This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Hijacked.... and more?

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

IP Location: Ukraine Ukrtelegroup Ltd
Resolve Host: [removed]-xbox.dedi.inhoster.com
IP Address: [removed]


No those shouldn't still be there.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
Spybot
Windows Defender


You can re-install them when we're finished


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O17 - HKLM\System\CCS\Services\Tcpip\..\{F5DE0D0B-9018-435C-9C90-FE16B98ABBC2}: NameServer = 85.255.114.26,85.255.112.155
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155

Close ALL windows and browsers except HijackThis and click "Fix checked"


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Something's weird. I uninstalled Spybot last week, and it's not showing up in the Installed Program list. Tonight I went in and deleted the Spybot folder and any remaining files, then checked msconfig (it doesn't appear in there), then rebooted, and THEN ran hijackthis, rebooted again, and ran HT once more. But it's still coming up with Spybot as a "running process" and those three lines are still in the log file. Any ideas?
One more thing: After runnning the fix, is there supposed to be a notice that the fix was applied? Because there never is, it just goes toa blank HT results screen.

New logfile below.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:12:21 PM, on 3/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hp\kbd\kbd.exe
C:\Program Files\HP\HP Software Update\HPWUCli.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geocities.com/dmdoug66/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [PCDrProfiler] C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe -r
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5DE0D0B-9018-435C-9C90-FE16B98ABBC2}: NameServer = 85.255.114.26,85.255.112.155
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8143 bytes
Lets try it this way.

Please download FixWareout from this site:
http://downloads.subratam.org/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.

Once the desktop loads a text that will open (report.txt) Please save this file, you'll need to post it with a new HijackThis log.
Okay, I downloaded and ran the install. I got the message "Unsupported WIndows version." It asked if I wanted to reinstall using recommended settings. I did so, then reran it, but got the same message. It didn't do the fix.
Download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
——————————————————————–
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.
——————————————————————–

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Give it atleast 20-30 minutes to finish
ComboFix results followed by new HT log:

ComboFix 08-03-22.1 - Dave 2008-03-22 21:07:44.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.301 [GMT -4:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-02-23 to 2008-03-23 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-21 20:51 319,456 —-a-w C:\Windows\DIFxAPI.dll
2008-03-21 20:51 315,392 —-a-w C:\Windows\HideWin.exe
2008-03-21 20:51 ——— d—–w C:\Program Files\Realtek
2008-03-21 12:27 ——— d—–w C:\Users\Dave\AppData\Roaming\AVG7
2008-03-16 23:45 ——— d—–w C:\ProgramData\Spybot - Search & Destroy
2008-03-16 23:42 ——— d—–w C:\Program Files\Java
2008-03-13 16:33 53,768 —-a-w C:\Windows\system32\drivers\avgwfp.sys
2008-03-07 01:16 ——— d—–w C:\Users\Dave\AppData\Roaming\WinBatch
2008-03-07 01:12 ——— d—–w C:\Program Files\Trend Micro
2008-03-05 10:11 ——— d—–w C:\ProgramData\avg7
2008-03-05 01:15 ——— d—–w C:\Program Files\CleanUp!
2008-03-05 01:13 ——— d—–w C:\Users\Dave\AppData\Roaming\Grisoft
2008-03-05 00:54 ——— d—–w C:\Program Files\InterMute
2008-03-05 00:49 ——— d—–w C:\ProgramData\Lavasoft
2008-03-05 00:48 ——— d—–w C:\Program Files\Lavasoft
2008-03-05 00:47 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-05 00:40 ——— d—–w C:\ProgramData\Grisoft
2008-03-05 00:34 9,216 —-a-w C:\Windows\System32\avgwlntf.dll
2008-03-05 00:18 ——— d—–w C:\ProgramData\Symantec
2008-03-05 00:17 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-05 00:14 ——— d—–w C:\Program Files\Norton Internet Security
2008-03-05 00:12 ——— d—–w C:\Program Files\Symantec
2008-03-01 22:14 ——— d—–w C:\Users\Dave\AppData\Roaming\Apple Computer
2008-03-01 22:13 ——— d—–w C:\ProgramData\Apple Computer
2008-03-01 22:13 ——— d—–w C:\Program Files\iTunes
2008-03-01 22:13 ——— d—–w C:\Program Files\iPod
2008-03-01 22:12 ——— d—–w C:\Program Files\QuickTime
2008-03-01 22:12 ——— d—–w C:\Program Files\Bonjour
2008-03-01 22:10 ——— d—–w C:\Program Files\Apple Software Update
2008-03-01 22:09 ——— d—–w C:\ProgramData\Apple
2008-03-01 22:09 ——— d—–w C:\Program Files\Common Files\Apple
2008-02-29 23:52 994 —-a-w C:\Users\Dave\AppData\Roaming\wklnhst.dat
2008-02-29 09:12 174 –sha-w C:\Program Files\desktop.ini
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Sidebar
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Mail
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Defender
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Calendar
2008-02-29 04:09 ——— d—–w C:\ProgramData\WildTangent
2008-02-29 04:08 ——— d—–w C:\Program Files\Microsoft Works
2008-02-29 04:08 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2008-02-29 04:01 ——— d—–w C:\Program Files\HP
2008-02-29 02:17 704,000 —-a-w C:\Windows\System32\PhotoScreensaver.scr
2008-02-29 02:17 67,584 —-a-w C:\Windows\System32\wlanhlp.dll
2008-02-29 02:17 542,720 —-a-w C:\Windows\System32\sysmain.dll
2008-02-29 02:17 502,784 —-a-w C:\Windows\System32\wlansvc.dll
2008-02-29 02:17 47,104 —-a-w C:\Windows\System32\wlanapi.dll
2008-02-29 02:17 297,984 —-a-w C:\Windows\System32\wlansec.dll
2008-02-29 02:17 290,816 —-a-w C:\Windows\System32\wlanmsm.dll
2008-02-29 02:17 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2008-02-29 02:17 24,064 —-a-w C:\Windows\System32\wtsapi32.dll
2008-02-29 02:17 2,923,520 —-a-w C:\Windows\explorer.exe
2008-02-29 02:17 2,027,008 —-a-w C:\Windows\System32\win32k.sys
2008-02-29 02:16 49,664 —-a-w C:\Windows\System32\csrsrv.dll
2008-02-29 02:16 376,320 —-a-w C:\Windows\System32\winsrv.dll
2008-02-29 02:16 194,560 —-a-w C:\Windows\System32\WebClnt.dll
2008-02-29 02:16 110,080 —-a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-29 02:08 8,147,968 —-a-w C:\Windows\System32\wmploc.DLL
2008-02-29 02:08 7,680 —-a-w C:\Windows\System32\spwmp.dll
2008-02-29 02:08 4,096 —-a-w C:\Windows\System32\dxmasf.dll
2008-02-29 02:08 356,864 —-a-w C:\Windows\System32\MediaMetadataHandler.dll
2008-02-29 02:07 86,016 —-a-w C:\Windows\System32\icfupgd.dll
2008-02-29 02:07 63,488 —-a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-02-29 02:07 61,952 —-a-w C:\Windows\System32\cmifw.dll
2008-02-29 02:07 396,800 —-a-w C:\Windows\System32\MPSSVC.dll
2008-02-29 02:07 392,192 —-a-w C:\Windows\System32\FirewallAPI.dll
2008-02-29 02:07 23,040 —-a-w C:\Windows\system32\drivers\tunnel.sys
2008-02-29 02:07 178,688 —-a-w C:\Windows\System32\iphlpsvc.dll
2008-02-29 02:07 16,896 —-a-w C:\Windows\System32\wfapigp.dll
2008-02-29 02:07 15,360 —-a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-02-29 02:06 45,112 —-a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-29 02:06 3,504,696 —-a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-29 02:06 3,470,392 —-a-w C:\Windows\System32\ntoskrnl.exe
2008-02-29 02:06 211,000 —-a-w C:\Windows\system32\drivers\volsnap.sys
2008-02-29 02:06 21,560 —-a-w C:\Windows\system32\drivers\atapi.sys
2008-02-29 02:06 154,624 —-a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-29 02:06 15,928 —-a-w C:\Windows\system32\drivers\pciide.sys
2008-02-29 02:06 109,624 —-a-w C:\Windows\system32\drivers\ataport.sys
2008-02-29 02:06 1,191,936 —-a-w C:\Windows\System32\msxml3.dll
2008-02-29 02:06 1,060,920 —-a-w C:\Windows\system32\drivers\ntfs.sys
2008-02-29 02:05 803,328 —-a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-29 02:05 24,064 —-a-w C:\Windows\System32\netcfg.exe
2008-02-29 02:05 22,016 —-a-w C:\Windows\System32\netiougc.exe
2008-02-29 02:05 216,632 —-a-w C:\Windows\system32\drivers\netio.sys
2008-02-29 02:05 167,424 —-a-w C:\Windows\System32\tcpipcfg.dll
2008-02-29 02:04 9,728 —-a-w C:\Windows\System32\LAPRXY.DLL
2008-02-29 02:04 223,232 —-a-w C:\Windows\System32\WMASF.DLL
2008-02-29 02:04 1,327,104 —-a-w C:\Windows\System32\quartz.dll
2008-02-29 02:03 57,856 —-a-w C:\Windows\System32\SLUINotify.dll
2008-02-29 02:03 566,784 —-a-w C:\Windows\System32\SLCommDlg.dll
2008-02-29 02:03 39,936 —-a-w C:\Windows\System32\slcinst.dll
2008-02-29 02:03 351,232 —-a-w C:\Windows\System32\SLUI.exe
2008-02-29 02:03 33,280 —-a-w C:\Windows\System32\slwmi.dll
2008-02-29 02:03 268,288 —-a-w C:\Windows\System32\mcbuilder.exe
2008-02-29 02:03 223,232 —-a-w C:\Windows\System32\SLC.dll
2008-02-29 02:03 2,605,568 —-a-w C:\Windows\System32\SLsvc.exe
2008-02-29 02:03 186,368 —-a-w C:\Windows\System32\SLLUA.exe
2008-02-29 02:02 1,335,296 —-a-w C:\Windows\System32\msxml6.dll
2008-02-29 02:00 53,760 —-a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-02-29 02:00 11,776 —-a-w C:\Windows\System32\sbunattend.exe
2008-02-29 01:59 84,992 —-a-w C:\Windows\system32\drivers\srvnet.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-28 22:00 1232896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-02-28 22:11 1006264]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 09:42 65536]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 11:16 65536]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 03:11 49152]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 21:15 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 21:15 8466432]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 21:15 81920]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-04 20:38 579072]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"PCDrProfiler"="C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" [2006-09-25 21:18 53248]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-04 20:34 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2008-03-04 20:34 9216 C:\Windows\System32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2006-09-14 08:55 61440 C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2007-01-09 22:59 115816 c:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmeve.tmp]
C:\Windows\system32\dmeve.tmp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmfeo.tmp]
C:\Windows\system32\dmfeo.tmp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmizw.tmp]
C:\Windows\system32\dmizw.tmp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmrkr.tmp]
C:\Windows\system32\dmrkr.tmp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmuhw.exe]
C:\Windows\system32\dmuhw.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmyyv.tmp]
C:\Windows\system32\dmyyv.tmp

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
–a—— 2006-11-16 18:59 1480296 C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-02-19 14:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
–a—— 2006-10-26 19:18 22696 c:\Program Files\Norton Internet Security\osCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3A6DFE6B-E9E0-4E74-B63C-0D01A665F747}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{4692530B-2D39-4EAA-892F-7608206D35A3}"= TCP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{812FD908-75A7-402C-8540-1DCD09941946}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{59AF12B0-7C58-4191-9C6B-2A4B207C1EBB}"= TCP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{DA9FA734-EBCE-4C21-AB53-0B45EEB1017C}"= C:\Program Files\HP Connections\6811507\Program\HP Connections:HP Connections
"{EEB11FFE-A941-4064-BC5E-98BE939C1495}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{BEF4D838-9265-4970-81EC-43D1B60AC8C2}"= TCP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{43C5C446-506B-44F8-8553-6B133AA5AC3A}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{54D48CF0-132F-4D52-9BE2-DD20F81E1956}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3A5C897F-AD18-4FAD-A376-3943EED7980E}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4D71ED0C-EC8B-491C-9834-3DE7FB17D623}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C56F3753-F64E-4641-B3F9-4198B85D0CD9}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3C054790-59E5-40B7-8451-F668955BA75A}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"TCP Query User{AC0323F3-82C3-4185-ACE3-78D8B35A4E84}C:\\neverwinternights\\nwn\\nwmain.exe"= UDP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"UDP Query User{360C4A4C-A49E-4CD1-96C1-8125F2A6488F}C:\\neverwinternights\\nwn\\nwmain.exe"= TCP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"{9D39AC6B-6E92-4B67-B214-DD93D6A222D0}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{2165788A-6B7D-4139-BECE-DD3F40694DE1}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{44A884F1-0334-4C21-8F53-7AA44105AAFA}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{95327BD8-7D2C-4FED-B825-ECF4287C2C98}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{FE5B654E-3172-4FD7-AA44-38A30335B714}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{1883E59C-77EB-4BE9-9103-7F4FDBB1A9A4}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{C05B81CA-3328-40C3-8867-9574187DADEF}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{EA3D174B-35AC-44CC-B2C6-8A2CD4911485}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20061025.029\IDSvix86.sys [2006-10-19 23:10]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-08-07 15:26]
R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2008-03-13 12:33]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2006-10-24 08:40]
S3 Symantec RemoteAssist;Symantec RemoteAssist;"C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe" [2008-01-29 17:09]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d92c04ee-ea43-11dc-b9a0-001a921036cf}]
\shell\AutoRun\command - L:\LaunchU3.exe -a

