![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| HijackThis Log Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help. |
![]() |
|
|
Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Apr 2008
Posts: 13
OS: xp
|
problems with wireless
after being on line for awhile (which can be anywhere from 15 minutes to several hours) i lose my wireless connection. when i try to connect again, i get a prompt that says "problem applying profile." the only way to connect to the internet after that is to restart.
******************************************************* Deckard's System Scanner v20071014.68 Run by chris on 2008-04-24 10:39:23 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 39: 2008-04-24 15:39:31 UTC - RP443 - Deckard's System Scanner Restore Point 38: 2008-04-23 21:40:25 UTC - RP442 - Install AnyDVD 37: 2008-04-23 19:43:56 UTC - RP441 - Installed Windows Internet Explorer 7. 36: 2008-04-23 19:43:40 UTC - RP440 - Installed Windows IDNMitigationAPIs. 35: 2008-04-23 19:43:16 UTC - RP439 - Installed Windows NLSDownlevelMapping. -- First Restore Point -- 1: 2008-04-02 07:05:43 UTC - RP405 - Software Distribution Service 3.0 Backed up registry hives. Performed disk cleanup. System Drive C: has 0.84 GiB (less than 15%) free. -- HijackThis Clone ------------------------------------------------------------ Emulating logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2008-04-24 10:41:56 Platform: Windows XP Service Pack 2 (5.01.2600) MSIE: Internet Explorer (7.00.6000.16640) Boot mode: Normal Running processes: C:\WINDOWS\system32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Windows Defender\MsMpEng.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\system32\ati2evxx.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\explorer.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\dlbccoms.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\lxcycoms.exe C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\chris\Desktop\dss.exe C:\WINDOWS\system32\taskmgr.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) F2 - REG:system.ini: Shell= O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll,_RunDLLEntry@16 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user') O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - CmdMapping - (file missing) O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing) O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing) O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe O15 - Trusted Zone: http://www.hotmail.com (HKCU) O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} () - http://codecs.microsoft.com/codecs/i386/fhg.CAB O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/...?1201403936281 O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/v...fo/webscan.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\ati2evxx.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: dlbc_device - Unknown owner - C:\WINDOWS\system32\dlbccoms.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE O23 - Service: lxcy_device - Unknown owner - C:\WINDOWS\system32\lxcycoms.exe O23 - Service: NBService - Unknown owner - C:\Program Files\Nero\Nero 7\Nero O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: SavRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 8624 bytes -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R3 ElbyDelay - c:\windows\system32\drivers\elbydelay.sys <Not Verified; Elaborate Bytes AG; CDRTools> R3 mcdbus (Driver for MagicISO SCSI Host Controller) - c:\windows\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller> S3 UKS11LDR (Midiman USB Keystation Loader) - c:\windows\system32\drivers\uks11ldr.sys <Not Verified; MIDIMAN; Ta Horng USB 1x1 Keyboard Loader> S3 USBAAPL (Apple Mobile USB Driver) - c:\windows\system32\drivers\usbaapl.sys (file missing) S3 USBKS1X1 (Midiman USB Keystation Midi Driver) - c:\windows\system32\drivers\usbks1x1.sys <Not Verified; Doug Fetter Software Wizardry; Midiman USB Keystation Midi Interface> S3 wanatw (WAN Miniport (ATW)) - c:\windows\system32\drivers\wanatw4.sys (file missing) -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service> R2 Bonjour Service - "c:\program files\bonjour\mdnsresponder.exe" <Not Verified; Apple Inc.; Bonjour> S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2008-04-24 10:37:36 330 --ah----- C:\WINDOWS\Tasks\MP Scheduled Scan.job 2008-04-21 22:18:02 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job -- Files created between 2008-03-24 and 2008-04-24 ----------------------------- 2008-04-23 15:38:23 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla 2008-04-23 15:37:52 0 d-------- C:\Documents and Settings\Administrator\Desktop 2008-04-23 15:37:52 0 d--hs---- C:\Documents and Settings\Administrator\Cookies 2008-04-23 15:37:52 0 dr-h----- C:\Documents and Settings\Administrator\Application Data 2008-04-23 15:37:52 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft 2008-04-23 15:37:52 0 d-------- C:\Documents and Settings\Administrator\Application Data\Intel 2008-04-23 15:37:51 0 d--h----- C:\Documents and Settings\Administrator\Templates 2008-04-23 15:37:51 0 dr------- C:\Documents and Settings\Administrator\Start Menu 2008-04-23 15:37:51 0 dr-h----- C:\Documents and Settings\Administrator\SendTo 2008-04-23 15:37:51 0 d--h----- C:\Documents and Settings\Administrator\Recent 2008-04-23 15:37:51 0 d--h----- C:\Documents and Settings\Administrator\PrintHood 2008-04-23 15:37:51 0 d--h----- C:\Documents and Settings\Administrator\NetHood 2008-04-23 15:37:51 0 d-------- C:\Documents and Settings\Administrator\My Documents 2008-04-23 15:37:51 0 d--h----- C:\Documents and Settings\Administrator\Local Settings 2008-04-23 15:37:51 0 d-------- C:\Documents and Settings\Administrator\Favorites 2008-04-23 15:37:50 786432 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT 2008-04-23 14:24:10 0 d-------- C:\ie-spyad_zo 2008-04-23 14:16:28 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2008-04-23 14:16:24 0 d-------- C:\Program Files\SpywareBlaster 2008-04-23 12:28:47 0 d-------- C:\Program Files\Panda Security 2008-04-20 21:33:59 0 d-------- C:\Program Files\Microsoft Works 2008-04-20 21:33:49 0 d-------- C:\Program Files\MSBuild 2008-04-20 21:27:42 0 d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-04-20 21:22:54 0 dr-h----- C:\MSOCache 2008-04-20 21:22:06 96256 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys <Not Verified; MagicISO, Inc.; MagicISO SCSI Host Controller> 2008-04-20 21:22:06 0 d-------- C:\Program Files\MagicDisc 2008-04-20 21:14:54 0 d-------- C:\Program Files\MagicISO 2008-04-18 12:18:36 376832 --a------ C:\WINDOWS\system32\AegisI5Installer.exe <Not Verified; ; AegisInstall Application> 2008-04-18 11:44:35 0 d-------- C:\WINDOWS\pss 2008-04-18 10:11:17 552 --a------ C:\WINDOWS\system32\d3d8caps.dat 2008-04-15 12:20:27 0 d-------- C:\Program Files\Trillian 2008-04-04 18:46:00 0 d-------- C:\Documents and Settings\All Users\Application Data\SlySoft 2008-04-04 00:14:50 0 d-------- C:\Program Files\Orbis Software 2008-03-24 11:11:11 0 d-------- C:\Documents and Settings\chris\Application Data\vlc -- Find3M Report --------------------------------------------------------------- 2008-04-24 10:34:57 0 d-------- C:\Program Files\Symantec AntiVirus 2008-04-23 17:13:28 43 ---hs---- C:\Documents and Settings\chris\Application Data\.zreglib 2008-04-23 12:28:48 2692 --a------ C:\WINDOWS\mozver.dat 2008-04-23 12:12:47 0 d-------- C:\Program Files\Elaborate Bytes 2008-04-21 15:10:13 0 d-------- C:\Program Files\Google 2008-04-21 13:55:50 0 d-------- C:\Program Files\lx_cats 2008-04-20 21:33:20 0 d-------- C:\Program Files\Common Files 2008-04-17 00:11:34 0 d-------- C:\Program Files\Soulseek 2008-04-08 19:48:39 0 d-------- C:\Documents and Settings\chris\Application Data\uTorrent 2008-04-08 19:43:51 0 d-------- C:\Program Files\SlySoft 2008-04-07 18:31:48 0 d-------- C:\Program Files\Microsoft Silverlight 2008-03-23 14:47:14 0 d-------- C:\Program Files\Vstplugins 2008-03-20 10:49:36 0 d-------- C:\Program Files\M-Audio 2008-03-20 10:49:35 0 d--h----- C:\Program Files\InstallShield Installation Information 2008-03-20 10:48:22 0 d-------- C:\Documents and Settings\chris\Application Data\InstallShield 2008-03-19 14:14:52 0 d-------- C:\Program Files\Java 2008-03-12 20:32:07 0 d-------- C:\Documents and Settings\chris\Application Data\dvdcss 2008-03-07 08:50:47 0 d-------- C:\Program Files\Native Instruments 2008-03-03 23:27:30 0 d-------- C:\Program Files\iTunes 2008-03-03 23:27:21 0 d-------- C:\Program Files\iPod 2008-03-01 12:53:53 0 dr-h----- C:\Documents and Settings\chris\Application Data\yahoo! 2008-03-01 12:53:47 0 d-------- C:\Program Files\Yahoo! -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LXCYCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCYtime.dll" [02/24/2006 08:54 AM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [02/28/2006 07:00 AM] "AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe" [04/05/2008 10:25 AM] [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "DWQueuedReporting"="C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^chris^Start Menu^Programs^Startup^MagicDisc.lnk] path=C:\Documents and Settings\chris\Start Menu\Programs\Startup\MagicDisc.lnk backup=C:\WINDOWS\pss\MagicDisc.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EzPrint] "C:\Program Files\Lexmark 3400 Series\ezprint.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] %systemroot%\system32\dumprep 0 -k [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxcymon.exe] "C:\Program Files\Lexmark 3400 Series\lxcymon.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray] MMTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray2K] MMTray2k.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTrayLSI] MMTrayLSI.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp] stsystra.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe -- End of Deckard's System Scanner: finished at 2008-04-24 10:42:35 ------------ |
|
|
|
|
|
#2 (permalink) |
|
Registered User
Join Date: Apr 2008
Posts: 13
OS: xp
|
here's the active scan too
;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-04-23 13:38:31 PROTECTIONS: 1 MALWARE: 27 SUSPECTS: 0 ;*********************************************************************************************************************************************************************************** PROTECTIONS Description Version Active Updated ;=================================================================================================================================================================================== Symantec AntiVirus Corporate Edition 10.1.6.6000 Yes Yes ;=================================================================================================================================================================================== MALWARE Id Description Type Active Severity Disinfectable Disinfected Location ;=================================================================================================================================================================================== 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.casalemedia.com/] 00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.casalemedia.com/] 00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.doubleclick.net/] 00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.atdmt.com/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.fastclick.net/] 00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.fastclick.net/] 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.tribalfusion.com/] 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.tribalfusion.com/] 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.tribalfusion.com/] 00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.tribalfusion.com/] 00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.mediaplex.com/] 00145792 Cookie/SexList TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.sexlist.com/] 00159564 Cookie/WUpd TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.revenue.net/] 00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.com.com/] 00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.yadro.ru/] 00167749 Cookie/Toplist TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.toplist.cz/] 00167795 Cookie/Cd Freaks TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Cookies\chris@club.cdfreaks[3].txt 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[ad.yieldmanager.com/] 00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[ad.yieldmanager.com/] 00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.apmebf.com/] 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.serving-sys.com/] 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.serving-sys.com/] 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.serving-sys.com/] 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.serving-sys.com/] 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.serving-sys.com/] 00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.serving-sys.com/] 00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.bs.serving-sys.com/] 00168105 Cookie/Cd Freaks TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Cookies\chris@cdfreaks[2].txt 00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.adtech.de/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.advertising.com/] 00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.advertising.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.ads.pointroll.com/] 00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.ads.pointroll.com/] 00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.realmedia.com/] 00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.realmedia.com/] 00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.realmedia.com/] 00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.realmedia.com/] 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.questionmarket.com/] 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.questionmarket.com/] 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.questionmarket.com/] 00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.questionmarket.com/] 00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.zedo.com/] 00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.zedo.com/] 00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.adultfriendfinder.com/] 00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.adultfriendfinder.com/] 00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.adultfriendfinder.com/] 00191644 Cookie/adultfriendfinder TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.adultfriendfinder.com/] 00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.go.com/] 00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.go.com/] 00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.go.com/] 00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.go.com/] 00199984 Cookie/Searchportal TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[searchportal.information.com/] 00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.atwola.com/] 00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Application Data\Mozilla\Firefox\Profiles\umnmnsxw.default\cookies.txt[.atwola.com/] 00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Documents and Settings\chris\Cookies\chris@atwola[1].txt ;=================================================================================================================================================================================== SUSPECTS Sent Location D ;=================================================================================================================================================================================== ;=================================================================================================================================================================================== VULNERABILITIES Id Severity Description D ;=================================================================================================================================================================================== ;=================================================================================================================================================================================== |
|
|
|
![]() |
| Thread Tools | |
|
|