This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] HijackThis Log

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my computer kicks me off line randomly for 5-10 seconds. I have a comcast cable modem and use windows home vista. I also have a netgear wireless router and vonage. Sometimes when I leave it on overnight, the next day the task bar is a different color (like blue or purple) and my quick launch buttons are re-arranged. When this happens, my computer locks up and I can't even shut it down without pressing the restart button on the actual CPU shell. I use NOD32 Antivirus and adaware but they haven't stopped it. When I run NOD32 it finds C:\Windows\System32\wdrv\wdrvser.bin and .dat but can't remove it. however it is quarantined. Also, I tried a system restore back to the time before this started but the earliest restore point it offered was 2/2/09. So I did that resore but I doubt that will help.

Below is the logfile from HijackThis. Thank you for your help!


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:03:24 PM, on 2/6/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16764)
Boot mode: Normal

Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\cchservice.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\cc32\webtmr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Users\Kevin Taylor\Program Files\DNA\btdna.exe
C:\Windows\ehome\ehmsas.exe
C:\WINDOWS\tray\wintmr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

https://login.yahoo.com/config/login?.src=f…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?

Ch=Retail&Br=GTW&Loc=ENG_US&Sys=DTP&M=GM5472
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?

Ch=Retail&Br=GTW&Loc=ENG_US&Sys=DTP&M=GM5472
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?

Ch=Retail&Br=GTW&Loc=ENG_US&Sys=DTP&M=GM5472
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =

http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft

Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Cm106Sound] RunDll32 cm106.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ChicoSys] C:\Windows\system32\cc32\webtmr.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Kevin Taylor\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [CCWinTray] C:\Windows\Tray\wintmr.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01

\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12

\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2

\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-

4/MyFunCardsInitialSetup1.0.1.1.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12

\GrooveSystemServices.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Gateway Games\Gateway Game

Console\GameConsoleService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company -

C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe (file

missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Windows-CCHook-Service - Salfeld Computer - C:\Windows\system32\cchservice.exe

–
End of file - 9054 bytes
Hello and Welcome to the forum.

Click: Start > All Programs> Accessories
Open Notepad, click on Format and uncheck Word Wrap.

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

1. These tools MUST be run every time you run them from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator")

==================================================================


Please do not delete anything unless instructed to.



Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

1. These tools MUST be run every time you run them from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator")



Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Right click on ComboFix.exe, Run as Administrator & follow the prompts.

    Note: Combofix will run without adding the Windows Recovery Console

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
LDTate, thank you so much for your help. Here are the combofix and hijackthis log files:

ComboFix log:

ComboFix 09-02-10.01 - Kevin Taylor 2009-02-10 14:42:48.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.3454.1973 [GMT -6:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\swctl.dll

.
((((((((((((((((((((((((( Files Created from 2009-01-10 to 2009-02-10 )))))))))))))))))))))))))))))))
.

2009-02-06 13:59 . 2009-02-06 13:49 15,688 –a—— c:\windows\System32\lsdelete.exe
2009-02-06 13:49 . 2009-02-06 13:49 d—-c— c:\windows\System32\DRVSTORE
2009-02-06 13:49 . 2009-02-06 13:49 64,160 –a—— c:\windows\System32\drivers\Lbd.sys
2009-02-06 13:03 . 2009-02-06 13:03 d——– c:\program files\Trend Micro
2009-02-02 17:29 . 2009-02-02 17:29 d——– c:\programdata\Lavasoft
2009-02-02 17:29 . 2009-02-06 13:49 d–h-c— c:\programdata\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-02-02 17:29 . 2009-02-02 17:29 d——– c:\program files\Lavasoft
2009-01-27 19:35 . 2009-01-27 19:36 d——– c:\users\Kevin Taylor\AppData\Roaming\vlc
2009-01-27 19:18 . 2009-01-27 19:18 d——– c:\program files\VideoLAN
2009-01-27 17:57 . 2009-01-27 17:57 d——– c:\users\Kevin Taylor\AppData\Roaming\DAEMON Tools Pro
2009-01-27 17:57 . 2009-01-27 17:57 d——– c:\users\Kevin Taylor\AppData\Roaming\DAEMON Tools
2009-01-27 17:56 . 2009-01-27 17:56 d——– c:\programdata\DAEMON Tools Lite
2009-01-27 17:56 . 2009-01-27 17:56 d——– c:\program files\DAEMON Tools Lite
2009-01-27 17:53 . 2009-01-27 18:01 d——– c:\users\Kevin Taylor\AppData\Roaming\DAEMON Tools Lite
2009-01-27 17:53 . 2009-01-27 17:53 717,296 –a—— c:\windows\System32\drivers\sptd.sys
2009-01-27 17:40 . 2009-01-27 17:40 d——– c:\program files\Smart Projects
2009-01-26 11:09 . 2008-03-03 14:25 5,702 –ah—– c:\windows\nod32restoretemdono.reg
2009-01-26 11:09 . 2008-03-03 18:21 568 –ah—– c:\windows\nod32fixtemdono.reg
2009-01-26 11:08 . 2009-01-26 11:08 d——– c:\programdata\ESET
2009-01-26 11:08 . 2009-01-26 11:08 d——– c:\program files\ESET
2009-01-24 09:14 . 2009-01-24 09:14 290,304 –a—— c:\windows\System32\drivers\srv.sys
2009-01-21 10:56 . 2009-01-21 10:56 d——– c:\program files\Common Files\xing shared
2009-01-21 10:55 . 2009-01-21 10:55 d——– c:\program files\Real
2009-01-21 10:55 . 2009-01-21 10:56 d——– c:\program files\Common Files\Real
2009-01-19 20:22 . 2009-01-19 20:22 dr——- c:\users\Raustin\Videos
2009-01-19 20:22 . 2009-01-19 20:22 dr——- c:\users\Raustin\Searches
2009-01-19 20:22 . 2009-01-19 20:22 dr——- c:\users\Raustin\Saved Games
2009-01-19 20:22 . 2009-01-19 20:22 dr——- c:\users\Raustin\Pictures
2009-01-19 20:22 . 2009-01-19 20:22 dr——- c:\users\Raustin\Music
2009-01-19 20:22 . 2009-01-19 20:22 dr——- c:\users\Raustin\Links
2009-01-19 20:22 . 2009-01-19 20:22 dr——- c:\users\Raustin\Downloads
2009-01-19 20:22 . 2009-01-19 20:22 dr——- c:\users\Raustin\Documents
2009-01-19 20:22 . 2009-01-19 20:22 dr——- c:\users\Raustin\Contacts
2009-01-19 20:22 . 2006-11-02 06:37 d——– c:\users\Raustin\AppData\Roaming\Media Center Programs
2009-01-19 20:22 . 2009-01-26 10:58 d——– c:\users\Raustin\AppData\Roaming\AVG7
2009-01-19 20:22 . 2009-01-19 20:22 d–h—– c:\users\Raustin\AppData
2009-01-19 20:22 . 2009-02-06 12:50 d——– c:\users\Raustin
2009-01-19 19:40 . 2009-01-19 20:16 d——– c:\windows\tray
2009-01-19 19:40 . 2009-01-19 20:16 d——– c:\windows\System32\wdrv
2009-01-19 19:40 . 2009-01-19 20:16 d——– c:\windows\System32\cc32
2009-01-19 19:40 . 2009-01-19 20:16 d——– c:\programdata\System
2009-01-19 19:40 . 2009-01-19 19:40 d——– c:\program files\Salfeld
2009-01-19 19:40 . 2009-01-19 19:41 d——– c:\program files\Common Files\System Shared
2009-01-19 19:40 . 2006-11-02 02:32 5,235,840 –a—— c:\windows\System32\httpsurl.dat
2009-01-19 19:40 . 2008-12-25 17:47 968,880 –a—— c:\windows\System32\cchservice.exe
2009-01-19 19:40 . 2009-01-12 12:56 358,576 –a—— c:\windows\System32\wdrvhook.dll
2009-01-19 19:40 . 2008-12-25 17:47 321,536 –a—— c:\windows\System32\wdrvtask.dll
2009-01-19 19:40 . 2008-12-25 17:47 301,744 –a—— c:\windows\System32\wdrvprg.dll
2009-01-19 19:40 . 2009-02-10 14:33 10,091 –ah-c— C:\NET.INI
2009-01-19 19:40 . 2006-11-02 02:32 529 –a—— c:\windows\System32\nochook.ini
2009-01-19 19:40 . 2006-11-02 02:32 144 —h—– c:\windows\System32\CTLSW.INI
2009-01-19 19:11 . 2009-01-19 19:11 d——– c:\program files\Speaking Clock Deluxe
2009-01-19 19:11 . 2009-01-19 19:11 41 –a—— c:\windows\Progs_.ini
2009-01-19 15:46 . 2009-01-19 15:46 d——– c:\users\Kevin Taylor\AppData\Roaming\Locktime
2009-01-19 15:45 . 2009-01-19 15:45 d——– c:\programdata\Locktime

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-10 20:41 ——— d—–w c:\users\Kevin Taylor\AppData\Roaming\DNA
2009-02-08 02:39 ——— d—–w c:\users\Kevin Taylor\AppData\Roaming\BitTorrent
2009-02-02 17:58 ——— d—–w c:\users\Kevin Taylor\AppData\Roaming\DVD Flick
2009-01-26 16:58 ——— d—–w c:\users\Kevin Taylor\AppData\Roaming\AVG7
2009-01-26 16:58 ——— d—–w c:\programdata\Avg7
2009-01-24 15:14 ——— d—–w c:\programdata\Microsoft Help
2009-01-24 15:14 ——— d—–w c:\program files\Windows Mail
2009-01-19 17:43 ——— d—–w c:\users\Kevin Taylor\AppData\Roaming\Canon
2009-01-05 19:08 ——— d—–w c:\programdata\Yahoo!
2009-01-05 19:08 ——— d—–w c:\program files\Yahoo!
2008-12-26 18:19 ——— d—–w c:\programdata\NVIDIA
2008-12-26 18:18 174 –sha-w c:\program files\desktop.ini
2008-12-26 00:01 61,440 —-a-w c:\windows\System32\winipsec.dll
2008-12-26 00:01 361,984 —-a-w c:\windows\System32\IPSECSVC.DLL
2008-12-26 00:01 28,672 —-a-w c:\windows\System32\FwRemoteSvr.dll
2008-12-26 00:01 272,896 —-a-w c:\windows\System32\polstore.dll
2008-12-26 00:00 95,232 —-a-w c:\windows\System32\PortableDeviceClassExtension.dll
2008-12-26 00:00 241,152 —-a-w c:\windows\System32\PortableDeviceApi.dll
2008-12-26 00:00 160,768 —-a-w c:\windows\System32\PortableDeviceTypes.dll
2008-12-25 23:58 428,032 —-a-w c:\windows\System32\EncDec.dll
2008-12-25 23:58 297,472 —-a-w c:\windows\System32\gdi32.dll
2008-12-25 23:58 292,352 —-a-w c:\windows\System32\psisdecd.dll
2008-12-25 23:58 1,244,672 —-a-w c:\windows\System32\mcmde.dll
2008-12-25 23:54 268,800 —-a-w c:\windows\System32\es.dll
2008-12-25 23:54 211,456 —-a-w c:\windows\system32\drivers\mrxsmb10.sys
2008-12-25 23:53 537,600 —-a-w c:\windows\AppPatch\AcLayers.dll
2008-12-25 23:53 52,736 —-a-w c:\windows\AppPatch\iebrshim.dll
2008-12-25 23:53 449,536 —-a-w c:\windows\AppPatch\AcSpecfc.dll
2008-12-25 23:53 4,247,552 —-a-w c:\windows\System32\GameUXLegacyGDFs.dll
2008-12-25 23:53 303,616 —-a-w c:\windows\System32\wmpeffects.dll
2008-12-25 23:53 28,672 —-a-w c:\windows\System32\Apphlpdm.dll
2008-12-25 23:53 2,560 —-a-w c:\windows\AppPatch\AcRes.dll
2008-12-25 23:53 2,144,256 —-a-w c:\windows\AppPatch\AcGenral.dll
2008-12-25 23:53 173,056 —-a-w c:\windows\AppPatch\AcXtrnal.dll
2008-12-25 23:53 1,687,040 —-a-w c:\windows\System32\gameux.dll
2008-12-25 23:52 2,048 —-a-w c:\windows\System32\msxml3r.dll
2008-12-25 23:52 2,027,520 —-a-w c:\windows\System32\win32k.sys
2008-12-25 23:52 1,194,496 —-a-w c:\windows\System32\msxml3.dll
2008-12-25 23:49 2,048 —-a-w c:\windows\System32\tzres.dll
2008-12-25 23:47 2,923,520 —-a-w c:\windows\explorer.exe
2008-12-25 23:46 826,368 —-a-w c:\windows\System32\wininet.dll
2008-12-25 23:45 56,320 —-a-w c:\windows\System32\iesetup.dll
2008-12-25 23:45 26,624 —-a-w c:\windows\System32\ieUnatt.exe
2008-12-25 23:43 9,845,248 —-a-w c:\windows\System32\NlsData000a.dll
2008-12-25 23:41 712,192 —-a-w c:\windows\System32\WindowsCodecs.dll
2008-12-25 23:41 425,472 —-a-w c:\windows\System32\PhotoMetadataHandler.dll
2008-12-25 23:41 347,136 —-a-w c:\windows\System32\WindowsCodecsExt.dll
2008-12-25 23:40 441,856 —-a-w c:\windows\System32\win32spl.dll
2008-12-25 23:40 37,376 —-a-w c:\windows\System32\printcom.dll
2008-12-25 23:39 996,352 —-a-w c:\windows\System32\WMNetMgr.dll
2008-12-25 23:39 98,816 —-a-w c:\windows\System32\mfps.dll
2008-12-25 23:39 94,720 —-a-w c:\windows\System32\logagent.exe
2008-12-25 23:39 84,480 —-a-w c:\windows\System32\INETRES.dll
2008-12-25 23:39 737,792 —-a-w c:\windows\System32\inetcomm.dll
2008-12-25 23:39 52,736 —-a-w c:\windows\System32\rrinstaller.exe
2008-12-25 23:39 24,576 —-a-w c:\windows\System32\mfpmp.exe
2008-12-25 23:39 2,855,424 —-a-w c:\windows\System32\mf.dll
2008-12-25 23:39 2,048 —-a-w c:\windows\System32\mferror.dll
2008-12-25 23:39 1,645,568 —-a-w c:\windows\System32\connect.dll
2008-12-25 23:38 3,505,208 —-a-w c:\windows\System32\ntkrnlpa.exe
2008-12-25 23:38 3,470,904 —-a-w c:\windows\System32\ntoskrnl.exe
2008-12-25 23:38 2,048 —-a-w c:\windows\System32\msxml6r.dll
2008-12-25 23:38 1,341,440 —-a-w c:\windows\System32\msxml6.dll
2008-12-25 23:38 ——— d—–w c:\program files\Microsoft Works
2008-12-25 23:17 51,224 —-a-w c:\windows\System32\wuauclt.exe
2008-12-25 23:17 43,544 —-a-w c:\windows\System32\wups2.dll
2008-12-25 23:17 1,809,944 —-a-w c:\windows\System32\wuaueng.dll
2008-12-25 23:17 1,524,736 —-a-w c:\windows\System32\wucltux.dll
2008-12-25 23:16 83,456 —-a-w c:\windows\System32\wudriver.dll
2008-12-25 23:16 561,688 —-a-w c:\windows\System32\wuapi.dll
2008-12-25 23:16 34,328 —-a-w c:\windows\System32\wups.dll
2008-12-25 23:16 31,232 —-a-w c:\windows\System32\wuapp.exe
2008-12-25 23:16 162,064 —-a-w c:\windows\System32\wuwebv.dll
2008-12-25 17:18 ——— d—–w c:\users\Kevin Taylor\AppData\Roaming\Creative
2008-12-25 15:18 ——— d—–w c:\programdata\Creative
2008-12-25 15:14 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-25 15:14 ——— d—–w c:\program files\Creative
2008-12-25 15:13 ——— d—–w c:\program files\Audible
2008-12-25 15:12 ——— d–h–w c:\program files\Creative Installation Information
2008-12-25 15:11 ——— d—–w c:\program files\Common Files\Creative
2008-12-17 19:11 ——— d—–w c:\program files\BitTorrent
2008-12-16 14:30 ——— d—–w c:\users\Kevin Taylor\AppData\Roaming\Snapfish
2008-08-31 15:03 3,080 —-a-w c:\users\Kevin Taylor\CDBIDXL.DAT
2008-08-31 15:03 2,670 —-a-w c:\users\Kevin Taylor\NETRKDB.DAT
2008-08-31 15:03 2,203 —-a-w c:\users\Kevin Taylor\NECDB.DAT
2008-08-31 15:03 2,056 —-a-w c:\users\Kevin Taylor\TDBIDXL.DAT
2008-01-12 03:53 0 —-a-w c:\users\Kevin Taylor\AppData\Roaming\wklnhst.dat
2008-08-05 14:40 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-08-05 14:40 32,768 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-08-05 14:40 16,384 –sha-w c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2008-01-07 09:12 397,312 –sha-w c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.0.6000.16480_none_ef1b6bb652cf8744\WinMail.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-11 1232896]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"BitTorrent DNA"="c:\users\Kevin Taylor\Program Files\DNA\btdna.exe" [2008-12-19 342848]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-11-05 4347120]
"CCWinTray"="c:\windows\Tray\wintmr.exe" [2009-01-12 5459384]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-20 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-20 92704]
"ChicoSys"="c:\windows\system32\cc32\webtmr.exe" [2009-01-12 4988344]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-01-21 185872]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-13 98304]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-06 509784]
"RtHDVCpl"="RtHDVCpl.exe" [2007-01-18 c:\windows\RtHDVCpl.exe]

c:\users\Kevin Taylor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-07 101440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"HideFastUserSwitching"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableClock"= 0 (0x0)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backupExtension=.CommonStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigFix]
–a—— 2006-11-16 17:04 2348584 c:\program files\BigFix\bigfix.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTCheck]
——— 2007-11-06 11:08 397312 c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
–a—-t- 2008-09-02 15:55 133104 c:\users\Kevin Taylor\AppData\Local\Google\Update\GoogleUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
–a—— 2007-03-01 15:57 153136 c:\program files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"PWRISOVM.EXE"=c:\program files\PowerISO\PWRISOVM.EXE
"ShowWnd"=ShowWnd.exe
"ModPS2"=ModPS2Key.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2908862468-2916969662-1638312087-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D56AAFEA-A5F7-4006-A483-E99583051F3A}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{EBA8E64D-61E8-4893-AAA7-9146DBB08AB1}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{F62EDEF3-567F-4112-A68D-8CF4417C5542}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{B76D16F7-29CE-4919-813F-875CDC5D6621}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{D7EACAA8-6950-4F64-930E-9414CA94DF65}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{A57911C4-FFAD-4EDC-9967-101A89E798E9}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"{08DC632C-4481-45B2-A0D1-4C1BB5E7D448}"= UDP:c:\program files\DNA\btdna.exe:DNA
"{5E0EFF34-15A9-4BDD-A275-8BF0F6B186B5}"= TCP:c:\program files\DNA\btdna.exe:DNA
"{0B479A11-BBCF-4538-9ABD-D567293A7B15}"= UDP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{30267E4F-B577-437F-BFF5-510A51D4A305}"= TCP:c:\program files\BitTorrent\bittorrent.exe:BitTorrent
"{950A4B76-8520-4D01-A629-E3484E375070}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{15A33B3F-14E2-4D78-9D8C-50F2C75F89CB}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{3EF3C320-DCD2-42C0-89EA-0DEB28777B40}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{67C0C513-0F6D-4EDA-95E5-4B530CC6DD36}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{50DB4CE1-68A8-4272-BD3D-7A60E8B4134C}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{B05EEDA1-F09F-4B14-93F4-C2B434110136}c:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 7.0.1.321\\english\\setup.exe"= UDP:c:\programdata\kaspersky lab setup files\kaspersky anti-virus 7.0.1.321\english\setup.exe:Kaspersky Anti-Virus 7.0 Setup
"UDP Query User{1EF4A96A-9AA2-4B72-BDDB-1603C477A4AA}c:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 7.0.1.321\\english\\setup.exe"= TCP:c:\programdata\kaspersky lab setup files\kaspersky anti-virus 7.0.1.321\english\setup.exe:Kaspersky Anti-Virus 7.0 Setup
"TCP Query User{12520028-4B2A-4F5C-A198-E782D298210C}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"UDP Query User{EAA00995-F2C9-44CF-8F9A-A16F55B5EE92}c:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:c:\program files\common files\ahead\nero web\setupx.exe:MSI starter
"TCP Query User{5D80A1CF-0A32-40A6-B243-9D5F59454B66}c:\\users\\kevin taylor\\appdata\\local\\temp\\nero web\\setupxu.exe"= UDP:c:\users\kevin taylor\appdata\local\temp\nero web\setupxu.exe:setupxu.exe
"UDP Query User{1115AC11-A09E-4C0A-84E0-C75ECC771CE0}c:\\users\\kevin taylor\\appdata\\local\\temp\\nero web\\setupxu.exe"= TCP:c:\users\kevin taylor\appdata\local\temp\nero web\setupxu.exe:setupxu.exe
"TCP Query User{D5C3BADC-0FFE-49BF-9D15-0C7EB6974763}c:\\program files\\soulseek\\slsk.exe"= UDP:c:\program files\soulseek\slsk.exe:SoulSeek
"UDP Query User{AE9FE731-94BC-4795-AB28-75C430067329}c:\\program files\\soulseek\\slsk.exe"= TCP:c:\program files\soulseek\slsk.exe:SoulSeek
"TCP Query User{EF67766B-39E1-4CFB-AD0D-54064FA878FA}c:\\program files\\nero\\nero 7\\nero showtime\\showtime.exe"= UDP:c:\program files\nero\nero 7\nero showtime\showtime.exe:Nero ShowTime
"UDP Query User{66238164-AC10-4765-9CA3-7742C88A74DD}c:\\program files\\nero\\nero 7\\nero showtime\\showtime.exe"= TCP:c:\program files\nero\nero 7\nero showtime\showtime.exe:Nero ShowTime
"TCP Query User{74FB0CB0-9F8A-4924-8137-4EA24F67435E}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{14C42E51-B318-4921-AAE6-84294319AFCF}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"{3A40BC2D-6915-483E-BD97-6D1C9E44C0B8}"= UDP:c:\program files\PPLive\PPLive.exe:PPLive
"{D242A228-256D-4419-82BA-45E4E17B3A13}"= TCP:c:\program files\PPLive\PPLive.exe:PPLive
"TCP Query User{D8BA0BAB-C702-4917-82CF-4FFA44BFF34F}c:\\program files\\parental control\\parentalcontrol.exe"= UDP:c:\program files\parental control\parentalcontrol.exe:Crawler Parental Control
"UDP Query User{FA40E327-8C52-4DD5-BB8F-21926CEC48A4}c:\\program files\\parental control\\parentalcontrol.exe"= TCP:c:\program files\parental control\parentalcontrol.exe:Crawler Parental Control
"TCP Query User{F7890F92-1185-4343-9186-CFA19DEFD839}c:\\users\\kevin taylor\\program files\\dna\\btdna.exe"= UDP:c:\users\kevin taylor\program files\dna\btdna.exe:btdna.exe
"UDP Query User{D6B02049-E27B-4BB5-B71D-6515342B1F3D}c:\\users\\kevin taylor\\program files\\dna\\btdna.exe"= TCP:c:\users\kevin taylor\program files\dna\btdna.exe:btdna.exe
"{80A7E92B-09DB-4F3C-B173-8B5B8F57646D}"= UDP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{4A40B97F-2150-4A40-A20F-5096F3F7A57B}"= TCP:c:\program files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"= c:\program files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [2009-02-06 64160]
R1 epfwtdir;epfwtdir;c:\windows\System32\drivers\epfwtdir.sys [2008-02-20 33800]
R2 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
R2 Windows-CCHook-Service;Windows-CCHook-Service;c:\windows\System32\cchservice.exe [2009-01-19 968880]
R3 AVer88xHD;AVerMedia 23888 AvStream Video Capture;c:\windows\System32\drivers\AVer88xHD.sys [2007-10-11 401408]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-18 950096]
S2 NOD32FiXTemDono;Eset Nod32 Boot;c:\windows\System32\regedt32.exe [2006-11-02 9216]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\System32\drivers\NETw2v32.sys [2006-11-02 2589184]
S3 USBMULCD;USB Multi-Channel Audio Device Interface;c:\windows\System32\drivers\CM106.sys [2008-12-31 1373696]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2009-01-23 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-04-26 21:51]

2009-02-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-06 13:49]

2009-02-10 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2908862468-2916969662-1638312087-1000.job
- c:\users\Kevin Taylor\AppData\Local\Google\Update\GoogleUpdate.exe [2008-09-02 15:55]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-Cm106Sound - cm106.cpl


.
——- Supplementary Scan ——-
.
uStart Page = https://login.yahoo.com/config/login?.src=f…//www.yahoo.com
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=DTP&M;=GM5472
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-10 14:44:58
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-02-10 14:46:31
ComboFix-quarantined-files.txt 2009-02-10 20:46:29

Pre-Run: 171,244,769,280 bytes free
Post-Run: 171,306,356,736 bytes free

309 — E O F — 2009-01-24 15:14:38





HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:55:01 PM, on 2/10/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16764)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\RtHDVCpl.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Users\Kevin Taylor\Program Files\DNA\btdna.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskeng.exe
C:\Users\Kevin Taylor\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\IEUser.exe
C:\Windows\Explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login?.src=f…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M;=GM5472
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ChicoSys] C:\Windows\system32\cc32\webtmr.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Kevin Taylor\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [CCWinTray] C:\Windows\Tray\wintmr.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - Unknown owner - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Windows-CCHook-Service - Salfeld Computer - C:\Windows\system32\cchservice.exe

–
End of file - 6573 bytes
Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    To be on the safe side, I would also change all my passwords.


    Here's my usual all clean post

    Log looks good :D


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
thanks again for your help. And I adjusted my security settings. I also added spybot search and destroy. I know this is probably how I got the bug in the first place, but now I can't seem to use bittorrent anymore. I used to download with serious quickness. now it shuts down all internet traffic. Is it one of the security settings? Spybot? Any ideas?

thanks again for your help. And I adjusted my security settings. I also added spybot search and destroy.

I know this is probably how I got the bug in the first place, but now I can't seem to use bittorrent anymore. I used to download with serious quickness. now it shuts down all internet traffic. Is it one of the security settings? Spybot? Any ideas?

Try uninstalling Spybot and see what happens.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI