Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

HijackThis Log

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

HijackThis Log

Unread postby stewy.23 » February 27th, 2008, 5:40 am

I had a backdoor trojan and i got rid of it but i think it may have come back.


Thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:37:37 PM, on 2/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Adam\Desktop\msnmsgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = http://localhost;
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Documents and Settings\Adam\Desktop\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partne ... nicode.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resour ... se4009.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microso ... 9595150156
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/vi ... ebscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... Client.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/a ... _en_dl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b32846.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{46D99EE4-E0D0-49F0-888C-E613F91FE630}: NameServer = 192.168.1.254
O17 - HKLM\System\CS1\Services\Tcpip\..\{46D99EE4-E0D0-49F0-888C-E613F91FE630}: NameServer = 192.168.1.254
O20 - AppInit_DLLs:
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\ISafe.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sansa Updater Service (SansaService) - Unknown owner - C:\Program Files\SanDisk\Sansa Updater\SansaSvr.exe (file missing)
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\eTrust Vet Antivirus\VetMsg.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
O24 - Desktop Component 1: (no name) - file:///C:/My%20Documents/adams/New%20Folder/sara001.jpg
O24 - Desktop Component 2: (no name) - file:///C:/My%20Documents/Photo001.jpg

--
End of file - 8766 bytes
stewy.23
Regular Member
 
Posts: 53
Joined: January 10th, 2008, 8:18 am
Advertisement
Register to Remove

Re: HijackThis Log

Unread postby dan12 » February 27th, 2008, 6:55 pm

Hi, and welcome to malwareremoval forums

I'm dan12, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • REMEMBER, ABSENCE OF SYMPTOMS DOES NOT MEAN THE INFECTION IS ALL GONE.
If you can do these things, everything should go smoothly.
  • Please note you'll need to have Administrator priviledges to perform the fixes. (XP accounts are Administrator by default)
  • Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.
It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

I'm presently looking over your log and hope not to be too long.
Will be back with you as soon as I can.
Thanks dan
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: HijackThis Log

Unread postby dan12 » February 27th, 2008, 7:00 pm

Hi, Stewy.23

Download Combofix from any of the links below, and save it to your desktop. For information regarding this download, please visit this webpage: http://www.bleepingcomputer.com/combofi ... e-combofix

Link 1
Link 2
Link 3


**Note: It is important that it is saved directly to your desktop**

--------------------------------------------------------------------

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
    When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.

Note:
Do not mouseclick combofix's window while it's running. That may cause it to stall


Dan
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: HijackThis Log

Unread postby stewy.23 » February 28th, 2008, 4:29 am

dan12 wrote:Hi, and welcome to malwareremoval forums

I'm dan12, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Perform all actions in the order given.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with it till you're given the all clear.
  • REMEMBER, ABSENCE OF SYMPTOMS DOES NOT MEAN THE INFECTION IS ALL GONE.
If you can do these things, everything should go smoothly.
  • Please note you'll need to have Administrator priviledges to perform the fixes. (XP accounts are Administrator by default)
  • Please let me know if you are using a computer with multiple accounts, as this can affect the instructions given.
It may be helpful to you to print out or take a copy of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

I'm presently looking over your log and hope not to be too long.
Will be back with you as soon as I can.
Thanks dan

Thanks,

I am using a computer with multiple accounts
stewy.23
Regular Member
 
Posts: 53
Joined: January 10th, 2008, 8:18 am

Re: HijackThis Log

Unread postby dan12 » February 28th, 2008, 4:51 am

Thanks for letting me know.
Please continue with Instruction from the admin account. :D
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: HijackThis Log

Unread postby stewy.23 » February 28th, 2008, 5:23 am

ComboFix 08-02-25.3 - Adam 2008-02-28 19:37:46.3 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.144 [GMT 11:00]
Running from: C:\Documents and Settings\Adam\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\MyWay
C:\WINDOWS\smdat32m.sys
C:\WINDOWS\Web\default.htt

.
((((((((((((((((((((((((( Files Created from 2008-01-28 to 2008-02-28 )))))))))))))))))))))))))))))))
.

2008-02-24 16:40 . 2008-02-24 16:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TVU networks
2008-02-23 10:52 . 2008-02-23 10:52 <DIR> d-------- C:\Documents and Settings\Stevo\Application Data\Apple Computer
2008-02-23 08:02 . 2008-02-23 08:02 <DIR> d-------- C:\Documents and Settings\Emmah Stewart\Application Data\LimeWire
2008-02-21 20:32 . 2008-02-21 20:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OnlineArmor
2008-02-21 20:32 . 2008-02-21 20:32 <DIR> d-------- C:\Documents and Settings\Adam\Application Data\OnlineArmor
2008-02-21 20:30 . 2008-02-08 04:36 69,120 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\OADriver.sys
2008-02-21 20:30 . 2008-02-17 02:43 25,088 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\OAmon.sys
2008-02-21 20:30 . 2007-12-26 05:14 22,016 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\oanet.sys
2008-02-16 15:32 . 2008-02-16 15:32 <DIR> d--h----- C:\Program Files\Zero G Registry
2008-02-16 15:32 . 2008-02-16 15:32 <DIR> d-------- C:\Program Files\Britannica 8.0
2008-02-16 15:30 . 2008-02-16 15:30 <DIR> d--h----- C:\Documents and Settings\Adam\InstallAnywhere
2008-02-12 20:51 . 2008-02-12 20:51 <DIR> d-------- C:\Program Files\Tall Emu
2008-02-09 23:20 . 2008-02-09 23:20 <DIR> d-------- C:\Documents and Settings\Emmah Stewart\Application Data\Apple Computer
2008-02-09 22:26 . 2008-02-09 22:26 <DIR> d-------- C:\Program Files\Zone Labs
2008-02-09 22:14 . 2008-02-09 22:14 <DIR> d-------- C:\Documents and Settings\Adam\Application Data\Kerio
2008-02-09 22:07 . 2008-02-09 22:07 <DIR> d-------- C:\Program Files\Kerio
2008-02-07 16:15 . 2008-02-07 16:15 <DIR> d-------- C:\Documents and Settings\Adam\.idlerc
2008-02-05 22:49 . 2008-02-05 22:49 <DIR> d-------- C:\Program Files\Microsoft Synchronization Services
2008-02-05 22:49 . 2008-02-05 22:49 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-02-05 22:49 . 2008-02-05 22:49 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-02-05 22:40 . 2008-02-05 22:41 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-02-05 22:40 . 2008-02-05 22:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-05 22:39 . 2008-02-05 22:39 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-02-05 22:33 . 2008-02-05 22:33 <DIR> d-------- C:\WINDOWS\SYSTEM32\XPSViewer
2008-02-05 22:33 . 2008-02-05 22:33 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-02-05 22:33 . 2008-02-05 22:33 <DIR> d-------- C:\Program Files\MSBuild
2008-02-05 22:30 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\SYSTEM32\spmsg2.dll
2008-02-05 22:17 . 2008-02-05 22:17 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-02-05 20:35 . 2008-02-05 20:35 <DIR> d-------- C:\e09ce048e2e00e4900
2008-02-03 16:46 . 2007-11-26 10:38 238,848 --a------ C:\WINDOWS\UNBOC.EXE
2008-02-03 16:46 . 2007-05-08 17:01 208,896 --a------ C:\WINDOWS\CMDLIC.DLL
2008-02-03 16:46 . 2004-08-04 12:00 22,528 --a------ C:\WINDOWS\SYSTEM32\wsock32.dlb
2008-02-03 14:49 . 2008-02-03 14:49 <DIR> d-------- C:\Program Files\EsetOnlineScanner
2008-01-31 17:44 . 2008-01-31 17:44 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-01-31 15:44 . 2008-01-31 15:44 <DIR> d-------- C:\Documents and Settings\Stevo\Application Data\HP
2008-01-31 12:36 . 2008-01-31 12:36 <DIR> d-------- C:\Program Files\SpywareGuard
2008-01-29 20:53 . 2008-01-29 20:54 <DIR> d-------- C:\Documents and Settings\Stevo\Application Data\vlc
2008-01-29 15:53 . 2008-01-29 15:53 <DIR> d-------- C:\Documents and Settings\Adam\Application Data\Grisoft
2008-01-29 15:53 . 2007-05-30 23:10 10,872 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2008-01-29 15:38 . 2008-01-29 15:38 <DIR> d-------- C:\Program Files\SpywareBlaster

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 11:17 4,851 ----a-w C:\WINDOWS\system32\drivers\kwflower.log
2008-02-09 11:14 2,257 ----a-w C:\WINDOWS\system32\drivers\kwfupper.log
2008-02-05 11:58 173,576 ----a-w C:\Documents and Settings\Steve\Application Data\GDIPFONTCACHEV1.DAT
2008-01-27 00:56 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-01-25 10:20 --------- d-----w C:\Documents and Settings\Emmah Stewart\Application Data\Subversion
2008-01-25 10:18 --------- d-----w C:\Documents and Settings\Emmah Stewart\Application Data\OnlineArmor
2008-01-25 10:18 --------- d-----w C:\Documents and Settings\Emmah Stewart\Application Data\Grisoft
2008-01-24 12:26 --------- d-----w C:\Documents and Settings\Stevo\Application Data\Subversion
2008-01-24 12:23 --------- d-----w C:\Documents and Settings\Stevo\Application Data\OnlineArmor
2008-01-24 12:23 --------- d-----w C:\Documents and Settings\Stevo\Application Data\Grisoft
2008-01-22 02:31 --------- d-----w C:\Documents and Settings\Steve\Application Data\OnlineArmor
2008-01-21 22:13 --------- d-----w C:\Documents and Settings\sera-jane\Application Data\OnlineArmor
2008-01-20 11:37 5,607 ----a-w C:\WINDOWS\~GLH0001.TMP
2008-01-20 11:37 27,136 ----a-w C:\WINDOWS\~GLH0000.TMP
2008-01-20 11:37 155,136 ----a-w C:\WINDOWS\~GLC0000.TMP
2008-01-20 06:30 --------- d-----w C:\Program Files\COMODO
2008-01-18 10:53 --------- d-----w C:\Documents and Settings\Adam\Application Data\vlc
2008-01-15 22:58 65,024 ----a-w C:\WINDOWS\system32\drivers\kvpndrv.sys
2008-01-13 06:54 --------- d-----w C:\Documents and Settings\sera-jane\Application Data\Ahead
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\SYSTEM32\dllcache\pngfilt.dll
2008-01-09 04:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\comodo
2008-01-09 04:20 --------- d-----w C:\Documents and Settings\Adam\Application Data\Comodo
2008-01-08 12:46 --------- d-----w C:\Program Files\TablEdit
2008-01-06 06:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-06 04:08 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-06 04:08 --------- d-----w C:\Program Files\Windows Live
2008-01-06 04:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-06 02:45 --------- d-----w C:\Program Files\SmartFTP Client
2008-01-06 02:44 --------- d-----w C:\Program Files\SmartFTP Client 2.5 Setup Files
2007-12-31 14:09 --------- d-----w C:\Program Files\Windows Defender
2007-12-28 01:30 --------- d-----w C:\Documents and Settings\sera-jane\Application Data\Grisoft
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\SYSTEM32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\SYSTEM32\dllcache\mrxdav.sys
2007-12-12 03:29 516,096 ----a-w C:\WINDOWS\iwexec.exe
2007-12-08 05:21 3,592,192 ------w C:\WINDOWS\SYSTEM32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS\SYSTEM32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS\SYSTEM32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ------w C:\WINDOWS\SYSTEM32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\SYSTEM32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\SYSTEM32\dllcache\oleaut32.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\SYSTEM32\oleaut32.dll
2005-07-24 08:05 1,586 ----a-w C:\Program Files\INSTALL.LOG
2004-12-24 21:03 13,824 ------w C:\WINDOWS\Internet Logs\xDB4264.TMP
2004-12-24 21:02 431,616 ------w C:\WINDOWS\Internet Logs\xDB4240.TMP
2004-12-24 20:58 9,216 ------w C:\WINDOWS\Internet Logs\xDB10D3.TMP
2004-12-24 20:51 11,264 ------w C:\WINDOWS\Internet Logs\xDBA186.TMP
2004-12-24 07:18 431,616 ------w C:\WINDOWS\Internet Logs\xDB271.TMP
2004-12-24 07:18 11,264 ------w C:\WINDOWS\Internet Logs\xDB23B0.TMP
2004-12-24 07:17 431,616 ------w C:\WINDOWS\Internet Logs\xDB2223.TMP
2004-12-24 07:17 11,264 ------w C:\WINDOWS\Internet Logs\xDB2280.TMP
2004-12-24 07:11 431,616 ------w C:\WINDOWS\Internet Logs\xDB10D4.TMP
2004-12-24 07:11 13,312 ------w C:\WINDOWS\Internet Logs\xDB1114.TMP
2004-12-24 07:05 431,616 ------w C:\WINDOWS\Internet Logs\xDBA252.TMP
2004-12-24 07:05 13,312 ------w C:\WINDOWS\Internet Logs\xDBA2A4.TMP
2004-12-24 07:02 13,824 ------w C:\WINDOWS\Internet Logs\xDB4374.TMP
2004-12-24 07:00 431,616 ------w C:\WINDOWS\Internet Logs\xDB4345.TMP
2004-12-24 01:17 431,616 ------w C:\WINDOWS\Internet Logs\xDBB0D1.TMP
2004-12-24 01:17 13,824 ------w C:\WINDOWS\Internet Logs\xDBB131.TMP
2004-12-24 01:12 14,848 ------w C:\WINDOWS\Internet Logs\xDBF1D5.TMP
2004-12-24 01:11 431,616 ------w C:\WINDOWS\Internet Logs\xDBF1A0.TMP
2004-12-23 21:45 431,616 ------w C:\WINDOWS\Internet Logs\xDB90F1.TMP
2004-12-23 21:45 13,312 ------w C:\WINDOWS\Internet Logs\xDB9120.TMP
2004-12-23 21:35 431,616 ------w C:\WINDOWS\Internet Logs\xDB7015.TMP
2004-12-23 21:35 13,824 ------w C:\WINDOWS\Internet Logs\xDBD035.TMP
2004-12-23 21:30 431,616 ------w C:\WINDOWS\Internet Logs\xDB2054.TMP
2004-12-23 21:29 11,264 ------w C:\WINDOWS\Internet Logs\xDB20A0.TMP
2004-12-23 21:26 13,824 ------w C:\WINDOWS\Internet Logs\xDBD2E0.TMP
2004-12-23 21:24 431,616 ------w C:\WINDOWS\Internet Logs\xDBD220.TMP
2004-12-23 21:18 431,616 ------w C:\WINDOWS\Internet Logs\xDB5320.TMP
2004-12-23 21:18 11,264 ------w C:\WINDOWS\Internet Logs\xDB5393.TMP
2004-12-23 06:33 11,264 ------w C:\WINDOWS\Internet Logs\xDB1375.TMP
2004-12-23 06:32 431,616 ------w C:\WINDOWS\Internet Logs\xDB1263.TMP
2004-12-23 06:32 24,064 ------w C:\WINDOWS\Internet Logs\xDB1283.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDBD011.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDBA132.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDB9343.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDB2373.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDB12B0.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDB10B5.TMP
2004-12-22 21:29 431,616 ------w C:\WINDOWS\Internet Logs\xDB1E4.TMP
2004-12-22 21:29 19,456 ------w C:\WINDOWS\Internet Logs\xDB233.TMP
2004-12-22 05:02 20,992 ------w C:\WINDOWS\Internet Logs\xDB32E6.TMP
2004-12-22 05:01 431,616 ------w C:\WINDOWS\Internet Logs\xDB32C3.TMP
2004-12-21 10:17 406,528 ------w C:\WINDOWS\Internet Logs\xDB3195.TMP
2004-12-21 10:17 16,896 ------w C:\WINDOWS\Internet Logs\xDB31B4.TMP
2004-12-21 03:49 22,016 ------w C:\WINDOWS\Internet Logs\xDB4311.TMP
2004-12-21 03:47 406,528 ------w C:\WINDOWS\Internet Logs\xDB42B1.TMP
2004-12-20 18:29 406,528 ------w C:\WINDOWS\Internet Logs\xDB1D2.TMP
2004-12-20 18:29 32,768 ------w C:\WINDOWS\Internet Logs\xDB224.TMP
2004-12-20 04:00 406,528 ------w C:\WINDOWS\Internet Logs\xDB1133.TMP
2004-12-20 04:00 14,336 ------w C:\WINDOWS\Internet Logs\xDB1171.TMP
2004-12-20 02:34 46,592 ------w C:\WINDOWS\Internet Logs\xDB71C5.TMP
2004-12-20 02:31 406,528 ------w C:\WINDOWS\Internet Logs\xDB7183.TMP
2004-12-19 10:28 404,480 ------w C:\WINDOWS\Internet Logs\xDBE2F6.TMP
2004-12-19 10:28 17,920 ------w C:\WINDOWS\Internet Logs\xDBE335.TMP
2004-12-19 07:28 404,480 ------w C:\WINDOWS\Internet Logs\xDBE283.TMP
2004-12-19 07:28 15,872 ------w C:\WINDOWS\Internet Logs\xDBE2A2.TMP
2004-12-19 02:16 404,480 ------w C:\WINDOWS\Internet Logs\xDB40D2.TMP
2004-12-19 02:16 13,824 ------w C:\WINDOWS\Internet Logs\xDB40F1.TMP
2004-12-19 01:36 36,864 ------w C:\WINDOWS\Internet Logs\xDBD190.TMP
1999-07-06 23:00 6 --sh--r C:\WINDOWS\@desktop@.dat
2005-05-13 06:12 217,073 --sha-r C:\WINDOWS\meta4.exe
2005-06-22 04:37 45,568 --sha-r C:\WINDOWS\SYSTEM32\cygz.dll
2004-01-24 13:00 70,656 --sha-r C:\WINDOWS\SYSTEM32\i420vfw.dll
2004-01-24 13:00 70,656 --sha-r C:\WINDOWS\SYSTEM32\yv12vfw.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@={30351346-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@={30351347-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@={30351348-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@={3035134B-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@={3035134C-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@={3035134D-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@={3035134E-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay]
@={7D688A77-C613-11D0-999B-00C04FD655E1}

[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{7D688A77-C613-11D0-999B-00C04FD655E1}]
2007-10-26 14:34 8460288 --a------ C:\WINDOWS\SYSTEM32\SHELL32.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
"msnmsgr"="C:\Documents and Settings\Adam\Desktop\msnmsgr.exe" [2007-10-18 11:34 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CAVRID"="C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe" [2007-05-03 13:16 230928]
"SoundMan"="SOUNDMAN.EXE" [2005-10-04 14:12 90112 C:\WINDOWS\soundman.exe]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-08-28 19:58 177416]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-01-27 16:38 316728]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"OnlineArmor GUI"="C:\Program Files\Tall Emu\Online Armor\oaui.exe" [2008-02-17 02:54 5492800]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 19:48 53760 C:\WINDOWS\SYSTEM32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 11:40:44 282624]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= C:\PROGRA~1\TALLEM~1\ONLINE~1\oaevent.dll [2008-02-17 02:54 660992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^w98Eject.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\w98Eject.exe
backup=C:\WINDOWS\pss\w98Eject.exeCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-06-01 13:32 94208 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-04-12 16:25 220160 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HomeFtp]
C:\Program Files\HomeFtp\HomeFtp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 11:18 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMprocess]
C:\Program Files\IM Names\IM-svr.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-10-30 09:36 256576 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
--a------ 2006-06-22 19:52 190024 C:\Program Files\MessengerPlus! 3\MsgPlus.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-14 03:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 20:50 155648 C:\WINDOWS\system32\\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 16:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2006-06-15 12:36 229376 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\YAHOO!\MESSEN~1\YAHOOM~1.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"Vet Alert"=C:\VET\VETMSG.EXE
"VetTray"=C:\VET\VETTRAY.EXE
"SoundMan"=SOUNDMAN.EXE

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\XLink Kai Evolution VII\\kaiLaunch.exe"=
"C:\\Program Files\\XLink Kai Evolution VII\\kaiEngine.exe"=
"C:\\Documents and Settings\\Adam\\Desktop\\msnmsgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 OADevice;OADriver;C:\WINDOWS\system32\drivers\OADriver.sys [2008-02-08 04:36]
R1 OAmon;OAmon;C:\WINDOWS\system32\drivers\OAmon.sys [2008-02-17 02:43]
R1 OAnet;OAnet;C:\WINDOWS\system32\drivers\OAnet.sys [2007-12-26 05:14]
R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [2006-11-09 14:29]
S2 SvcOnlineArmor;Online Armor;"C:\Program Files\Tall Emu\Online Armor\oasrv.exe" [2008-02-17 02:54]
S3 DIGIRPS;Digi PortServer Driver;C:\WINDOWS\system32\DRIVERS\digirlpt.sys [2001-08-17 12:17]
S3 kvpndev;Kerio VPN adapter;C:\WINDOWS\system32\DRIVERS\kvpndrv.sys [2008-01-16 09:58]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;C:\WINDOWS\system32\DRIVERS\kwflower.sys []
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
S3 WPRO_40_755;WinPcap Packet Driver (WPRO_40_755);C:\WINDOWS\system32\drivers\WPRO_40_755.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e3972666-3ca6-11dc-88d8-000d6112e9d0}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2008-02-06 12:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-07-02 21:35:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-02-28 08:40:52 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-28 19:44:37
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-28 19:45:58
ComboFix-quarantined-files.txt 2008-02-28 08:45:56
.
2008-02-27 06:08:35 --- E O F ---
stewy.23
Regular Member
 
Posts: 53
Joined: January 10th, 2008, 8:18 am

Re: HijackThis Log

Unread postby dan12 » February 28th, 2008, 9:23 am

Can you down load cf again from my link
lets take care of the older version first:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    • Image
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: HijackThis Log

Unread postby dan12 » February 28th, 2008, 7:59 pm

How we doing? :)
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: HijackThis Log

Unread postby stewy.23 » March 1st, 2008, 3:07 am

ComboFix 08-03-01 - Adam 2008-03-01 17:49:44.4 - FAT32x86
Running from: C:\Documents and Settings\Adam\Desktop\ComboFix.exe
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
/wow section - STAGE 43

((((((((((((((((((((((((( Files Created from 2008-02-01 to 2008-03-01 )))))))))))))))))))))))))))))))
.

2008-03-01 17:03 . 2004-08-04 12:00 388,608 --a------ C:\kmd.exe
2008-03-01 08:52 . 2008-03-01 08:52 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-01 08:52 . 2008-03-01 08:52 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-24 16:40 . 2008-02-24 16:40 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TVU networks
2008-02-23 10:52 . 2008-02-23 10:52 <DIR> d-------- C:\Documents and Settings\Stevo\Application Data\Apple Computer
2008-02-23 08:02 . 2008-02-23 08:02 <DIR> d-------- C:\Documents and Settings\Emmah Stewart\Application Data\LimeWire
2008-02-21 20:32 . 2008-02-21 20:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\OnlineArmor
2008-02-21 20:32 . 2008-02-21 20:32 <DIR> d-------- C:\Documents and Settings\Adam\Application Data\OnlineArmor
2008-02-21 20:30 . 2008-02-08 04:36 69,120 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\OADriver.sys
2008-02-21 20:30 . 2008-02-17 02:43 25,088 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\OAmon.sys
2008-02-21 20:30 . 2007-12-26 05:14 22,016 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\oanet.sys
2008-02-16 15:32 . 2008-02-16 15:32 <DIR> d--h----- C:\Program Files\Zero G Registry
2008-02-16 15:32 . 2008-02-16 15:32 <DIR> d-------- C:\Program Files\Britannica 8.0
2008-02-16 15:30 . 2008-02-16 15:30 <DIR> d--h----- C:\Documents and Settings\Adam\InstallAnywhere
2008-02-12 20:51 . 2008-02-12 20:51 <DIR> d-------- C:\Program Files\Tall Emu
2008-02-09 23:20 . 2008-02-09 23:20 <DIR> d-------- C:\Documents and Settings\Emmah Stewart\Application Data\Apple Computer
2008-02-09 22:26 . 2008-02-09 22:26 <DIR> d-------- C:\Program Files\Zone Labs
2008-02-09 22:14 . 2008-02-09 22:14 <DIR> d-------- C:\Documents and Settings\Adam\Application Data\Kerio
2008-02-09 22:07 . 2008-02-09 22:07 <DIR> d-------- C:\Program Files\Kerio
2008-02-07 16:15 . 2008-02-07 16:15 <DIR> d-------- C:\Documents and Settings\Adam\.idlerc
2008-02-05 22:49 . 2008-02-05 22:49 <DIR> d-------- C:\Program Files\Microsoft Synchronization Services
2008-02-05 22:49 . 2008-02-05 22:49 <DIR> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-02-05 22:49 . 2008-02-05 22:49 <DIR> d-------- C:\Program Files\Microsoft Silverlight
2008-02-05 22:40 . 2008-02-05 22:41 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-02-05 22:40 . 2008-02-05 22:41 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-05 22:39 . 2008-02-05 22:39 <DIR> d-------- C:\Program Files\Microsoft SDKs
2008-02-05 22:33 . 2008-02-05 22:33 <DIR> d-------- C:\WINDOWS\SYSTEM32\XPSViewer
2008-02-05 22:33 . 2008-02-05 22:33 <DIR> d-------- C:\Program Files\Reference Assemblies
2008-02-05 22:33 . 2008-02-05 22:33 <DIR> d-------- C:\Program Files\MSBuild
2008-02-05 22:30 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\SYSTEM32\spmsg2.dll
2008-02-05 22:17 . 2008-02-05 22:17 <DIR> d-------- C:\Program Files\MSXML 6.0
2008-02-05 20:35 . 2008-02-05 20:35 <DIR> d-------- C:\e09ce048e2e00e4900
2008-02-03 16:46 . 2007-11-26 10:38 238,848 --a------ C:\WINDOWS\UNBOC.EXE
2008-02-03 16:46 . 2007-05-08 17:01 208,896 --a------ C:\WINDOWS\CMDLIC.DLL
2008-02-03 16:46 . 2004-08-04 12:00 22,528 --a------ C:\WINDOWS\SYSTEM32\wsock32.dlb
2008-02-03 14:49 . 2008-02-03 14:49 <DIR> d-------- C:\Program Files\EsetOnlineScanner

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-09 11:17 4,851 ----a-w C:\WINDOWS\system32\drivers\kwflower.log
2008-02-09 11:14 2,257 ----a-w C:\WINDOWS\system32\drivers\kwfupper.log
2008-02-05 11:58 173,576 ----a-w C:\Documents and Settings\Steve\Application Data\GDIPFONTCACHEV1.DAT
2008-01-31 06:44 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-31 04:44 --------- d-----w C:\Documents and Settings\Stevo\Application Data\HP
2008-01-31 01:36 --------- d-----w C:\Program Files\SpywareGuard
2008-01-29 09:54 --------- d-----w C:\Documents and Settings\Stevo\Application Data\vlc
2008-01-29 04:53 --------- d-----w C:\Documents and Settings\Adam\Application Data\Grisoft
2008-01-29 04:38 --------- d-----w C:\Program Files\SpywareBlaster
2008-01-27 00:56 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-01-25 10:20 --------- d-----w C:\Documents and Settings\Emmah Stewart\Application Data\Subversion
2008-01-25 10:18 --------- d-----w C:\Documents and Settings\Emmah Stewart\Application Data\OnlineArmor
2008-01-25 10:18 --------- d-----w C:\Documents and Settings\Emmah Stewart\Application Data\Grisoft
2008-01-24 12:26 --------- d-----w C:\Documents and Settings\Stevo\Application Data\Subversion
2008-01-24 12:23 --------- d-----w C:\Documents and Settings\Stevo\Application Data\OnlineArmor
2008-01-24 12:23 --------- d-----w C:\Documents and Settings\Stevo\Application Data\Grisoft
2008-01-22 02:31 --------- d-----w C:\Documents and Settings\Steve\Application Data\OnlineArmor
2008-01-21 22:13 --------- d-----w C:\Documents and Settings\sera-jane\Application Data\OnlineArmor
2008-01-20 11:37 5,607 ----a-w C:\WINDOWS\~GLH0001.TMP
2008-01-20 11:37 27,136 ----a-w C:\WINDOWS\~GLH0000.TMP
2008-01-20 11:37 155,136 ----a-w C:\WINDOWS\~GLC0000.TMP
2008-01-20 06:30 --------- d-----w C:\Program Files\COMODO
2008-01-18 10:53 --------- d-----w C:\Documents and Settings\Adam\Application Data\vlc
2008-01-15 22:58 65,024 ----a-w C:\WINDOWS\system32\drivers\kvpndrv.sys
2008-01-13 06:54 --------- d-----w C:\Documents and Settings\sera-jane\Application Data\Ahead
2008-01-11 05:53 44,544 ----a-w C:\WINDOWS\SYSTEM32\dllcache\pngfilt.dll
2008-01-09 04:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\comodo
2008-01-09 04:20 --------- d-----w C:\Documents and Settings\Adam\Application Data\Comodo
2008-01-08 12:46 --------- d-----w C:\Program Files\TablEdit
2008-01-06 06:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-06 04:08 --------- d-sh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-06 04:08 --------- d-----w C:\Program Files\Windows Live
2008-01-06 04:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-06 02:45 --------- d-----w C:\Program Files\SmartFTP Client
2008-01-06 02:44 --------- d-----w C:\Program Files\SmartFTP Client 2.5 Setup Files
2007-12-19 23:01 347,136 ----a-w C:\WINDOWS\SYSTEM32\dllcache\dxtmsft.dll
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\SYSTEM32\dllcache\mrxdav.sys
2007-12-12 03:29 516,096 ----a-w C:\WINDOWS\iwexec.exe
2007-12-08 05:21 3,592,192 ------w C:\WINDOWS\SYSTEM32\dllcache\mshtml.dll
2007-12-06 11:01 625,664 ------w C:\WINDOWS\SYSTEM32\dllcache\iexplore.exe
2007-12-06 11:00 70,656 ------w C:\WINDOWS\SYSTEM32\dllcache\ie4uinit.exe
2007-12-06 11:00 13,824 ------w C:\WINDOWS\SYSTEM32\dllcache\ieudinit.exe
2007-12-06 04:59 161,792 ------w C:\WINDOWS\SYSTEM32\dllcache\ieakui.dll
2007-12-04 18:38 550,912 ----a-w C:\WINDOWS\SYSTEM32\dllcache\oleaut32.dll
2007-12-04 18:38 550,912 ------w C:\WINDOWS\SYSTEM32\oleaut32.dll
2005-07-24 08:05 1,586 ----a-w C:\Program Files\INSTALL.LOG
2004-12-24 21:03 13,824 ------w C:\WINDOWS\Internet Logs\xDB4264.TMP
2004-12-24 21:02 431,616 ------w C:\WINDOWS\Internet Logs\xDB4240.TMP
2004-12-24 20:58 9,216 ------w C:\WINDOWS\Internet Logs\xDB10D3.TMP
2004-12-24 20:51 11,264 ------w C:\WINDOWS\Internet Logs\xDBA186.TMP
2004-12-24 07:18 431,616 ------w C:\WINDOWS\Internet Logs\xDB271.TMP
2004-12-24 07:18 11,264 ------w C:\WINDOWS\Internet Logs\xDB23B0.TMP
2004-12-24 07:17 431,616 ------w C:\WINDOWS\Internet Logs\xDB2223.TMP
2004-12-24 07:17 11,264 ------w C:\WINDOWS\Internet Logs\xDB2280.TMP
2004-12-24 07:11 431,616 ------w C:\WINDOWS\Internet Logs\xDB10D4.TMP
2004-12-24 07:11 13,312 ------w C:\WINDOWS\Internet Logs\xDB1114.TMP
2004-12-24 07:05 431,616 ------w C:\WINDOWS\Internet Logs\xDBA252.TMP
2004-12-24 07:05 13,312 ------w C:\WINDOWS\Internet Logs\xDBA2A4.TMP
2004-12-24 07:02 13,824 ------w C:\WINDOWS\Internet Logs\xDB4374.TMP
2004-12-24 07:00 431,616 ------w C:\WINDOWS\Internet Logs\xDB4345.TMP
2004-12-24 01:17 431,616 ------w C:\WINDOWS\Internet Logs\xDBB0D1.TMP
2004-12-24 01:17 13,824 ------w C:\WINDOWS\Internet Logs\xDBB131.TMP
2004-12-24 01:12 14,848 ------w C:\WINDOWS\Internet Logs\xDBF1D5.TMP
2004-12-24 01:11 431,616 ------w C:\WINDOWS\Internet Logs\xDBF1A0.TMP
2004-12-23 21:45 431,616 ------w C:\WINDOWS\Internet Logs\xDB90F1.TMP
2004-12-23 21:45 13,312 ------w C:\WINDOWS\Internet Logs\xDB9120.TMP
2004-12-23 21:35 431,616 ------w C:\WINDOWS\Internet Logs\xDB7015.TMP
2004-12-23 21:35 13,824 ------w C:\WINDOWS\Internet Logs\xDBD035.TMP
2004-12-23 21:30 431,616 ------w C:\WINDOWS\Internet Logs\xDB2054.TMP
2004-12-23 21:29 11,264 ------w C:\WINDOWS\Internet Logs\xDB20A0.TMP
2004-12-23 21:26 13,824 ------w C:\WINDOWS\Internet Logs\xDBD2E0.TMP
2004-12-23 21:24 431,616 ------w C:\WINDOWS\Internet Logs\xDBD220.TMP
2004-12-23 21:18 431,616 ------w C:\WINDOWS\Internet Logs\xDB5320.TMP
2004-12-23 21:18 11,264 ------w C:\WINDOWS\Internet Logs\xDB5393.TMP
2004-12-23 06:33 11,264 ------w C:\WINDOWS\Internet Logs\xDB1375.TMP
2004-12-23 06:32 431,616 ------w C:\WINDOWS\Internet Logs\xDB1263.TMP
2004-12-23 06:32 24,064 ------w C:\WINDOWS\Internet Logs\xDB1283.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDBD011.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDBA132.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDB9343.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDB2373.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDB12B0.TMP
2004-12-23 06:26 431,616 ------w C:\WINDOWS\Internet Logs\xDB10B5.TMP
2004-12-22 21:29 431,616 ------w C:\WINDOWS\Internet Logs\xDB1E4.TMP
2004-12-22 21:29 19,456 ------w C:\WINDOWS\Internet Logs\xDB233.TMP
2004-12-22 05:02 20,992 ------w C:\WINDOWS\Internet Logs\xDB32E6.TMP
2004-12-22 05:01 431,616 ------w C:\WINDOWS\Internet Logs\xDB32C3.TMP
2004-12-21 10:17 406,528 ------w C:\WINDOWS\Internet Logs\xDB3195.TMP
2004-12-21 10:17 16,896 ------w C:\WINDOWS\Internet Logs\xDB31B4.TMP
2004-12-21 03:49 22,016 ------w C:\WINDOWS\Internet Logs\xDB4311.TMP
2004-12-21 03:47 406,528 ------w C:\WINDOWS\Internet Logs\xDB42B1.TMP
2004-12-20 18:29 406,528 ------w C:\WINDOWS\Internet Logs\xDB1D2.TMP
2004-12-20 18:29 32,768 ------w C:\WINDOWS\Internet Logs\xDB224.TMP
2004-12-20 04:00 406,528 ------w C:\WINDOWS\Internet Logs\xDB1133.TMP
2004-12-20 04:00 14,336 ------w C:\WINDOWS\Internet Logs\xDB1171.TMP
2004-12-20 02:34 46,592 ------w C:\WINDOWS\Internet Logs\xDB71C5.TMP
2004-12-20 02:31 406,528 ------w C:\WINDOWS\Internet Logs\xDB7183.TMP
2004-12-19 10:28 404,480 ------w C:\WINDOWS\Internet Logs\xDBE2F6.TMP
2004-12-19 10:28 17,920 ------w C:\WINDOWS\Internet Logs\xDBE335.TMP
2004-12-19 07:28 404,480 ------w C:\WINDOWS\Internet Logs\xDBE283.TMP
1999-07-06 23:00 6 --sh--r C:\WINDOWS\@desktop@.dat
2005-05-13 06:12 217,073 --sha-r C:\WINDOWS\meta4.exe
2005-06-22 04:37 45,568 --sha-r C:\WINDOWS\SYSTEM32\cygz.dll
2004-01-24 13:00 70,656 --sha-r C:\WINDOWS\SYSTEM32\i420vfw.dll
2004-01-24 13:00 70,656 --sha-r C:\WINDOWS\SYSTEM32\yv12vfw.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@={30351346-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@={30351347-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@={30351348-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@={3035134B-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@={3035134C-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@={3035134D-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@={3035134E-7B7D-4FCC-81B4-1E394CA267EB}

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SlowFile Icon Overlay]
@={7D688A77-C613-11D0-999B-00C04FD655E1}

[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2007-08-26 11:40 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CLASSES_ROOT\CLSID\{7D688A77-C613-11D0-999B-00C04FD655E1}]
2007-10-26 14:34 8460288 --a------ C:\WINDOWS\SYSTEM32\SHELL32.DLL

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 12:00 15360]
"msnmsgr"="C:\Documents and Settings\Adam\Desktop\msnmsgr.exe" [2007-10-18 11:34 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CAVRID"="C:\Program Files\CA\eTrust Vet Antivirus\CAVRID.exe" [2007-05-03 13:16 230928]
"SoundMan"="SOUNDMAN.EXE" [2005-10-04 14:12 90112 C:\WINDOWS\soundman.exe]
"cctray"="C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe" [2007-08-28 19:58 177416]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 19:20 866584]
"WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2008-01-27 16:38 316728]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"OnlineArmor GUI"="C:\Program Files\Tall Emu\Online Armor\oaui.exe" [2008-02-17 02:54 5492800]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2006-10-04 19:48 53760 C:\WINDOWS\SYSTEM32\narrator.exe]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 11:40:44 282624]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= C:\PROGRA~1\TALLEM~1\ONLINE~1\oaevent.dll [2008-02-17 02:54 660992]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^KODAK Software Updater.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\KODAK Software Updater.lnk
backup=C:\WINDOWS\pss\KODAK Software Updater.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^w98Eject.exe]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\w98Eject.exe
backup=C:\WINDOWS\pss\w98Eject.exeCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-06-01 13:32 94208 C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
--a------ 2007-04-12 16:25 220160 C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HomeFtp]
C:\Program Files\HomeFtp\HomeFtp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 11:18 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMprocess]
C:\Program Files\IM Names\IM-svr.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-10-30 09:36 256576 C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
--a------ 2006-06-22 19:52 190024 C:\Program Files\MessengerPlus! 3\MsgPlus.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-14 03:24 1694208 C:\Program Files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
--a------ 2001-07-09 20:50 155648 C:\WINDOWS\system32\\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 16:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
--a------ 2006-06-15 12:36 229376 C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\YAHOO!\MESSEN~1\YAHOOM~1.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"Vet Alert"=C:\VET\VETMSG.EXE
"VetTray"=C:\VET\VETTRAY.EXE
"SoundMan"=SOUNDMAN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\SmartFTP Client\\SmartFTP.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\XLink Kai Evolution VII\\kaiLaunch.exe"=
"C:\\Program Files\\XLink Kai Evolution VII\\kaiEngine.exe"=
"C:\\Documents and Settings\\Adam\\Desktop\\msnmsgr.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=

R1 OADevice;OADriver;C:\WINDOWS\system32\drivers\OADriver.sys [2008-02-08 04:36]
R1 OAmon;OAmon;C:\WINDOWS\system32\drivers\OAmon.sys [2008-02-17 02:43]
R1 OAnet;OAnet;C:\WINDOWS\system32\drivers\OAnet.sys [2007-12-26 05:14]
R2 SVKP;SVKP;C:\WINDOWS\system32\SVKP.sys [2006-11-09 14:29]
S2 SvcOnlineArmor;Online Armor;"C:\Program Files\Tall Emu\Online Armor\oasrv.exe" [2008-02-17 02:54]
S3 DIGIRPS;Digi PortServer Driver;C:\WINDOWS\system32\DRIVERS\digirlpt.sys [2001-08-17 12:17]
S3 kvpndev;Kerio VPN adapter;C:\WINDOWS\system32\DRIVERS\kvpndrv.sys [2008-01-16 09:58]
S3 kwflower;Kerio WinRoute Firewall Driver - Lower Layer;C:\WINDOWS\system32\DRIVERS\kwflower.sys []
S3 PsSdk30;PsSdk30;C:\WINDOWS\system32\Drivers\PsSdk30.drv []
S3 WPRO_40_755;WinPcap Packet Driver (WPRO_40_755);C:\WINDOWS\system32\drivers\WPRO_40_755.sys []

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e3972666-3ca6-11dc-88d8-000d6112e9d0}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a


[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"C:\PROGRA~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
C:\WINDOWS\SYSTEM32\updcrl.exe -e -u C:\WINDOWS\SYSTEM\verisignpub1.crl
.
Contents of the 'Scheduled Tasks' folder
"2008-02-29 22:00:02 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-07-02 21:35:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-01 05:55:26 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-01 17:56:01
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-03-01 17:59:48
ComboFix2.txt 2008-02-28 08:46:00
.
2008-02-27 06:08:35 --- E O F ---
stewy.23
Regular Member
 
Posts: 53
Joined: January 10th, 2008, 8:18 am

Re: HijackThis Log

Unread postby dan12 » March 1st, 2008, 12:28 pm

Hi,stewy.23

  • Open HijackThis.
  • Click on the Open the Misc Tools section button.
  • Look under System tools.
  • Click on the Open Uninstall Manager... button.
  • Click on the Save list... button.
  • It will prompt you to save. Save this log in a convenient location. By default it's named uninstall_list.txt.
  • Notepad will open. Please post this log in your next reply.
  • Please download Malwarebytes' Anti-Malware and save it to a convenient location.
  • Double click on mbam-setup.exe to install it.
  • Before clicking the Finish button, make sure that these 2 boxes are checked (ticked):
      Update Malwarebytes' Anti-Malware
      Launch Malwarebytes' Anti-Malware
  • Malwarebytes' Anti-Malware will now check for updates. If your firewall prompts, please allow it. If you can't update it, select the Update tab. Under Update Mirror, select one of the websites and click on Check for Updates.
  • Select the Scanner tab. Click on Perform full scan, then click on Scan.
  • Leave the default options as it is and click on Start Scan.
  • When done, you will be prompted. Click OK, then click on Show Results.
  • Checked (ticked) all items and click on Remove Selected.
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest.


Please go to Kaspersky website and perform an online antivirus scan. Please use Internet Explorer as it uses ActiveX.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an ActiveX from Kaspersky. Click Yes.
  • When the downloads have finished, click on Next button.
  • Click on Scan Settings button.
  • Select extended under Scan using the following antivirus database:
  • Check (tick) these boxes under Scan options:
    • Scan Archives
    • Scan Mail Bases
  • Click OK
  • Click on My Computer under Please select a target to scan:
  • Once the scan is complete it will display if your system has been infected. Click on Save as text button and save it to your desktop.
  • Copy and paste this log in your next reply.
Please post back makwarebytes log.
uninstall list and the kaspersky scan
dan
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: HijackThis Log

Unread postby stewy.23 » March 2nd, 2008, 1:56 am

Malwarebytes' Anti-Malware 1.05
Database version: 437

Scan type: Full Scan (C:\|)
Objects scanned: 145741
Time elapsed: 43 minute(s), 21 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 18
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{0be385a3-85a5-4722-b677-68dae891ff21} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{272c0d60-0561-4c83-b3db-eb0a71f9d2eb} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{284477e4-a7cb-4055-9e1b-0ea7cba28945} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{70ca4938-6a0f-4641-a9a9-c936e4c1e7de} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7468213e-010e-4ec6-a17d-642e909ba7ec} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{89dc33a2-f86f-42a1-8b5f-d4d1943efc9c} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b86f4810-19a9-4050-9ac9-b5cf60b5799a} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bb5b7e14-f8b4-4365-a24d-f4965c33e1ee} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c13d4627-02f5-4b03-897a-bf6a90022dd2} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{c636f1fc-6ae4-4e6a-90ab-6d61d821a0dd} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cb971ac0-6408-40da-a540-92f9f256f51f} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d5694dfe-43b6-4e05-aa29-8c556c968973} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e2032ec2-a9ac-4ed7-9bdb-ebecacf076f2} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{ebab4a71-8c34-461a-b57d-dd041d439555} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f06fea43-0cc3-4bf6-a85b-5efb1c07aa4b} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fc94a0f7-9c7c-4ae2-9106-5c212332b209} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{2850bdc7-2330-4e31-9fa0-88268846539a} (Adware.WhenUSave) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
stewy.23
Regular Member
 
Posts: 53
Joined: January 10th, 2008, 8:18 am

Re: HijackThis Log

Unread postby dan12 » March 2nd, 2008, 5:48 am

You have the other two logs?
uninstall_list.txt.
Kaspersky log
Thanks dan
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: HijackThis Log

Unread postby stewy.23 » March 5th, 2008, 1:50 am

i tried kaspersky a few times but it takes over 3 hours to scan about 50,000 files it worked for me awhile back but not anymore is there anyother scanner i could use that is close to kaspersky?



Adobe Flash Player 9 ActiveX
Adobe Flash Player ActiveX
Adobe Flash Player Plugin
Adobe Photoshop 7.0
Adobe Reader 8.1.2
Adobe Shockwave Player
Adobe SVG Viewer 3.0
Allok Video to 3GP Converter 2.3.2
Apple Software Update
Audacity 1.2.6
AutoUpdate
AVG Anti-Spyware 7.5
Britannica 2002 Standard Edition
CA Anti-Virus
CCleaner (remove only)
CLEO - Hot Celeb March Jules Screen Saver
C-Media WDM Audio Driver
CompuServe 2000
CuteFTP
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
ESET Online Scanner
e-tax 2007
Express Burn Uninstall
Express Rip Uninstall
FLV Player 1.3.3
Google Desktop Search
Google Toolbar for Internet Explorer
Guitar Pro 5.0
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB929120)
HP Extended Capabilities 6.1
HP Imaging Device Functions 6.1
HP PSC & OfficeJet 6.1.A
HP Solution Center and Imaging Support Tools 6.1
ICQ Toolbar
Interactive Guitar Course
iPod for Windows 2006-03-23
iTunes
Jasc Animation Shop 3
Jasc Paint Shop Pro 9
Kaspersky Online Scanner
Kerio Visual C++ 2005 redistributable permanent package
LimeWire 4.16.6
MailWasher Free
Malwarebytes' Anti-Malware
Messenger Plus! 3
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft .NET Framework 3.0 Service Pack 1
Microsoft .NET Framework 3.5
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft SQL Server Compact 3.5 Design Tools ENU
Microsoft SQL Server Compact 3.5 ENU
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual Basic 2008 Express Edition - ENU
Microsoft Visual C++ 2005 Redistributable
Microsoft Windows SDK for Visual Studio 2008 Express Tools for .NET Framework
Microsoft Windows SDK for Visual Studio 2008 Express Tools for Win32
Mozilla Firefox (2.0.0.12)
MSN Music Assistant
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
Multimedia Keyboard
Nero 7 Premium
Network Play System (Patching)
Nokia Connectivity Cable Driver
Nokia PC Connectivity Solution
Nokia PC Suite
NoteWorthy Composer
Online Armor 2.1
Paint Shop Pro 4.12 Shareware
Power Tab Editor 1.7
Python 2.5.1
QuickTime
RealPlayer
Realtek AC'97 Audio
RTLSetup for Realtek RTL8139/810x Family NIC 3.00
Samsung PC Studio
Samsung PC Studio 3 USB Driver Installer
Samsung USB Driver (MCCI 4.24)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
SmartFTP Client
SmartFTP Client 2.5 Setup Files (remove only)
SmartSound Quicktracks Plugin
SpywareBlaster v3.5.1
Switch Uninstall
TablEdit 2.65
TC Web Conferencing
Texas Calculatem 4 with "AutoRead"
TortoiseSVN 1.4.5.10425 (32 bit)
TVUPlayer 2.3.5.4
Ultimate Reference Suite
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB900930)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB946627)
VGA USB Camera
VideoLAN VLC media player 0.8.6d
WavePad Uninstall
WebFldrs XP
Windows Defender
Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21)
Windows Genuine Advantage Notifications (KB905474)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live installer
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Sign-in Assistant
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinPatrol 2007
WinRAR archiver
XLink Kai Evolution 7
XRay Vision(TM)
Yahoo! Toolbar
Z510 IMEI
stewy.23
Regular Member
 
Posts: 53
Joined: January 10th, 2008, 8:18 am

Re: HijackThis Log

Unread postby dan12 » March 5th, 2008, 4:12 am

P2P Warning!

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

LimeWire 4.16.6

Please note that as long as you are using any form of Peer-to-Peer networking and downloading files from non-documented sources, you can expect infestations of malware to occur
Once upon a time, P2P file sharing was fairly safe. That is no longer true. You may continue to use P2P sharing at your own risk; however, please keep in mind that this practice may be the source of your current malware infestation

I'd like you to read the Guidelines for P2P Programs where we explain why it's not a good idea to have them.

References for the risk of these programs can be found in these links: http://www.microsoft.com/windows/ie/community/columns/protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm

I would recommend that you uninstall LimeWire 4.16.6, however that choice is up to you.
If you wish to keep it, please do not use it until your computer is cleaned.



Run Panda's ActiveScan from here and perform a full system scan.
- Once you are on the Panda site click the "Scan your PC" button
- A new window will open...click the big "Check Now" button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
- Click on "Local Disks" to start the scan
- Save the log file to your desktop

please post the results and a fresh HJT log
dan
User avatar
dan12
MRU Honors Grad Emeritus
 
Posts: 6123
Joined: March 30th, 2006, 3:22 am
Location: Leicestershire

Re: HijackThis Log

Unread postby stewy.23 » March 5th, 2008, 5:33 am

thanks i didn't realize that limewire was even installed.
stewy.23
Regular Member
 
Posts: 53
Joined: January 10th, 2008, 8:18 am
Advertisement
Register to Remove

Next

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 133 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware