This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] computer has been behaving strangely

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, i have a fairly new system and am new to vista and need some advice! My pc would not start (crashed) correctly so i had to power down and start again. this time on powering up, start up repair was launched and said that a problem could not be found and asked if i wanted to restore to an earlier tome….I opted yes…..once booted up agian, norton was disabled and had out of date definitions. When i attempted to fix i was prompted to download the norton UAC tool but must've ran the fix incorrectly because now i have a message telling me that some startup programs have been blocked by windows (registry editor) and i dont know why. here is a HJT log, advice is appreciated.

Sorry but i am now getting an error message when trying to do a HJT scan……"for some reason your system denied write access to the hosts file. any ideas?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:37:41, on 16/12/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\nvraidservice.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\System32\CTxfispi.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk/ig/dell?hl=en&…amp;ibd=5080925
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ig/dell?hl=en&…amp;ibd=5080925
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [UACEnableEntry] regedit.exe /s C:\Users\Dom\AppData\Local\Temp\\UAC_Enable.reg
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" resetprofile
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

–
End of file - 10473 bytes
:welcome:

My name is BHowett and I will be helping you to get sorted. If for any reason you do not understand any of the instructions, or are just unsure then please do not guess , simply post back with your question, and we will go through it again. This seems like a tech issue and not a malware problem, but lets take a look and see what we find.

Sorry for the delay, please do the following…

ComboFix

Please ownload ComboFix from Here or Here

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt, and a fresh Hijackthis log in your next reply.

Do not mouse-click Combofix's window while it is running. That may cause it to stall.
Hi and thanks for your assistance, here are the requested logs




ComboFix 08-12-28.03 - Dom 2008-12-29 13:56:11.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2813.1779 [GMT 0:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *enabled*
.

((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-29 )))))))))))))))))))))))))))))))
.

2008-12-26 23:30 . 2008-12-26 23:31 d——– c:\users\Dom\AppData\Roaming\Sports Interactive
2008-12-26 23:30 . 2008-12-26 23:30 d——– c:\users\All Users\Sports Interactive
2008-12-26 23:30 . 2008-12-26 23:30 d——– c:\programdata\Sports Interactive
2008-12-26 23:30 . 2008-03-05 15:56 3,786,760 –a—— c:\windows\System32\D3DX9_37.dll
2008-12-26 23:29 . 2007-05-16 16:45 3,497,832 –a—— c:\windows\System32\d3dx9_34.dll
2008-12-26 22:58 . 2008-12-26 22:58 d——– c:\users\All Users\Media Center Programs
2008-12-26 22:58 . 2008-12-26 22:58 d——– c:\programdata\Media Center Programs
2008-12-26 22:44 . 2008-12-27 10:39 d——– c:\program files\Common Files\Steam
2008-12-26 22:43 . 2008-12-26 22:44 d–h—– c:\program files\Zero G Registry
2008-12-26 22:43 . 2008-12-29 13:38 d——– c:\program files\Steam
2008-12-26 22:43 . 2008-12-26 22:43 d——– c:\program files\Sports Interactive
2008-12-26 22:42 . 2008-12-26 22:42 d–h—– c:\users\Dom\InstallAnywhere
2008-12-17 18:46 . 2008-12-17 18:46 0 –ah—– c:\windows\System32\drivers\Msft_User_PCCSWpdDriver_01_05_00.Wdf
2008-12-17 18:35 . 2008-12-17 18:35 d——– c:\windows\Downloaded Installations
2008-12-17 18:35 . 2008-12-17 18:46 d——– c:\users\Dom\AppData\Roaming\Nokia
2008-12-17 18:35 . 2008-12-17 18:46 d——– c:\users\All Users\PC Suite
2008-12-17 18:35 . 2008-12-17 18:46 d——– c:\programdata\PC Suite
2008-12-17 18:34 . 2008-12-17 18:35 d——– c:\users\Dom\AppData\Roaming\PC Suite
2008-12-17 18:34 . 2008-12-17 18:34 d——– c:\program files\Common Files\PCSuite
2008-12-17 18:33 . 2008-12-17 18:33 d——– c:\program files\PC Connectivity Solution
2008-12-17 18:30 . 2008-12-17 18:30 d——– c:\program files\Nokia
2008-12-17 18:30 . 2007-02-22 10:15 90,624 –a—— c:\windows\System32\nmwcdcls.dll
2008-12-16 02:37 . 2008-12-16 02:37 d——– c:\program files\Trend Micro
2008-12-14 12:53 . 2008-12-14 12:53 410,984 –a—— c:\windows\System32\deploytk.dll
2008-12-12 03:03 . 2008-10-22 01:22 2,048 –a—— c:\windows\System32\tzres.dll
2008-12-07 18:04 . 2008-12-07 18:04 d——– c:\users\Dom\AppData\Roaming\Red Alert 3
2008-12-07 17:55 . 2008-12-07 17:55 d——– c:\users\All Users\Electronic Arts
2008-12-07 17:55 . 2008-12-07 17:55 d——– c:\programdata\Electronic Arts
2008-12-07 17:52 . 2008-12-07 17:52 dr——- c:\windows\System32\config\systemprofile\Videos
2008-12-07 17:52 . 2008-12-07 17:52 dr——- c:\windows\System32\config\systemprofile\Pictures
2008-12-07 17:52 . 2008-12-07 17:52 dr——- c:\windows\System32\config\systemprofile\Downloads
2008-12-07 17:52 . 2008-12-07 17:52 dr——- c:\windows\System32\config\systemprofile\Documents
2008-12-07 17:52 . 2008-12-07 17:52 7,004 –a—— c:\windows\System32\ealregsnapshot1.reg
2008-12-07 17:32 . 2008-05-30 14:11 3,850,760 –a—— c:\windows\System32\D3DX9_38.dll
2008-12-07 17:32 . 2007-07-19 18:14 3,727,720 –a—— c:\windows\System32\d3dx9_35.dll
2008-12-07 17:32 . 2008-05-30 14:11 1,491,992 –a—— c:\windows\System32\D3DCompiler_38.dll
2008-12-07 17:32 . 2007-07-19 18:14 1,358,192 –a—— c:\windows\System32\D3DCompiler_35.dll
2008-12-07 17:32 . 2008-05-30 14:11 467,984 –a—— c:\windows\System32\d3dx10_38.dll
2008-12-07 17:32 . 2007-07-19 18:14 444,776 –a—— c:\windows\System32\d3dx10_35.dll
2008-12-02 22:49 . 2008-10-16 21:13 1,809,944 –a—— c:\windows\System32\wuaueng.dll
2008-12-02 22:49 . 2008-10-16 20:56 1,524,736 –a—— c:\windows\System32\wucltux.dll
2008-12-02 22:49 . 2008-10-16 21:09 51,224 –a—— c:\windows\System32\wuauclt.exe
2008-12-02 22:49 . 2008-10-16 21:09 43,544 –a—— c:\windows\System32\wups2.dll
2008-12-02 22:48 . 2008-10-16 21:12 561,688 –a—— c:\windows\System32\wuapi.dll
2008-12-02 22:48 . 2008-10-16 14:08 162,064 –a—— c:\windows\System32\wuwebv.dll
2008-12-02 22:48 . 2008-10-16 20:55 83,456 –a—— c:\windows\System32\wudriver.dll
2008-12-02 22:48 . 2008-10-16 21:08 34,328 –a—— c:\windows\System32\wups.dll
2008-12-02 22:48 . 2008-10-16 13:56 31,232 –a—— c:\windows\System32\wuapp.exe
2008-11-30 08:06 . 2008-11-30 08:06 8,284 –a—— c:\windows\System32\eps_icon.avi

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-29 00:23 ——— d—–w c:\programdata\Symantec
2008-12-28 21:52 ——— d—–w c:\programdata\Google Updater
2008-12-25 12:05 920 —-a-w c:\users\Dom\AppData\Roaming\wklnhst.dat
2008-12-14 12:53 ——— d—–w c:\program files\Java
2008-12-12 03:13 ——— d—–w c:\program files\Windows Mail
2008-12-07 17:55 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-07 17:55 ——— d—–w c:\program files\Electronic Arts
2008-11-30 08:16 ——— d—–w c:\program files\epson
2008-11-17 17:33 ——— d—–w c:\program files\Syncrosoft
2008-11-14 19:04 ——— d—–w c:\programdata\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-14 19:04 ——— d—–w c:\program files\iTunes
2008-11-14 19:04 ——— d—–w c:\program files\iPod
2008-11-13 18:18 ——— d—–w c:\programdata\UDL
2008-11-13 18:14 ——— d—–w c:\program files\ABBYY FineReader 6.0 Sprint
2008-11-12 10:53 ——— d—–w c:\program files\Common Files\Symantec Shared
2008-11-01 03:44 541,696 —-a-w c:\windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2008-11-01 03:44 2,154,496 —-a-w c:\windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2008-11-01 01:21 4,240,384 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-10-29 19:34 368,640 —-a-w c:\windows\System32\ReWire.dll
2008-10-29 19:34 233,472 —-a-w c:\windows\System32\REX Shared Library.dll
2008-10-29 19:34 ——— d—–w c:\programdata\Propellerhead Software
2008-10-29 19:33 ——— d—–w c:\users\Dom\AppData\Roaming\Propellerhead Software
2008-10-29 15:59 ——— d—–w c:\users\Dom\AppData\Roaming\Steinberg
2008-10-29 15:55 ——— d—–w c:\programdata\Steinberg
2008-10-29 15:50 2,892 —-a-w c:\windows\System32\audcon.sys
2008-10-29 15:50 ——— d—–w c:\programdata\Syncrosoft
2008-10-29 06:29 2,927,104 —-a-w c:\windows\explorer.exe
2008-10-22 03:57 241,152 —-a-w c:\windows\System32\PortableDeviceApi.dll
2008-10-21 05:25 296,960 —-a-w c:\windows\System32\gdi32.dll
2008-10-21 05:25 1,645,568 —-a-w c:\windows\System32\connect.dll
2008-10-16 04:47 827,392 —-a-w c:\windows\System32\wininet.dll
2008-10-03 23:11 98,304 —-a-w c:\windows\system32CmdLineExt.dll
2008-01-21 02:43 174 –sha-w c:\program files\desktop.ini
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-03-11 202544]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-25 68856]
"NVIDIA nTune"="c:\program files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" [2008-05-30 110592]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Steam"="c:\program files\Steam\Steam.exe" [2008-12-26 1410296]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-29 17920]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-23 13531680]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-23 92704]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-14 136600]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2008-01-03 184864]
"VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 184320]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-25 29744]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-03-11 202544]
"NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 3100672]
"Bluetooth HCI Monitor"="HCIMNTR.DLL" [2006-12-07 c:\windows\System32\HCIMNTR.DLL]
"CTxfiHlp"="CTXFIHLP.EXE" [2008-06-30 c:\windows\System32\Ctxfihlp.exe]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-02-13 715568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]
2008-09-25 01:24 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-10-01 18:57 289576 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-09-06 14:09 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{5F1A1A11-789F-4FA0-A90E-0C844578FF29}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{F47C3A71-5B6B-400D-9868-D502B771E750}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{DBA247DC-F37D-4A51-BF5C-C46407FB7BEB}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{71732326-17C7-4703-8B5E-9D47860A9411}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{42395F04-FEDB-4DF0-A334-CAFFFC97DAA4}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{459ACBF5-7512-430C-BF4F-FF26095AD1B6}"= UDP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009
"{5556F4D3-9D37-4F4B-B1AE-6ED13F984592}"= TCP:c:\program files\Steam\SteamApps\common\football manager 2009\fm.exe:Football Manager 2009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R1 IDSvix86;Symantec Intrusion Prevention Driver;\??\c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20081220.001\IDSvix86.sys [2008-12-20 270384]
R2 LiveUpdate Notice;LiveUpdate Notice;"c:\program files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon [2008-01-08 149352]
R3 COH_Mon;COH_Mon;\??\c:\windows\system32\Drivers\COH_Mon.sys [2008-01-08 23888]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-29 99376]
R3 SYMNDISV;SYMNDISV;c:\windows\system32\Drivers\SYMNDISV.SYS [2008-06-13 41008]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service;"c:\program files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe" [2008-09-25 79360]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys [2008-10-29 23288]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{67dc625a-8aa4-11dd-970a-806e6f6e6963}]
\shell\AutoRun\command - E:\autorun.exe

*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-12-15 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Dom.job
- c:\program files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2008-01-08 02:46]
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 13:59:27
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(5580)
c:\windows\system32\btmmhook.dll
.
Completion time: 2008-12-29 14:09:58
ComboFix-quarantined-files.txt 2008-12-29 14:09:55

Pre-Run: 863,016,087,552 bytes free
Post-Run: 861,935,968,256 bytes free

199 — E O F — 2008-12-26 19:41:44








And also a fresh HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:37:41, on 16/12/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\nvraidservice.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\System32\CTxfispi.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co.uk/ig/dell?hl=en&…amp;ibd=5080925
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ig/dell?hl=en&…amp;ibd=5080925
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [UACEnableEntry] regedit.exe /s C:\Users\Dom\AppData\Local\Temp\\UAC_Enable.reg
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" resetprofile
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

–
End of file - 10473 bytes



Thanks again
Hi dom1978,

sorry for the delay, for some reason I didn't get the email notification. Please do the following…

Malwarebytes' Anti-Malware

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

===============================================

And lets take a deeper look at some things…

RSIT
  • Download random's system information tool (RSIT) by random/random from here.
  • It is important that is saved to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<

===============================================

Needed in the next reply:

Malwarebytes log
RSIT logs

Also let me know how things are running :thumbup:
Happy new year…. Here are the requested logs

Malwarebytes' Anti-Malware 1.31
Database version: 1587
Windows 6.0.6001 Service Pack 1

01/01/2009 00:41:50
mbam-log-2009-01-01 (00-41-50).txt

Scan type: Quick Scan
Objects scanned: 47248
Time elapsed: 3 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




And also….

Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090101004928.013000-000
Event Type: Audit Failure
User:

Computer Name: Dom-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys
Record Number: 11369
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090101004928.034000-000
Event Type: Audit Failure
User:

Computer Name: Dom-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

File Name: \Device\HarddiskVolume3\Windows\System32\drivers\tcpip.sys
Record Number: 11370
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20090101004928.058000-000
Event Type: Audit Failure
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\PC Connectivity Solution;C:\Program Files\Common Files\Roxio Shared\DLLShared;C:\Program Files\Common Files\Roxio Shared\10.0\DLLShared;C:\Program Files\QuickTime\QTSystem
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=x86
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
"PROCESSOR_REVISION"=0f0b
"NUMBER_OF_PROCESSORS"=4
"TRACE_FORMAT_SEARCH_PATH"=\\NTREL202.ntdev.corp.microsoft.com\4F18C3A5-CA09-4DBD-B6FC-219FDD4C6BE0\TraceFormat
"DFSTRACINGON"=FALSE
"RoxioCentral"=C:\Program Files\Common Files\Roxio Shared\10.0\Roxio Central36\
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip

—————–EOF—————–



Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-01-01 00:49:19
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 823 GB (87%) free of 944 GB
Total RAM: 2813 MB (46% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 00:49:29, on 01/01/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\System32\nvraidservice.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Windows\System32\Ctxfihlp.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\CTxfispi.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\Macromed\Flash\FlashUtil9f.exe
C:\Users\Dom\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Dom.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ig/dell?hl=en&…amp;ibd=5080925
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
O4 - HKLM\..\Run: [Bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NVRaidService] C:\Windows\system32\nvraidservice.exe
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe" resetprofile
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe
O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

–
End of file - 9665 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Norton Internet Security - Run Full System Scan - Dom.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll [2008-01-08 316784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll [2008-09-29 116088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java™ Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-14 320920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar2.dll [2008-09-29 2549368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll [2008-10-01 652784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CA6319C0-31B7-401E-A518-A07C3DB8F777}]
CBrowserHelperObject Object - C:\Program Files\Dell\BAE\BAE.dll [2006-11-09 98304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java™ Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-14 34816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Show Norton Toolbar - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll [2008-01-08 316784]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar2.dll [2008-09-29 2549368]
{EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ECenter"=C:\Dell\E-Center\EULALauncher.exe [2008-02-29 17920]
"Bluetooth HCI Monitor"=RunDll32 HCIMNTR.DLL []
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-05-23 13531680]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-05-23 92704]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-14 136600]
"NVRaidService"=C:\Windows\system32\nvraidservice.exe [2008-01-03 184864]
"VolPanel"=C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe [2007-04-17 184320]
"CTxfiHlp"=C:\Windows\system32\CTXFIHLP.EXE [2008-06-30 23552]
"UpdReg"=C:\Windows\UpdReg.EXE [2000-05-11 90112]
"Adobe Reader Speed Launcher"=c:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-25 29744]
"dscactivate"=C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [2008-03-11 16384]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2008-10-17 51048]
"DellSupportCenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-03-11 202544]
"NSLauncher"=C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe [2007-09-07 3100672]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2008-12-03 399504]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DellSupportCenter"=C:\Program Files\Dell Support Center\bin\sprtcmd.exe [2008-03-11 202544]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-09-25 68856]
"NVIDIA nTune"=C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [2008-05-30 110592]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2008-09-06 413696]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GoToAssist]
C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2008-09-25 10536]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\GoToAssist]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{67dc625a-8aa4-11dd-970a-806e6f6e6963}]
shell\AutoRun\command - E:\autorun.exe


======List of files/folders created in the last 3 months======

2009-01-01 00:49:19 —-D—- C:\rsit
2009-01-01 00:33:14 —-D—- C:\Users\Dom\AppData\Roaming\Malwarebytes
2009-01-01 00:33:09 —-D—- C:\ProgramData\Malwarebytes
2009-01-01 00:33:09 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-29 14:22:57 —-A—- C:\log.txt
2008-12-29 14:09:58 —-A—- C:\ComboFix.txt
2008-12-29 13:54:38 —-A—- C:\Windows\zip.exe
2008-12-29 13:54:38 —-A—- C:\Windows\VFIND.exe
2008-12-29 13:54:38 —-A—- C:\Windows\SWXCACLS.exe
2008-12-29 13:54:38 —-A—- C:\Windows\SWSC.exe
2008-12-29 13:54:38 —-A—- C:\Windows\SWREG.exe
2008-12-29 13:54:38 —-A—- C:\Windows\sed.exe
2008-12-29 13:54:38 —-A—- C:\Windows\NIRCMD.exe
2008-12-29 13:54:38 —-A—- C:\Windows\grep.exe
2008-12-29 13:54:38 —-A—- C:\Windows\fdsv.exe
2008-12-29 13:54:09 —-D—- C:\Windows\ERDNT
2008-12-29 13:54:09 —-D—- C:\Qoobox
2008-12-29 13:54:08 —-D—- C:\ComboFix
2008-12-26 23:30:44 —-D—- C:\Users\Dom\AppData\Roaming\Sports Interactive
2008-12-26 23:30:13 —-D—- C:\ProgramData\Sports Interactive
2008-12-26 23:30:12 —-A—- C:\Windows\system32\XAudio2_1.dll
2008-12-26 23:30:12 —-A—- C:\Windows\system32\XAPOFX1_0.dll
2008-12-26 23:30:11 —-A—- C:\Windows\system32\xactengine3_1.dll
2008-12-26 23:30:11 —-A—- C:\Windows\system32\X3DAudio1_4.dll
2008-12-26 23:30:09 —-A—- C:\Windows\system32\XAudio2_0.dll
2008-12-26 23:30:08 —-A—- C:\Windows\system32\xactengine3_0.dll
2008-12-26 23:30:08 —-A—- C:\Windows\system32\X3DAudio1_3.dll
2008-12-26 23:30:07 —-A—- C:\Windows\system32\d3dx10_37.dll
2008-12-26 23:30:07 —-A—- C:\Windows\system32\D3DCompiler_37.dll
2008-12-26 23:30:06 —-A—- C:\Windows\system32\xactengine2_10.dll
2008-12-26 23:30:06 —-A—- C:\Windows\system32\D3DX9_37.dll
2008-12-26 23:30:04 —-A—- C:\Windows\system32\d3dx9_36.dll
2008-12-26 23:30:04 —-A—- C:\Windows\system32\d3dx10_36.dll
2008-12-26 23:30:04 —-A—- C:\Windows\system32\D3DCompiler_36.dll
2008-12-26 23:30:03 —-A—- C:\Windows\system32\xactengine2_9.dll
2008-12-26 23:30:00 —-A—- C:\Windows\system32\xactengine2_8.dll
2008-12-26 23:30:00 —-A—- C:\Windows\system32\X3DAudio1_2.dll
2008-12-26 23:30:00 —-A—- C:\Windows\system32\d3dx10_34.dll
2008-12-26 23:30:00 —-A—- C:\Windows\system32\D3DCompiler_34.dll
2008-12-26 23:29:59 —-A—- C:\Windows\system32\xinput1_3.dll
2008-12-26 23:29:59 —-A—- C:\Windows\system32\d3dx9_34.dll
2008-12-26 23:29:58 —-A—- C:\Windows\system32\xactengine2_7.dll
2008-12-26 23:29:57 —-A—- C:\Windows\system32\d3dx9_33.dll
2008-12-26 23:29:57 —-A—- C:\Windows\system32\d3dx10_33.dll
2008-12-26 23:29:57 —-A—- C:\Windows\system32\D3DCompiler_33.dll
2008-12-26 23:29:56 —-A—- C:\Windows\system32\xactengine2_6.dll
2008-12-26 23:29:53 —-A—- C:\Windows\system32\xactengine2_5.dll
2008-12-26 23:29:52 —-A—- C:\Windows\system32\d3dx10.dll
2008-12-26 23:29:51 —-A—- C:\Windows\system32\xactengine2_4.dll
2008-12-26 23:29:51 —-A—- C:\Windows\system32\x3daudio1_1.dll
2008-12-26 23:29:51 —-A—- C:\Windows\system32\d3dx9_32.dll
2008-12-26 23:29:50 —-A—- C:\Windows\system32\d3dx9_31.dll
2008-12-26 23:29:49 —-A—- C:\Windows\system32\xinput1_2.dll
2008-12-26 23:29:49 —-A—- C:\Windows\system32\xactengine2_3.dll
2008-12-26 23:29:48 —-A—- C:\Windows\system32\xinput1_1.dll
2008-12-26 23:29:48 —-A—- C:\Windows\system32\xactengine2_2.dll
2008-12-26 23:29:47 —-A—- C:\Windows\system32\xactengine2_1.dll
2008-12-26 23:29:38 —-A—- C:\Windows\system32\d3dx9_30.dll
2008-12-26 23:29:37 —-A—- C:\Windows\system32\xactengine2_0.dll
2008-12-26 23:29:37 —-A—- C:\Windows\system32\x3daudio1_0.dll
2008-12-26 23:29:36 —-A—- C:\Windows\system32\d3dx9_29.dll
2008-12-26 23:29:35 —-A—- C:\Windows\system32\d3dx9_28.dll
2008-12-26 23:29:34 —-A—- C:\Windows\system32\d3dx9_27.dll
2008-12-26 23:29:33 —-A—- C:\Windows\system32\d3dx9_26.dll
2008-12-26 23:29:32 —-A—- C:\Windows\system32\d3dx9_25.dll
2008-12-26 23:29:32 —-A—- C:\Windows\system32\d3dx9_24.dll
2008-12-26 22:58:32 —-D—- C:\ProgramData\Media Center Programs
2008-12-26 22:44:11 —-D—- C:\Program Files\Common Files\Steam
2008-12-26 22:43:49 —-D—- C:\Program Files\Steam
2008-12-26 22:43:02 —-HD—- C:\Program Files\Zero G Registry
2008-12-26 22:43:02 —-D—- C:\Program Files\Sports Interactive
2008-12-18 15:37:35 —-A—- C:\Windows\system32\mshtml.dll
2008-12-17 18:35:56 —-D—- C:\ProgramData\PC Suite
2008-12-17 18:35:39 —-D—- C:\Users\Dom\AppData\Roaming\Nokia
2008-12-17 18:35:26 —-D—- C:\Windows\Downloaded Installations
2008-12-17 18:34:55 —-D—- C:\Program Files\Common Files\PCSuite
2008-12-17 18:34:02 —-D—- C:\Users\Dom\AppData\Roaming\PC Suite
2008-12-17 18:33:59 —-D—- C:\Program Files\PC Connectivity Solution
2008-12-17 18:30:28 —-A—- C:\Windows\system32\nmwcdcls.dll
2008-12-17 18:30:19 —-D—- C:\Program Files\Nokia
2008-12-16 02:37:34 —-D—- C:\Program Files\Trend Micro
2008-12-16 02:27:04 —-D—- C:\Program Files\Hijackthis
2008-12-14 12:53:57 —-A—- C:\Windows\system32\javaws.exe
2008-12-14 12:53:57 —-A—- C:\Windows\system32\javaw.exe
2008-12-14 12:53:57 —-A—- C:\Windows\system32\java.exe
2008-12-14 12:53:57 —-A—- C:\Windows\system32\deploytk.dll
2008-12-12 03:03:15 —-A—- C:\Windows\system32\tzres.dll
2008-12-11 23:46:50 —-A—- C:\Windows\system32\gdi32.dll
2008-12-11 23:46:48 —-A—- C:\Windows\system32\Apphlpdm.dll
2008-12-11 23:46:47 —-A—- C:\Windows\system32\GameUXLegacyGDFs.dll
2008-12-11 23:46:41 —-A—- C:\Windows\system32\shell32.dll
2008-12-11 23:46:37 —-A—- C:\Windows\explorer.exe
2008-12-11 23:46:34 —-A—- C:\Windows\system32\urlmon.dll
2008-12-11 23:46:34 —-A—- C:\Windows\system32\ieframe.dll
2008-12-11 23:46:33 —-A—- C:\Windows\system32\wininet.dll
2008-12-11 23:46:33 —-A—- C:\Windows\system32\mstime.dll
2008-12-11 23:46:33 —-A—- C:\Windows\system32\iertutil.dll
2008-12-11 23:46:32 —-A—- C:\Windows\system32\jsproxy.dll
2008-12-11 23:46:30 —-A—- C:\Windows\system32\WMVCORE.DLL
2008-12-11 23:46:30 —-A—- C:\Windows\system32\mf.dll
2008-12-11 23:46:29 —-A—- C:\Windows\system32\WMNetMgr.dll
2008-12-11 23:46:29 —-A—- C:\Windows\system32\logagent.exe
2008-12-07 18:04:31 —-D—- C:\Users\Dom\AppData\Roaming\Red Alert 3
2008-12-07 17:55:23 —-D—- C:\ProgramData\Electronic Arts
2008-12-07 17:32:45 —-A—- C:\Windows\system32\D3DX9_38.dll
2008-12-07 17:32:45 —-A—- C:\Windows\system32\d3dx10_38.dll
2008-12-07 17:32:45 —-A—- C:\Windows\system32\D3DCompiler_38.dll
2008-12-07 17:32:44 —-A—- C:\Windows\system32\d3dx9_35.dll
2008-12-07 17:32:44 —-A—- C:\Windows\system32\d3dx10_35.dll
2008-12-07 17:32:44 —-A—- C:\Windows\system32\D3DCompiler_35.dll
2008-12-02 22:49:10 —-A—- C:\Windows\system32\wups2.dll
2008-12-02 22:49:10 —-A—- C:\Windows\system32\wuauclt.exe
2008-12-02 22:49:09 —-A—- C:\Windows\system32\wucltux.dll
2008-12-02 22:49:09 —-A—- C:\Windows\system32\wuaueng.dll
2008-12-02 22:48:57 —-A—- C:\Windows\system32\wups.dll
2008-12-02 22:48:57 —-A—- C:\Windows\system32\wudriver.dll
2008-12-02 22:48:57 —-A—- C:\Windows\system32\wuapi.dll
2008-12-02 22:48:53 —-A—- C:\Windows\system32\wuwebv.dll
2008-12-02 22:48:53 —-A—- C:\Windows\system32\wuapp.exe
2008-11-30 08:06:28 —-A—- C:\Windows\EPSMTL32.TXT
2008-11-26 06:52:27 —-A—- C:\Windows\system32\PortableDeviceApi.dll
2008-11-26 06:52:26 —-A—- C:\Windows\system32\WindowsCodecsExt.dll
2008-11-26 06:52:26 —-A—- C:\Windows\system32\WindowsCodecs.dll
2008-11-26 06:52:26 —-A—- C:\Windows\system32\PhotoMetadataHandler.dll
2008-11-26 06:52:25 —-A—- C:\Windows\system32\connect.dll
2008-11-14 19:04:34 —-D—- C:\Program Files\iPod
2008-11-14 19:04:33 —-D—- C:\ProgramData\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-14 19:04:33 —-D—- C:\Program Files\iTunes
2008-11-13 18:30:27 —-A—- C:\Windows\system32\E_DCINST.DLL
2008-11-13 18:30:23 —-A—- C:\Windows\system32\E_FLBBIE.DLL
2008-11-13 18:30:22 —-A—- C:\Windows\system32\E_FD4BBIE.DLL
2008-11-13 18:14:57 —-D—- C:\ProgramData\UDL
2008-11-13 18:14:21 —-D—- C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-11-13 18:09:20 —-A—- C:\Windows\system32\PICSDK2.dll
2008-11-13 18:09:20 —-A—- C:\Windows\system32\PICSDK.ini
2008-11-13 18:09:20 —-A—- C:\Windows\system32\PICSDK.dll
2008-11-13 18:09:20 —-A—- C:\Windows\system32\PICEntry.dll
2008-11-13 18:09:20 —-A—- C:\Windows\system32\EpPicPrt.dll
2008-11-13 18:09:20 —-A—- C:\Windows\system32\EPPicMgr.dll
2008-11-13 18:00:18 —-D—- C:\Program Files\epson
2008-11-13 18:00:10 —-A—- C:\Windows\CDE DX6000EFDG.ini
2008-11-12 11:15:41 —-A—- C:\Windows\system32\msxml3.dll
2008-11-12 11:10:34 —-A—- C:\Windows\system32\msxml6.dll
2008-11-03 16:49:18 —-A—- C:\Windows\system32\EncDec.dll
2008-11-03 16:49:17 —-A—- C:\Windows\system32\psisdecd.dll
2008-10-29 19:34:07 —-D—- C:\ProgramData\Propellerhead Software
2008-10-29 19:34:07 —-A—- C:\Windows\system32\REX Shared Library.dll
2008-10-29 19:34:07 —-A—- C:\Windows\system32\ReWire.dll
2008-10-29 19:33:55 —-D—- C:\Users\Dom\AppData\Roaming\Propellerhead Software
2008-10-29 15:55:26 —-D—- C:\ProgramData\Steinberg
2008-10-29 15:51:03 —-D—- C:\Users\Dom\AppData\Roaming\Steinberg
2008-10-29 15:50:35 —-D—- C:\ProgramData\Syncrosoft
2008-10-29 15:49:18 —-A—- C:\Windows\system32\Synsopos.exe
2008-10-29 15:49:10 —-A—- C:\Windows\system32\SynsoLChk.dll
2008-10-29 15:49:09 —-A—- C:\Windows\system32\SYNSOACC.dll
2008-10-29 15:49:08 —-D—- C:\Program Files\Syncrosoft
2008-10-29 12:07:12 —-A—- C:\Windows\system32\wersvc.dll
2008-10-29 12:07:12 —-A—- C:\Windows\system32\Faultrep.dll
2008-10-29 12:07:11 —-A—- C:\Windows\system32\win32spl.dll
2008-10-24 18:36:53 —-A—- C:\Windows\system32\netapi32.dll
2008-10-20 00:03:15 —-D—- C:\ProgramData\Microgaming
2008-10-20 00:03:15 —-D—- C:\ProgramData\MGS
2008-10-19 19:28:07 —-D—- C:\Users\Dom\AppData\Roaming\Template
2008-10-15 16:22:00 —-A—- C:\Windows\system32\ntoskrnl.exe
2008-10-15 16:22:00 —-A—- C:\Windows\system32\ntkrnlpa.exe
2008-10-03 23:12:15 —-D—- C:\Users\Dom\AppData\Roaming\Command & Conquer 3 Tiberium Wars
2008-10-03 23:11:59 —-RHD—- C:\Users\Dom\AppData\Roaming\SecuROM
2008-10-03 23:11:59 —-A—- C:\Windows\system32CmdLineExt.dll
2008-10-03 22:55:13 —-D—- C:\Program Files\Electronic Arts

======List of files/folders modified in the last 3 months======

2009-01-01 00:49:29 —-D—- C:\Windows\Prefetch
2009-01-01 00:49:24 —-D—- C:\Windows\Temp
2009-01-01 00:33:12 —-D—- C:\Windows\system32\drivers
2009-01-01 00:33:09 —-RD—- C:\Program Files
2009-01-01 00:33:09 —-HD—- C:\ProgramData
2009-01-01 00:14:42 —-D—- C:\ProgramData\Symantec
2009-01-01 00:14:29 —-SHD—- C:\System Volume Information
2008-12-30 23:52:47 —-D—- C:\ProgramData\Google Updater
2008-12-29 22:35:16 —-D—- C:\Windows
2008-12-29 14:10:00 —-D—- C:\Windows\system32\en-US
2008-12-29 14:10:00 —-D—- C:\Windows\System32
2008-12-29 13:59:28 —-A—- C:\Windows\system.ini
2008-12-29 13:58:38 —-D—- C:\Windows\AppPatch
2008-12-29 13:58:38 —-D—- C:\Program Files\Common Files
2008-12-26 23:29:46 —-RSD—- C:\Windows\assembly
2008-12-26 23:29:39 —-D—- C:\Windows\Microsoft.NET
2008-12-26 22:44:12 —-SHD—- C:\Windows\Installer
2008-12-23 21:33:24 —-D—- C:\Windows\system32\catroot2
2008-12-18 15:38:03 —-D—- C:\Windows\winsxs
2008-12-18 15:37:48 —-D—- C:\Windows\system32\catroot
2008-12-18 15:20:21 —-A—- C:\Windows\system32\PerfStringBackup.INI
2008-12-18 15:20:20 —-D—- C:\Windows\inf
2008-12-16 02:20:46 —-D—- C:\Windows\system32\Tasks
2008-12-14 12:53:36 —-D—- C:\Program Files\Java
2008-12-14 02:40:06 —-SD—- C:\Users\Dom\AppData\Roaming\Microsoft
2008-12-12 17:15:42 —-D—- C:\Windows\Debug
2008-12-12 14:41:23 —-D—- C:\Windows\rescache
2008-12-12 03:13:15 —-D—- C:\Program Files\Windows Mail
2008-12-09 23:24:37 —-A—- C:\Windows\system32\mrt.exe
2008-12-07 17:55:30 —-HD—- C:\Program Files\InstallShield Installation Information
2008-12-07 17:32:39 —-D—- C:\Windows\Logs
2008-12-06 22:28:25 —-D—- C:\Windows\system32\config
2008-12-06 22:28:22 —-D—- C:\Windows\Tasks
2008-12-06 22:28:22 —-D—- C:\Windows\system32\spool
2008-12-06 22:28:22 —-D—- C:\Windows\system32\Msdtc
2008-12-06 22:28:21 —-D—- C:\Windows\system32\wbem
2008-12-06 22:28:21 —-D—- C:\Windows\registration
2008-11-30 08:15:04 —-D—- C:\Windows\twain_32
2008-11-16 20:12:49 —-D—- C:\Windows\system32\LogFiles
2008-11-12 10:53:06 —-D—- C:\Program Files\Common Files\Symantec Shared
2008-11-03 19:16:17 —-D—- C:\Windows\ehome
2008-10-26 22:05:28 —-D—- C:\Users\Dom\AppData\Roaming\Microgaming
2008-10-20 00:03:15 —-D—- C:\Microgaming
2008-10-15 17:52:27 —-D—- C:\Windows\system32\migration
2008-10-14 18:10:32 —-D—- C:\Windows\system32\NDF
2008-10-04 00:25:30 —-D—- C:\Windows\system32\WDI
2008-10-02 01:32:01 —-D—- C:\Windows\Minidump

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2008-09-17 371248]
R1 IDSvix86;Symantec Intrusion Prevention Driver; \??\C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20081220.001\IDSvix86.sys [2008-09-12 270384]
R1 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [2008-09-05 447024]
R1 SRTSPX;SRTSPX; C:\Windows\System32\Drivers\SRTSPX.SYS [2007-11-30 43696]
R1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys [2008-06-13 24112]
R1 SYMTDI;SYMTDI; C:\Windows\System32\Drivers\SYMTDI.SYS [2008-06-13 184240]
R2 CO_Mon;CO_Mon; \??\C:\Windows\system32\drivers\CO_Mon.sys [2008-01-08 36056]
R3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-21 19456]
R3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
R3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2008-09-25 29184]
R3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2007-04-02 79664]
R3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-04-02 80688]
R3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-04-02 16432]
R3 CT20XUT.DLL;CT20XUT.DLL; C:\Windows\system32\CT20XUT.DLL [2008-06-30 171032]
R3 ctaud2k;Creative Audio Driver (WDM); C:\Windows\system32\drivers\ctaud2k.sys [2008-06-30 525464]
R3 CTEXFIFX.DLL;CTEXFIFX.DLL; C:\Windows\system32\CTEXFIFX.DLL [2008-06-30 1324056]
R3 CTHWIUT.DLL;CTHWIUT.DLL; C:\Windows\system32\CTHWIUT.DLL [2008-06-30 72728]
R3 ctprxy2k;Creative Proxy Driver; C:\Windows\system32\drivers\ctprxy2k.sys [2008-06-30 14360]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\Windows\system32\drivers\ctsfm2k.sys [2008-06-30 158744]
R3 emupia;E-mu Plug-in Architecture Driver; C:\Windows\system32\drivers\emupia2k.sys [2008-06-30 95768]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-17 99376]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2008-04-17 15464]
R3 ha20x2k;Creative 20X HAL Driver; C:\Windows\system32\drivers\ha20x2k.sys [2008-06-30 1177112]
R3 NAVENG;NAVENG; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20081231.003\NAVENG.SYS [2098-01-01 89104]
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~2\Symantec\DEFINI~1\VIRUSD~1\20081231.003\NAVEX15.SYS [2098-01-01 876112]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-01-15 1040544]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-05-23 7437792]
R3 NVR0Dev;NVR0Dev; \??\C:\Windows\nvoclock.sys [2008-05-30 29824]
R3 ossrv;Creative OS Services Driver; C:\Windows\system32\drivers\ctoss2k.sys [2008-06-30 129560]
R3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-21 49664]
R3 SRTSP;SRTSP; C:\Windows\System32\Drivers\SRTSP.SYS [2007-11-30 279088]
R3 SYMDNS;SYMDNS; C:\Windows\System32\Drivers\SYMDNS.SYS [2008-06-13 13616]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2008-09-29 123952]
R3 SYMFW;SYMFW; C:\Windows\System32\Drivers\SYMFW.SYS [2008-06-13 96432]
R3 SYMNDISV;SYMNDISV; C:\Windows\System32\Drivers\SYMNDISV.SYS [2008-06-13 41008]
R3 SYMREDRV;SYMREDRV; C:\Windows\System32\Drivers\SYMREDRV.SYS [2008-06-13 22320]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2008-09-25 220160]
S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
S3 COH_Mon;COH_Mon; \??\C:\Windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
S3 ctac32k;Creative AC3 Software Decoder; C:\Windows\system32\drivers\ctac32k.sys [2008-06-30 511000]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 e1express;Intel® PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2008-01-21 220672]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 nmwcd;Nokia USB Phone Parent; C:\Windows\system32\drivers\nmwcd.sys [2007-02-22 137216]
S3 nmwcdc;Nokia USB Generic; C:\Windows\system32\drivers\nmwcdc.sys [2007-02-22 8320]
S3 nmwcdcj;Nokia USB Port; C:\Windows\system32\drivers\nmwcdcj.sys [2007-02-22 12288]
S3 nmwcdcm;Nokia USB Modem; C:\Windows\system32\drivers\nmwcdcm.sys [2007-02-22 12288]
S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 2028032]
S3 SRTSPL;SRTSPL; C:\Windows\System32\Drivers\SRTSPL.SYS [2007-11-30 317616]
S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 SynasUSB;SynasUSB; C:\Windows\system32\drivers\SynasUSB.sys [2007-10-24 23288]
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2007-08-31 243064]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2007-02-13 441136]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-01 168432]
R2 LiveUpdate Notice;LiveUpdate Notice; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-10-17 149352]
R2 nTuneService;Performance Service; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [2008-05-30 155648]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-05-23 118784]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter); C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-03-11 202544]
R3 Symantec Core LC;Symantec Core LC; C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe [2008-09-29 1251720]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 comHost;COM Host; C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe [2008-01-08 55640]
S3 Creative ALchemy AL1 Licensing Service;Creative ALchemy AL1 Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe [2008-09-25 79360]
S3 GoogleDesktopManager-010708-104812;Google Desktop Manager 5.7.801.7324; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-09-25 29744]
S3 GoToAssist;GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [2008-09-25 16680]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2008-01-08 3192184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2007-02-08 212480]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2008-12-26 104944]
S3 stllssvr;stllssvr; C:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2008-03-24 74384]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]

—————–EOF—————–
Hi dom1978,

are you still having any problems?

Kaspersky WebScanner
please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Hi, sorry for the delay, i have had a week of long nightshift, here is the kapersky report. ——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Friday, January 9, 2009 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Friday, January 09, 2009 11:31:45 Records in database: 1593147 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ G:\ H:\ I:\ J:\ Scan statistics: Files scanned: 154138 Threat name: 1 Infected objects: 1 Suspicious objects: 0 Duration of the scan: 01:30:33 File name / Threat name / Threats count C:\Users\Dom\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\7f91991e-7c503da9 Infected: Trojan-Downloader.Java.OpenConnection.ar 1 The selected area was scanned.
Hi dom1978,

sorry for the delay, I didn't get the email notification. Please do the following


OTMoveIt3 by OldTimer

Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy everything inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Files
    C:\Users\Dom\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\7f91991e-7c503da9
    :Reg
    :Commands
    [purity]
    [emptytemp]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

also let me know how things are running, and if you have any problems :thumbup:
Hi there, here is the log file for o move it ========== FILES ========== C:\Users\Dom\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30\7f91991e-7c503da9 moved successfully. ========== REGISTRY ========== ========== COMMANDS ========== File delete failed. C:\Users\Dom\AppData\Local\Temp\Low\~DFE5A3.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\Dom\AppData\Local\Temp\Low\~DFE5C9.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\Dom\AppData\Local\Temp\~DF8ECE.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\Dom\AppData\Local\Temp\~DF8EEF.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\Dom\AppData\Local\Temp\~DFC5A5.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\Dom\AppData\Local\Temp\~DFC61C.tmp scheduled to be deleted on reboot. File delete failed. C:\Users\Dom\AppData\Local\Temp\~DFEAE7.tmp scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. Local Service Temporary Internet Files folder emptied. File delete failed. C:\Windows\temp\JETC7EF.tmp scheduled to be deleted on reboot. Windows Temp folder emptied. Temp folders emptied. OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01122009_164730 Files moved on Reboot… File C:\Users\Dom\AppData\Local\Temp\Low\~DFE5A3.tmp not found! File C:\Users\Dom\AppData\Local\Temp\Low\~DFE5C9.tmp not found! File C:\Users\Dom\AppData\Local\Temp\~DF8ECE.tmp not found! File C:\Users\Dom\AppData\Local\Temp\~DF8EEF.tmp not found! File C:\Users\Dom\AppData\Local\Temp\~DFC5A5.tmp not found! File C:\Users\Dom\AppData\Local\Temp\~DFC61C.tmp not found! C:\Users\Dom\AppData\Local\Temp\~DFEAE7.tmp moved successfully. File C:\Windows\temp\JETC7EF.tmp not found! Things seem to be running ok and the message about startup programs being blocked that i mentioned in my first post has gone. Cheers Dom
dom1978,

Good to hear, just a few clean up steps and your good to go….

ComboFix Removal

Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    [external image: Posted Image]
===============================================
CleanUp

Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Click on the CleanUp! button
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You may be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
===============================================

This is my standard post for when you are clear - which you now are - or seem to be. Please advise me of any problems you still have. . I know you already have some of these items like antivirus or firewall, but I like to include them anyway incase you ever need them or want to change them.

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

[external image: Posted Image] 1.) Watch what you download!
Many freeware programs, and P2P programs like Grokster, Imesh, Kazaa and others are amongst the most notorious, come with an enormous amount of bundled spyware that will eat system resources, slow down your system, clash with other installed software, or just plain crash your browser or even Windows itself. If you insist on using a P2P program, please read This Article written by Mike Healan of Spywareinfo.com fame. It is an updated and comprehensive article that gives in-depth detail about which P2P programs are "safe" to use.

[external image: Posted Image] 2.) Go to Intenet Explorer > Tools > Windows Update > Product Updates, and install ALL High-Priority Security Updates listed. If you're running Windows XP, that of course includes the Service Pack 2! If you suspect your computer is infected with Malware of any type, we advise you to not install SP2 if you don't already have it. You can post a HijackThis log on our Forums to get free Expert help cleaning your machine. Once you are sure you have a clean system, it is highly recommended to install SP2 to help prevent against future infections.

It's important to always keep current with the latest security fixes from Microsoft.
Install those patches for Internet Explorer, and make sure your installation of Java VM is up-to-date. There are some well known security bugs with Microsoft Java VM which are exploited regularly by browser hijackers.

[external image: Posted Image] 3.) Open Intenet Explorer and go to Internet Options > Security > Internet, then press "Default Level", then OK. Now press "Custom Level." In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".

Now you will be asked whether you want ActiveX objects to be executed and whether you want software to be installed.
Sites that you know for sure are above suspicion can be moved to the Trusted Zone in Internet Option > Security.

So why is ActiveX so dangerous that you have to increase the security for it?
When your browser runs an activex control, it is running an executable program. It's no different from doubleclicking an exe file on your hard drive.
Would you run just any random file downloaded off a web site without knowing what it is and what it does?

[external image: Posted Image] 4.) Install Javacool's SpywareBlaster

It will protect you from most spy/foistware in it's database by blocking installation of their ActiveX objects.

Download and install, download the latest updates, and you'll see a list of all spyware programs covered by the program (NOTE: this is NOT spyware found on your computer) Press "Enable All Protection", and you're done.
The spyware that you told Spywareblaster to set the "kill bit" for won't be a hazard to you any longer. Although it won't protect you from every form of spyware known to man, it is a very potent extra layer of protection.
Don't forget to check for updates every week or so.

[external image: Posted Image] 5.) Let's also not forget that Spybot Search & Destroy has the Immunize feature which works roughly the same way. Another feature within Spybot is the TeaTimer option. This option immediately detects known malicious processes wanting to start and terminates them. TeaTimer also detects when something wants to change some critical registry keys and gives you an option to allow them or not.

[external image: Posted Image] 6.) Microsoft now offers their own free malicious software blocking tool. Windows Defender improves Internet browsing safety by guarding over fifty (50) ways spyware can enter your PC.

[external image: Posted Image] 7.) Another excellent program by Javacool we recommend is SpywareGuard.
It provides a degree of real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.

[external image: Posted Image] 8.) IE-SPYAD puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all. Another good hosts program is mvpshosts. This little program packs a powerful punch as it block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers. For information on how to download and install, please read this tutorial.

*It is important to note that all of the above programs/files can be run simultaneously on your system. They will work together in layers, so to speak, to help protect your computer. However, the following suggestions are designed to only run one of each. It is not a good idea to run more than one firewall, and one anti-virus program. Running more than one of these at a time can cause system crashes, high system usage and/or conflicts with each other.*

[external image: Posted Image] 9.) It is critical that you use a firewall to protect your computer from hackers. We don't recommend the firewall that comes built in to Windows. It doesn't block everything that may try to get in, and the entire firewall is written to the registry. As various kinds of malware hack the Registry in order to disable the Windows firewall, it's far preferable to install one of the excellent third party solutions. Three good ones that are freeware to boot are ZoneAlarm, Kerio and Sygate

[external image: Posted Image] 10.) An Anti-Virus product is a necessity. There are many excellent programs that you can purchase. However, we choose to advocate the use of free programs whenever possible. Some very good and easy-to-use free A/V programs are AVG, Avast, and AntiVir. It's a good idea to set these to receive automatic updates so you are always as fully protected as possible from the newest virus threats.

NOTE: DO NOT install more than one anti-virus program. They will conflict, and provide less protection, not more.


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Thanks for letting us help you!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI