Gringo,
Attached are the logs you requested.
A couple of things have happened; 1) "The J2SE Runtime Environment (JRE)… seems to have been updated, as this selection is not on the screen. I could not get the part to work where I save the link to "Windows Offline Installation" to my desktop. I ended up with two icons on my Desktop. Clicking on one got a a window saying, "jre-6u11-windows-i586-p.exe is not a valid Win32 application"; and the other got a window saying, "Windows cannot open this file, jre-6u11-windows-i586-p.exe.part.
Also, when my PC restarted after the ComboFix, IE seemed to try to start. it looked like it might work (I got s window that said, "Welcome to Explorer 8"), but i shut it down, and clicked on another window that made FF my default browser.
I can't think of anything else significant.
Thanks again,
Bosan
ComboFix 09-01-18.06 - bodillinc 2009-01-20 9:46:07.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.511.221 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\bodillinc.THEBIGONE\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
FILE ::
c:\documents and settings\bodillinc.THEBIGONE\Application Data\GDIPFONTCACHEV1.DAT
c:\windows\_detmp.1
c:\windows\_detmp.2
c:\windows\Internet Logs\xDB3.tmp
c:\windows\Internet Logs\xDB4.tmp
c:\windows\system32\ropfnqz.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\bodillinc.THEBIGONE\Application Data\GDIPFONTCACHEV1.DAT
c:\program files\AskBarDis
c:\program files\AskBarDis\bar\bin\askBar.dll
c:\program files\AskBarDis\bar\bin\askBar1.dll
c:\program files\AskBarDis\bar\bin\askBar2.dll
c:\program files\AskBarDis\bar\bin\askBar3.dll
c:\program files\AskBarDis\bar\bin\askBar4.dll
c:\program files\AskBarDis\bar\bin\askBar5.dll
c:\program files\AskBarDis\bar\bin\askPopStp.dll
c:\program files\AskBarDis\bar\bin\askPopStp1.dll
c:\program files\AskBarDis\bar\bin\askPopStp2.dll
c:\program files\AskBarDis\bar\bin\askPopStp3.dll
c:\program files\AskBarDis\bar\bin\askPopStp4.dll
c:\program files\AskBarDis\bar\bin\askPopStp5.dll
c:\program files\AskBarDis\bar\bin\psvince.dll
c:\program files\AskBarDis\bar\Cache\
002BE373
c:\program files\AskBarDis\bar\Cache\
002BE9FC.bin
c:\program files\AskBarDis\bar\Cache\
002BF14C.bin
c:\program files\AskBarDis\bar\Cache\
002BF4AA.bin
c:\program files\AskBarDis\bar\Cache\
002BF7C1.bin
c:\program files\AskBarDis\bar\Cache\
002BF998.bin
c:\program files\AskBarDis\bar\Cache\files.ini
c:\program files\AskBarDis\bar\History\search
c:\program files\AskBarDis\bar\Settings\config.dat
c:\program files\AskBarDis\bar\Settings\config.dat.bak
c:\program files\AskBarDis\bar\Settings\prevcfg.htm
c:\program files\AskBarDis\PopSwatter\History\notallow
c:\program files\AskBarDis\unins000.dat
c:\program files\AskBarDis\unins000.exe
c:\windows\_detmp.1
c:\windows\_detmp.2
c:\windows\Internet Logs\xDB3.tmp
c:\windows\Internet Logs\xDB4.tmp
.
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.
2009-01-16 14:10 . 2009-01-16 14:10 d——– C:\rsit
2009-01-14 18:28 . 2009-01-14 18:28 d——– c:\program files\Trend Micro
2009-01-14 18:24 . 2009-01-14 18:24 d——– c:\program files\ERUNT
2009-01-14 17:55 . 2009-01-14 17:55 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-14 17:55 . 2009-01-14 17:55 d——– c:\documents and settings\bodillinc.THEBIGONE\Application Data\Malwarebytes
2009-01-14 17:55 . 2009-01-14 17:55 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-14 17:55 . 2009-01-04 18:38 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 17:55 . 2009-01-04 18:38 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-07 18:04 . 2009-01-07 18:04 d——– c:\windows\ie8updates
2009-01-07 10:54 . 2009-01-07 10:56 d–h-c— c:\windows\ie8
2009-01-06 13:03 . 2009-01-20 08:46 d——– c:\windows\system32\drivers\Avg
2009-01-06 13:03 . 2009-01-06 13:03 97,928 –a—— c:\windows\system32\drivers\avgldx86.sys
2009-01-06 13:03 . 2009-01-06 13:03 76,040 –a—— c:\windows\system32\drivers\avgtdix.sys
2009-01-06 13:03 . 2009-01-06 13:03 10,520 –a—— c:\windows\system32\avgrsstx.dll
2009-01-06 13:02 . 2009-01-06 13:02 d——– c:\documents and settings\bodillinc.THEBIGONE\Application Data\AVGTOOLBAR
2009-01-02 08:43 . 2009-01-02 11:09 d——– c:\documents and settings\All Users\Application Data\SITEguard
2009-01-02 08:42 . 2009-01-02 08:42 d——– c:\program files\Common Files\iS3
2009-01-02 08:42 . 2009-01-02 11:13 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-19 16:39 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-19 16:38 ——— d—–w c:\program files\SpywareBlaster
2009-01-15 23:47 ——— d—–w c:\program files\Glary Utilities
2009-01-09 19:19 ——— d—–w c:\program files\WinFax
2009-01-09 19:19 ——— d—–w c:\program files\PhoTags Express
2009-01-09 19:19 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-09 16:47 ——— d—–w c:\program files\Sierra On-Line
2009-01-07 18:36 ——— d—–w c:\documents and settings\bodillinc.THEBIGONE\Application Data\OpenOffice.org2
2009-01-06 18:21 ——— d—–w c:\program files\Free Window Registry Repair
2009-01-06 18:02 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2008-12-30 02:43 ——— d—–w c:\program files\AutoCAD R14
2008-12-27 00:49 ——— d—–w c:\program files\CCleaner
2008-12-16 14:37 ——— d—–w c:\program files\Pwrchute
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-06 20:26 ——— d—–w c:\program files\Common Files\Adobe AIR
2008-12-06 20:25 ——— d—–w c:\program files\Common Files\Adobe
2008-12-06 20:15 ——— d—–w c:\documents and settings\All Users\Application Data\NOS
2008-12-06 20:05 ——— d—–w c:\program files\NOS
2008-12-03 15:20 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-07-21 16:03 449,043 —-a-w c:\program files\RegSeeker.zip
2008-07-21 15:23 788,434 —-a-w c:\program files\RegpairSetup.exe
2008-06-28 00:42 2,223,444 —-a-w c:\program files\FreeWebshop.org2.2.9_R2.zip
2008-06-27 13:28 133,227,519 —-a-w c:\program files\OOo_2.4.1_Win32Intel_install_wJRE_en-US.exe
2008-06-24 17:08 1,786,594 —-a-w c:\program files\Arachnophilia.exe
2008-06-11 21:34 6,890,528 —-a-w c:\program files\nvu-1.0-win32-installer-full.exe
2008-05-29 20:56 37,375 —-a-w c:\program files\openoffice.org-xsltfilter.cab
2008-05-29 20:56 207,388 —-a-w c:\program files\openoffice.org-testtool.cab
2008-05-29 20:56 2,490,452 —-a-w c:\program files\openoffice.org-writer.cab
2008-05-29 20:55 919,329 —-a-w c:\program files\openoffice.org-draw.cab
2008-05-29 20:55 86,870 —-a-w c:\program files\openoffice.org-graphicfilter.cab
2008-05-29 20:55 51,973 —-a-w c:\program files\openoffice.org-onlineupdate.cab
2008-05-29 20:55 3,842,531 —-a-w c:\program files\openoffice.org-core07.cab
2008-05-29 20:55 293,078 —-a-w c:\program files\openoffice.org-core08.cab
2008-05-29 20:55 2,769 —-a-w c:\program files\openoffice.org-emailmerge.cab
2008-05-29 20:55 2,504,975 —-a-w c:\program files\openoffice.org-pyuno.cab
2008-05-29 20:55 2,031,954 —-a-w c:\program files\openoffice.org-core09.cab
2008-05-29 20:55 118,910 —-a-w c:\program files\openoffice.org-javafilter.cab
2008-05-29 20:55 1,254,017 —-a-w c:\program files\openoffice.org-impress.cab
2008-05-29 20:55 1,090,334 —-a-w c:\program files\openoffice.org-math.cab
2008-05-29 20:54 28,847,705 —-a-w c:\program files\openoffice.org-core06.cab
2008-05-29 20:50 18,634,513 —-a-w c:\program files\openoffice.org-core05.cab
2008-05-29 20:49 16,503,595 —-a-w c:\program files\openoffice.org-core04.cab
2008-05-29 20:48 9,117,929 —-a-w c:\program files\openoffice.org-core03.cab
2008-05-29 20:48 3,860,980 —-a-w c:\program files\openoffice.org-core02.cab
2008-05-29 20:47 4,694,039 —-a-w c:\program files\openoffice.org-calc.cab
2008-05-29 20:47 15,104,219 —-a-w c:\program files\openoffice.org-core01.cab
2008-05-29 20:47 1,803,630 —-a-w c:\program files\openoffice.org-base.cab
2008-05-29 20:46 43,005 —-a-w c:\program files\openoffice.org-activex.cab
2008-05-29 20:46 4,372,992 —-a-w c:\program files\openofficeorg24.msi
2008-05-29 20:46 217 —-a-w c:\program files\setup.ini
2006-02-03 18:30 188,406 —-a-w c:\program files\updatecdr4_53_71.exe
2004-07-13 13:26 169,744 —-a-w c:\documents and settings\bodillinc.THEBIGONE\Application Data\shb.dat
2004-03-01 22:05 58,472 —-a-w c:\program files\floorplan.dwg
2004-03-01 21:46 98,490 —-a-w c:\program files\BDlogo.dwg
2004-02-29 06:10 52,611 —-a-w c:\program files\superD.dwg
2004-02-24 08:00 10,003 —-a-w c:\program files\acad14.cfg
2004-02-24 07:58 78,538 —-a-w c:\program files\DeIsL2.isu
2004-02-24 07:58 7,471,616 —-a-w c:\program files\acad.exe
2004-02-19 00:23 116,953 —-a-w c:\program files\BDwings.dwg
2003-05-31 08:33 536 —-a-w c:\program files\acad.err
2003-04-04 00:28 32,849 —-a-w c:\program files\Scaffold Disk.dwg
2003-03-29 18:47 80,755 —-a-w c:\program files\DeIsL1.isu
2002-03-11 09:06 1,822,520 —-a-w c:\program files\instmsiw.exe
2002-03-11 08:45 1,708,856 —-a-w c:\program files\instmsia.exe
1997-05-06 10:27 90,358 —-a-w c:\program files\render.xmx
1997-05-06 10:27 28,672 —-a-w c:\program files\lsobj.arx
1997-05-06 10:27 1,333,248 —-a-w c:\program files\render.arx
1997-05-06 10:25 971,776 —-a-w c:\program files\asidb3.exe
1997-05-06 10:25 934,400 —-a-w c:\program files\asiodbc.exe
1997-05-06 10:25 925,696 —-a-w c:\program files\asiora7.exe
1997-05-06 10:25 587,776 —-a-w c:\program files\asicfg.exe
1997-05-06 10:25 524,800 —-a-w c:\program files\asilisp.arx
1997-05-06 10:25 52,609 —-a-w c:\program files\asiloc.xmx
1997-05-06 10:25 5,121 —-a-w c:\program files\asidb3.xmx
1997-05-06 10:25 38,705 —-a-w c:\program files\aseloc.xmx
1997-05-06 10:25 2,803 —-a-w c:\program files\asilisp.xmx
1997-05-06 10:25 2,625 —-a-w c:\program files\asiora7.xmx
1997-05-06 10:25 2,145 —-a-w c:\program files\asiodbc.xmx
1997-05-06 10:23 968 —-a-w c:\program files\acshell.pif
1997-05-06 10:23 52,736 —-a-w c:\program files\gdi3.hdi
1997-05-06 10:23 49,152 —-a-w c:\program files\dwf3.hdi
1997-05-06 10:23 48,640 —-a-w c:\program files\lfb3.hdi
1997-05-06 10:23 418,816 —-a-w c:\program files\dswhip.dll
1997-05-06 10:23 17,408 —-a-w c:\program files\rblast3.hdi
1997-05-06 10:23 13,312 —-a-w c:\program files\slide3.hdi
1997-05-06 10:23 125,952 —-a-w c:\program files\dlint3.dll
1997-05-06 10:18 1,828 —-a-w c:\program files\mtextmap.ini
1997-05-06 10:16 47,104 —-a-w c:\program files\ddelib.dll
1997-05-06 10:16 39,936 —-a-w c:\program files\dwfiu.arx
1997-05-06 10:16 3,392 —-a-w c:\program files\internet.avi
1997-05-06 10:16 207,872 —-a-w c:\program files\whiptk.dll
1997-05-06 10:16 115,712 —-a-w c:\program files\dwfout.arx
1997-05-06 10:16 100,352 —-a-w c:\program files\internet.arx
1997-05-06 04:15 44,544 —-a-w c:\program files\UNACAD.DLL
2008-09-27 15:31 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008092720080928\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2006-10-22 7700480]
"NeroCheck"="c:\windows\System32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-06 1261336]
"WinFaxAppPortStarter"="wfxsnt40.exe" [2001-09-10 c:\windows\system32\WFXSNT40.EXE]
"nwiz"="nwiz.exe" [2006-10-22 c:\windows\system32\nwiz.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
ZoneAlarm.lnk - c:\program files\Zone Labs\ZoneAlarm\zonealarm.exe [2002-10-13 623936]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
–a—— 2004-05-28 14:22 4882432 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NAV Agent]
–a—— 2002-02-27 11:27 75384 c:\progra~1\NORTON~1\NORTON~1\NAVAPW32.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QD FastAndSafe]
–a—— 2002-02-27 11:27 75384 c:\progra~1\NORTON~1\NORTON~1\NAVAPW32.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
——— 2008-09-16 11:16 1833296 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"SymWSC"=2 (0x2)
"Symantec Core LC"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SAVScan"=3 (0x3)
"NPFMntor"=2 (0x2)
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"SBService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"PrinTray"=c:\windows\System32\spool\DRIVERS\W32X86\2\printray.exe
"LXSUPMON"=c:\windows\System32\LXSUPMON.EXE RUN
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Verizon_McciTrayApp"=c:\program files\Verizon\McciTrayApp.exe
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-06 97928]
R4 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-06 875288]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-06 231704]
R4 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-06 76040]
R4 NProtectService;Norton Unerase Protection;c:\program files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE [2002-10-17 135168]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-06 33752]
.
Contents of the 'Scheduled Tasks' folder
2009-01-20 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2008-10-29 17:58]
2006-10-12 c:\windows\Tasks\Norton SystemWorks One Button Checkup.job
- c:\program files\Common Files\Symantec Shared\NMAIN.EXE [2004-08-13 20:17]
.
.
——- Supplementary Scan ——-
.
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: ppctlcab - hxxp://www.pestscan.com/scanner/ppctlcab.cab
DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} - hxxp://download.verizon.net/sfp/Cabs/max_update/VOLUpdate_1-0-0.cab
DPF: {BCD5A227-8720-497B-AF5F-4403E94342E3} - hxxps://netservices.verizon.net/portal/verizon/passwdchg/activex/DSLControl.cab
DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} - hxxp://www2.verizon.net/update/msnwebinstall/includes/vzWebIns.CAB
FF - ProfilePath - c:\documents and settings\bodillinc.THEBIGONE\Application Data\Mozilla\Firefox\Profiles\8q90me4v.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-20 09:51:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\software\KasperskyLab\AVP32]
@DACL=(02 0000)
@SACL=
[HKEY_LOCAL_MACHINE\software\KasperskyLab\Components]
@DACL=(02 0000)
@SACL=
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\BRSS01A.EXE
c:\windows\system32\LexBceS.exe
c:\windows\system32\Lexpps.exe
c:\windows\system32\rundll32.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\progra~1\NORTON~1\SPEEDD~1\NOPDB.EXE
c:\windows\system32\ZoneLabs\vsmon.exe
c:\windows\system32\fxssvc.exe
c:\progra~1\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-01-20 9:55:23 - machine was rebooted
ComboFix-quarantined-files.txt 2009-01-20 14:55:14
ComboFix2.txt 2009-01-19 16:23:59
Pre-Run: 65,597,407,232 bytes free
Post-Run: 65,571,377,152 bytes free
Current=3 Default=3 Failed=1 LastKnownGood=2 Sets=1,2,3,4
301 — E O F — 2009-01-14 16:56:09
Malwarebytes' Anti-Malware 1.32
Database version: 1653
Windows 5.1.2600 Service Pack 3
1/20/2009 10:05:51 AM
mbam-log-2009-01-20 (10-05-51).txt
Scan type: Quick Scan
Objects scanned: 53230
Time elapsed: 3 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:33:43 AM, on 1/20/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wfxsnt40.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\BLSearch\SearchEnh1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - AutorunsDisabled - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: ZoneAlarm.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zonealarm.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {1011E032-5CF3-4795-B751-3AA5E008CCA6} -
http://download.verizon.net/sfp/Cabs/max_u…pdate_1-0-0.cab
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) -
http://www.alternatiff.com/install/00/alttiff.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…trl/tgctlsr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {BCD5A227-8720-497B-AF5F-4403E94342E3} (CDDM Object) -
https://netservices.verizon.net/portal/veri…/DSLControl.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://www.verizon.net/checkmypc/includes/MotivePreQual.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) -
http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
–
End of file - 9682 bytes
Again, thanks.