Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Cleaning up a hijack

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Cleaning up a hijack

Unread postby MuckyMouse » January 2nd, 2010, 4:52 pm

I got hit with a nasty "Internet2010" worm that I got some help (mostly - key word!) to remove. I seem to have fixed my Outlook.pst. but the computer is still really slow, doesn't shut down properly, won't go on standby, and Mozilla and Acrobat crashes periodically. I had one LogMeIn set up with permission but there appear to be 2 now, I can't tell the difference between the two. I suspect there are evil files still lurking. I'm still in the elementary learning stages - can someone take a look for me and give me advice on how to proceed?
Thanks!

Ran HiJack scan, here's the log:

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 12:46:49 PM, on 1/2/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
E:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\McAfee\Common Framework\FrameworkService.exe
E:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
E:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
E:\Program Files\Microsoft LifeCam\MSCamSvc.exe
E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Analog Devices\SoundMAX\SMTray.exe
E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
E:\WINDOWS\vVX3000.exe
E:\WINDOWS\system32\igfxtray.exe
E:\WINDOWS\system32\hkcmd.exe
E:\WINDOWS\system32\igfxpers.exe
E:\Program Files\McAfee\Common Framework\UdaterUI.exe
E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
E:\Program Files\LogMeIn\x86\LogMeInSystray.exe
E:\Program Files\McAfee\Common Framework\McTray.exe
E:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
E:\Program Files\LogMeIn\x86\LMIGuardian.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Messenger\msmsgs.exe
E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
E:\Program Files\Windows Desktop Search\WindowsSearch.exe
E:\Program Files\LingvoSoft\LingvoSoft Dictionary 2008\LD_2008.exe
E:\WINDOWS\system32\SearchIndexer.exe
E:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\Program Files\Mozilla Firefox\firefox.exe
E:\WINDOWS\system32\dwwin.exe
E:\WINDOWS\system32\HPZinw12.exe
E:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
E:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe
E:\WINDOWS\system32\SearchProtocolHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - E:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Smapp] E:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [SetRefresh] E:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe
O4 - HKLM\..\Run: [LifeCam] "E:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX3000] E:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [igfxtray] E:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] E:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] E:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ShStatEXE] "E:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "E:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "E:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "E:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: LingvoSoft Dictionary 2008 (English-Lithuanian).lnk = E:\Program Files\LingvoSoft\LingvoSoft Dictionary 2008 (English-Lithuanian) for Windows\LDStub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Windows Search.lnk = E:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://E:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.4.1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7231413546
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - E:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - E:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9eb1d2b97100a) (gupdate1c9eb1d2b97100a) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - E:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - E:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - E:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - E:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 10698 bytes

AND uninstall_list.txt:

Adobe Acrobat 7.0 Professional
Adobe Anchor Service CS4
Adobe Bridge CS4
Adobe CMaps CS4
Adobe Color - Photoshop Specific CS4
Adobe Color EU Extra Settings CS4
Adobe Color JA Extra Settings CS4
Adobe Color NA Recommended Settings CS4
Adobe Color Video Profiles CS CS4
Adobe CSI CS4
Adobe Default Language CS4
Adobe ExtendScript Toolkit CS4
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Fonts All
Adobe Linguistics CS4
Adobe Output Module
Adobe PDF Library Files CS4
Adobe Photoshop CS4
Adobe Photoshop CS4
Adobe Photoshop CS4
Adobe Photoshop CS4 Support
Adobe Photoshop Lightroom 2.3
Adobe Search for Help
Adobe Service Manager Extension
Adobe Setup
Adobe Type Support CS4
Adobe Update Manager CS4
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS4
AdobeColorCommonSetCMYK
AdobeColorCommonSetRGB
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
Broadcom NetXtreme Ethernet Controller
Connect
Critical Update for Windows Media Player 11 (KB959772)
CyberView X - SF v1.18c
Google Earth
Google Update Helper
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Extended Capabilities 4.7
HP Image Zone 4.7
HP Precisionscan Pro 3.1
HP Product Assistant
HP PSC & OfficeJet 4.7
HP SetRefresh
HP Share-to-Web
HP Update
Intel(R) Extreme Graphics 2 Driver
iTunes
kuler
LingvoSoft Dictionary 2008 English<->Lithuanian for Windows
LiveUpdate 3.1 (Symantec Corporation)
LogMeIn
Malwarebytes' Anti-Malware
McAfee VirusScan Enterprise
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft LifeCam
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Ultimate 2007
Microsoft Office Ultimate 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Mozilla Firefox (3.5.6)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 7 Ultra Edition
neroxml
OGA Notifier 2.0.0048.0
PDF Settings CS4
Photoshop Camera Raw
Picasa 3
PowerDesk 7
PowerQuest PartitionMagic Pro 7.0
QuickTime
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB973704)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB973593)
Security Update for Microsoft Office Outlook 2007 (KB972363)
Security Update for Microsoft Office PowerPoint 2007 (KB957789)
Security Update for Microsoft Office Publisher 2007 (KB969693)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB969613)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB969604)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SoundMAX
Suite Shared Configuration CS4
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office InfoPath 2007 (KB976416)
Update for Outlook 2007 Junk Email Filter (kb976884)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB898461)
Update for Windows XP (KB943729)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Windows Driver Package - PIE Image 10/22/2002 1.1.1
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Internet Explorer 7
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Search 4.0
Last edited by MuckyMouse on January 3rd, 2010, 1:48 am, edited 1 time in total.
MuckyMouse
Active Member
 
Posts: 10
Joined: January 2nd, 2010, 4:37 pm
Advertisement
Register to Remove

Re: Cleaning up a hijack

Unread postby MWR 3 day Mod » January 7th, 2010, 1:46 am

Hi,

We are sorry to see your topic is over three days old and no one has yet been able to respond and offer help.

If you still require assistance, please post a link to your topic in our Waiting for help with malware removal? forum, and our staff will make an effort to assist you as promptly as possible. Only post a LINK to this topic, DO NOT post your DDS log!

Please do not reply to this topic.

If you haven't posted within two days in the "Waiting for help with malware removal?" forum, we will assume you have been able to get assistance in other ways and this topic will be closed.
MWR 3 day Mod
MRU Undergrad
MRU Undergrad
 
Posts: 2534
Joined: April 4th, 2008, 8:40 am

Re: Cleaning up a hijack

Unread postby muppy03 » January 9th, 2010, 10:04 pm

Hello and welcome to Malware Removal Forums

IMPORTANT

Whatever repairs we make, are for fixing your computer problems only and by no means should be used on another computer.
To make cleaning this machine easier:-
  • Continue to respond to this thread until I give you the All Clean!
  • Please DO NOT uninstall/install any programs unless asked to. It is more difficult when files/programs appear or disappear from the logs.
  • Please do not run any scans other than those requested and do not post any logs/reports unless specifically requested to do so.
  • Please follow all instructions in the order posted.
  • If you have any questions or do not understand instructions, please ask before continuing.
  • Please reply to this thread. Do not start a new topic.

1. Go to Start-Settings-Control Panel, click on Add remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

    LiveUpdate 3.1 (Symantec Corporation)

2. TFC(Temp File Cleaner):

  • Please download TFC to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.

Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.



3. NEXT Download and Run: RSIT

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)

Please reply with:-
  • RSIT logs ( info.txt and log.txt)
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4798
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Cleaning up a hijack

Unread postby MuckyMouse » January 10th, 2010, 4:04 pm

Thank you for the response. Idon't have time to do this until Monday or maybe Tuesday. please hold the case open for me, OK?
MuckyMouse
Active Member
 
Posts: 10
Joined: January 2nd, 2010, 4:37 pm

Re: Cleaning up a hijack

Unread postby muppy03 » January 10th, 2010, 5:26 pm

Thanks for letting me know. The thread will be left open for 3 days. :)
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4798
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Cleaning up a hijack

Unread postby MuckyMouse » January 13th, 2010, 5:35 pm

OK I'm working on it now, hope the topic's still open. Thanks for the advice, will let you know if it worked.
MuckyMouse
Active Member
 
Posts: 10
Joined: January 2nd, 2010, 4:37 pm

Re: Cleaning up a hijack

Unread postby MuckyMouse » January 13th, 2010, 8:11 pm

Got through th TFC Cleaner process, total success except for one error on a change2.log.
Started to download RSIT, but found all kinds of warnings on Google search page that RSIT.exe is unsafe, actually a Trojan. Huh?????
Awaiting your reply..........
MuckyMouse
Active Member
 
Posts: 10
Joined: January 2nd, 2010, 4:37 pm

Re: Cleaning up a hijack

Unread postby MuckyMouse » January 14th, 2010, 3:19 am

OK, RSIT run - here are the logs:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Venta at 2010-01-13 23:13:30
Microsoft Windows XP Professional Service Pack 3
System drive E: has 7 GB (21%) free of 33 GB
Total RAM: 1527 MB (16% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:13:51 PM, on 1/13/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16945)
Boot mode: Normal

Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
E:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\McAfee\Common Framework\FrameworkService.exe
E:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
E:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
E:\Program Files\Microsoft LifeCam\MSCamSvc.exe
E:\WINDOWS\system32\HPZipm12.exe
E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\Google\Update\1.2.183.13\GoogleCrashHandler.exe
E:\Program Files\Analog Devices\SoundMAX\SMTray.exe
E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
E:\WINDOWS\vVX3000.exe
E:\WINDOWS\system32\igfxtray.exe
E:\WINDOWS\system32\hkcmd.exe
E:\WINDOWS\system32\igfxpers.exe
E:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
E:\Program Files\McAfee\Common Framework\UdaterUI.exe
E:\Program Files\McAfee\Common Framework\McTray.exe
E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
E:\Program Files\LogMeIn\x86\LogMeInSystray.exe
E:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
E:\Program Files\LogMeIn\x86\LMIGuardian.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\WINDOWS\system32\ctfmon.exe
E:\Program Files\Messenger\msmsgs.exe
E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
E:\Program Files\Windows Desktop Search\WindowsSearch.exe
E:\Program Files\LingvoSoft\LingvoSoft Dictionary 2008\LD_2008.exe
E:\WINDOWS\system32\SearchIndexer.exe
E:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\WINDOWS\system32\wuauclt.exe
E:\Program Files\Mozilla Firefox\firefox.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
E:\Program Files\Microsoft Office\Office12\WINWORD.EXE
E:\Program Files\Microsoft Office\Office12\EXCEL.EXE
E:\WINDOWS\system32\SearchProtocolHost.exe
D:\Venta\Downloads\RSIT.exe
E:\Program Files\trend micro\Venta.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - E:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - E:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Smapp] E:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
O4 - HKLM\..\Run: [SetRefresh] E:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe
O4 - HKLM\..\Run: [LifeCam] "E:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX3000] E:\WINDOWS\vVX3000.exe
O4 - HKLM\..\Run: [igfxtray] E:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] E:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] E:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ShStatEXE] "E:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "E:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "E:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "E:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "E:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Dropbox.lnk = E:\Documents and Settings\Venta\Application Data\Dropbox\bin\Dropbox.exe
O4 - Startup: LingvoSoft Dictionary 2008 (English-Lithuanian).lnk = E:\Program Files\LingvoSoft\LingvoSoft Dictionary 2008 (English-Lithuanian) for Windows\LDStub.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Windows Search.lnk = E:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://E:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - E:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/v ... .2.4.1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 7231413546
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - E:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate1c9eb1d2b97100a) (gupdate1c9eb1d2b97100a) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - E:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - E:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - E:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - E:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: NBService - Nero AG - E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - E:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 11209 bytes

======Scheduled tasks folder======

E:\WINDOWS\tasks\AppleSoftwareUpdate.job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
E:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - E:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 63136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - E:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - E:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll [2006-11-30 67136]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
AcroIEToolbarHelper Class - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - E:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-13 41760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - E:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2010-01-13 73728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14 225280]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Smapp"=E:\Program Files\Analog Devices\SoundMAX\SMTray.exe [2003-05-05 143360]
"DrvLsnr"=E:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe [2003-05-08 69632]
"SetRefresh"=E:\Program Files\COMPAQ\SetRefresh\\SetRefresh.exe [2003-11-20 525824]
"LifeCam"=E:\Program Files\Microsoft LifeCam\LifeExp.exe [2006-06-29 269104]
"VX3000"=E:\WINDOWS\vVX3000.exe [2006-06-29 707376]
"igfxtray"=E:\WINDOWS\system32\igfxtray.exe [2005-09-20 94208]
"igfxhkcmd"=E:\WINDOWS\system32\hkcmd.exe [2005-09-20 77824]
"igfxpers"=E:\WINDOWS\system32\igfxpers.exe [2005-09-20 114688]
"NeroFilterCheck"=E:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-09 153136]
"ShStatEXE"=E:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE [2007-02-22 112216]
"McAfeeUpdaterUI"=E:\Program Files\McAfee\Common Framework\UdaterUI.exe [2006-12-19 136768]
"GrooveMonitor"=E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2008-10-25 31072]
"LogMeIn GUI"=E:\Program Files\LogMeIn\x86\LogMeInSystray.exe [2008-07-24 63048]
"AdobeCS4ServiceManager"=E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
"Acrobat Assistant 7.0"=E:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [2004-12-14 483328]
""= []
"HP Software Update"=E:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2007-05-08 54840]
"QuickTime Task"=E:\Program Files\QuickTime\qttask.exe [2009-11-10 417792]
"iTunesHelper"=E:\Program Files\iTunes\iTunesHelper.exe [2009-11-12 141600]
"KernelFaultCheck"=E:\WINDOWS\system32\dumprep 0 -k []
"SunJavaUpdateSched"=E:\Program Files\Java\jre6\bin\jusched.exe [2010-01-13 149280]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=E:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"AdobeBridge"= []
"MSMSGS"=E:\Program Files\Messenger\msmsgs.exe [2008-04-14 1695232]

E:\Documents and Settings\All Users\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
HP Image Zone Fast Start.lnk - E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
Windows Search.lnk - E:\Program Files\Windows Desktop Search\WindowsSearch.exe

E:\Documents and Settings\Venta\Start Menu\Programs\Startup
Dropbox.lnk - E:\Documents and Settings\Venta\Application Data\Dropbox\bin\Dropbox.exe
LingvoSoft Dictionary 2008 (English-Lithuanian).lnk - E:\Program Files\LingvoSoft\LingvoSoft Dictionary 2008 (English-Lithuanian) for Windows\LDStub.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
E:\WINDOWS\system32\igfxdev.dll [2005-09-20 135168]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
E:\WINDOWS\system32\LMIinit.dll [2009-10-01 87352]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
E:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=E:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=E:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-12 2217848]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSetActiveDesktop"=0
"NoActiveDesktopChanges"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoSetActiveDesktop"=
"NoActiveDesktopChanges"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\temp\HP_WebRelease\Setup\HPZnet01.exe"="C:\temp\HP_WebRelease\Setup\HPZnet01.exe:*:Enabled:Install Consumer Experience Network Plug in"
"E:\Program Files\Microsoft LifeCam\LifeCam.exe"="E:\Program Files\Microsoft LifeCam\LifeCam.exe:*:Enabled:LifeCam.exe"
"E:\Program Files\Microsoft LifeCam\LifeExp.exe"="E:\Program Files\Microsoft LifeCam\LifeExp.exe:*:Enabled:LifeExp.exe"
"E:\Program Files\McAfee\Common Framework\FrameworkService.exe"="E:\Program Files\McAfee\Common Framework\FrameworkService.exe:*:Enabled:McAfee Framework Service"
"E:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="E:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"E:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="E:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"E:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="E:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:HP Digital Imaging Monitor"
"E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"E:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="E:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:HP AiO Fax Manager"
"E:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="E:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw"
"E:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="E:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:HP CUE-Scanning Flow Component"
"E:\Program Files\Bonjour\mDNSResponder.exe"="E:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"E:\Documents and Settings\Venta\Local Settings\Temp\7zS54C2\Setup\HPZnet01.exe"="E:\Documents and Settings\Venta\Local Settings\Temp\7zS54C2\Setup\HPZnet01.exe:*:Enabled:Install Consumer Experience Network Plug in"
"E:\Program Files\iTunes\iTunes.exe"="E:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"E:\Documents and Settings\Venta\Local Settings\Temp\7zS0306\Setup\HPZnet01.exe"="E:\Documents and Settings\Venta\Local Settings\Temp\7zS0306\Setup\HPZnet01.exe:*:Enabled:Install Consumer Experience Network Plug in"
"E:\Documents and Settings\Venta\Application Data\Dropbox\bin\Dropbox.exe"="E:\Documents and Settings\Venta\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

======List of files/folders created in the last 1 months======

2010-01-13 23:13:30 ----DC---- E:\rsit
2010-01-13 15:34:45 ----AC---- E:\WINDOWS\system32\javaws.exe
2010-01-13 15:34:45 ----AC---- E:\WINDOWS\system32\javaw.exe
2010-01-13 15:34:45 ----AC---- E:\WINDOWS\system32\deploytk.dll
2010-01-13 15:34:44 ----AC---- E:\WINDOWS\system32\java.exe
2010-01-13 15:34:03 ----DC---- E:\Program Files\Java
2010-01-13 15:30:23 ----DC---- E:\Documents and Settings\Venta\Application Data\Sun
2010-01-09 11:40:13 ----DC---- E:\Documents and Settings\Venta\Application Data\Dropbox
2010-01-01 15:21:17 ----DC---- E:\Program Files\TrendMicro
2009-12-31 18:37:08 ----DC---- E:\Program Files\Trend Micro
2009-12-26 09:49:25 ----DC---- E:\WINDOWS\system32\appmgmt
2009-12-25 12:29:02 ----AC---- E:\WINDOWS\VPC32.INI
2009-12-25 11:57:18 ----ADC---- E:\Documents and Settings\All Users\Application Data\TEMP
2009-12-24 23:10:11 ----HDC---- E:\WINDOWS\PIF
2009-12-24 22:58:04 ----AC---- E:\WINDOWS\system32\capicom.dll
2009-12-24 22:57:16 ----DC---- E:\Documents and Settings\All Users\Application Data\Symantec

======List of files/folders modified in the last 1 months======

2010-01-13 23:13:15 ----DC---- E:\WINDOWS\Prefetch
2010-01-13 17:57:53 ----DC---- E:\WINDOWS\Temp
2010-01-13 17:42:05 ----DC---- E:\WINDOWS\system32
2010-01-13 16:18:00 ----DC---- E:\WINDOWS\system32\wbem
2010-01-13 15:45:50 ----SHD---- E:\System Volume Information
2010-01-13 15:44:39 ----DC---- E:\Documents and Settings\Venta\Application Data\Macromedia
2010-01-13 15:43:08 ----DC---- E:\WINDOWS
2010-01-13 15:41:53 ----DC---- E:\WINDOWS\security
2010-01-13 15:41:53 ----DC---- E:\WINDOWS\Debug
2010-01-13 15:39:26 ----SDC---- E:\Documents and Settings\All Users\Application Data\Microsoft
2010-01-13 15:36:59 ----SHDC---- E:\WINDOWS\Installer
2010-01-13 15:34:55 ----HDC---- E:\Config.Msi
2010-01-13 15:34:03 ----RDC---- E:\Program Files
2010-01-13 14:40:27 ----DC---- E:\Program Files\Common Files
2010-01-13 12:29:43 ----DC---- E:\Program Files\Mozilla Firefox
2010-01-13 09:36:30 ----DC---- E:\WINDOWS\system32\CatRoot2
2010-01-13 00:10:12 ----N---- E:\WINDOWS\SchedLgU.Txt
2010-01-09 07:19:44 ----DC---- E:\QUARANTINE
2009-12-30 23:28:04 ----DC---- E:\Program Files\Malwarebytes' Anti-Malware
2009-12-30 23:26:08 ----DC---- E:\WINDOWS\system32\drivers
2009-12-29 20:02:42 ----DC---- E:\WINDOWS\system32\Restore
2009-12-26 09:27:32 ----DC---- E:\WINDOWS\WinSxS
2009-12-26 07:57:07 ----DC---- E:\Program Files\LogMeIn
2009-12-25 12:33:55 ----RAHC---- E:\WINDOWS\system32\cdplayer.exe.manifest
2009-12-25 11:58:26 ----DC---- E:\Program Files\Common Files\Microsoft Shared
2009-12-24 22:47:37 ----HDC---- E:\WINDOWS\inf
2009-12-23 18:26:20 ----DC---- E:\Documents and Settings
2009-12-22 23:04:59 ----AC---- E:\WINDOWS\system32\SS3600ICE_LOG.TXT
2009-12-22 20:41:08 ----RSHDC---- E:\WINDOWS\system32\dllcache
2009-12-21 08:21:08 ----DC---- E:\Program Files\Google
2009-12-20 22:09:41 ----DC---- E:\WINDOWS\AppPatch
2009-12-15 10:08:52 ----AC---- E:\WINDOWS\system32\PerfStringBackup.INI
2009-12-15 09:22:19 ----DC---- E:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-12-15 09:21:03 ----DC---- E:\WINDOWS\system32\en-US
2009-12-15 09:21:03 ----DC---- E:\Program Files\Internet Explorer
2009-12-15 09:20:53 ----DC---- E:\WINDOWS\ie7updates
2009-12-15 09:20:22 ----RSDC---- E:\WINDOWS\assembly
2009-12-15 09:14:56 ----SDC---- E:\WINDOWS\Tasks

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 intelppm;Intel Processor Driver; E:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 mferkdk;VSCore mferkdk; \??\E:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys []
R1 mfetdik;McAfee Inc.; E:\WINDOWS\system32\drivers\mfetdik.sys [2006-11-30 52136]
R1 PQNTDrv;PQNTDrv; E:\WINDOWS\system32\drivers\PQNTDrv.sys [2001-08-10 3252]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\E:\Program Files\LogMeIn\x86\RaInfo.sys []
R2 LMIRfsDriver;LogMeIn Remote File System Driver; \??\E:\WINDOWS\system32\drivers\LMIRfsDriver.sys []
R3 aeaudio;aeaudio; E:\WINDOWS\system32\drivers\aeaudio.sys [2003-03-13 100224]
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; E:\WINDOWS\system32\DRIVERS\b57xp32.sys [2008-07-25 176640]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; E:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 hidusb;Microsoft HID Class Driver; E:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 ialm;ialm; E:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-09-20 1302332]
R3 lmimirr;lmimirr; E:\WINDOWS\system32\DRIVERS\lmimirr.sys [2008-07-24 10144]
R3 mfeapfk;McAfee Inc.; E:\WINDOWS\system32\drivers\mfeapfk.sys [2006-11-30 64360]
R3 mfeavfk;McAfee Inc.; E:\WINDOWS\system32\drivers\mfeavfk.sys [2006-11-30 72264]
R3 mfebopk;McAfee Inc.; E:\WINDOWS\system32\drivers\mfebopk.sys [2006-11-30 34152]
R3 mfehidk;McAfee Inc.; E:\WINDOWS\system32\drivers\mfehidk.sys [2007-02-22 170408]
R3 mouhid;Mouse HID Driver; E:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 smwdm;smwdm; E:\WINDOWS\system32\drivers\smwdm.sys [2003-05-27 578304]
R3 StillCam;Still Serial Digital Camera Driver; E:\WINDOWS\system32\DRIVERS\serscan.sys [2001-08-17 6784]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; E:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; E:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbscan;USB Scanner Driver; E:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 usbstor;USB Mass Storage Driver; E:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; E:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S1 kbdhid;Keyboard HID Driver; E:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S3 CCDECODE;Closed Caption Decoder; E:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; E:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; E:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248]
S3 NdisIP;Microsoft TV/Video Connection; E:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880]
S3 SLIP;BDA Slip De-Framer; E:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136]
S3 streamip;BDA IPSink; E:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232]
S3 usbaudio;USB Audio Driver (WDM); E:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032]
S3 usbccgp;Microsoft USB Generic Parent Driver; E:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
S3 VX3000;VX-3000; E:\WINDOWS\system32\DRIVERS\VX3000.sys [2006-06-29 1966256]
S3 WSTCODEC;World Standard Teletext Codec; E:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; E:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; E:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 LMIRfsClientNP;LMIRfsClientNP; E:\WINDOWS\system32\drivers\LMIRfsClientNP.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; E:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 Apple Mobile Device;Apple Mobile Device; E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
R2 Bonjour Service;Bonjour Service; E:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 JavaQuickStarterService;Java Quick Starter; E:\Program Files\Java\jre6\bin\jqs.exe [2010-01-13 153376]
R2 McAfeeFramework;McAfee Framework Service; E:\Program Files\McAfee\Common Framework\FrameworkService.exe [2006-12-19 104000]
R2 McShield;McAfee McShield; E:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe [2007-02-22 144960]
R2 McTaskManager;McAfee Task Manager; E:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe [2007-02-22 54872]
R2 MSCamSvc;MSCamSvc; E:\Program Files\Microsoft LifeCam\MSCamSvc.exe [2006-06-29 187184]
R2 Pml Driver HPZ12;Pml Driver HPZ12; E:\WINDOWS\system32\HPZipm12.exe [2007-08-08 73728]
R2 SoundMAX Agent Service (default);SoundMAX Agent Service; E:\Program Files\Analog Devices\SoundMAX\SMAgent.exe [2002-09-20 45056]
R3 iPod Service;iPod Service; E:\Program Files\iPod\bin\iPodService.exe [2009-11-12 545568]
R3 WSearch;Windows Search; E:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
S2 gupdate1c9eb1d2b97100a;Google Update Service (gupdate1c9eb1d2b97100a); E:\Program Files\Google\Update\GoogleUpdate.exe [2009-06-11 133104]
S3 aspnet_state;ASP.NET State Service; E:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; e:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-03-19 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; e:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 gusvc;Google Updater Service; E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-20 136120]
S3 idsvc;Windows CardSpace; e:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; E:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2008-10-25 65888]
S3 NBService;NBService; E:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe [2007-03-14 779824]
S3 NMIndexingService;NMIndexingService; E:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-03-12 271920]
S3 odserv;Microsoft Office Diagnostics Service; E:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; E:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; E:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; E:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 LMIMaint;LogMeIn Maintenance Service; E:\Program Files\LogMeIn\x86\RaMaint.exe [2009-10-01 116032]
S4 LogMeIn;LogMeIn; E:\Program Files\LogMeIn\x86\LogMeIn.exe [2008-07-24 63040]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; e:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

-----------------EOF-----------------
AND...........................

info.txt logfile of random's system information tool 1.06 2010-01-13 23:13:57

======Uninstall list======

-->E:\Program Files\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL
-->E:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
-->E:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
-->E:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->E:\WINDOWS\UNNeroVision.exe /UNINSTALL
-->E:\WINDOWS\UNRecode.exe /UNINSTALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 E:\WINDOWS\INF\PCHealth.inf
Adobe Acrobat 7.0 Professional-->msiexec /I {AC76BA86-1033-0000-7760-100000000002}
Adobe Anchor Service CS4-->MsiExec.exe /I{1618734A-3957-4ADD-8199-F973763109A8}
Adobe Bridge CS4-->MsiExec.exe /I{83877DB1-8B77-45BC-AB43-2BAC22E093E0}
Adobe CMaps CS4-->MsiExec.exe /I{94D398EB-D2FD-4FD1-B8C4-592635E8A191}
Adobe Color - Photoshop Specific CS4-->MsiExec.exe /I{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}
Adobe Color EU Extra Settings CS4-->MsiExec.exe /I{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}
Adobe Color JA Extra Settings CS4-->MsiExec.exe /I{0D6013AB-A0C7-41DC-973C-E93129C9A29F}
Adobe Color NA Recommended Settings CS4-->MsiExec.exe /I{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}
Adobe Color Video Profiles CS CS4-->MsiExec.exe /I{63C24A08-70F3-4C8E-B9FB-9F21A903801D}
Adobe CSI CS4-->MsiExec.exe /I{0F723FC1-7606-4867-866C-CE80AD292DAF}
Adobe Default Language CS4-->MsiExec.exe /I{C52E3EC1-048C-45E1-8D53-10B0C6509683}
Adobe ExtendScript Toolkit CS4-->MsiExec.exe /I{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}
Adobe Flash Player 10 ActiveX-->E:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->E:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Fonts All-->MsiExec.exe /I{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}
Adobe Linguistics CS4-->MsiExec.exe /I{931AB7EA-3656-4BB7-864D-022B09E3DD67}
Adobe Output Module-->MsiExec.exe /I{BB4E33EC-8181-4685-96F7-8554293DEC6A}
Adobe PDF Library Files CS4-->MsiExec.exe /I{F93C84A6-0DC6-42AF-89FA-776F7C377353}
Adobe Photoshop CS4 Support-->MsiExec.exe /I{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}
Adobe Photoshop CS4-->E:\Program Files\Common Files\Adobe\Installers\faf656ef605427ee2f42989c3ad31b8\Setup.exe --uninstall=1
Adobe Photoshop CS4-->MsiExec.exe /I{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}
Adobe Photoshop CS4-->MsiExec.exe /I{E4848436-0345-47E2-B648-8B522FCDA623}
Adobe Photoshop Lightroom 2.3-->MsiExec.exe /I{7CBD8A89-45F4-4203-9923-673F72603747}
Adobe Search for Help-->MsiExec.exe /I{F0E64E2E-3A60-40D8-A55D-92F6831875DA}
Adobe Service Manager Extension-->MsiExec.exe /I{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}
Adobe Setup-->MsiExec.exe /I{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}
Adobe Type Support CS4-->MsiExec.exe /I{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}
Adobe Update Manager CS4-->MsiExec.exe /I{05308C4E-7285-4066-BAE3-6B50DA6ED755}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}
Adobe XMP Panels CS4-->MsiExec.exe /I{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}
AdobeColorCommonSetCMYK-->MsiExec.exe /I{68243FF8-83CA-466B-B2B8-9F99DA5479C4}
AdobeColorCommonSetRGB-->MsiExec.exe /I{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}
Apple Application Support-->MsiExec.exe /I{3FA365DF-2D68-45ED-8F83-8C8A33E65143}
Apple Mobile Device Support-->MsiExec.exe /I{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
Broadcom NetXtreme Ethernet Controller-->MsiExec.exe /X{F870B987-18BC-45FC-9BE8-35C02DCDA10F}
Connect-->MsiExec.exe /I{B29AD377-CC12-490A-A480-1452337C618D}
Critical Update for Windows Media Player 11 (KB959772)-->"E:\WINDOWS\$NtUninstallKB959772_WM11$\spuninst\spuninst.exe"
CyberView X - SF v1.18c-->"E:\Program Files\InstallShield Installation Information\{D8FF6E29-36B4-474F-A88F-973087650C00}\setup.exe" -runfromtemp -l0x0009 -removeonly
Google Earth-->MsiExec.exe /X{C084BC61-E537-11DE-8616-005056806466}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
HijackThis 2.0.2-->"E:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
HiJackThis-->MsiExec.exe /X{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->E:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->E:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hotfix for Windows Media Format 11 SDK (KB929399)-->"E:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
Hotfix for Windows Media Player 11 (KB939683)-->"E:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB915800-v4)-->"E:\WINDOWS\$NtUninstallKB915800-v4$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB952287)-->"E:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB961118)-->"E:\WINDOWS\$NtUninstallKB961118$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB970653-v3)-->"E:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
Hotfix for Windows XP (KB976098-v2)-->"E:\WINDOWS\$NtUninstallKB976098-v2$\spuninst\spuninst.exe"
HP Extended Capabilities 4.7-->E:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
HP Image Zone 4.7-->E:\Program Files\HP\Digital Imaging\uninstall\hpzscr01.exe -datfile hpqscr01.dat
HP Precisionscan Pro 3.1-->MsiExec.exe /I{6B36DEBF-27D0-4B1E-858D-D397091C6C7D}
HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
HP PSC & OfficeJet 4.7-->"E:\Program Files\HP\Digital Imaging\{342C7C88-D335-4bc2-8CF1-281857629CE2}\setup\hpzscr01.exe" -datfile hposcr05.dat
HP SetRefresh-->MsiExec.exe /X{F5242227-2051-4158-AC42-0F2BAA3CD3D6}
HP Share-to-Web-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{748F4870-8350-11D3-B0BF-080009FB4A19}\setup.exe" %MAIN -l9
HP Update-->MsiExec.exe /X{818ABC3C-635C-4651-8183-D0E9640B7DD1}
Intel(R) Extreme Graphics 2 Driver-->RUNDLL32.EXE E:\WINDOWS\system32\ialmrem.dll,UninstallW2KIGfx PCI\VEN_8086&DEV_2572
iTunes-->MsiExec.exe /I{A6FDF86A-F541-4E7B-AEA0-8849A2A700D5}
Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
kuler-->MsiExec.exe /I{098727E1-775A-4450-B573-3F441F1CA243}
LingvoSoft Dictionary 2008 English<->Lithuanian for Windows-->E:\Program Files\LingvoSoft\LingvoSoft Dictionary 2008 (English-Lithuanian) for Windows\Uninstall.exe
LogMeIn-->MsiExec.exe /I{7F831576-6246-42C7-B523-55B3F96509CC}
Malwarebytes' Anti-Malware-->"E:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
McAfee VirusScan Enterprise-->MsiExec.exe /I{35C03C04-3F1F-42C2-A989-A757EE691F65}
Microsoft .NET Framework 1.1 Security Update (KB953297)-->"E:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "E:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M953297\M953297Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->E:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP-->"E:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Internationalized Domain Names Mitigation APIs-->"E:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
Microsoft LifeCam-->MsiExec.exe /X{4DEE75B1-B201-4DA3-A50F-007CDB00DA23}
Microsoft National Language Support Downlevel APIs-->"E:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0044-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00A1-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-00BA-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0114-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Ultimate 2007-->"E:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ULTIMATER /dll OSETUP.DLL
Microsoft Office Ultimate 2007-->MsiExec.exe /X{91120000-002E-0000-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"E:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148-->MsiExec.exe /X{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Mozilla Firefox (3.5.7)-->E:\Program Files\Mozilla Firefox\uninstall\helper.exe
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Nero 7 Ultra Edition-->MsiExec.exe /I{43FFE159-3199-4188-A1CD-629166AD1033}
neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
PDF Settings CS4-->MsiExec.exe /I{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}
Photoshop Camera Raw-->MsiExec.exe /I{CC75AB5C-2110-4A7F-AF52-708680D22FE8}
Picasa 3-->"E:\Program Files\Google\Picasa3\Uninstall.exe"
PowerDesk 7-->MsiExec.exe /X{B93251B5-9209-4DAB-867C-AA98D91584CD}
PowerQuest PartitionMagic Pro 7.0-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{E39C74DF-58FD-4E52-9888-2CC59DFB0B34}\Setup.exe"
QuickTime-->MsiExec.exe /I{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
Security Update for Microsoft Office Outlook 2007 (KB972363)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
Security Update for Microsoft Office Word 2007 (KB969604)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {CF3D6499-709C-43D0-8908-BC5652656050}
Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"E:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"E:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB961260)-->"E:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB963027)-->"E:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB969897)-->"E:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB972260)-->"E:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB974455)-->"E:\WINDOWS\ie7updates\KB974455-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB976325)-->"E:\WINDOWS\ie7updates\KB976325-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB952069)-->"E:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB954155)-->"E:\WINDOWS\$NtUninstallKB954155_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB968816)-->"E:\WINDOWS\$NtUninstallKB968816_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player (KB973540)-->"E:\WINDOWS\$NtUninstallKB973540_WM9$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"E:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"E:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows Search 4 - KB963093-->"E:\WINDOWS\$NtUninstallKB963093$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923561)-->"E:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923689)-->"E:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->E:\WINDOWS\system32\MacroMed\Flash\genuinst.exe E:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464-v2)-->"E:\WINDOWS\$NtUninstallKB938464-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"E:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"E:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"E:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"E:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"E:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"E:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"E:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"E:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"E:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952004)-->"E:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"E:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"E:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954600)-->"E:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"E:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956572)-->"E:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956744)-->"E:\WINDOWS\$NtUninstallKB956744$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956802)-->"E:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"E:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"E:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956844)-->"E:\WINDOWS\$NtUninstallKB956844$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"E:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"E:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958687)-->"E:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958690)-->"E:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958869)-->"E:\WINDOWS\$NtUninstallKB958869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB959426)-->"E:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960225)-->"E:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960715)-->"E:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960803)-->"E:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB960859)-->"E:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961371)-->"E:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961373)-->"E:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
Security Update for Windows XP (KB961501)-->"E:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
Security Update for Windows XP (KB968537)-->"E:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969059)-->"E:\WINDOWS\$NtUninstallKB969059$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969898)-->"E:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
Security Update for Windows XP (KB969947)-->"E:\WINDOWS\$NtUninstallKB969947$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970238)-->"E:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
Security Update for Windows XP (KB970430)-->"E:\WINDOWS\$NtUninstallKB970430$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971486)-->"E:\WINDOWS\$NtUninstallKB971486$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971557)-->"E:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971633)-->"E:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971657)-->"E:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
Security Update for Windows XP (KB971961)-->"E:\WINDOWS\$NtUninstallKB971961$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973346)-->"E:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973354)-->"E:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973507)-->"E:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973525)-->"E:\WINDOWS\$NtUninstallKB973525$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973869)-->"E:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
Security Update for Windows XP (KB973904)-->"E:\WINDOWS\$NtUninstallKB973904$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974112)-->"E:\WINDOWS\$NtUninstallKB974112$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974318)-->"E:\WINDOWS\$NtUninstallKB974318$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974392)-->"E:\WINDOWS\$NtUninstallKB974392$\spuninst\spuninst.exe"
Security Update for Windows XP (KB974571)-->"E:\WINDOWS\$NtUninstallKB974571$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975025)-->"E:\WINDOWS\$NtUninstallKB975025$\spuninst\spuninst.exe"
Security Update for Windows XP (KB975467)-->"E:\WINDOWS\$NtUninstallKB975467$\spuninst\spuninst.exe"
SoundMAX-->RunDll32 E:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "E:\Program Files\InstallShield Installation Information\{F0A37341-D692-11D4-A984-009027EC0A9C}\Setup.exe"
Suite Shared Configuration CS4-->MsiExec.exe /I{842B4B72-9E8F-4962-B3C1-1C422A5C4434}
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->E:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Microsoft Office InfoPath 2007 (KB976416)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {432C5EE4-8096-4FF1-95E1-65219365DFF7}
Update for Outlook 2007 Junk Email Filter (kb976884)-->msiexec /package {91120000-002E-0000-0000-0000000FF1CE} /uninstall {FB60F280-C70F-4174-BADB-471412AA42F0}
Update for Windows Internet Explorer 7 (KB976749)-->"E:\WINDOWS\ie7updates\KB976749-IE7\spuninst\spuninst.exe"
Update for Windows XP (KB898461)-->"E:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
Update for Windows XP (KB943729)-->"E:\WINDOWS\$NtUninstallKB943729$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"E:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Update for Windows XP (KB955759)-->"E:\WINDOWS\$NtUninstallKB955759$\spuninst\spuninst.exe"
Update for Windows XP (KB955839)-->"E:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
Update for Windows XP (KB967715)-->"E:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
Update for Windows XP (KB968389)-->"E:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
Update for Windows XP (KB971737)-->"E:\WINDOWS\$NtUninstallKB971737$\spuninst\spuninst.exe"
Update for Windows XP (KB973687)-->"E:\WINDOWS\$NtUninstallKB973687$\spuninst\spuninst.exe"
Update for Windows XP (KB973815)-->"E:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
Windows Driver Package - PIE Image 10/22/2002 1.1.1-->E:\WINDOWS\system32\DRVSTORE\Pf1800lc_3d4d1e7469145e230b6f1f02e521cadf1bed999e\DpInst.exe /u Pf1800lc_3d4d1e7469145e230b6f1f02e521cadf1bed999e
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray-->"E:\WINDOWS\$NtUninstallKB952011$\spuninst\spuninst.exe"
Windows Internet Explorer 7-->"E:\WINDOWS\ie7\spuninst\spuninst.exe"
Windows Media Format 11 runtime-->"E:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"E:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"E:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"E:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Search 4.0-->"E:\WINDOWS\$NtUninstallKB940157$\spuninst\spuninst.exe"

======Hosts File======

192.168.1.68 HP0018715D4276
127.0.0.1 activate.adobe.com

======Security center information======

AV: McAfee VirusScan Enterprise

======System event log======

Computer Name: DUCHESS
Event Code: 19
Message: Sharing printer failed + 1722, Printer Microsoft XPS Document Writer share name Printer2.

Record Number: 51458
Source Name: Print
Time Written: 20100113093515.000000-480
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: DUCHESS
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 51452
Source Name: W32Time
Time Written: 20100112222018.000000-480
Event Type: warning
User:

Computer Name: DUCHESS
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 50705
Source Name: W32Time
Time Written: 20100109041722.000000-480
Event Type: warning
User:

Computer Name: DUCHESS
Event Code: 19
Message: Sharing printer failed + 1722, Printer Microsoft XPS Document Writer share name Printer2.

Record Number: 49332
Source Name: Print
Time Written: 20100107091149.000000-480
Event Type: error
User: NT AUTHORITY\SYSTEM

Computer Name: DUCHESS
Event Code: 36
Message: The time service has not been able to synchronize the system time
for 49152 seconds because none of the time providers has been able to
provide a usable time stamp. The system clock is unsynchronized.

Record Number: 48995
Source Name: W32Time
Time Written: 20100105011914.000000-480
Event Type: warning
User:

=====Application event log=====

Computer Name: DUCHESS
Event Code: 36
Message: Outlook Search has encountered an error and is temporarily disabling indexing for store E:\Documents and Settings\Venta\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst (error=0x80040805).

Record Number: 57
Source Name: Outlook
Time Written: 20091225142516.000000-480
Event Type: warning
User:

Computer Name: DUCHESS
Event Code: 1000
Message: Faulting application outlook.exe, version 12.0.6514.5000, stamp 4a89dc70, faulting module unknown, version 0.0.0.0, stamp 00000000, debug? 0, fault address 0x07a19b92.

Record Number: 56
Source Name: Microsoft Office 12
Time Written: 20091225142412.000000-480
Event Type: error
User:

Computer Name: DUCHESS
Event Code: 1000
Message: Faulting application rundll32.exe, version 5.1.2600.5512, faulting module , version 0.0.0.0, fault address 0x00000000.

Record Number: 53
Source Name: Application Error
Time Written: 20091225133331.000000-480
Event Type: error
User:

Computer Name: DUCHESS
Event Code: 1517
Message: Windows saved user DUCHESS\Venta registry while an application or service was still using the registry during log off. The memory used by the user's registry has not been freed. The registry will be unloaded when it is no longer in use.


This is often caused by services running as a user account, try configuring the services to run in either the LocalService or NetworkService account.

Record Number: 32
Source Name: Userenv
Time Written: 20091225131546.000000-480
Event Type: warning
User: NT AUTHORITY\SYSTEM

Computer Name: DUCHESS
Event Code: 1524
Message: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use.



Record Number: 31
Source Name: Userenv
Time Written: 20091225131544.000000-480
Event Type: warning
User: DUCHESS\Venta

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;E:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 3 Stepping 4, GenuineIntel
"PROCESSOR_REVISION"=0304
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"VSEDEFLOGDIR"=E:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
"DEFLOGDIR"=E:\Documents and Settings\All Users\Application Data\McAfee\DesktopProtection
"CLASSPATH"=.;E:\Program Files\QuickTime\QTSystem\QTJava.zip
"QTJAVA"=E:\Program Files\QuickTime\QTSystem\QTJava.zip

-----------------EOF-----------------
MuckyMouse
Active Member
 
Posts: 10
Joined: January 2nd, 2010, 4:37 pm

Re: Cleaning up a hijack

Unread postby muppy03 » January 14th, 2010, 6:10 am

Please update me on problems you are still having after doing the following.

This next step is your choice. The below items I am getting you to fix with HJT are for programs that do not need to start up when you turn your computer on. Doing the below step WILL NOT UNINSTALL these programs ONLY stop them from running at startup. All will be available when you need them. The bonus is it will make your startup time a bit shorter

Open Hijack This and select Do a System Scan Only place a check next to the below lines if still present

    O4 - HKLM\..\Run: [Smapp] E:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    O4 - HKLM\..\Run: [igfxtray] E:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxpers] E:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] E:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [GrooveMonitor] "E:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "E:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "E:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe


Once selected close all windows except HJT an click on Fix Checked

I see by your Uninstall List that you have Malwarebytes' Anti-Malware installed on your computer.

Please do a Malwarebytes' Anti-Malware scan using these settings:
    • Open Malwarebytes' Anti-Malware
    • Select the Update tab
    • Click Check for Updates
    • After the update have been completed, Select the Scanner tab.
    • Make sure the "Perform full scan" option is selected.
    • Then click on the Scan button.
    • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button
    • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
    • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
    • Click OK to close the message box and continue with the removal process.

Back at the main Scanner screen:

    • Click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • The log can also be found here:

    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

    Copy and paste the contents of that report in your next reply and exit MBAM.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Please reply with:-
  • MBAM log
  • New HJT log
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4798
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Cleaning up a hijack

Unread postby MuckyMouse » January 14th, 2010, 6:05 pm

Malwarebytes won't run. It starts but then crashes my PC, and I get a "Blue Screen Error caused by device or driver" report. I uninstalled Malwarebytes, but thought I should check in here before re-installing, to make sure I do it right. Sounds like I still have a smart virus lurking.. (????)
MuckyMouse
Active Member
 
Posts: 10
Joined: January 2nd, 2010, 4:37 pm

Re: Cleaning up a hijack

Unread postby muppy03 » January 15th, 2010, 8:02 am

Run TDSSKiller first the re-install MBAM using the below link and instructions.

TDSSKiller

  • Please Download TDSSKiller.zip and save it on your desktop.
  • Next extract (unzip) its contents to your Desktop.
  • Next double-click the TDSSKiller Folder on your desktop.
  • Next right-click on TDSSKiller.exe and click Copy then Paste it directly on to your Desktop.
  • Next Highlight and copy the text in the codebox below.
    Code: Select all
    "%userprofile%\Desktop\TDSSKiller.exe" -v
  • Click Start, click Run... and paste the text above into the Open: line and click OK.
  • If malicious services or files have been detected, the utility will prompt to reboot the PC in order to complete the disinfection procedure. Please reboot when prompted.
  • After reboot, the driver will delete malicious registry keys and files as well as remove itself from the services list.
  • a log file should be created on your C: drive named something like TDSSKiller 2.1.1 Dec 20 2009 02:40:02
  • To find the log click Start then Computer then Vista ( C:).
  • Please post the contents of that log in your next reply.


Please download Malwarebytes' Anti-Malware and save to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to:

    Update Malwarebytes' Anti-Malware
    Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply

    Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.

Please reply with:-
  • TDSS Killer log
  • MBAM log
  • New HJT log
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4798
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Cleaning up a hijack

Unread postby MuckyMouse » January 15th, 2010, 4:30 pm

Hi, here's the first log, reinstalling Malwarebytes & will follow up with that log:

12:01:27:328 1264 TDSS rootkit removing tool 2.2.2 Jan 13 2010 08:42:25
12:01:27:328 1264 ================================================================================
12:01:27:328 1264 SystemInfo:

12:01:27:328 1264 OS Version: 5.1.2600 ServicePack: 3.0
12:01:27:328 1264 Product type: Workstation
12:01:27:328 1264 ComputerName: DUCHESS
12:01:27:328 1264 UserName: Venta
12:01:27:328 1264 Windows directory: E:\WINDOWS
12:01:27:328 1264 Processor architecture: Intel x86
12:01:27:328 1264 Number of processors: 1
12:01:27:328 1264 Page size: 0x1000
12:01:27:328 1264 Boot type: Normal boot
12:01:27:328 1264 ================================================================================
12:01:27:343 1264 UnloadDriverW: NtUnloadDriver error 2
12:01:27:343 1264 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
12:01:27:343 1264 MyNtCreateFileW: NtCreateFile(\??\E:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
12:01:27:437 1264 UtilityInit: KLMD drop and load success
12:01:27:437 1264 KLMD_OpenDevice: Trying to open KLMD Device(KLMD201000)
12:01:27:437 1264 UtilityInit: KLMD open success
12:01:27:437 1264 UtilityInit: Initialize success
12:01:27:437 1264
12:01:27:437 1264 Scanning Services ...
12:01:27:437 1264 CreateRegParser: Registry parser init started
12:01:27:437 1264 DisableWow64Redirection: GetProcAddress(Wow64DisableWow64FsRedirection) error 127
12:01:27:437 1264 CreateRegParser: DisableWow64Redirection error
12:01:27:437 1264 wfopen_ex: Trying to open file E:\WINDOWS\system32\config\system
12:01:27:437 1264 MyNtCreateFileW: NtCreateFile(\??\E:\WINDOWS\system32\config\system) returned status C0000043
12:01:27:437 1264 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
12:01:27:437 1264 wfopen_ex: Trying to KLMD file open
12:01:27:437 1264 KLMD_CreateFileW: Trying to open file E:\WINDOWS\system32\config\system
12:01:27:437 1264 wfopen_ex: File opened ok (Flags 2)
12:01:27:437 1264 CreateRegParser: HIVE_ADAPTER(E:\WINDOWS\system32\config\system) init success: 3849B8
12:01:27:437 1264 wfopen_ex: Trying to open file E:\WINDOWS\system32\config\software
12:01:27:437 1264 MyNtCreateFileW: NtCreateFile(\??\E:\WINDOWS\system32\config\software) returned status C0000043
12:01:27:437 1264 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
12:01:27:437 1264 wfopen_ex: Trying to KLMD file open
12:01:27:453 1264 KLMD_CreateFileW: Trying to open file E:\WINDOWS\system32\config\software
12:01:27:453 1264 wfopen_ex: File opened ok (Flags 2)
12:01:27:453 1264 CreateRegParser: HIVE_ADAPTER(E:\WINDOWS\system32\config\software) init success: 384A60
12:01:27:453 1264 EnableWow64Redirection: GetProcAddress(Wow64RevertWow64FsRedirection) error 127
12:01:27:453 1264 CreateRegParser: EnableWow64Redirection error
12:01:27:453 1264 CreateRegParser: RegParser init completed
12:01:27:718 1264 GetAdvancedServicesInfo: Raw services enum returned 346 services
12:01:27:718 1264 fclose_ex: Trying to close file E:\WINDOWS\system32\config\system
12:01:27:718 1264 fclose_ex: Trying to close file E:\WINDOWS\system32\config\software
12:01:27:718 1264
12:01:27:734 1264 Scanning Kernel memory ...
12:01:27:734 1264 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk
12:01:27:734 1264 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 898C3030
12:01:27:734 1264 DetectCureTDL3: KLMD_GetDeviceObjectList returned 5 DevObjects
12:01:27:734 1264
12:01:27:734 1264 DetectCureTDL3: DEVICE_OBJECT: 894E09F0
12:01:27:734 1264 KLMD_GetLowerDeviceObject: Trying to get lower device object for 894E09F0
12:01:27:734 1264 KLMD_ReadMem: Trying to ReadMemory 0x894E09F0[0x38]
12:01:27:734 1264 DetectCureTDL3: DRIVER_OBJECT: 898C3030
12:01:27:734 1264 KLMD_ReadMem: Trying to ReadMemory 0x898C3030[0xA8]
12:01:27:734 1264 KLMD_ReadMem: Trying to ReadMemory 0xE14BD390[0x18]
12:01:27:734 1264 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
12:01:27:734 1264 DetectCureTDL3: IrpHandler (0) addr: F763DBB0
12:01:27:734 1264 DetectCureTDL3: IrpHandler (1) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (2) addr: F763DBB0
12:01:27:734 1264 DetectCureTDL3: IrpHandler (3) addr: F7637D1F
12:01:27:734 1264 DetectCureTDL3: IrpHandler (4) addr: F7637D1F
12:01:27:734 1264 DetectCureTDL3: IrpHandler (5) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (6) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (7) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (8) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (9) addr: F76382E2
12:01:27:734 1264 DetectCureTDL3: IrpHandler (10) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (11) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (12) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (13) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (14) addr: F76383BB
12:01:27:734 1264 DetectCureTDL3: IrpHandler (15) addr: F763BF28
12:01:27:734 1264 DetectCureTDL3: IrpHandler (16) addr: F76382E2
12:01:27:734 1264 DetectCureTDL3: IrpHandler (17) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (18) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (19) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (20) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (21) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (22) addr: F7639C82
12:01:27:734 1264 DetectCureTDL3: IrpHandler (23) addr: F763E99E
12:01:27:734 1264 DetectCureTDL3: IrpHandler (24) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (25) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (26) addr: 804F9739
12:01:27:734 1264 TDL3_FileDetect: Processing driver: Disk
12:01:27:734 1264 TDL3_FileDetect: Processing driver file: E:\WINDOWS\system32\DRIVERS\disk.sys
12:01:27:734 1264 KLMD_CreateFileW: Trying to open file E:\WINDOWS\system32\DRIVERS\disk.sys
12:01:27:734 1264 TDL3_FileDetect: E:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
12:01:27:734 1264
12:01:27:734 1264 DetectCureTDL3: DEVICE_OBJECT: 894EBAB8
12:01:27:734 1264 KLMD_GetLowerDeviceObject: Trying to get lower device object for 894EBAB8
12:01:27:734 1264 DetectCureTDL3: DEVICE_OBJECT: 8958D938
12:01:27:734 1264 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8958D938
12:01:27:734 1264 KLMD_ReadMem: Trying to ReadMemory 0x8958D938[0x38]
12:01:27:734 1264 DetectCureTDL3: DRIVER_OBJECT: 89592220
12:01:27:734 1264 KLMD_ReadMem: Trying to ReadMemory 0x89592220[0xA8]
12:01:27:734 1264 KLMD_ReadMem: Trying to ReadMemory 0xE14B5498[0x1E]
12:01:27:734 1264 DetectCureTDL3: DRIVER_OBJECT name: \Driver\usbstor, Driver Name: usbstor
12:01:27:734 1264 DetectCureTDL3: IrpHandler (0) addr: F779C218
12:01:27:734 1264 DetectCureTDL3: IrpHandler (1) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (2) addr: F779C218
12:01:27:734 1264 DetectCureTDL3: IrpHandler (3) addr: F779C23C
12:01:27:734 1264 DetectCureTDL3: IrpHandler (4) addr: F779C23C
12:01:27:734 1264 DetectCureTDL3: IrpHandler (5) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (6) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (7) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (8) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (9) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (10) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (11) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (12) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (13) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (14) addr: F779C180
12:01:27:734 1264 DetectCureTDL3: IrpHandler (15) addr: 8959D2B0
12:01:27:734 1264 DetectCureTDL3: IrpHandler (16) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (17) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (18) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (19) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (20) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (21) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (22) addr: F779B5F0
12:01:27:734 1264 DetectCureTDL3: IrpHandler (23) addr: F7799A6E
12:01:27:734 1264 DetectCureTDL3: IrpHandler (24) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (25) addr: 804F9739
12:01:27:734 1264 DetectCureTDL3: IrpHandler (26) addr: 804F9739
12:01:27:734 1264 KLMD_ReadMem: Trying to ReadMemory 0xF7798F26[0x400]
12:01:27:734 1264 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
12:01:27:734 1264 TDL3_FileDetect: Processing driver: usbstor
12:01:27:734 1264 TDL3_FileDetect: Processing driver file: E:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
12:01:27:734 1264 KLMD_CreateFileW: Trying to open file E:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
12:01:27:750 1264 TDL3_FileDetect: E:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: Clean
12:01:27:750 1264
12:01:27:750 1264 DetectCureTDL3: DEVICE_OBJECT: 898BDC68
12:01:27:750 1264 KLMD_GetLowerDeviceObject: Trying to get lower device object for 898BDC68
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0x898BDC68[0x38]
12:01:27:750 1264 DetectCureTDL3: DRIVER_OBJECT: 898C3030
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0x898C3030[0xA8]
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0xE14BD390[0x18]
12:01:27:750 1264 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
12:01:27:750 1264 DetectCureTDL3: IrpHandler (0) addr: F763DBB0
12:01:27:750 1264 DetectCureTDL3: IrpHandler (1) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (2) addr: F763DBB0
12:01:27:750 1264 DetectCureTDL3: IrpHandler (3) addr: F7637D1F
12:01:27:750 1264 DetectCureTDL3: IrpHandler (4) addr: F7637D1F
12:01:27:750 1264 DetectCureTDL3: IrpHandler (5) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (6) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (7) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (8) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (9) addr: F76382E2
12:01:27:750 1264 DetectCureTDL3: IrpHandler (10) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (11) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (12) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (13) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (14) addr: F76383BB
12:01:27:750 1264 DetectCureTDL3: IrpHandler (15) addr: F763BF28
12:01:27:750 1264 DetectCureTDL3: IrpHandler (16) addr: F76382E2
12:01:27:750 1264 DetectCureTDL3: IrpHandler (17) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (18) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (19) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (20) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (21) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (22) addr: F7639C82
12:01:27:750 1264 DetectCureTDL3: IrpHandler (23) addr: F763E99E
12:01:27:750 1264 DetectCureTDL3: IrpHandler (24) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (25) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (26) addr: 804F9739
12:01:27:750 1264 TDL3_FileDetect: Processing driver: Disk
12:01:27:750 1264 TDL3_FileDetect: Processing driver file: E:\WINDOWS\system32\DRIVERS\disk.sys
12:01:27:750 1264 KLMD_CreateFileW: Trying to open file E:\WINDOWS\system32\DRIVERS\disk.sys
12:01:27:750 1264 TDL3_FileDetect: E:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
12:01:27:750 1264
12:01:27:750 1264 DetectCureTDL3: DEVICE_OBJECT: 8966BC68
12:01:27:750 1264 KLMD_GetLowerDeviceObject: Trying to get lower device object for 8966BC68
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0x8966BC68[0x38]
12:01:27:750 1264 DetectCureTDL3: DRIVER_OBJECT: 898C3030
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0x898C3030[0xA8]
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0xE14BD390[0x18]
12:01:27:750 1264 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk
12:01:27:750 1264 DetectCureTDL3: IrpHandler (0) addr: F763DBB0
12:01:27:750 1264 DetectCureTDL3: IrpHandler (1) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (2) addr: F763DBB0
12:01:27:750 1264 DetectCureTDL3: IrpHandler (3) addr: F7637D1F
12:01:27:750 1264 DetectCureTDL3: IrpHandler (4) addr: F7637D1F
12:01:27:750 1264 DetectCureTDL3: IrpHandler (5) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (6) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (7) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (8) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (9) addr: F76382E2
12:01:27:750 1264 DetectCureTDL3: IrpHandler (10) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (11) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (12) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (13) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (14) addr: F76383BB
12:01:27:750 1264 DetectCureTDL3: IrpHandler (15) addr: F763BF28
12:01:27:750 1264 DetectCureTDL3: IrpHandler (16) addr: F76382E2
12:01:27:750 1264 DetectCureTDL3: IrpHandler (17) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (18) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (19) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (20) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (21) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (22) addr: F7639C82
12:01:27:750 1264 DetectCureTDL3: IrpHandler (23) addr: F763E99E
12:01:27:750 1264 DetectCureTDL3: IrpHandler (24) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (25) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (26) addr: 804F9739
12:01:27:750 1264 TDL3_FileDetect: Processing driver: Disk
12:01:27:750 1264 TDL3_FileDetect: Processing driver file: E:\WINDOWS\system32\DRIVERS\disk.sys
12:01:27:750 1264 KLMD_CreateFileW: Trying to open file E:\WINDOWS\system32\DRIVERS\disk.sys
12:01:27:750 1264 TDL3_FileDetect: E:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: Clean
12:01:27:750 1264
12:01:27:750 1264 DetectCureTDL3: DEVICE_OBJECT: 898FBAB8
12:01:27:750 1264 KLMD_GetLowerDeviceObject: Trying to get lower device object for 898FBAB8
12:01:27:750 1264 DetectCureTDL3: DEVICE_OBJECT: 89913F18
12:01:27:750 1264 KLMD_GetLowerDeviceObject: Trying to get lower device object for 89913F18
12:01:27:750 1264 DetectCureTDL3: DEVICE_OBJECT: 898DA940
12:01:27:750 1264 KLMD_GetLowerDeviceObject: Trying to get lower device object for 898DA940
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0x898DA940[0x38]
12:01:27:750 1264 DetectCureTDL3: DRIVER_OBJECT: 897EC308
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0x897EC308[0xA8]
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0xE14C4370[0x1A]
12:01:27:750 1264 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi
12:01:27:750 1264 DetectCureTDL3: IrpHandler (0) addr: F74A46F2
12:01:27:750 1264 DetectCureTDL3: IrpHandler (1) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (2) addr: F74A46F2
12:01:27:750 1264 DetectCureTDL3: IrpHandler (3) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (4) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (5) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (6) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (7) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (8) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (9) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (10) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (11) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (12) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (13) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (14) addr: F74A4712
12:01:27:750 1264 DetectCureTDL3: IrpHandler (15) addr: F74A0852
12:01:27:750 1264 DetectCureTDL3: IrpHandler (16) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (17) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (18) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (19) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (20) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (21) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (22) addr: F74A473C
12:01:27:750 1264 DetectCureTDL3: IrpHandler (23) addr: F74AB336
12:01:27:750 1264 DetectCureTDL3: IrpHandler (24) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (25) addr: 804F9739
12:01:27:750 1264 DetectCureTDL3: IrpHandler (26) addr: 804F9739
12:01:27:750 1264 KLMD_ReadMem: Trying to ReadMemory 0xF74A1864[0x400]
12:01:27:750 1264 TDL3_StartIoHookDetect: CheckParameters: 0, 00000000, 0
12:01:27:750 1264 TDL3_FileDetect: Processing driver: atapi
12:01:27:750 1264 TDL3_FileDetect: Processing driver file: E:\WINDOWS\system32\DRIVERS\atapi.sys
12:01:27:750 1264 KLMD_CreateFileW: Trying to open file E:\WINDOWS\system32\DRIVERS\atapi.sys
12:01:27:765 1264 TDL3_FileDetect: E:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: Clean
12:01:27:765 1264
12:01:27:765 1264 Completed
12:01:27:765 1264
12:01:27:765 1264 Results:
12:01:27:765 1264 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
12:01:27:765 1264 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
12:01:27:765 1264 File objects infected / cured / cured on reboot: 0 / 0 / 0
12:01:27:765 1264
12:01:27:765 1264 MyNtCreateFileW: NtCreateFile(\??\E:\WINDOWS\system32\drivers\klmd.sys) returned status 00000000
12:01:27:765 1264 UtilityDeinit: KLMD(ARK) unloaded successfully
MuckyMouse
Active Member
 
Posts: 10
Joined: January 2nd, 2010, 4:37 pm

Re: Cleaning up a hijack

Unread postby muppy03 » January 15th, 2010, 8:58 pm

Ok Post results when ready.
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4798
Joined: December 4th, 2007, 5:30 am
Location: Australia

Re: Cleaning up a hijack

Unread postby MuckyMouse » January 16th, 2010, 4:44 pm

Malwarebytes uninstalled/reinstalled but computer crashes totally during the scan.
MuckyMouse
Active Member
 
Posts: 10
Joined: January 2nd, 2010, 4:37 pm

Re: Cleaning up a hijack

Unread postby muppy03 » January 17th, 2010, 6:19 am

Malwarebytes uninstalled/reinstalled but computer crashes totally during the scan.

Please describe what happens. When does it crash, at the beginning, middle or end for example.

got hit with a nasty "Internet2010" worm that I got some help (mostly - key word!) to remove

Can you explain a bit about what the help was?

Lets see if GMER will run

GMER Rootkit Scanner
Download GMER Rootkit Scanner from here.
  • Double click the .exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO

    Image
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file
  • Save it where you can easily find it, such as your desktop, and post it in reply
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries


Please reply with:-
  • GMER log
  • New HJT log
  • Answer to questions
User avatar
muppy03
MRU Emeritus
MRU Emeritus
 
Posts: 4798
Joined: December 4th, 2007, 5:30 am
Location: Australia
Advertisement
Register to Remove

Next

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 153 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware