mesa215
Topic Starter
Hi, I posted a thread before and it got closed due to inactivity. I hadn't recieved any replies to my thread for a lond time so I didn't check back right away. Apparently someone did reply. ..jpshortstuff. . If this is you, I did what you told me and got a DDS report. Below is my initial post and jpshortstuff reply. If anyone else is reading this and can help, please let me know. Sorry this is such a long post. I appreciate the time.
Here is my initial post:
I use a program called Advanced System Care 3, It has a feature that does a hijack report. It also promts me that not all the processes are problems or malware. How do I know which ones to choose for the program to fix. The program prompted me to save and post this log to a hijack this forum. My computer runs slow and sometimes the browser closes without warning or asking to send an error report. I also sometimes get a message telling me that my virtual memmory is low and that I have too many processes running. I really didn't think I had a lot of things downloaded on my computer. I have a 2.8 GHz Processor and 512 MB RAM. Are these problems related to any of the processes or are they due to something else. I use Threatfire as my antivirus protection. Also could you please tell me if I need to let Advanced System Care fix any of the below listed processes. I've heard that some of these programs delete important files. It is hard to know which programs to trust. Please help. Thank you for your time. I appreciate it.
Logfile of Advanced SystemCare 3 Security Analyzer
Scan saved at 7:31:09 PM, on 1/1/2009
Platform: Windows XP (WinNT 5.1)
MSIE: Internet Explorer v7.0 (7.0.5730.13)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AcroIEHelperStub - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: AcroIEHelperStub - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AcroIEHelperStub - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: JQSIEStartDetectorImpl - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} -
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_11) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…ows-i586-jc.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O23 - Service: (Ati HotKey Poller) - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Unknown - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
Please note the items listed here are not all problems or malware. They are critical settings of your system and common targets of malware. Before you remove any item, make sure it is malware. The log file of Security Analyzer is 100% compatible with HijackThis log so you can save this report and submit it to any qualified online HijackThis log analyzer and HijackThis forums.
This was the reply:
Hi, and Welcome to WhatTheTech
My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
• I will be working on your Malware issues, this may or may not solve other issues you have with your machine.
• The fixes are specific to your problem and should only be used for the issues on this machine.
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• It's often worth reading through the instructions before starting to follow them to make sure you understand everything you have to do.
• If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
• Please reply to this thread. Do not start a new topic.
Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around. If you still require help, please do the following:
Please download DDS and save it to your desktop.
• Disable any script blocking protection
• Double click dds.scr to run the tool.
• When done, DDS.txt will open.
• Click Yes at the next prompt for Optional Scan.
• Save both reports to your desktop.
—————————————————
• Post the contents of the DDS.txt report in your next reply
• Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
Thanks.
Here is the DDS report:
DDS (Ver_09-01-19.01) - NTFSx86
Run by [removed] at 8:02:33.39 on Sun 01/25/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.194 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aim toolbar\aimtbServer.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Documents and Settings\Mom\Local Settings\Temporary Internet Files\Content.IE5\KJSGYG36\dds[1].scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.mediacomtoday.com/
uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
BHO: EWPP - No File
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [ThreatFire] c:\program files\threatfire\TFTray.exe
mRun: [EPSON Stylus CX4800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231204105531
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?AuthParam=1230064253_b5d2401e226813170ebeeff477610c76&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab&File=jinstall-6u11-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2008-12-23 51488]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2008-12-23 39200]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2008-12-23 33056]
R4 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-1-16 464264]
R4 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-1-16 234888]
R4 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service –> c:\program files\threatfire\TFService.exe service [?]
R4 Viewpoint Service;Viewpoint Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-16 30152]
=============== Created Last 30 ================
2009-01-23 15:47 159,744 a——- c:\windows\system32\lfpng13n.dll
2009-01-22 19:57 –d—– c:\program files\Shockwave.com
2009-01-21 07:07 –d—– c:\program files\MSECache
2009-01-19 07:47 –d—– C:\ConverterOutput
2009-01-19 07:45 395,776 a——- c:\windows\system32\libmplayer.dll
2009-01-19 07:45 262,144 a——- c:\windows\system32\TomsMoComp_ff.dll
2009-01-19 07:45 172,032 a——- c:\windows\system32\ac3filter.ax
2009-01-19 07:45 112,640 a——- c:\windows\system32\libmpeg2_ff.dll
2009-01-19 07:45 –d—– c:\program files\Cucusoft
2009-01-19 00:37 –d—– c:\program files\uTorrent
2009-01-19 00:37 –d—– c:\docume~1\mom\applic~1\uTorrent
2009-01-19 00:14 –d—– c:\program files\Combined Community Codec Pack
2009-01-17 03:17 –d—– c:\program files\Sector 69
2009-01-17 00:07 –d—– c:\program files\MSXML 4.0
2009-01-16 12:13 –d—– c:\docume~1\mom\applic~1\PCF-VLC
2009-01-16 12:02 –d—– c:\docume~1\mom\applic~1\Participatory Culture Foundation
2009-01-16 12:01 –d—– c:\program files\Participatory Culture Foundation
2009-01-16 06:47 –d—– c:\docume~1\alluse~1\applic~1\Azureus
2009-01-16 06:47 –d—– c:\docume~1\mom\applic~1\Azureus
2009-01-16 06:47 –d—– c:\program files\AskBarDis
2009-01-16 06:44 –d—– c:\program files\Vuze
2009-01-16 04:15 87,608 a——- c:\docume~1\mom\applic~1\inst.exe
2009-01-16 04:15 47,360 a——- c:\windows\system32\drivers\pcouffin.sys
2009-01-16 04:15 47,360 a——- c:\docume~1\mom\applic~1\pcouffin.sys
2009-01-16 03:55 –d—– c:\program files\VideoLAN
2009-01-16 03:38 –d—– C:\divx
2009-01-16 03:26 –d—– c:\program files\DivX
2009-01-16 03:19 –d—– c:\program files\Viewpoint
2009-01-16 02:57 –d—– c:\windows\system32\quicktime
2009-01-16 02:37 –d—– c:\program files\common files\Hypnotizer
2009-01-16 02:26 –d—– c:\docume~1\mom\applic~1\AVS4YOU
2009-01-16 02:25 –d—– c:\docume~1\alluse~1\applic~1\AVS4YOU
2009-01-16 02:23 82,944 a——- c:\windows\system32\vct3216.acm
2009-01-16 02:23 38,912 a——- c:\windows\system32\alf2cd.acm
2009-01-16 02:23 13,239 a——- c:\windows\system32\Scg726.acm
2009-01-16 02:23 261,632 a——- c:\windows\system32\mcdvd_32.dll
2009-01-16 02:23 156,910 a——- c:\windows\WMSysPr8.prx
2009-01-16 02:22 –d—– c:\program files\common files\AVSMedia
2009-01-16 02:21 974,848 a——- c:\windows\system32\mfc70.dll
2009-01-16 02:21 1,700,352 a——- c:\windows\system32\GdiPlus.dll
2009-01-16 02:21 –d—– c:\program files\AVS4YOU
2009-01-16 00:20 82,432 a——- c:\windows\system32\msxml4r.dll
2009-01-16 00:20 –d—– c:\program files\Zortam Mp3 Media Studio
2009-01-14 20:32 –d—– c:\program files\common files\Software Update Utility
2009-01-14 20:31 –d—– c:\program files\AIM Toolbar
2009-01-14 20:31 –d—– c:\docume~1\alluse~1\applic~1\AIM Toolbar
2009-01-14 20:31 –d—– c:\docume~1\alluse~1\applic~1\Viewpoint
2009-01-14 20:31 –d—– c:\docume~1\alluse~1\applic~1\acccore
2009-01-14 20:31 –d—– c:\program files\common files\AOL
2009-01-14 20:30 –d—– c:\program files\AIM6
2009-01-14 20:30 432 a—h— C:\IPH.PH
2009-01-11 23:14 462,848 a——- c:\windows\system32\ltkrn13n.dll
2009-01-11 23:14 450,560 a——- c:\windows\system32\ltimg13n.dll
2009-01-11 23:14 401,408 a——- c:\windows\system32\lfcmp13n.dll
2009-01-11 23:14 299,008 a——- c:\windows\system32\ltdis13n.dll
2009-01-11 23:14 206,336 a——- c:\windows\system32\ltefx13n.dll
2009-01-11 23:14 163,840 a——- c:\windows\system32\ltfil13n.dll
2009-01-11 23:14 69,632 a——- c:\windows\system32\lfgif13n.dll
2009-01-11 23:14 57,344 a——- c:\windows\system32\lfbmp13n.dll
2009-01-10 19:01 28,040 a——- c:\windows\system32\mdimon.dll
2009-01-10 19:00 –d—– c:\program files\Microsoft ActiveSync
2009-01-10 18:53 44,032 ——– c:\windows\system32\CTSVCCDA.EXE
2009-01-10 18:53 90,112 ——– c:\windows\Updreg.EXE
2009-01-10 18:53 84,992 ——– c:\windows\system32\SFCVRT32.DLL
2009-01-10 18:53 53,552 ——– c:\windows\CTCCW.DLL
2009-01-10 18:53 40,960 ——– c:\windows\system32\AC3API.DLL
2009-01-10 18:53 24,976 ——– c:\windows\CTRES.DLL
2009-01-10 18:53 231 ——– c:\windows\AC3API.INI
2009-01-10 18:53 82,432 ——– c:\windows\system32\CTWFLT32.DLL
2009-01-10 18:53 54,784 ——– c:\windows\system32\INETWH32.DLL
2009-01-10 18:53 26,768 ——– c:\windows\system32\CTL3D.DLL
2009-01-10 18:53 –d—– c:\windows\system32\Defaults
2009-01-10 18:53 1,048,576 ——– c:\windows\system32\SFMAN.DAT
2009-01-10 18:51 176,128 a——- c:\windows\system32\USBAudio.cpl
2009-01-10 18:51 135,168 a——- c:\windows\system32\USBAudio.crl
2009-01-10 18:51 45,390 a——- c:\windows\system32\usbaudio.chm
2009-01-10 18:51 692 a——- c:\windows\system32\USBAudio.cpl.manifest
2009-01-10 18:49 15,840 a—-r– c:\windows\system32\drivers\Pfmodnt.sys
2009-01-10 18:36 –d—– c:\windows\SxsCaPendDel
2009-01-07 13:02 –d—– c:\windows\system32\XPSViewer
2009-01-07 13:00 14,048 ——– c:\windows\system32\spmsg2.dll
2009-01-07 08:15 0 a——- c:\windows\ativpsrm.bin
2009-01-07 07:32 –d—– C:\ATI
2009-01-05 22:58 27,496 a——- c:\windows\system32\mucltui.dll.mui
2009-01-05 22:58 268,648 a——- c:\windows\system32\mucltui.dll
2009-01-05 16:18 90,112 a——- c:\windows\system32\QuickTimeVR.qtx
2009-01-05 16:18 57,344 a——- c:\windows\system32\QuickTime.qts
2009-01-04 09:49 –d—– c:\docume~1\mom\applic~1\ErrorFix
2009-01-04 03:41 –d—– c:\program files\common files\CA Shared
2008-12-28 15:44 –d—– c:\program files\Cat Daddy Games
2008-12-28 15:31 45,056 a——- c:\windows\system32\wnaspi32.dll
2008-12-28 15:31 25,244 a——- c:\windows\system32\drivers\aspi32.sys
2008-12-28 15:31 5,600 a——- c:\windows\system\winaspi.dll
2008-12-28 15:31 4,672 a——- c:\windows\system\wowpost.exe
2008-12-28 15:31 203,776 a——- c:\windows\system32\clrviddc.dll
2008-12-28 14:58 53,248 a——- c:\windows\system32\CSVer.dll
2008-12-28 14:58 –d—– C:\Intel
2008-12-28 14:07 –d—– c:\program files\Unity
2008-12-28 14:06 –d—– c:\windows\system32\LogFiles
2008-12-28 13:52 –d—– c:\program files\common files\L&H
2008-12-26 22:27 1,182 a——- c:\docume~1\mom\applic~1\wklnhst.dat
2008-12-26 22:15 32,592 a——- c:\windows\system32\msonpmon.dll
2008-12-26 22:00 –d—– c:\docume~1\mom\applic~1\GetRightToGo
2008-12-26 21:57 24 a——- C:\url_history.xml
2008-12-26 21:24 –d—– c:\program files\Windows Media Connect 2
2008-12-26 20:57 –d—– c:\docume~1\mom\applic~1\Software Informer
==================== Find3M ====================
2008-12-23 22:16 499,712 a——- c:\windows\system32\msvcp71.dll
2008-12-23 16:07 77,423 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-12-23 15:30 410,984 a——- c:\windows\system32\deploytk.dll
2008-12-23 13:56 21,640 a——- c:\windows\system32\emptyregdb.dat
2008-12-11 05:57 333,952 a——- c:\windows\system32\drivers\srv.sys
2008-12-10 19:33 200,704 a——- c:\windows\system32\dtu100.dll
2008-12-10 19:33 86,016 a——- c:\windows\system32\dpl100.dll
2008-12-08 21:28 593,920 a——- c:\windows\system32\dpuGUI11.dll
2008-12-08 21:28 344,064 a——- c:\windows\system32\dpus11.dll
2008-12-08 21:28 294,912 a——- c:\windows\system32\dpu11.dll
2008-12-08 21:28 57,344 a——- c:\windows\system32\dpv11.dll
2008-12-05 22:18 348,160 a——- c:\windows\system32\msvcr71.dll
2008-12-01 17:13 3,452,928 a——- c:\windows\system32\drivers\ati2mtag.sys
2008-12-01 15:52 425,984 a——- c:\windows\system32\ATIDEMGX.dll
2008-12-01 15:51 318,464 a——- c:\windows\system32\ati2dvag.dll
2008-12-01 15:46 11,304,960 a——- c:\windows\system32\atioglxx.dll
2008-12-01 15:41 188,416 a——- c:\windows\system32\atipdlxx.dll
2008-12-01 15:40 147,456 a——- c:\windows\system32\Oemdspif.dll
2008-12-01 15:40 26,112 a——- c:\windows\system32\Ati2mdxx.exe
2008-12-01 15:40 43,520 a——- c:\windows\system32\ati2edxx.dll
2008-12-01 15:40 143,360 a——- c:\windows\system32\ati2evxx.dll
2008-12-01 15:38 598,016 a——- c:\windows\system32\ati2evxx.exe
2008-12-01 15:37 53,248 a——- c:\windows\system32\ATIDDC.DLL
2008-12-01 15:27 4,120,384 a——- c:\windows\system32\ati3duag.dll
2008-12-01 15:19 307,200 a——- c:\windows\system32\atiiiexx.dll
2008-12-01 15:11 2,495,360 a——- c:\windows\system32\ativvaxx.dll
2008-12-01 15:11 3,107,788 a——- c:\windows\system32\ativvaxx.dat
2008-12-01 15:11 3,107,788 a——- c:\windows\system32\ativva5x.dat
2008-12-01 15:11 887,724 a——- c:\windows\system32\ativva6x.dat
2008-12-01 14:57 48,640 a——- c:\windows\system32\amdpcom32.dll
2008-12-01 14:53 401,408 a——- c:\windows\system32\atikvmag.dll
2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalrt.dll
2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalcl.dll
2008-12-01 14:52 86,016 a——- c:\windows\system32\atiadlxx.dll
2008-12-01 14:52 17,408 a——- c:\windows\system32\atitvo32.dll
2008-12-01 14:51 53,248 a——- c:\windows\system32\drivers\ati2erec.dll
2008-12-01 14:50 286,720 a——- c:\windows\system32\atiok3x2.dll
2008-12-01 14:50 3,252,224 a——- c:\windows\system32\Amdcaldd.dll
2008-12-01 14:45 577,536 a——- c:\windows\system32\ati2cqag.dll
2008-12-01 14:35 593,920 ——– c:\windows\system32\ati2sgag.exe
2008-11-06 11:37 524,288 a——- c:\windows\system32\DivXsm.exe
2008-11-06 11:37 3,596,288 a——- c:\windows\system32\qt-dx331.dll
2008-11-06 11:37 129,784 ——– c:\windows\system32\pxafs.dll
2008-11-06 11:37 120,056 ——– c:\windows\system32\pxcpyi64.exe
2008-11-06 11:37 118,520 ——– c:\windows\system32\pxinsi64.exe
2008-11-06 11:35 1,044,480 a——- c:\windows\system32\libdivx.dll
2008-11-06 11:35 200,704 a——- c:\windows\system32\ssldivx.dll
2008-11-06 11:33 823,296 a——- c:\windows\system32\divx_xx0c.dll
2008-11-06 11:33 823,296 a——- c:\windows\system32\divx_xx07.dll
2008-11-06 11:33 815,104 a——- c:\windows\system32\divx_xx0a.dll
2008-11-06 11:33 802,816 a——- c:\windows\system32\divx_xx11.dll
2008-11-06 11:33 684,032 a——- c:\windows\system32\DivX.dll
2008-11-06 11:33 12,288 a——- c:\windows\system32\DivXWMPExtType.dll
2008-11-05 11:39 92,326 a——- c:\windows\system32\HKCU_GNU.reg
2008-10-30 09:45 180,720 a——- c:\windows\system32\atiicdxx.dat
============= FINISH: 8:03:30.82 ===============
I've also attached the attach.txt report.
I also did another hijack scan with Advanced System Care. Here is the results of the new scan:
Logfile of Advanced SystemCare 3 Security Analyzer
Scan saved at 8:14:35 AM, on 1/25/2009
Platform: Windows XP (WinNT 5.1)
MSIE: Internet Explorer v7.0 (7.0.5730.13)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aim toolbar\aimtbServer.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: AskBar BHO - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: AskBar BHO - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: AIM Toolbar Loader - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: JQSIEStartDetectorImpl - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} -
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1231204105531
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_11) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…ows-i586-jc.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v57/wof/wof.cab
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O23 - Service: ASKService - Unknown - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: (Ati HotKey Poller) - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: Viewpoint Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Here is my initial post:
I use a program called Advanced System Care 3, It has a feature that does a hijack report. It also promts me that not all the processes are problems or malware. How do I know which ones to choose for the program to fix. The program prompted me to save and post this log to a hijack this forum. My computer runs slow and sometimes the browser closes without warning or asking to send an error report. I also sometimes get a message telling me that my virtual memmory is low and that I have too many processes running. I really didn't think I had a lot of things downloaded on my computer. I have a 2.8 GHz Processor and 512 MB RAM. Are these problems related to any of the processes or are they due to something else. I use Threatfire as my antivirus protection. Also could you please tell me if I need to let Advanced System Care fix any of the below listed processes. I've heard that some of these programs delete important files. It is hard to know which programs to trust. Please help. Thank you for your time. I appreciate it.
Logfile of Advanced SystemCare 3 Security Analyzer
Scan saved at 7:31:09 PM, on 1/1/2009
Platform: Windows XP (WinNT 5.1)
MSIE: Internet Explorer v7.0 (7.0.5730.13)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AcroIEHelperStub - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: AcroIEHelperStub - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AcroIEHelperStub - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: JQSIEStartDetectorImpl - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} -
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_11) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…ows-i586-jc.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O23 - Service: (Ati HotKey Poller) - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Unknown - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
Please note the items listed here are not all problems or malware. They are critical settings of your system and common targets of malware. Before you remove any item, make sure it is malware. The log file of Security Analyzer is 100% compatible with HijackThis log so you can save this report and submit it to any qualified online HijackThis log analyzer and HijackThis forums.
This was the reply:
Hi, and Welcome to WhatTheTech
My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
• I will be working on your Malware issues, this may or may not solve other issues you have with your machine.
• The fixes are specific to your problem and should only be used for the issues on this machine.
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• It's often worth reading through the instructions before starting to follow them to make sure you understand everything you have to do.
• If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
• Please reply to this thread. Do not start a new topic.
Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around. If you still require help, please do the following:
Please download DDS and save it to your desktop.
• Disable any script blocking protection
• Double click dds.scr to run the tool.
• When done, DDS.txt will open.
• Click Yes at the next prompt for Optional Scan.
• Save both reports to your desktop.
—————————————————
• Post the contents of the DDS.txt report in your next reply
• Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.
Thanks.
Here is the DDS report:
DDS (Ver_09-01-19.01) - NTFSx86
Run by [removed] at 8:02:33.39 on Sun 01/25/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.194 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aim toolbar\aimtbServer.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Documents and Settings\Mom\Local Settings\Temporary Internet Files\Content.IE5\KJSGYG36\dds[1].scr
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.mediacomtoday.com/
uURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
mURLSearchHooks: AIM Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: AIM Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
BHO: EWPP - No File
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: AIM Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe"
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [ThreatFire] c:\program files\threatfire\TFTray.exe
mRun: [EPSON Stylus CX4800 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
IE: &AIM Toolbar Search - c:\documents and settings\all users\application data\aim toolbar\ietoolbar\resources\en-us\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {0b83c99c-1efa-4259-858f-bcb33e007a5b} - {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - hxxp://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} - hxxp://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231204105531
DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} - hxxp://www.worldwinner.com/games/shared/wwlaunch.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?AuthParam=1230064253_b5d2401e226813170ebeeff477610c76&GroupName=JSC&BHost=javadl.sun.com&FilePath=/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab&File=jinstall-6u11-windows-i586-jc.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} - hxxp://www.worldwinner.com/games/v57/wof/wof.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2008-12-23 51488]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2008-12-23 39200]
R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2008-12-23 33056]
R4 ASKService;ASKService;c:\program files\askbardis\bar\bin\AskService.exe [2009-1-16 464264]
R4 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-1-16 234888]
R4 ThreatFire;ThreatFire;c:\program files\threatfire\tfservice.exe service –> c:\program files\threatfire\TFService.exe service [?]
R4 Viewpoint Service;Viewpoint Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-1-16 30152]
=============== Created Last 30 ================
2009-01-23 15:47 159,744 a——- c:\windows\system32\lfpng13n.dll
2009-01-22 19:57 –d—– c:\program files\Shockwave.com
2009-01-21 07:07 –d—– c:\program files\MSECache
2009-01-19 07:47 –d—– C:\ConverterOutput
2009-01-19 07:45 395,776 a——- c:\windows\system32\libmplayer.dll
2009-01-19 07:45 262,144 a——- c:\windows\system32\TomsMoComp_ff.dll
2009-01-19 07:45 172,032 a——- c:\windows\system32\ac3filter.ax
2009-01-19 07:45 112,640 a——- c:\windows\system32\libmpeg2_ff.dll
2009-01-19 07:45 –d—– c:\program files\Cucusoft
2009-01-19 00:37 –d—– c:\program files\uTorrent
2009-01-19 00:37 –d—– c:\docume~1\mom\applic~1\uTorrent
2009-01-19 00:14 –d—– c:\program files\Combined Community Codec Pack
2009-01-17 03:17 –d—– c:\program files\Sector 69
2009-01-17 00:07 –d—– c:\program files\MSXML 4.0
2009-01-16 12:13 –d—– c:\docume~1\mom\applic~1\PCF-VLC
2009-01-16 12:02 –d—– c:\docume~1\mom\applic~1\Participatory Culture Foundation
2009-01-16 12:01 –d—– c:\program files\Participatory Culture Foundation
2009-01-16 06:47 –d—– c:\docume~1\alluse~1\applic~1\Azureus
2009-01-16 06:47 –d—– c:\docume~1\mom\applic~1\Azureus
2009-01-16 06:47 –d—– c:\program files\AskBarDis
2009-01-16 06:44 –d—– c:\program files\Vuze
2009-01-16 04:15 87,608 a——- c:\docume~1\mom\applic~1\inst.exe
2009-01-16 04:15 47,360 a——- c:\windows\system32\drivers\pcouffin.sys
2009-01-16 04:15 47,360 a——- c:\docume~1\mom\applic~1\pcouffin.sys
2009-01-16 03:55 –d—– c:\program files\VideoLAN
2009-01-16 03:38 –d—– C:\divx
2009-01-16 03:26 –d—– c:\program files\DivX
2009-01-16 03:19 –d—– c:\program files\Viewpoint
2009-01-16 02:57 –d—– c:\windows\system32\quicktime
2009-01-16 02:37 –d—– c:\program files\common files\Hypnotizer
2009-01-16 02:26 –d—– c:\docume~1\mom\applic~1\AVS4YOU
2009-01-16 02:25 –d—– c:\docume~1\alluse~1\applic~1\AVS4YOU
2009-01-16 02:23 82,944 a——- c:\windows\system32\vct3216.acm
2009-01-16 02:23 38,912 a——- c:\windows\system32\alf2cd.acm
2009-01-16 02:23 13,239 a——- c:\windows\system32\Scg726.acm
2009-01-16 02:23 261,632 a——- c:\windows\system32\mcdvd_32.dll
2009-01-16 02:23 156,910 a——- c:\windows\WMSysPr8.prx
2009-01-16 02:22 –d—– c:\program files\common files\AVSMedia
2009-01-16 02:21 974,848 a——- c:\windows\system32\mfc70.dll
2009-01-16 02:21 1,700,352 a——- c:\windows\system32\GdiPlus.dll
2009-01-16 02:21 –d—– c:\program files\AVS4YOU
2009-01-16 00:20 82,432 a——- c:\windows\system32\msxml4r.dll
2009-01-16 00:20 –d—– c:\program files\Zortam Mp3 Media Studio
2009-01-14 20:32 –d—– c:\program files\common files\Software Update Utility
2009-01-14 20:31 –d—– c:\program files\AIM Toolbar
2009-01-14 20:31 –d—– c:\docume~1\alluse~1\applic~1\AIM Toolbar
2009-01-14 20:31 –d—– c:\docume~1\alluse~1\applic~1\Viewpoint
2009-01-14 20:31 –d—– c:\docume~1\alluse~1\applic~1\acccore
2009-01-14 20:31 –d—– c:\program files\common files\AOL
2009-01-14 20:30 –d—– c:\program files\AIM6
2009-01-14 20:30 432 a—h— C:\IPH.PH
2009-01-11 23:14 462,848 a——- c:\windows\system32\ltkrn13n.dll
2009-01-11 23:14 450,560 a——- c:\windows\system32\ltimg13n.dll
2009-01-11 23:14 401,408 a——- c:\windows\system32\lfcmp13n.dll
2009-01-11 23:14 299,008 a——- c:\windows\system32\ltdis13n.dll
2009-01-11 23:14 206,336 a——- c:\windows\system32\ltefx13n.dll
2009-01-11 23:14 163,840 a——- c:\windows\system32\ltfil13n.dll
2009-01-11 23:14 69,632 a——- c:\windows\system32\lfgif13n.dll
2009-01-11 23:14 57,344 a——- c:\windows\system32\lfbmp13n.dll
2009-01-10 19:01 28,040 a——- c:\windows\system32\mdimon.dll
2009-01-10 19:00 –d—– c:\program files\Microsoft ActiveSync
2009-01-10 18:53 44,032 ——– c:\windows\system32\CTSVCCDA.EXE
2009-01-10 18:53 90,112 ——– c:\windows\Updreg.EXE
2009-01-10 18:53 84,992 ——– c:\windows\system32\SFCVRT32.DLL
2009-01-10 18:53 53,552 ——– c:\windows\CTCCW.DLL
2009-01-10 18:53 40,960 ——– c:\windows\system32\AC3API.DLL
2009-01-10 18:53 24,976 ——– c:\windows\CTRES.DLL
2009-01-10 18:53 231 ——– c:\windows\AC3API.INI
2009-01-10 18:53 82,432 ——– c:\windows\system32\CTWFLT32.DLL
2009-01-10 18:53 54,784 ——– c:\windows\system32\INETWH32.DLL
2009-01-10 18:53 26,768 ——– c:\windows\system32\CTL3D.DLL
2009-01-10 18:53 –d—– c:\windows\system32\Defaults
2009-01-10 18:53 1,048,576 ——– c:\windows\system32\SFMAN.DAT
2009-01-10 18:51 176,128 a——- c:\windows\system32\USBAudio.cpl
2009-01-10 18:51 135,168 a——- c:\windows\system32\USBAudio.crl
2009-01-10 18:51 45,390 a——- c:\windows\system32\usbaudio.chm
2009-01-10 18:51 692 a——- c:\windows\system32\USBAudio.cpl.manifest
2009-01-10 18:49 15,840 a—-r– c:\windows\system32\drivers\Pfmodnt.sys
2009-01-10 18:36 –d—– c:\windows\SxsCaPendDel
2009-01-07 13:02 –d—– c:\windows\system32\XPSViewer
2009-01-07 13:00 14,048 ——– c:\windows\system32\spmsg2.dll
2009-01-07 08:15 0 a——- c:\windows\ativpsrm.bin
2009-01-07 07:32 –d—– C:\ATI
2009-01-05 22:58 27,496 a——- c:\windows\system32\mucltui.dll.mui
2009-01-05 22:58 268,648 a——- c:\windows\system32\mucltui.dll
2009-01-05 16:18 90,112 a——- c:\windows\system32\QuickTimeVR.qtx
2009-01-05 16:18 57,344 a——- c:\windows\system32\QuickTime.qts
2009-01-04 09:49 –d—– c:\docume~1\mom\applic~1\ErrorFix
2009-01-04 03:41 –d—– c:\program files\common files\CA Shared
2008-12-28 15:44 –d—– c:\program files\Cat Daddy Games
2008-12-28 15:31 45,056 a——- c:\windows\system32\wnaspi32.dll
2008-12-28 15:31 25,244 a——- c:\windows\system32\drivers\aspi32.sys
2008-12-28 15:31 5,600 a——- c:\windows\system\winaspi.dll
2008-12-28 15:31 4,672 a——- c:\windows\system\wowpost.exe
2008-12-28 15:31 203,776 a——- c:\windows\system32\clrviddc.dll
2008-12-28 14:58 53,248 a——- c:\windows\system32\CSVer.dll
2008-12-28 14:58 –d—– C:\Intel
2008-12-28 14:07 –d—– c:\program files\Unity
2008-12-28 14:06 –d—– c:\windows\system32\LogFiles
2008-12-28 13:52 –d—– c:\program files\common files\L&H
2008-12-26 22:27 1,182 a——- c:\docume~1\mom\applic~1\wklnhst.dat
2008-12-26 22:15 32,592 a——- c:\windows\system32\msonpmon.dll
2008-12-26 22:00 –d—– c:\docume~1\mom\applic~1\GetRightToGo
2008-12-26 21:57 24 a——- C:\url_history.xml
2008-12-26 21:24 –d—– c:\program files\Windows Media Connect 2
2008-12-26 20:57 –d—– c:\docume~1\mom\applic~1\Software Informer
==================== Find3M ====================
2008-12-23 22:16 499,712 a——- c:\windows\system32\msvcp71.dll
2008-12-23 16:07 77,423 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-12-23 15:30 410,984 a——- c:\windows\system32\deploytk.dll
2008-12-23 13:56 21,640 a——- c:\windows\system32\emptyregdb.dat
2008-12-11 05:57 333,952 a——- c:\windows\system32\drivers\srv.sys
2008-12-10 19:33 200,704 a——- c:\windows\system32\dtu100.dll
2008-12-10 19:33 86,016 a——- c:\windows\system32\dpl100.dll
2008-12-08 21:28 593,920 a——- c:\windows\system32\dpuGUI11.dll
2008-12-08 21:28 344,064 a——- c:\windows\system32\dpus11.dll
2008-12-08 21:28 294,912 a——- c:\windows\system32\dpu11.dll
2008-12-08 21:28 57,344 a——- c:\windows\system32\dpv11.dll
2008-12-05 22:18 348,160 a——- c:\windows\system32\msvcr71.dll
2008-12-01 17:13 3,452,928 a——- c:\windows\system32\drivers\ati2mtag.sys
2008-12-01 15:52 425,984 a——- c:\windows\system32\ATIDEMGX.dll
2008-12-01 15:51 318,464 a——- c:\windows\system32\ati2dvag.dll
2008-12-01 15:46 11,304,960 a——- c:\windows\system32\atioglxx.dll
2008-12-01 15:41 188,416 a——- c:\windows\system32\atipdlxx.dll
2008-12-01 15:40 147,456 a——- c:\windows\system32\Oemdspif.dll
2008-12-01 15:40 26,112 a——- c:\windows\system32\Ati2mdxx.exe
2008-12-01 15:40 43,520 a——- c:\windows\system32\ati2edxx.dll
2008-12-01 15:40 143,360 a——- c:\windows\system32\ati2evxx.dll
2008-12-01 15:38 598,016 a——- c:\windows\system32\ati2evxx.exe
2008-12-01 15:37 53,248 a——- c:\windows\system32\ATIDDC.DLL
2008-12-01 15:27 4,120,384 a——- c:\windows\system32\ati3duag.dll
2008-12-01 15:19 307,200 a——- c:\windows\system32\atiiiexx.dll
2008-12-01 15:11 2,495,360 a——- c:\windows\system32\ativvaxx.dll
2008-12-01 15:11 3,107,788 a——- c:\windows\system32\ativvaxx.dat
2008-12-01 15:11 3,107,788 a——- c:\windows\system32\ativva5x.dat
2008-12-01 15:11 887,724 a——- c:\windows\system32\ativva6x.dat
2008-12-01 14:57 48,640 a——- c:\windows\system32\amdpcom32.dll
2008-12-01 14:53 401,408 a——- c:\windows\system32\atikvmag.dll
2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalrt.dll
2008-12-01 14:53 45,056 a——- c:\windows\system32\amdcalcl.dll
2008-12-01 14:52 86,016 a——- c:\windows\system32\atiadlxx.dll
2008-12-01 14:52 17,408 a——- c:\windows\system32\atitvo32.dll
2008-12-01 14:51 53,248 a——- c:\windows\system32\drivers\ati2erec.dll
2008-12-01 14:50 286,720 a——- c:\windows\system32\atiok3x2.dll
2008-12-01 14:50 3,252,224 a——- c:\windows\system32\Amdcaldd.dll
2008-12-01 14:45 577,536 a——- c:\windows\system32\ati2cqag.dll
2008-12-01 14:35 593,920 ——– c:\windows\system32\ati2sgag.exe
2008-11-06 11:37 524,288 a——- c:\windows\system32\DivXsm.exe
2008-11-06 11:37 3,596,288 a——- c:\windows\system32\qt-dx331.dll
2008-11-06 11:37 129,784 ——– c:\windows\system32\pxafs.dll
2008-11-06 11:37 120,056 ——– c:\windows\system32\pxcpyi64.exe
2008-11-06 11:37 118,520 ——– c:\windows\system32\pxinsi64.exe
2008-11-06 11:35 1,044,480 a——- c:\windows\system32\libdivx.dll
2008-11-06 11:35 200,704 a——- c:\windows\system32\ssldivx.dll
2008-11-06 11:33 823,296 a——- c:\windows\system32\divx_xx0c.dll
2008-11-06 11:33 823,296 a——- c:\windows\system32\divx_xx07.dll
2008-11-06 11:33 815,104 a——- c:\windows\system32\divx_xx0a.dll
2008-11-06 11:33 802,816 a——- c:\windows\system32\divx_xx11.dll
2008-11-06 11:33 684,032 a——- c:\windows\system32\DivX.dll
2008-11-06 11:33 12,288 a——- c:\windows\system32\DivXWMPExtType.dll
2008-11-05 11:39 92,326 a——- c:\windows\system32\HKCU_GNU.reg
2008-10-30 09:45 180,720 a——- c:\windows\system32\atiicdxx.dat
============= FINISH: 8:03:30.82 ===============
I've also attached the attach.txt report.
I also did another hijack scan with Advanced System Care. Here is the results of the new scan:
Logfile of Advanced SystemCare 3 Security Analyzer
Scan saved at 8:14:35 AM, on 1/25/2009
Platform: Windows XP (WinNT 5.1)
MSIE: Internet Explorer v7.0 (7.0.5730.13)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\ThreatFire\TFService.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\aim toolbar\aimtbServer.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: AskBar BHO - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: AskBar BHO - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll
O2 - BHO: AIM Toolbar Loader - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: JQSIEStartDetectorImpl - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} -
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…etup1.0.1.1.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {615F158E-D5CA-422F-A8E7-F6A5EED7063B} (Bejeweled Control) - http://www.worldwinner.com/games/v46/bejeweled/bejeweled.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1231204105531
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_11) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u1…ows-i586-jc.cab
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab
O16 - DPF: {A52FBD2B-7AB3-4F6B-90E3-91C772C5D00F} (WoF Control) - http://www.worldwinner.com/games/v57/wof/wof.cab
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab
O23 - Service: ASKService - Unknown - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: (Ati HotKey Poller) - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: Viewpoint Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe