View Single Post
Old 08-07-2006, 08:39 AM   #5 (permalink)
DJslim09
Registered User
 
DJslim09's Avatar
 
Join Date: Jul 2006
Location: Cleveland, OH
Posts: 37
OS: Vista 64-bit SP1


AIMFix version: 1.6.85.024 (Aug 5 2006 00:24:30)
SeDebug Privilege set successfully
First, closing any running copies of AOL Instant Messenger (aim.exe):
KillProcByName(): aim.exe successfully terminated.

***ANY VIRUS FILES REMOVED WILL BE LISTED BELOW***

RegRunKeyExist(): Found HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\stratas
RegRunKeyExist(): Found HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\stratas
FU rootkit detected!
AIMFix set to run at startup in RunOnce
RegRunKeyExist(): Found HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\stratas
RegRunKeyExist(): Found HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\stratas
RegKill(): Found HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\stratas
RegKill(): Removed HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\stratas
RegKill(): "Run" key stratas found, removing value "lockx.exe"
RegKill(): "Run" key stratas found, removing value "lockx.exe"
RegKill(): Found HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\stratas
RegKill(): Removed HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\stratas
RegKill(): "Run" key stratas found, removing value "lockx.exe"
RegKill(): "Run" key stratas found, removing value "lockx.exe"
RegKill(): "Run" key stratas found, removing value "lockx.exe"
RegKill(): "Run" key stratas found, removing value "lockx.exe"
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\msdirectx.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\msdirectx.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\msdirectx.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\msdirectx.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lo70.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lo70.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lo70.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lo70.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lover.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lover.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lover.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lover.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\haxdrv.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\haxdrv.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\haxdrv.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\haxdrv.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\msdrv.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\msdrv.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\msdrv.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\msdrv.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\sdkcore.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\sdkcore.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\sdkcore.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\sdkcore.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lo31.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lo31.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lo31.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lo31.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\rdriv.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\rdriv.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\rdriv.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\rdriv.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lock1.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lock1.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lock1.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lock1.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\l071.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\l071.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\l071.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\l071.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\remon.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\remon.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\remon.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\remon.sys
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockbr.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockbr.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockbr.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockbr.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\nvidGUIv.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\nvidGUIv.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\nvidGUIv.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\nvidGUIv.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockbar.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockbar.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockbar.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockbar.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\cdROM Drivers
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\cdROM Drivers
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\cdROM Drivers
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\cdROM Drivers
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\l074.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\l074.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\l074.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\l074.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\xz.bat
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\xz.bat
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\xz.bat
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\xz.bat
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\pics.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\pics.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\pics.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\pics.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\pics[1].exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\pics[1].exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\pics[1].exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\pics[1].exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx10.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx10.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx10.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx10.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx11.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx11.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx11.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx11.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx12.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx12.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx12.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx12.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx2.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx2.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx2.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx2.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx3.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx3.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx3.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx3.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx4.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx4.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx4.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx4.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx5.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx5.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx5.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx5.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx7.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx7.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx7.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx7.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx8.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx8.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx8.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx8.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx1.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx1.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx1.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx1.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx6.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx6.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx6.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx6.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockx9.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockx9.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockx9.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockx9.exe
quarantine(): Attemtped to Quarantine nonexistent file C:\Documents and Settings\Michael\lockts.xexe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system32\lockts.xexe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\system\lockts.xexe
quarantine(): Attemtped to Quarantine nonexistent file C:\WINDOWS\lockts.xexe
Reboot cancelled by user
BlockRemove(): Now checking for Block-Checker: .5
BlockRemove(): Block-Checker not found
IMNamesRemove(): Now checking for IMNames: .2
IMNamesRemove(): IM Names not found
CleanMstc(): mstc not found


Hijack this Log:

Logfile of HijackThis v1.99.1
Scan saved at 10:39:17 AM, on 8/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CASIO\Photo Loader\Plauto.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LMPDPUI.EXE
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\htj\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://securityresponse.symantec.com...r/fix_homepage
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir...ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.alltel.net/newuser/benefits/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [LMPDPSRV] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LMPDPSRV.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [tunebite.exe] C:\Program Files\tunebite\tunebite.exe -hidden
O4 - HKCU\..\RunOnce: [*AIMFix] C:\D
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Photo Loader supervisory.lnk = C:\Program Files\CASIO\Photo Loader\Plauto.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZR
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/117p/html/gtdownlr.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by109w.bay109.mail.live.com/m...s/MsnPUpld.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1123033659984
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1133667456218
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/v...fo/webscan.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10...o.cab34246.cab
O16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} (Downloader Class) - http://www.stopzilla.com/_download/A...ler/dwnldr.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{179967DC-9AF3-4ECC-AE23-D7D1F840B62F}: NameServer = 192.168.0.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{179967DC-9AF3-4ECC-AE23-D7D1F840B62F}: NameServer = 192.168.0.1
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
DJslim09 is offline