![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jan 2007
Posts: 39
OS: XP
|
Slow Laptop!
My laptop is really slow on opening applications sometimes, but sometimes it's normal speed.
Here's my HijackThis log: Logfile of HijackThis v1.99.1 Scan saved at 8:47:06 PM, on 2/10/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\stsystra.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\dlbxcoms.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\NetWaiting\netWaiting.exe C:\Program Files\Dell Support\DSAgnt.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\cleanmgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE C:\Documents and Settings\Amy Schwanger\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.peoplepc.com/websearch R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://home.peoplepc.com/search R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [dlbxmon.exe] "C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe" O4 - HKLM\..\Run: [PrinterAnywhere] C:\Program Files\PrinterAnywhere\paConsole.exe -minimized O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - Global Startup: Digital Line Detect.lnk = ? O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster 16\pmremind.exe O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1168098479187 O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.0 Control) - http://winkflash.com/photo/loaders/ImageUploader3.cab O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: dlbx_device - Dell - C:\WINDOWS\system32\dlbxcoms.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE |
|
|
|
|
|
#4 (permalink) |
|
Analyst, Security Team
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,565
OS: Windows XP Pro
|
Hi and welcome to TSF.
I am currently reviewing your log. Please note that this is under the supervision of an expert analyst, and I will be back with a fix for your problem as soon as possible. You may wish to Subscribe to this thread so that you are notified when you receive a reply. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Add Subscription. Please be patient with me during this time.
__________________
![]() Proud Member of ASAP Proud Member of UNITE Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support. Donation link for Tech Support Forum |
|
|
|
|
|
#5 (permalink) |
|
Analyst, Security Team
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,565
OS: Windows XP Pro
|
Before you continue with my set of instructions. If you could please describe to me which applications run slow at times? What else are you currently doing at the time when trying to open these applications? Are you surfing the web, checking email, etc?
--------------------------------------------------------------------------------------------- Please save these instructions to Notepad as the internet will not be available to you at certain points of the removal process. Please ensure that there aren't any opened browsers when you are carrying out the procedures below. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes. --------------------------------------------------------------------------------------------- The cleaning process is not instant. Please follow through to the end until I tell you your machine is clear. The absence of symptoms does not mean that everything is clean. Please make every effort to reply to my posts in a timely manner. Malware spreads quickly, and the longer an infection remains on a system, increases the llikelihood of any additional infections coming into your computer. --------------------------------------------------------------------------------------------- Update Anti-Spyware I see you have AVG Anti-Spyware already. Please update it's definitions, and run a scan where I have placed it in this fix. Run AVG Anti-Spyware
--------------------------------------------------------------------------------------------- Please download ATF Cleaner - http://www.atribune.org/ccount/click.php?id=1 ATF Cleaner * Double-click ATF-Cleaner.exe to run the program. * Click Select All found at the bottom of the list. * Click the Empty Selected button. If you use Firefox browser, do this also: * Click Firefox at the top and choose Select All from the list. * Click the Empty Selected button. * NOTE : If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browser, do this also: * Click Opera at the top and choose Select All from the list. * Click the Empty Selected button. * NOTE : If you would like to keep your saved passwords, please click No at the prompt. Click Exit on the Main menu to close the program. --------------------------------------------------------------------------------------------- Enter Safe Mode
Note: Some systems, this may be the F5 key, so try that if F8 doesn't work. --------------------------------------------------------------------------------------------- Run AVG Anti-Spyware Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
--------------------------------------------------------------------------------------------- Restart your computer in Normal Mode --------------------------------------------------------------------------------------------- Perform an online scan with Internet Explorer with Panda ActiveScan
![]()
* Turn off the real time scanner of any existing antivirus program while performing the online scan --------------------------------------------------------------------------------------------- Download ComboScan to your Desktop.
To attach a file to a new post, simply: 1. Click the [Manage Attachments] button under Additional Options > Attach Files on the post composition page, and 2. Copy and paste the following into the "Upload File from your Computer" box: C:\ComboScan\Supplementary.txt 3. Click Upload. --------------------------------------------------------------------------------------------- Please include the following in your next reply: AVG Anti-Spyware Results Panda Results C:\ComboScan\ComboScan.txt C:\ComboScan\Supplementary.txt - Please attach
__________________
![]() Proud Member of ASAP Proud Member of UNITE Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support. Donation link for Tech Support Forum |
|
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Jan 2007
Posts: 39
OS: XP
|
AVG Anti-Spyware Results
--------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 7:13:54 PM 2/27/2007 + Scan result: :mozilla.173:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.326:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.43:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.44:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.45:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.46:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.47:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.48:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.49:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.50:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.51:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.52:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.53:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.54:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.55:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.56:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.57:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.321:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.322:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.358:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.359:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.59:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.60:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.61:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.62:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.63:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.161:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.339:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.92:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.96:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.97:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.98:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.99:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.351:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Centrport : Cleaned. :mozilla.386:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.58:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.316:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.317:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.219:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.220:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.221:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.268:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.269:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.270:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.271:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.272:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.273:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.274:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.275:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.276:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.301:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.369:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.370:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.371:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.372:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.373:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.397:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Information : Cleaned. :mozilla.308:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.309:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.310:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.324:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.325:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.340:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.341:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.218:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.311:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.312:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.313:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.314:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.375:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.376:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.377:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.93:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.94:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.222:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.27:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.32:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.33:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.34:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.36:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.37:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.38:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.39:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.40:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.41:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.42:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.20:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.23:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.24:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.25:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.304:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.187:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.188:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.189:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.192:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.193:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.151:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.152:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.153:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.154:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.155:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.156:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.157:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.158:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.159:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.242:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.166:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.142:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.143:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.144:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.145:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.146:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.147:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.196:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.197:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.198:C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. ::Report end Panda Results: Incident Status Location Adware:adware/24-7-search Not disinfected c:\windows\system32\unPPC.exe Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt[.atdmt.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt[.2o7.net/] Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt[.mediaplex.com/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt[.adrevolver.com/] Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt[.bravenet.com/] Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt[.atwola.com/] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt[.go.com/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Amy Schwanger\Application Data\Mozilla\Firefox\Profiles\comfnnao.default\cookies.txt[.apmebf.com/] ComboScan.txt ComboScan v20070226.18 run by Amy Schwanger on 2007-02-28 at 17:37:06 Computer is in Normal Mode. -------------------------------------------------------------------------------- Successfully created restore point. Performed disk cleanup. -- HijackThis Clone ------------------------------------------------------------- Emulating logfile of HijackThis v1.99.1 Scan saved at 2007-02-28 17:38:06 Platform: Windows XP Service Pack 2 (5.01.2600) MSIE: Internet Explorer (6.0.2900.2180) Running processes: C:\WINDOWS\system32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\WLTRYSVC.EXE C:\WINDOWS\system32\BCMWLTRY.EXE C:\Program Files\Common Files\Symantec Shared\CCSETMGR.EXE C:\Program Files\Common Files\Symantec Shared\CCEVTMGR.EXE C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Norton AntiVirus\NAVAPSVC.EXE C:\Program Files\Dell\QuickSet\NicConfigSvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMNTOR.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe C:\WINDOWS\system32\WLTRAY.EXE C:\WINDOWS\stsystra.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Real\RealPlayer\realplay.exe C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Common Files\Symantec Shared\CCAPP.EXE C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exE C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\NetWaiting\netwaiting.exe C:\Program Files\Dell Support\DSAgnt.exe C:\Program Files\Digital Line Detect\DLG.exe C:\WINDOWS\system32\dlbxcoms.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\Documents and Settings\Amy Schwanger\My Documents\My Downloads\comboscan.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://home.peoplepc.com/search R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.peoplepc.com/websearch R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://home.peoplepc.com/search R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NAVSHEXT.DLL O2 - BHO: PDFCreator Toolbar Helper - {C451C08A-EC37-45DF-AAAD-18B51AB5E837} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NAVSHEXT.DLL O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [dlbxmon.exe] "C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe" O4 - HKLM\..\Run: [PrinterAnywhere] C:\Program Files\PrinterAnywhere\paConsole.exe -minimized O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: Event Reminder.lnk = C:\Program Files\PrintMaster 16\pmremind.exe O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file) O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O9 - Extra 'Tools' menuitem: (no name) - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing) O9 - Extra 'Tools' menuitem: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing) O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra 'Tools' menuitem: (no name) - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing) O9 - Extra 'Tools' menuitem: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1168098479187 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\system32\igfxdev.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\system32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll O23 - Service: Alerter - C:\WINDOWS\system32\svchost.exe -k LocalService O23 - Service: Application Layer Gateway Service (ALG) - C:\WINDOWS\system32\alg.exe O23 - Service: Application Management (AppMgmt) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: ASP.NET State Service (aspnet_state) - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe O23 - Service: Windows Audio (AudioSrv) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Automatic LiveUpdate Scheduler - "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" O23 - Service: AVG Anti-Spyware Guard - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Background Intelligent Transfer Service (BITS) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Computer Browser (Browser) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Symantec Event Manager (ccEvtMgr) - "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" O23 - Service: Symantec Settings Manager (ccSetMgr) - "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" O23 - Service: Indexing Service (CiSvc) - C:\WINDOWS\system32\cisvc.exe O23 - Service: ClipBook (ClipSrv) - C:\WINDOWS\system32\clipsrv.exe O23 - Service: .NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe O23 - Service: COM+ System Application (COMSysApp) - C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} O23 - Service: Cryptographic Services (CryptSvc) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: DCOM Server Process Launcher (DcomLaunch) - C:\WINDOWS\system32\svchost -k DcomLaunch O23 - Service: DHCP Client (Dhcp) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: dlbx_device - C:\WINDOWS\system32\dlbxcoms.exe -service O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - C:\WINDOWS\System32\dmadmin.exe /com O23 - Service: Logical Disk Manager (dmserver) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: DNS Client (Dnscache) - C:\WINDOWS\system32\svchost.exe -k NetworkService O23 - Service: Error Reporting Service (ERSvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Event Log (Eventlog) - C:\WINDOWS\system32\services.exe O23 - Service: COM+ Event System (EventSystem) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Fast User Switching Compatibility (FastUserSwitchingCompatibility) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Fax - C:\WINDOWS\system32\fxssvc.exe O23 - Service: Help and Support (helpsvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Human Interface Device Access (HidServ) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: HTTP SSL (HTTPFilter) - C:\WINDOWS\System32\svchost.exe -k HTTPFilter O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - C:\WINDOWS\system32\imapi.exe O23 - Service: Server (LanmanServer) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Workstation (lanmanworkstation) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: LiveUpdate - "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE" O23 - Service: TCP/IP NetBIOS Helper (LmHosts) - C:\WINDOWS\system32\svchost.exe -k LocalService O23 - Service: Messenger - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - C:\WINDOWS\system32\mnmsrvc.exe O23 - Service: Distributed Transaction Coordinator (MSDTC) - C:\WINDOWS\system32\msdtc.exe O23 - Service: Windows Installer (MSIServer) - C:\WINDOWS\system32\msiexec.exe /V O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - "C:\Program Files\Norton AntiVirus\navapsvc.exe" O23 - Service: Network DDE (NetDDE) - C:\WINDOWS\system32\netdde.exe O23 - Service: Network DDE DSDM (NetDDEdsdm) - C:\WINDOWS\system32\netdde.exe O23 - Service: Net Logon (Netlogon) - C:\WINDOWS\system32\lsass.exe O23 - Service: Network Connections (Netman) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: NICCONFIGSVC - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe O23 - Service: Network Location Awareness (NLA) (Nla) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - "C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe" O23 - Service: Norton Protection Center Service (NSCService) - "C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE" O23 - Service: NT LM Security Support Provider (NtLmSsp) - C:\WINDOWS\system32\lsass.exe O23 - Service: Removable Storage (NtmsSvc) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Office Source Engine (ose) - "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" O23 - Service: Plug and Play (PlugPlay) - C:\WINDOWS\system32\services.exe O23 - Service: IPSEC Services (PolicyAgent) - C:\WINDOWS\system32\lsass.exe O23 - Service: Protected Storage (ProtectedStorage) - C:\WINDOWS\system32\lsass.exe O23 - Service: Remote Access Auto Connection Manager (RasAuto) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Remote Access Connection Manager (RasMan) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Remote Desktop Help Session Manager (RDSessMgr) - C:\WINDOWS\system32\sessmgr.exe O23 - Service: Routing and Remote Access (RemoteAccess) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Remote Procedure Call (RPC) Locator (RpcLocator) - C:\WINDOWS\system32\locator.exe O23 - Service: Remote Procedure Call (RPC) (RpcSs) - C:\WINDOWS\system32\svchost -k rpcss O23 - Service: QoS RSVP (RSVP) - C:\WINDOWS\system32\rsvp.exe O23 - Service: Security Accounts Manager (SamSs) - C:\WINDOWS\system32\lsass.exe O23 - Service: Symantec AVScan (SAVScan) - "C:\Program Files\Norton AntiVirus\SAVScan.exe" O23 - Service: Smart Card (SCardSvr) - C:\WINDOWS\system32\scardsvr.exe O23 - Service: Task Scheduler (Schedule) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Secondary Logon (seclogon) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: System Event Notification (SENS) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Shell Hardware Detection (ShellHWDetection) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Symantec Network Drivers Service (SNDSrvc) - "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe" O23 - Service: SPBBCSvc - "C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe" O23 - Service: Print Spooler (Spooler) - C:\WINDOWS\system32\spoolsv.exe O23 - Service: System Restore Service (srservice) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: SSDP Discovery Service (SSDPSRV) - C:\WINDOWS\system32\svchost.exe -k LocalService O23 - Service: Windows Image Acquisition (WIA) (stisvc) - C:\WINDOWS\system32\svchost.exe -k imgsvc O23 - Service: MS Software Shadow Copy Provider (SwPrv) - C:\WINDOWS\system32\dllhost.exe /Processid:{A445BD1E-49EE-4607-B370-5CCA447377C4} O23 - Service: Symantec Core LC - "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" O23 - Service: Performance Logs and Alerts (SysmonLog) - C:\WINDOWS\system32\smlogsvc.exe O23 - Service: Telephony (TapiSrv) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Terminal Services (TermService) - C:\WINDOWS\System32\svchost -k DComLaunch O23 - Service: Themes - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Distributed Link Tracking Client (TrkWks) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Universal Plug and Play Device Host (upnphost) - C:\WINDOWS\system32\svchost.exe -k LocalService O23 - Service: Uninterruptible Power Supply (UPS) - C:\WINDOWS\system32\ups.exe O23 - Service: TrueVector Internet Monitor (vsmon) - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service O23 - Service: Volume Shadow Copy (VSS) - C:\WINDOWS\system32\vssvc.exe O23 - Service: WebClient - C:\WINDOWS\system32\svchost.exe -k LocalService O23 - Service: Windows Management Instrumentation (winmgmt) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - C:\WINDOWS\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe O23 - Service: Portable Media Serial Number Service (WmdmPmSN) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: WMI Performance Adapter (WmiApSrv) - C:\WINDOWS\system32\wbem\wmiapsrv.exe O23 - Service: Windows Media Player Network Sharing Service (WMPNetworkSvc) - C:\Program Files\Windows Media Player\wmpnetwk.exe O23 - Service: Security Center (wscsvc) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Automatic Updates (wuauserv) - C:\WINDOWS\system32\svchost.exe -k netsvcs O23 - Service: Windows Driver Foundation - User-mode Driver Framework (WudfSvc) - C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup O23 - Service: Wireless Zero Configuration (WZCSVC) - C:\WINDOWS\System32\svchost.exe -k netsvcs O23 - Service: Network Provisioning Service (xmlprov) - C:\WINDOWS\System32\svchost.exe -k netsvcs -- File Associations ------------------------------------------------------------ .bat - batfile - "%1" %* .chm - chm.file - "C:\WINDOWS\hh.exe" %1 .cmd - cmdfile - "%1" %* .com - comfile - "%1" %* .exe - exefile - "%1" %* .hlp - hlpfile - %SystemRoot%\System32\winhlp32.exe %1 .inf - inffile - %SystemRoot%\System32\NOTEPAD.EXE %1 .ini - inifile - %SystemRoot%\System32\NOTEPAD.EXE %1 .js - JSFile - %SystemRoot%\System32\WScript.exe "%1" %* .lnk - lnkfile - {00021401-0000-0000-C000-000000000046} .pif - piffile - "%1" %* .reg - regfile - regedit.exe "%1" .scr - scrfile - "%1" /S .txt - txtfile - %SystemRoot%\system32\NOTEPAD.EXE %1 .vbs - VBSFile - %SystemRoot%\System32\WScript.exe "%1" %* -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------- 4S agpCPQ (Compaq AGP Bus Filter) - C:\WINDOWS\system32\drivers\AGPCPQ.SYS 4S alim1541 (ALI AGP Bus Filter) - C:\WINDOWS\system32\drivers\ALIM1541.SYS 4S amdagp (AMD AGP Bus Filter Driver) - C:\WINDOWS\system32\drivers\AMDAGP.SYS 1R APPDRV - C:\WINDOWS\system32\drivers\APPDRV.SYS 2R ASCTRM - C:\WINDOWS\system32\drivers\asctrm.sys 1R AVG Anti-Spyware Driver - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys 1R AvgAsCln (AVG Anti-Spyware Clean Driver) - C:\WINDOWS\system32\drivers\AvgAsCln.sys 3R BCM43XX (Dell Wireless WLAN Card Driver) - C:\WINDOWS\system32\drivers\BCMWL5.SYS 3S bcm4sbxp (Broadcom 440x 10/100 Integrated Controller XP Driver) - C:\WINDOWS\system32\drivers\bcm4sbxp.sys 4S cbidf - C:\WINDOWS\system32\drivers\cbidf2k.sys 4S dac2w2k - C:\WINDOWS\system32\drivers\dac2w2k.sys 0R drvmcdb - C:\WINDOWS\system32\drivers\drvmcdb.sys 2R drvnddm - C:\WINDOWS\system32\drivers\drvnddm.sys 3S E100B (Intel(R) PRO Adapter Driver) - C:\WINDOWS\system32\drivers\e100b325.sys 1R eeCtrl (Symantec Eraser Control driver) - C:\Program Files\Common Files\Symantec Shared\eengine\eectrl.sys 3R EraserUtilRebootDrv - C:\Program Files\Common Files\Symantec Shared\eengine\EraserUtilRebootDrv.sys 3R HDAudBus (Microsoft UAA Bus Driver for High Definition Audio) - C:\WINDOWS\system32\drivers\Hdaudbus.sys 3S HidUsb (Microsoft HID Class Driver) - C:\WINDOWS\system32\drivers\hidusb.sys 3R HSFHWAZL - C:\WINDOWS\system32\drivers\HSFHWAZL.sys 3R HSF_DPV - C:\WINDOWS\system32\drivers\HSF_DPV.sys 3R ialm - C:\WINDOWS\system32\drivers\ialmnt5.sys 1R intelppm (Intel Processor Driver) - C:\WINDOWS\system32\drivers\intelppm.sys 2R mdmxsdk - C:\WINDOWS\system32\drivers\mdmxsdk.sys 3R NAVENG - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070228.017\NAVENG.SYS 3R NAVEX15 - C:\Program Files\Common Files\Symantec Shared\VirusDefs\20070228.017\NAVEX15.SYS 3S nv - C:\WINDOWS\system32\drivers\nv4_mini.sys 3R pfc (Padus ASPI Shell) - C:\WINDOWS\system32\drivers\pfc.sys 0R PxHelp20 - C:\WINDOWS\system32\drivers\pxhelp20.sys 3S RIOUNIV (Rio universal USB driver) - C:\WINDOWS\system32\drivers\RIOUNIV.SYS 3R SAVRT - C:\Program Files\Norton AntiVirus\savrt.sys 1R SAVRTPEL - C:\Program Files\Norton AntiVirus\Savrtpel.sys 4S sisagp (SIS AGP Bus Filter) - C:\WINDOWS\system32\drivers\SISAGP.SYS 1R SPBBCDrv - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 0R srescan - C:\WINDOWS\system32\ZoneLabs\srescan.sys 1R sscdbhk5 - C:\WINDOWS\system32\drivers\sscdbhk5.sys 1R ssrtln - C:\WINDOWS\system32\drivers\ssrtln.sys 3R STHDA (SigmaTel High Definition Audio CODEC) - C:\WINDOWS\system32\drivers\sthda.sys 3R SYMDNS - C:\WINDOWS\system32\drivers\symdns.sys 3R SymEvent - C:\WINDOWS\system32\drivers\SYMEVENT.SYS 3R SYMFW - C:\WINDOWS\system32\drivers\symfw.sys 3R SYMIDS - C:\WINDOWS\system32\drivers\symids.sys 3R SYMIDSCO - C:\Program Files\Common Files\Symantec Shared\SymcData\ids-diskless\20070221.002\SymIDSCo.sys 2R symlcbrd - C:\WINDOWS\system32\drivers\symlcbrd.sys 3R SYMNDIS - C:\WINDOWS\system32\drivers\symndis.sys 3R SYMREDRV - C:\WINDOWS\system32\drivers\symredrv.sys 1R SYMTDI - C:\WINDOWS\system32\drivers\symtdi.sys 2R tfsnboio - C:\WINDOWS\system32\dla\tfsnboio.sys 2R tfsncofs - C:\WINDOWS\system32\dla\tfsncofs.sys 2R tfsndrct - C:\WINDOWS\system32\dla\tfsndrct.sys 2R tfsndres - C:\WINDOWS\system32\dla\tfsndres.sys 2R tfsnifs - C:\WINDOWS\system32\dla\tfsnifs.sys 2R tfsnopio - C:\WINDOWS\system32\dla\tfsnopio.sys 2R tfsnpool - C:\WINDOWS\system32\dla\tfsnpool.sys 2R tfsnudf - C:\WINDOWS\system32\dla\tfsnudf.sys 2R tfsnudfa - C:\WINDOWS\system32\dla\tfsnudfa.sys 3S usbccgp (Microsoft USB Generic Parent Driver) - C:\WINDOWS\system32\drivers\usbccgp.sys 3R usbehci (Microsoft USB 2.0 Enhanced Host Controller Miniport Driver) - C:\WINDOWS\system32\drivers\usbehci.sys 3S usbprint (Microsoft USB PRINTER Class) - C:\WINDOWS\system32\drivers\usbprint.sys 3S usbscan (USB Scanner Driver) - C:\WINDOWS\system32\drivers\usbscan.sys 3S USBSTOR (USB Mass Storage Driver) - C:\WINDOWS\system32\drivers\USBSTOR.SYS 4S viaagp (VIA AGP Bus Filter) - C:\WINDOWS\system32\drivers\VIAAGP.SYS 1R vsdatant - C:\WINDOWS\system32\vsdatant.sys 3S wanatw (WAN Miniport (ATW)) - C:\WINDOWS\system32\DRIVERS\wanatw4.sys (not found) 3R winachsf - C:\WINDOWS\system32\drivers\HSF_CNXT.sys 3S WudfPf (Windows Driver Foundation - User-mode Driver Framework Platform Driver) - C:\WINDOWS\system32\drivers\WudfPf.sys 3S WudfRd (Windows Driver Foundation - User-mode Driver Framework Reflector) - C:\WINDOWS\system32\drivers\WudfRd.sys -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- 3S aspnet_state (ASP.NET State Service) - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe 2R Automatic LiveUpdate Scheduler - "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" 2R AVG Anti-Spyware Guard - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe 2R ccEvtMgr (Symantec Event Manager) - "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" 2R ccSetMgr (Symantec Settings Manager) - "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" 3S clr_optimization_v2.0.50727_32 (.NET Runtime Optimization Service v2.0.50727_X86) - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 3R dlbx_device - C:\WINDOWS\system32\dlbxcoms.exe -service 2S Fax - C:\WINDOWS\system32\fxssvc.exe 3S LiveUpdate - "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE" 2R navapsvc (Norton AntiVirus Auto-Protect Service) - "C:\Program Files\Norton AntiVirus\navapsvc.exe" 2R NICCONFIGSVC - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe 2R NPFMntor (Norton AntiVirus Firewall Monitor Service) - "C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe" 3R NSCService (Norton Protection Center Service) - "C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE" 3S ose (Office Source Engine) - "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE" 3S SAVScan (Symantec AVScan) - "C:\Program Files\Norton AntiVirus\SAVScan.exe" 2R SNDSrvc (Symantec Network Drivers Service) - "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe" 2R SPBBCSvc - "C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe" 2R Symantec Core LC - "C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe" 2R vsmon (TrueVector Internet Monitor) - C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service 2R wltrysvc (Dell Wireless WLAN Tray Service) - C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe -- Scheduled Tasks -------------------------------------------------------------- 2007-02-24 06:22:07 546 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Amy Schwanger.job<NORTON~1.JOB> -- Files created between 2007-01-28 and 2007-02-28 ------------------------------ 2007-02-27 19:23:02 0 d-------- C:\WINDOWS\system32\ActiveScan<ACTIVE~1> 2007-02-27 10:37:15 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\Wal-Mart Digital Photo Manager<WAL-MA~2> 2007-02-27 10:37:05 0 d-------- C:\Program Files\Common Files\HP 2007-02-27 10:37:03 0 d-------- C:\Program Files\Wal-Mart 2007-02-27 10:22:40 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\Wal-Mart Digital Photo Viewer<WAL-MA~1> 2007-02-18 13:30:52 528 --a------ C:\WINDOWS\womssbeta.dat<WOMSSB~1.DAT> 2007-02-18 13:30:42 0 d-------- C:\Program Files\WOMGames 2007-02-09 20 48 3968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys2007-02-09 20 43 0 d-------- C:\Program Files\Grisoft2007-01-29 17:47:06 197120 --a------ C:\WINDOWS\system32\BMA_ValentineDoodles.scr<BMA_VA~1.SCR> 2007-01-29 17:47:06 0 d-------- C:\WINDOWS\system32\BMA_ValentineDoodles dir<BMA_VA~1> -- Find3M Report ---------------------------------------------------------------- 2007-02-28 17:26:53 0 d-------- C:\Program Files\Mozilla Thunderbird<MOZILL~2> 2007-02-28 17:02:07 0 d-------- C:\Program Files\Symantec 2007-02-28 16:59:58 0 d-------- C:\Program Files\NetWaiting<NETWAI~1> 2007-02-28 16:55:35 0 d-------- C:\Program Files\Digital Line Detect<DIGITA~1> 2007-02-28 16:55:33 0 d-------- C:\Program Files\Dell Support<DELLSU~1> 2007-02-28 16:55:22 0 d-------- C:\Program Files\Dell Photo AIO Printer 962<DELLPH~1> 2007-02-28 16:53:51 0 d-------- C:\Program Files\Common Files\Symantec Shared<SYMANT~1> 2007-02-28 16:30:24 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\Symantec 2007-02-28 07:16:43 0 d-------- C:\Program Files\Mozilla Firefox<MOZILL~1> 2007-02-27 20 34 0 d-------- C:\Program Files\Messenger<MESSEN~1>2007-02-17 17:48:07 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\U3 2007-02-11 12:54:53 8516 --a----c- C:\WINDOWS\mozver.dat 2007-01-29 03:58:06 60416 -----n--- C:\WINDOWS\system32\tzchange.exe 2007-01-25 18:10:38 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\AdobeUM 2007-01-25 07:26:37 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\Viewpoint<VIEWPO~1> 2007-01-21 16:50:07 4212 ---h----- C:\WINDOWS\system32\zllictbl.dat 2007-01-20 07:44:18 197120 --a------ C:\WINDOWS\system32\BMA_SillyBear.scr<BMA_SI~1.SCR> 2007-01-19 17:29:41 0 d-------- C:\Program Files\Future Pinball<FUTURE~1> 2007-01-19 17:29:24 0 d-------- C:\Program Files\BitTorrent<BITTOR~1> 2007-01-13 17:35:27 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\BitTorrent<BITTOR~1> 2007-01-11 06:31:10 0 d-------- C:\Program Files\Winkflash<WINKFL~1> 2007-01-10 07:32:16 197120 --a------ C:\WINDOWS\system32\Bluemountain-Home for Christmas.scr<BLUEMO~1.SCR> 2007-01-08 19:20:40 0 d-------- C:\Program Files\AIM Gadgets<AIMGAD~1> 2007-01-08 14:29:40 75512 --a------ C:\WINDOWS\zllsputility.exe<ZLLSPU~1.EXE> 2007-01-08 14:29:14 1087216 --a------ C:\WINDOWS\system32\zpeng24.dll 2007-01-06 14:49:12 0 d-------- C:\Program Files\Windows Media Connect 2<WI4DF6~1> 2007-01-06 14:44:31 0 d-------- C:\Program Files\Microsoft Works<MIF2B0~1> 2007-01-05 12:41:24 0 d-------- C:\Program Files\PrinterAnywhere<PRINTE~1> 2007-01-04 16:33:01 0 d-------- C:\Program Files\Common Files\AOL 2007-01-02 20:13:33 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\acccore 2007-01-02 20:13:21 0 d-------- C:\Program Files\AIM6 2007-01-01 12:40:49 0 d-------- C:\Program Files\Windows Powertools<WINDOW~4> 2007-01-01 10:16:16 0 d-------- C:\Program Files\Abexo 2007-01-01 10 21 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\Uniblue2007-01-01 09:14:45 0 d-------- C:\Documents and Settings\Amy Schwanger\Application Data\Lavasoft 2007-01-01 09:14:41 0 d-------- C:\Program Files\Lavasoft 2006-12-28 06:27:33 0 d-------- C:\Program Files\Yahoo! 2006-12-27 06:49:11 532480 --a------ C:\WINDOWS\system32\BMA_Countdown.scr<BMA_CO~1.SCR> 2006-12-24 15:49:17 197120 --a------ C:\WINDOWS\system32\BMA_ChristmasDecorating.scr<BMA_CH~1.SCR> 2006-12-21 19:17:59 48776 --a------ C:\WINDOWS\system32\S32EVNT1.DLL 2006-12-19 16:52:18 134656 --a------ C:\WINDOWS\system32\shsvcs.dll 2006-12-19 13:16:47 333824 --a------ C:\WINDOWS\system32\wiaservc.dll 2006-12-17 08:27:01 4 --a----c- C:\WINDOWS\uccspecb.sys -- Registry Dump ---------------------------------------------------------------- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "ModemOnHold"="C:\\Program Files\\NetWaiting\\netWaiting.exe" "DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup" "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" "Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe" "igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe" "igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe" "SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_03\\bin\\jusched.exe" "Broadcom Wireless Manager UI"="C:\\WINDOWS\\system32\\WLTRAY.exe" "SigmatelSysTrayApp"="stsystra.exe" "Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe" "DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\"" "RealTray"="C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe SYSTEMBOOTHIDEPLAYER" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe" "ISUSPM Startup"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup" "ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start" "MSKDetectorExe"="C:\\Program Files\\McAfee\\SpamKiller\\MSKDetct.exe /uninstall" "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "dlbxmon.exe"="\"C:\\Program Files\\Dell Photo AIO Printer 962\\dlbxmon.exe\"" "PrinterAnywhere"="C:\\Program Files\\PrinterAnywhere\\paConsole.exe -minimized" "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\"" "!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="aim6" "hkey"="HKCU" "command"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="bittorrent" "hkey"="HKCU" "inimapping"="0" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=dword:00000000 [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 -- End of ComboScan: finished at 2007-02-28 at 17:38:44 ------------------------- |
|
|