View Single Post
Old 09-20-2006, 09:45 PM   #6 (permalink)
calechko
Registered User
 
Join Date: Sep 2006
Posts: 5
OS: XP


Ok, I have done all the steps you have asked me to. Here are the logs you asked for.

Chris - 06-09-20 9:30:15.73 Service Pack 2
ComboFix 06.09.20 - Running from: "C:\Documents and Settings\Chris\desktop"
Command switches used :: /v awtqn

(((((((((((((((((((((((((((((((((((((((((((((((( Vundo Log )))))))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\awtqn.dll
C:\WINDOWS\system32\nqtwa.bak1
C:\WINDOWS\system32\nqtwa.bak2
C:\WINDOWS\system32\nqtwa.ini
C:\WINDOWS\system32\nqtwa.ini2
C:\WINDOWS\system32\nqtwa.tmp


* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *



(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\components


((((((((((((((((((((((((((((((( Files Created from 2009-19-06 to 2009/20/2006 ))))))))))))))))))))))))))))))))))


No new files created in this timespan


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2012/18/2004 08:32 PM 38229 --------- C:\WINDOWS\system32\drivers\StMp3Rec.sys
2012/17/2004 08:13 PM 145920 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2012/15/2004 11:18 AM 703232 --a------ C:\WINDOWS\system32\drivers\HSF_CNXT.sys
2012/15/2004 11:18 AM 207232 --a------ C:\WINDOWS\system32\drivers\HSFHWICH.sys
2012/15/2004 11:18 AM 1038208 --a------ C:\WINDOWS\system32\drivers\HSF_DP.sys
2011/17/2004 06:17 AM 293120 --a------ C:\WINDOWS\system32\drivers\camcaud.sys
2011/17/2004 06:17 AM 280192 --a------ C:\WINDOWS\system32\drivers\camchal.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"LSBWatcher"="c:\\hp\\drivers\\hplsbwatcher\\lsburnwatcher.exe"
"HP Component Manager"="\"C:\\Program Files\\HP\\hpcoretech\\hpcmpmgr.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb10.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Windows Defender"="\"C:\\Program Files\\Windows Defender\\MSASCui.exe\" -hide"
"Symantec NetDriver Monitor"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Enterprise"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"vptray"="C:\\PROGRA~1\\SYMANT~1\\VPTray.exe"
"PrevxOne"="\"C:\\Program Files\\Prevx1\\PXConsole.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,50,01,00,00,00,00,00,00,40,05,00,00,f8,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}"="Microsoft AntiMalware ShellExecuteHook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~2.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
"backup"="C:\\WINDOWS\\pss\\Microsoft Office.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\MICROS~4\\Office10\\OSA.EXE -b -l"
"item"="Microsoft Office"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^Chris^Start Menu^Programs^Startup^Zeno.lnk]
"backup"="C:\\WINDOWS\\pss\\Zeno.lnkStartup"
"location"="Startup"
"item"="Zeno"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\AIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="aim"
"hkey"="HKCU"
"command"="C:\\Program Files\\AIM\\aim.exe -cnetwait.odl"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ATIPTA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="atiptaxx"
"hkey"="HKLM"
"command"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BearShare]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BearShare"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\BearShare\\BearShare.exe\" /pause"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BrowserUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="lwinlsaw"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\fmuz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="fmuzm"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\hpWirelessAssistant]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HP Wireless Assistant"
"hkey"="HKLM"
"command"="C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MSMSGS]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msmsgs"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MsnMsgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="MsnMsgr"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\MSPY2002]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ImScInst"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe /SYNC"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NaviSearch]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nls"
"hkey"="HKLM"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PHIME2002A]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TINTSETP"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\PHIME2002ASync]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="TINTSETP"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime Alternative\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Screen Calendar]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="scrcal"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Screen Calendar\\scrcal.exe\" -m"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\services32]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="mc-110-12-0000187"
"hkey"="HKCU"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SynTPLpr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SynTPLpr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\WhenUSave]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Save"
"hkey"="HKLM"
"inimapping"="0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winpsa32

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Scan.job

Completion time: Wed 09/20/2006 9:37:05.65
ComboFix.txt


SmitFraudFix v2.96

Scan done at 22:00:37.57, 06-09-20
Run from C:\Documents and Settings\Chris\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\ot.ico FOUND !
C:\WINDOWS\system32\ts.ico FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Chris\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Chris\FAVORI~1

C:\DOCUME~1\Chris\FAVORI~1\Antivirus Test Online.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End


---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 21:48 06-09-20

+ Scan result:



C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\WhenUSave -> Adware.SaveNow : Cleaned with backup (quarantined).
:mozilla.86:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.26:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.27:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.28:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.29:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.30:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.6:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Atdmt : Error during cleaning.
:mozilla.106:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.107:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.46:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Coremetrics : Error during cleaning.
:mozilla.52:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Coremetrics : Error during cleaning.
:mozilla.108:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.109:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.110:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.111:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Cpvfeed : Error during cleaning.
:mozilla.31:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Doubleclick : Error during cleaning.
:mozilla.102:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Fastclick : Error during cleaning.
:mozilla.103:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Fastclick : Error during cleaning.
:mozilla.55:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.56:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.57:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.58:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.60:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Questionmarket : Error during cleaning.
:mozilla.61:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Questionmarket : Error during cleaning.
C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{23D49DE9-CCF2-4DA9-9A64-8C4154EAB27F}.txt/{23D49DE9-CCF2-4DA9-9A64-8C4154EAB27F}.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.123:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.124:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.125:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.126:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.12:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.13:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.14:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.15:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Starware : Error during cleaning.
:mozilla.67:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Tribalfusion : Error during cleaning.
:mozilla.68:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Tribalfusion : Error during cleaning.
:mozilla.100:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.101:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt/{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.16:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.17:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.18:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.19:C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt/{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt -> TrackingCookie.Yieldmanager : Error during cleaning.


::Report end



Incident Status Location

Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico
Adware:adware/savenow Not disinfected Windows Registry
Adware:adware/sqwire Not disinfected Windows Registry
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Chris\Cookies\chris@atwola[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Chris\Cookies\chris@casalemedia[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris\Desktop\SmitfraudFix\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\8X6VSPIJ\SmitfraudFix[1].zip[SmitfraudFix/Process.exe]
Spyware:Cookie/Atlas DMT Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.atdmt.com/]
Spyware:Cookie/Advertising Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.doubleclick.net/]
Spyware:Cookie/Coremetrics Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][data.coremetrics.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.ads.pointroll.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.realmedia.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.tribalfusion.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][ad.yieldmanager.com/]
Spyware:Cookie/FastClick Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.fastclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt[{229072D9-A4EA-440D-890C-9FDC88DBE350}.txt][.casalemedia.com/]
Spyware:Cookie/Atwola Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{12A84AB5-C819-4E96-A1D8-296DBC4E34ED}\{EB311F4D-F2A3-410F-AF4D-80086B1E1E3D}.txt[{EB311F4D-F2A3-410F-AF4D-80086B1E1E3D}.txt]
Spyware:Cookie/Atwola Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{19D31794-AE2B-4680-8BC8-376B5CD1EEE2}.txt[{19D31794-AE2B-4680-8BC8-376B5CD1EEE2}.txt]
Spyware:Cookie/YieldManager Not disinfected C:\Program Files\iolo\System Mechanic 6\Undo\Manual\{E83B2D44-C915-4194-80F8-32E0DF932CA6}\{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt[{B8EB3374-0939-44EE-A7DE-524E4B179CA2}.txt][ad.yieldmanager.com/]
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
Logfile of HijackThis v1.99.1
Scan saved at 23:44, on 06-09-20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\iTunes\iTunes.exe
C:\HJT\doom.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Enterprise
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
calechko is offline