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-29 09:09:50 C:\Windows\Tasks\HPCeeScheduleForDave.job"
- C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe
"2008-03-22 23:49:31 C:\Windows\Tasks\User_Feed_Synchronization-{A6B763B9-6750-4DE9-80AF-E1887569F446}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-22 21:10:36
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-22 21:11:12
ComboFix-quarantined-files.txt 2008-03-23 01:11:08
.
2008-03-01 10:21:14 — E O F —







Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:12:21 PM, on 3/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hp\kbd\kbd.exe
C:\Program Files\HP\HP Software Update\HPWUCli.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geocities.com/dmdoug66/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [PCDrProfiler] C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe -r
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5DE0D0B-9018-435C-9C90-FE16B98ABBC2}: NameServer = 85.255.114.26,85.255.112.155
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8143 bytes
Open notepad and copy/paste the text in the quotebox below into it:

File::
C:\Windows\system32\dmeve.tmp
C:\Windows\system32\dmfeo.tmp
C:\Windows\system32\dmizw.tmp
C:\Windows\system32\dmrkr.tmp
C:\Windows\system32\dmuhw.exe
C:\Windows\system32\dmyyv.tmp
C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

Folder::
C:\Program Files\Bonjour
C:\Program Files\Windows Defender
C:\ProgramData\Spybot - Search & Destroy

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmeve.tmp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmfeo.tmp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmizw.tmp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmrkr.tmp]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmuhw.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dmyyv.tmp]

Save this as Save this as "CFScript"


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
ComboFix 08-03-22.1 - Dave 2008-03-22 21:51:41.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.277 [GMT -4:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\Dave\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
C:\Windows\system32\dmeve.tmp
C:\Windows\system32\dmfeo.tmp
C:\Windows\system32\dmizw.tmp
C:\Windows\system32\dmrkr.tmp
C:\Windows\system32\dmuhw.exe
C:\Windows\system32\dmyyv.tmp
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Bonjour
C:\Program Files\Bonjour\About Bonjour.rtf
C:\Program Files\Bonjour\mdnsNSP.dll
C:\Program Files\Bonjour\mDNSResponder.exe
C:\ProgramData\Spybot - Search & Destroy
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080304-2036.log
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080304-2049.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080304-2057.log
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080304-2108.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080306-1809.log
C:\ProgramData\Spybot - Search & Destroy\Logs\Checks.080306-1820.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Fixes.080304-2051.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Fixes.080304-2108.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Fixes.080306-1849.txt
C:\ProgramData\Spybot - Search & Destroy\Logs\Resident.log
C:\ProgramData\Spybot - Search & Destroy\Logs\Update downloads.log
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger1.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger2.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger3.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger4.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDNSChanger5.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot1.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot2.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot3.zip
C:\ProgramData\Spybot - Search & Destroy\Recovery\ZlobDownloadersot4.zip
C:\Program Files\Windows Defender . . . . failed to delete
C:\Program Files\Windows Defender\en-US\MpAsDesc.dll.mui . . . . failed to delete
C:\Program Files\Windows Defender\en-US\MpEvMsg.dll.mui . . . . failed to delete
C:\Program Files\Windows Defender\en-US\MsMpRes.dll.mui . . . . failed to delete
C:\Program Files\Windows Defender\MpAsDesc.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpClient.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpCmdRun.exe . . . . failed to delete
C:\Program Files\Windows Defender\MpEvMsg.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpOAV.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpRtMon.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpRtPlug.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpSigDwn.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpSoftEx.dll . . . . failed to delete
C:\Program Files\Windows Defender\MpSvc.dll . . . . failed to delete
C:\Program Files\Windows Defender\MSASCui.exe . . . . failed to delete
C:\Program Files\Windows Defender\MsMpCom.dll . . . . failed to delete
C:\Program Files\Windows Defender\MsMpLics.dll . . . . failed to delete
C:\Program Files\Windows Defender\MsMpRes.dll . . . . failed to delete

.
((((((((((((((((((((((((( Files Created from 2008-02-23 to 2008-03-23 )))))))))))))))))))))))))))))))
.

No new files created in this timespan

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-21 20:51 319,456 —-a-w C:\Windows\DIFxAPI.dll
2008-03-21 20:51 315,392 —-a-w C:\Windows\HideWin.exe
2008-03-21 20:51 ——— d—–w C:\Program Files\Realtek
2008-03-21 12:27 ——— d—–w C:\Users\Dave\AppData\Roaming\AVG7
2008-03-16 23:42 ——— d—–w C:\Program Files\Java
2008-03-13 16:33 53,768 —-a-w C:\Windows\system32\drivers\avgwfp.sys
2008-03-07 01:16 ——— d—–w C:\Users\Dave\AppData\Roaming\WinBatch
2008-03-07 01:12 ——— d—–w C:\Program Files\Trend Micro
2008-03-05 10:11 ——— d—–w C:\ProgramData\avg7
2008-03-05 01:15 ——— d—–w C:\Program Files\CleanUp!
2008-03-05 01:13 ——— d—–w C:\Users\Dave\AppData\Roaming\Grisoft
2008-03-05 00:54 ——— d—–w C:\Program Files\InterMute
2008-03-05 00:49 ——— d—–w C:\ProgramData\Lavasoft
2008-03-05 00:48 ——— d—–w C:\Program Files\Lavasoft
2008-03-05 00:47 ——— d—–w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-05 00:40 ——— d—–w C:\ProgramData\Grisoft
2008-03-05 00:34 9,216 —-a-w C:\Windows\System32\avgwlntf.dll
2008-03-05 00:18 ——— d—–w C:\ProgramData\Symantec
2008-03-05 00:17 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-03-05 00:14 ——— d—–w C:\Program Files\Norton Internet Security
2008-03-05 00:12 ——— d—–w C:\Program Files\Symantec
2008-03-01 22:14 ——— d—–w C:\Users\Dave\AppData\Roaming\Apple Computer
2008-03-01 22:13 ——— d—–w C:\ProgramData\Apple Computer
2008-03-01 22:13 ——— d—–w C:\Program Files\iTunes
2008-03-01 22:13 ——— d—–w C:\Program Files\iPod
2008-03-01 22:12 ——— d—–w C:\Program Files\QuickTime
2008-03-01 22:10 ——— d—–w C:\Program Files\Apple Software Update
2008-03-01 22:09 ——— d—–w C:\ProgramData\Apple
2008-03-01 22:09 ——— d—–w C:\Program Files\Common Files\Apple
2008-02-29 23:52 994 —-a-w C:\Users\Dave\AppData\Roaming\wklnhst.dat
2008-02-29 09:12 174 –sha-w C:\Program Files\desktop.ini
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Sidebar
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Mail
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Defender
2008-02-29 09:08 ——— d—–w C:\Program Files\Windows Calendar
2008-02-29 04:09 ——— d—–w C:\ProgramData\WildTangent
2008-02-29 04:08 ——— d—–w C:\Program Files\Microsoft Works
2008-02-29 04:08 ——— d—–w C:\Program Files\Common Files\SureThing Shared
2008-02-29 04:01 ——— d—–w C:\Program Files\HP
2008-02-29 02:17 704,000 —-a-w C:\Windows\System32\PhotoScreensaver.scr
2008-02-29 02:17 67,584 —-a-w C:\Windows\System32\wlanhlp.dll
2008-02-29 02:17 542,720 —-a-w C:\Windows\System32\sysmain.dll
2008-02-29 02:17 502,784 —-a-w C:\Windows\System32\wlansvc.dll
2008-02-29 02:17 47,104 —-a-w C:\Windows\System32\wlanapi.dll
2008-02-29 02:17 297,984 —-a-w C:\Windows\System32\wlansec.dll
2008-02-29 02:17 290,816 —-a-w C:\Windows\System32\wlanmsm.dll
2008-02-29 02:17 258,232 —-a-w C:\Windows\system32\drivers\acpi.sys
2008-02-29 02:17 24,064 —-a-w C:\Windows\System32\wtsapi32.dll
2008-02-29 02:17 2,923,520 —-a-w C:\Windows\explorer.exe
2008-02-29 02:17 2,027,008 —-a-w C:\Windows\System32\win32k.sys
2008-02-29 02:16 49,664 —-a-w C:\Windows\System32\csrsrv.dll
2008-02-29 02:16 376,320 —-a-w C:\Windows\System32\winsrv.dll
2008-02-29 02:16 194,560 —-a-w C:\Windows\System32\WebClnt.dll
2008-02-29 02:16 110,080 —-a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-29 02:08 8,147,968 —-a-w C:\Windows\System32\wmploc.DLL
2008-02-29 02:08 7,680 —-a-w C:\Windows\System32\spwmp.dll
2008-02-29 02:08 4,096 —-a-w C:\Windows\System32\dxmasf.dll
2008-02-29 02:08 356,864 —-a-w C:\Windows\System32\MediaMetadataHandler.dll
2008-02-29 02:07 86,016 —-a-w C:\Windows\System32\icfupgd.dll
2008-02-29 02:07 63,488 —-a-w C:\Windows\system32\drivers\mpsdrv.sys
2008-02-29 02:07 61,952 —-a-w C:\Windows\System32\cmifw.dll
2008-02-29 02:07 396,800 —-a-w C:\Windows\System32\MPSSVC.dll
2008-02-29 02:07 392,192 —-a-w C:\Windows\System32\FirewallAPI.dll
2008-02-29 02:07 23,040 —-a-w C:\Windows\system32\drivers\tunnel.sys
2008-02-29 02:07 178,688 —-a-w C:\Windows\System32\iphlpsvc.dll
2008-02-29 02:07 16,896 —-a-w C:\Windows\System32\wfapigp.dll
2008-02-29 02:07 15,360 —-a-w C:\Windows\system32\drivers\TUNMP.SYS
2008-02-29 02:06 45,112 —-a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-29 02:06 3,504,696 —-a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-29 02:06 3,470,392 —-a-w C:\Windows\System32\ntoskrnl.exe
2008-02-29 02:06 211,000 —-a-w C:\Windows\system32\drivers\volsnap.sys
2008-02-29 02:06 21,560 —-a-w C:\Windows\system32\drivers\atapi.sys
2008-02-29 02:06 154,624 —-a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-29 02:06 15,928 —-a-w C:\Windows\system32\drivers\pciide.sys
2008-02-29 02:06 109,624 —-a-w C:\Windows\system32\drivers\ataport.sys
2008-02-29 02:06 1,191,936 —-a-w C:\Windows\System32\msxml3.dll
2008-02-29 02:06 1,060,920 —-a-w C:\Windows\system32\drivers\ntfs.sys
2008-02-29 02:05 803,328 —-a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-29 02:05 24,064 —-a-w C:\Windows\System32\netcfg.exe
2008-02-29 02:05 22,016 —-a-w C:\Windows\System32\netiougc.exe
2008-02-29 02:05 216,632 —-a-w C:\Windows\system32\drivers\netio.sys
2008-02-29 02:05 167,424 —-a-w C:\Windows\System32\tcpipcfg.dll
2008-02-29 02:04 9,728 —-a-w C:\Windows\System32\LAPRXY.DLL
2008-02-29 02:04 223,232 —-a-w C:\Windows\System32\WMASF.DLL
2008-02-29 02:04 1,327,104 —-a-w C:\Windows\System32\quartz.dll
2008-02-29 02:03 57,856 —-a-w C:\Windows\System32\SLUINotify.dll
2008-02-29 02:03 566,784 —-a-w C:\Windows\System32\SLCommDlg.dll
2008-02-29 02:03 39,936 —-a-w C:\Windows\System32\slcinst.dll
2008-02-29 02:03 351,232 —-a-w C:\Windows\System32\SLUI.exe
2008-02-29 02:03 33,280 —-a-w C:\Windows\System32\slwmi.dll
2008-02-29 02:03 268,288 —-a-w C:\Windows\System32\mcbuilder.exe
2008-02-29 02:03 223,232 —-a-w C:\Windows\System32\SLC.dll
2008-02-29 02:03 2,605,568 —-a-w C:\Windows\System32\SLsvc.exe
2008-02-29 02:03 186,368 —-a-w C:\Windows\System32\SLLUA.exe
2008-02-29 02:02 1,335,296 —-a-w C:\Windows\System32\msxml6.dll
2008-02-29 02:00 53,760 —-a-w C:\Windows\system32\drivers\hdaudbus.sys
2008-02-29 02:00 11,776 —-a-w C:\Windows\System32\sbunattend.exe
2008-02-29 01:59 84,992 —-a-w C:\Windows\system32\drivers\srvnet.sys
2008-02-29 01:59 788,992 —-a-w C:\Windows\System32\rpcrt4.dll
2008-02-29 01:59 58,368 —-a-w C:\Windows\system32\drivers\mrxsmb20.sys
.

((((((((((((((((((((((((((((( snapshot@2008-03-22_21.10.59.99 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-23 00:05:52 67,584 –s-a-w C:\Windows\bootstat.dat
+ 2008-03-23 01:56:08 67,584 –s-a-w C:\Windows\bootstat.dat
- 2008-03-23 00:21:07 262,144 —-a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
+ 2008-03-23 01:21:03 262,144 —-a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
- 2008-03-23 00:07:31 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-03-23 01:56:47 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
- 2008-03-23 01:07:13 262,144 —-a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-03-23 01:51:19 262,144 —-a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-03-23 00:07:25 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-03-23 01:56:47 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-02-28 22:00 1232896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-03-22 21:54 1006264]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2006-09-28 09:42 65536]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 11:16 65536]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 11:26 4874240 C:\Windows\RtHDVCpl.exe]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 03:11 49152]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 21:15 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 21:15 8466432]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-06 21:15 81920]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-03-04 20:38 579072]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"PCDrProfiler"="C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" [2006-09-25 21:18 53248]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-03-04 20:34 219136]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgwlntf]
avgwlntf.dll 2008-03-04 20:34 9216 C:\Windows\System32\avgwlntf.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2006-09-14 08:55 61440 C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
–a—— 2007-01-09 22:59 115816 c:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPADVISOR]
–a—— 2006-11-16 18:59 1480296 C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-02-19 14:10 267048 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
–a—— 2006-10-26 19:18 22696 c:\Program Files\Norton Internet Security\osCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-02-01 00:13 385024 C:\Program Files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3A6DFE6B-E9E0-4E74-B63C-0D01A665F747}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{4692530B-2D39-4EAA-892F-7608206D35A3}"= TCP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{812FD908-75A7-402C-8540-1DCD09941946}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{59AF12B0-7C58-4191-9C6B-2A4B207C1EBB}"= TCP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{DA9FA734-EBCE-4C21-AB53-0B45EEB1017C}"= C:\Program Files\HP Connections\6811507\Program\HP Connections:HP Connections
"{EEB11FFE-A941-4064-BC5E-98BE939C1495}"= UDP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{BEF4D838-9265-4970-81EC-43D1B60AC8C2}"= TCP:C:\Program Files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{43C5C446-506B-44F8-8553-6B133AA5AC3A}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{54D48CF0-132F-4D52-9BE2-DD20F81E1956}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3A5C897F-AD18-4FAD-A376-3943EED7980E}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{4D71ED0C-EC8B-491C-9834-3DE7FB17D623}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C56F3753-F64E-4641-B3F9-4198B85D0CD9}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{3C054790-59E5-40B7-8451-F668955BA75A}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"TCP Query User{AC0323F3-82C3-4185-ACE3-78D8B35A4E84}C:\\neverwinternights\\nwn\\nwmain.exe"= UDP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"UDP Query User{360C4A4C-A49E-4CD1-96C1-8125F2A6488F}C:\\neverwinternights\\nwn\\nwmain.exe"= TCP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"{9D39AC6B-6E92-4B67-B214-DD93D6A222D0}"= Disabled:UDP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{2165788A-6B7D-4139-BECE-DD3F40694DE1}"= Disabled:TCP:C:\Program Files\Adobe\Photoshop Elements 5.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
"{44A884F1-0334-4C21-8F53-7AA44105AAFA}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{95327BD8-7D2C-4FED-B825-ECF4287C2C98}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{FE5B654E-3172-4FD7-AA44-38A30335B714}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{1883E59C-77EB-4BE9-9103-7F4FDBB1A9A4}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{C05B81CA-3328-40C3-8867-9574187DADEF}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{EA3D174B-35AC-44CC-B2C6-8A2CD4911485}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20061025.029\IDSvix86.sys [2006-10-19 23:10]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-08-07 15:26]
R3 AvgWFP;AVG7 Firewall Driver x86;C:\Windows\system32\Drivers\avgwfp.sys [2008-03-13 12:33]
R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2006-10-24 08:40]
S3 Symantec RemoteAssist;Symantec RemoteAssist;"C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe" [2008-01-29 17:09]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d92c04ee-ea43-11dc-b9a0-001a921036cf}]
\shell\AutoRun\command - L:\LaunchU3.exe -a

*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-02-29 09:09:50 C:\Windows\Tasks\HPCeeScheduleForDave.job"
- C:\Program Files\hewlett-packard\sdp\ceement\HPCEE.exe
"2008-03-22 23:49:31 C:\Windows\Tasks\User_Feed_Synchronization-{A6B763B9-6750-4DE9-80AF-E1887569F446}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-22 21:56:59
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Windows\System32\rundll32.exe
C:\hp\kbd\kbd.exe
.
**************************************************************************
.
Completion time: 2008-03-22 21:59:14 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-23 01:59:10
ComboFix2.txt 2008-03-23 01:11:13
.
2008-03-01 10:21:14 — E O F —



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:12:21 PM, on 3/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hp\kbd\kbd.exe
C:\Program Files\HP\HP Software Update\HPWUCli.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geocities.com/dmdoug66/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [PCDrProfiler] C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe -r
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5DE0D0B-9018-435C-9C90-FE16B98ABBC2}: NameServer = 85.255.114.26,85.255.112.155
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8143 bytes
I think this works for Vista as well.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:

Enter your Control Panel and double-click on Network Connections

Then right click on your Default Connection
Usually Local Area Connection for Cable and DSL
Left click on Properties
Double-Click on the Internet Protocol (TCP/IP) item
Select the radio dial that says Obtain DNS Servers Automatically
Press OK twice to get out of the properties screen and reboot if it asks

If that didn't work try the next.


Try freshening up your IP and clearing your DNS

Start - Run - (type)cmd
this will bring up a DOS Box display with a blinking cursor

At the blinking cursor type the following commands in sequence, waiting for the procedures to complete before entering the next command:

ipconfig /release - enter <– notice the required space before the "/"
ipconfig /renew - enter <– notice the required space before the "/"
ipconfig /flushDNS - enter <– notice the required space before the "/"

(Each of the above ipconfig steps may take from a few seconds to a minute or so to complete.
Wait for the blinking cursor to return before moving on to typing the next command.)

Then type in Exit tap enter.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O17 - HKLM\System\CCS\Services\Tcpip\..\{F5DE0D0B-9018-435C-9C90-FE16B98ABBC2}: NameServer = 85.255.114.26,85.255.112.155
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155

Close ALL windows and browsers except HijackThis and click "Fix checked"


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Sorry that shouldn't be there

Enter your Control Panel and double-click on Network Connections

Then right click on your Default Connection
Usually Local Area Connection for Cable and DSL
Left click on Properties
Double-Click on the Internet Protocol (TCP/IP) item
Select the radio dial that says Obtain DNS Servers Automatically
Press OK twice to get out of the properties screen and reboot if it asks

If that didn't work try the next.


Try freshening up your IP and clearing your DNS

Start - Run - (type)cmd
this will bring up a DOS Box display with a blinking cursor

At the blinking cursor type the following commands in sequence, waiting for the procedures to complete before entering the next command:

ipconfig /release - enter <– notice the required space before the "/"
ipconfig /renew - enter <– notice the required space before the "/"
ipconfig /flushDNS - enter <– notice the required space before the "/"

(Each of the above ipconfig steps may take from a few seconds to a minute or so to complete.
Wait for the blinking cursor to return before moving on to typing the next command.)

Then type in Exit tap enter.


Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

O17 - HKLM\System\CCS\Services\Tcpip\..\{F5DE0D0B-9018-435C-9C90-FE16B98ABBC2}: NameServer = 85.255.114.26,85.255.112.155
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155

Close ALL windows and browsers except HijackThis and click "Fix checked"


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
There were two choices for TCP/IP: Versions 4 and 6. Both already had "Obtain DNS Servers Automatically" already checked on the radio dials.

I entered all three commands, ran HT, checked the three boxes, chose Fix, then rebooted. Below is the new log file. Are we trying to get rid of those three lines, or just modify them? Because they're still there. The computer still appears to be running normal, although I've been avoiding surfing because of the hijacking.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:12:21 PM, on 3/6/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\hp\kbd\kbd.exe
C:\Program Files\HP\HP Software Update\HPWUCli.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.geocities.com/dmdoug66/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [PCDrProfiler] C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe -r
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O13 - Gopher Prefix:
O17 - HKLM\System\CCS\Services\Tcpip\..\{F5DE0D0B-9018-435C-9C90-FE16B98ABBC2}: NameServer = 85.255.114.26,85.255.112.155
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.26 85.255.112.155
O20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec RemoteAssist - Symantec, Inc. - C:\Program Files\Common Files\Symantec Shared\Support Controls\ssrc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 8143 bytes

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI