-04-28 18:05 81920 C:\WINDOWS\system32\nvmctray.dll]
"AT&T Communication Manager"="C:\Program Files\AT&T\Communication Manager\ATTCM.exe" [2008-01-27 12:59 33280]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [ ]
"PrintServer Diagnostic"="C:\Program Files\Print Server\PTP\PSDiagnostic.exe" [ ]

C:\Documents and Settings\TPS\Start Menu\Programs\Startup\
hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]

C:\Documents and Settings\Todd Baker\Start Menu\Programs\Startup\
Hamachi.lnk - C:\Program Files\Hamachi\hamachi.exe [2007-05-24 11:23:56 624416]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Bluetooth Manager.lnk - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2005-11-18 16:46:00 1724416]
SEL Update Manager.lnk - C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe [2007-04-09 14:29:44 303104]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsNetHood"= 01000000

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\Program Files\Eraser\eraser.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PrintServer Diagnostic]
C:\Program Files\Print Server\PTP\PSDiagnostic.exe

R1 tcpipBM;Bytemobile Kernel Network Provider;C:\WINDOWS\system32\drivers\tcpipBM.sys [2007-09-08 20:17]
R2 CBN;CBN;C:\WINDOWS\System32\Drivers\CBN.SYS [2007-11-08 20:09]
R3 guardian2;guardian2;C:\WINDOWS\system32\Drivers\oz776.sys [2007-02-23 14:47]
S3 CSRBC;CSRBC.Sys CSR test driver;C:\WINDOWS\system32\Drivers\csrbcxp.sys [2007-01-16 10:22]
S3 DN2AKNET;Dualnet IM Driver;C:\Program Files\Common Files\Deterministic Networks\Dnet2\bin\DN2AKNET.sys [2006-02-20 11:18]
S3 DniVad;Kongsberg Maritime virtual Network Adapter;C:\WINDOWS\system32\DRIVERS\dnvad.sys [2006-02-20 11:18]
S3 motmodem;Motorola USB CDC ACM Driver;C:\WINDOWS\system32\DRIVERS\motmodem.sys [2007-05-04 15:54]
S3 PCTINDIS5;PCTINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\PCTINDIS5.SYS [2007-09-08 20:13]
S3 SE2Cbus;Sony Ericsson Device 044 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cbus.sys [2006-11-10 08:54]
S3 SE2Cmdfl;Sony Ericsson Device 044 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Cmdfl.sys [2006-11-10 08:54]
S3 SE2Cmdm;Sony Ericsson Device 044 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Cmdm.sys [2006-11-10 08:54]
S3 SE2Cmgmt;Sony Ericsson Device 044 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Cmgmt.sys [2006-11-10 08:54]
S3 se2Cnd5;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se2Cnd5.sys [2006-11-10 08:54]
S3 SE2Cobex;Sony Ericsson Device 044 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Cobex.sys [2006-11-10 08:54]
S3 se2Cunic;Sony Ericsson Device 044 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se2Cunic.sys [2006-11-10 08:54]
S3 SEL-5860 Time Service;SEL-5860 Time Service;"C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe" [2006-06-30 07:50]
S3 SWNC8U20;Sierra Wireless MUX NDIS Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swnc8u20.sys [2007-09-05 15:56]
S3 SWNC8U51;Sierra Wireless MUX NDIS Driver (UMTS51);C:\WINDOWS\system32\DRIVERS\swnc8u51.sys []
S3 SWUMX20;Sierra Wireless USB MUX Driver (UMTS20);C:\WINDOWS\system32\DRIVERS\swumx20.sys [2007-09-05 15:56]
S3 SWUMX51;Sierra Wireless USB MUX Driver (UMTS51);C:\WINDOWS\system32\DRIVERS\swumx51.sys []
S3 USBDongle;USBDongle;C:\WINDOWS\system32\DRIVERS\USBKey.sys [2002-12-27 01:09]
S3 V0070VID;Creative WebCam Notebook Ultra;C:\WINDOWS\system32\DRIVERS\V0070Vid.sys [2005-02-18 00:24]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{286a2e99-0a18-11dc-b0f5-cb21c15f200b}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{87cd5e04-1306-11dc-b108-0019b9694767}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bdaf34f0-5737-11dc-b65f-00164148b3dc}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f90b679c-84c6-11dc-b6b6-00a0d5ffff85}]
\Shell\AutoRun\command - E:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe

.
**************************************************************************

disk not found C:\

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

disk not found C:\

**************************************************************************
.
Completion time: 2008-02-01 6:33:56
ComboFix-quarantined-files.txt 2008-02-01 12:33:05
ComboFix2.txt 2008-02-01 04:04:53
ComboFix3.txt 2008-01-31 18:39:07
ComboFix4.txt 2008-01-31 12:29:12
.
2008-01-08 20:38:25 — E O F —


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 06:34, on 2008-02-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\Macromed\Flash\FlashUtil9c.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.47.6.3:8887
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AT&T Communication Manager] "C:\Program Files\AT&T\Communication Manager\ATTCM.exe" -a
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [PrintServer Diagnostic] C:\Program Files\Print Server\PTP\PSDiagnostic.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Walgreens PhotoShow Media Manager] C:\PROGRA~1\WALGRE~1\WALGRE~1\data\Xtras\mssysmgr.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - Startup: Hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Bluetooth Manager.lnk = C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
O4 - Global Startup: SEL Update Manager.lnk = C:\Program Files\SEL\AcSELerator\SELUpdate Manager\SELUpdateManager.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1180326421187
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = TPS
O17 - HKLM\Software\..\Telephony: DomainName = TPS
O17 - HKLM\System\CCS\Services\Tcpip\..\{06DED577-FDB1-4CD0-9491-D956C6614714}: NameServer = 5.35.153.15
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Iap - Dell Inc. - C:\Program Files\Dell\OpenManage\Client\Iap.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SEL-5860 Time Service - Schweitzer Engineering Laboratories, Inc. - C:\Program Files\SEL\SEL5860\SEL-5860 Time Service.exe
O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 11744 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI