![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Jan 2007
Posts: 39
OS: XP
|
Display changes automatically.
My display changes from XP style to Classic style every night around 4 or 5 pm.
Here's my log: Logfile of HijackThis v1.99.1 Scan saved at 5:34:46 PM, on 1/21/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\system32\CTsvcCDA.exe C:\WINDOWS\scvhost.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\PrinterAnywhere\paConsole.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Logitech\MediaLife\MediaLifeService.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\WINDOWS\system32\wuauclt.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\AIM6\aolsoftware.exe C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe C:\Program Files\Mozilla Firefox\firefox.exe c:\program files\windows media player\wmplayer.exe C:\Program Files\Windows Media Player\setup_wm.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\user\Desktop\HijackThis\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Auto EPSON Stylus CX4800 Series on AMYLAPTOP] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P44 "Auto EPSON Stylus CX4800 Series on AMYLAPTOP" /O17 "\\AMYLAPTOP\EPSON" /M "Stylus CX4800" O4 - HKLM\..\Run: [PrinterAnywhere] C:\Program Files\PrinterAnywhere\paConsole.exe -minimized O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [MediaLifeService] "C:\Program Files\Logitech\MediaLife\MediaLifeService.exe" O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800" O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [Microsoft] svhost.exe O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\RunServices: [Microsoft] svhost.exe O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: LaunchU3.exe.lnk = ? O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\npjpi150_10.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1167957340500 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1168097020812 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramewor...o.cab53083.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{8D0EFBCB-FE0C-4259-BCA9-3B7FB4664377}: NameServer = 205.246.142.11,204.117.214.10 O18 - Protocol: bw+0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: offline-8876480 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Microsoft Workstation Application - Unknown owner - C:\WINDOWS\scvhost.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: windows firewall svc - Unknown owner - C:\WINDOWS\navapsvc.exe (file missing) |
|
|
|
|
#5 (permalink) |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 19,747
OS: WinXP and Vista
|
Hello chickenNsims2,
Thank you for your patience, our apologies for the oversight of your thread. ![]() Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions. It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence. *************************************************** Download AVG Anti Spyware Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows" ![]()
-------------------------------------------------------------------- Download Combofix and save it to your desktop. **Note: It is important that it is saved directly to your desktop** ------------------------------------- Close any open browsers. ------------------------------------- ![]() Go to <<Start>> then <<Run>> then copy/paste the following red text into the Run box then click OK "%userprofile%\desktop\combofix.exe" /wow-drv Microsoft Workstation Application windows firewall svc When finished, it shall produce a log for you that will ultimately be named ComboFix2.txt. I'll need that log in your next reply. Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall -------------------------------------------------------------------- Please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Use the up arrow key to highlight Safe Mode and press Enter. 5) Login with your usual account. Make sure to close any open browsers. -------------------------------------------------------------------- Open HijackThis and click on 'Do a System Scan Only'. 'Check' the following entries: R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cust.../www.yahoo.com O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Microsoft] svhost.exe O4 - HKLM\..\RunServices: [Microsoft] svhost.exe Fix all of those Logitech O18 entries except the very first, and the last one listed. Click 'Fix Checked' and close HijackThis. -------------------------------------------------------------------- Go to My Computer->Tools->Folder Options->View tab: * Under the Hidden files and folders heading: * select Show hidden files and folders. * Uncheck Hide protected operating system files (recommended) option. *Also, make sure there is no checkmark beside Hide file extensions for known file types. * Click OK. -------------------------------------------------------------------- Using 'My Computer', navigate to and delete the following Files if they still exist. **Please be very careful of the spelling--make sure you are deleting the files spelled exactly as shown below: C:\WINDOWS\ scvhost.exe svhost.exe <--Do a search via Start>Search>All Files and folders and delete. -------------------------------------------------------------------- IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess: Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
-------------------------------------------------------------------- Reboot into Normal Mode. -------------------------------------------------------------------- Please run this online scan to search for any remnants. It can take some time, so please be patient and allow it to run it's full course: Perform an online scan with Internet Explorer with Panda ActiveScan
![]()
* Turn off the real time scanner of any existing antivirus program while performing the online scan -------------------------------------------------------------------- Double click on combofix.exe & follow the prompts. When finished, it shall produce a log for you. Note: Do not mouseclick combofix's window while it's running. That may cause it to stall Post the ComboFix.txt in your next reply. -------------------------------------------------------------------- Run a new scan with HijackThis and save the log. -------------------------------------------------------------------- Please include the following in your next reply: C:\ComboFix2.txt AVG Anti-Spyware results Panda results C:\ComboFix.txt New HijackThis log |
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: Jan 2007
Posts: 39
OS: XP
|
Ok, I only had one problem, I think I have a different version of AVG Anti-Spyware than what the directions said. So I'm not sure if that stuff is right...
C:\ComboFix2.txt- "user" - 07-02-04 17:14:02 Service Pack 2 ComboFix 07.02.04 - Running from: "C:\Documents and Settings\user\desktop" Command switches used :: /wow-drv Microsoft Workstation Application windows firewall svc (((((((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) C:\a.exe C:\b.exe C:\p.exe C:\WINDOWS\scvhost.exe ((((((((((((((((((((((((((((((( Files Created from 2007-01-04 to 2007-02-04 )))))))))))))))))))))))))))))))))) 2007-02-04 17:56 <DIR> dr-h----- C:\$VAULT$.AVG 2007-02-04 17:05 816,672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys 2007-02-04 17:05 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys 2007-02-04 17:05 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys 2007-02-04 17:05 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys 2007-02-04 17:05 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys 2007-02-04 17:05 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys 2007-02-04 17:05 <DIR> d-------- C:\DOCUME~1\user\Application Data\AVG7 2007-02-04 17:05 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\AVG7 2007-02-04 17:04 <DIR> d-------- C:\Program Files\Grisoft 2007-02-04 17:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Grisoft 2007-02-04 17:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\avg7 2007-02-03 16:36 <DIR> d-------- C:\DOCUME~1\user\Application Data\ArcSoft 2007-02-03 16:31 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL 2007-02-03 16:31 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS 2007-02-03 14:06 8,413 --a------ C:\WINDOWS\system32\drivers\mcstrm.sys 2007-02-03 14:06 <DIR> d-------- C:\DOCUME~1\user\Application Data\Real 2007-02-03 14:05 <DIR> d-------- C:\Program Files\Best Buy Rhapsody 2007-02-03 13:50 10,368 --------- C:\WINDOWS\system32\drivers\iviaspi.sys 2007-02-03 13:49 10,368 --a------ C:\WINDOWS\system32\iviaspi.sys 2007-02-03 13:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\InstallShield 2007-02-03 13:48 <DIR> d-------- C:\Program Files\Sandisk 2007-02-03 13:48 <DIR> d-------- C:\Program Files\Common Files\SWF Studio 2007-01-31 15:25 <DIR> d-------- C:\DOCUME~1\user\Application Data\IDS_COMPANY 2007-01-21 08:03 75,512 --a------ C:\WINDOWS\zllsputility.exe 2007-01-21 08:03 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll 2007-01-21 08:03 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll 2007-01-21 08:03 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs 2007-01-20 19:40 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-01-19 18:57 <DIR> d-------- C:\Program Files\balldroppings 2007-01-16 15:44 <DIR> d-------- C:\WINDOWS\pss 2007-01-14 14:30 <DIR> d-------- C:\DOCUME~1\user\Application Data\EPSON 2007-01-14 12:00 <DIR> d-------- C:\Program Files\GameSpy Arcade 2007-01-14 08:44 <DIR> d-------- C:\Program Files\Future Pinball 2007-01-13 16:41 <DIR> d-------- C:\DOCUME~1\user\Application Data\BitTorrent 2007-01-13 16:40 <DIR> d-------- C:\Program Files\BitTorrent 2007-01-13 14:56 <DIR> d-------- C:\Program Files\Disaffected 2007-01-13 12:51 <DIR> d-------- C:\Program Files\De Blob 2007-01-13 09:41 <DIR> d-------- C:\rh 2007-01-11 10:57 <DIR> d-------- C:\DOCUME~1\user\Application Data\Viewpoint 2007-01-06 21:44 <DIR> d-------- C:\WINDOWS\system32\Lang 2007-01-06 21:42 <DIR> d-------- C:\WINDOWS\system32\RTCOM 2007-01-06 21:42 <DIR> d-------- C:\Program Files\Realtek 2007-01-06 21:20 90,112 --a------ C:\WINDOWS\SOUNDMAN.EXE 2007-01-06 21:20 9,698,816 --a------ C:\WINDOWS\RTLCPL.EXE 2007-01-06 21:20 69,632 --a------ C:\WINDOWS\ALCMTR.EXE 2007-01-06 21:20 40,960 -r------- C:\WINDOWS\system32\ChCfg.exe 2007-01-06 21:20 3,160,576 --a------ C:\WINDOWS\system32\drivers\RtkHDAud.sys 2007-01-06 21:20 294,912 --a------ C:\WINDOWS\HideWin.exe 2007-01-06 21:20 2,805,248 --a------ C:\WINDOWS\ALCWZRD.EXE 2007-01-06 21:20 2,087,936 --a------ C:\WINDOWS\MicCal.exe 2007-01-06 21:20 14,565,376 --a------ C:\WINDOWS\RTHDCPL.EXE 2007-01-06 21:19 487,424 -r------- C:\WINDOWS\RtlExUpd.dll 2007-01-06 13:46 127,208 --a------ C:\WINDOWS\system32\mucltui.dll 2007-01-06 10:35 <DIR> d-------- C:\WINDOWS\system32\PreInstall (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-02-04 17:57 -------- d-------- C:\Documents and Settings\user\Application Data\avg7 2007-02-04 17:07 -------- d-------- C:\Program Files\mozilla firefox 2007-02-04 17:04 -------- d---s---- C:\Documents and Settings\user\Application Data\microsoft 2007-02-03 16:36 -------- d-------- C:\Documents and Settings\user\Application Data\arcsoft 2007-02-03 14:15 -------- d-------- C:\Program Files\creative 2007-02-03 14:07 -------- d-------- C:\Program Files\Common Files\real 2007-02-03 14:06 -------- d-------- C:\Program Files\real 2007-02-03 14:06 -------- d-------- C:\Documents and Settings\user\Application Data\real 2007-02-03 13:48 -------- d--h----- C:\Program Files\installshield installation information 2007-01-31 15:25 -------- d-------- C:\Documents and Settings\user\Application Data\ids_company 2007-01-28 14:30 -------- d-------- C:\Program Files\Common Files\symantec shared 2007-01-27 15:13 -------- d-------- C:\Documents and Settings\user\Application Data\u3 2007-01-23 13:26 -------- d-------- C:\Program Files\printeranywhere 2007-01-18 17:22 -------- d-------- C:\Program Files\java 2007-01-14 14:30 -------- d-------- C:\Documents and Settings\user\Application Data\epson 2007-01-14 13:33 -------- d-------- C:\Program Files\sierra 2007-01-13 16:42 -------- d-------- C:\Documents and Settings\user\Application Data\bittorrent 2007-01-11 10:57 -------- d-------- C:\Documents and Settings\user\Application Data\viewpoint 2007-01-06 09:05 -------- d-------- C:\Program Files\aim gadgets 2007-01-01 17:56 -------- d-------- C:\Program Files\movie maker 2007-01-01 14:00 -------- d-------- C:\Documents and Settings\user\Application Data\utorrent 2007-01-01 10:48 -------- d-------- C:\Program Files\abexo 2006-12-27 16:46 -------- d-------- C:\Program Files\playlinc 2006-12-26 13:25 -------- d-------- C:\Program Files\pcpitstop 2006-12-23 21:46 802816 --a------ C:\WINDOWS\feedingfrenzy.scr 2006-12-23 21:45 774144 --a------ C:\Program Files\rnginterstitial.dll 2006-12-23 21:24 -------- d-------- C:\Program Files\microsoft windows vista upgrade advisor 2006-12-23 19:57 27615 --a------ C:\ba.exe 2006-12-21 19:17 -------- d-------- C:\Documents and Settings\user\Application Data\snapfish 2006-12-21 17:07 -------- d-------- C:\Program Files\stormregion 2006-12-17 08:10 -------- d-------- C:\Program Files\Common Files\aol 2006-12-16 10:56 -------- d-------- C:\Program Files\yahoo! 2006-12-16 10:56 -------- d-------- C:\Program Files\nch swift sound 2006-12-16 09:48 -------- d-------- C:\Program Files\aim6 2006-11-27 03:45 60416 --------- C:\WINDOWS\system32\tzchange.exe 2006-11-04 14:14 1245696 --a------ C:\WINDOWS\system32\msxml4.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp" "Steam"="" "LDM"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "Auto EPSON Stylus CX4800 Series on AMYLAPTOP"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIADA.EXE /P44 \"Auto EPSON Stylus CX4800 Series on AMYLAPTOP\" /O17 \"\\\\AMYLAPTOP\\EPSON\" /M \"Stylus CX4800\"" "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "UpdReg"="C:\\WINDOWS\\UpdReg.EXE" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\"" "SoundMan"="SOUNDMAN.EXE" "RTHDCPL"="RTHDCPL.EXE" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "P17Helper"="Rundll32 P17.dll,P17Helper" "nwiz"="nwiz.exe /install" "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "MediaLifeService"="\"C:\\Program Files\\Logitech\\MediaLife\\MediaLifeService.exe\"" "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "High Definition Audio Property Page Shortcut"="HDAShCut.exe" "EPSON Stylus CX4800 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIADA.EXE /P26 \"EPSON Stylus CX4800 Series\" /O6 \"USB001\" /M \"Stylus CX4800\"" "CTSysVol"="C:\\Program Files\\Creative\\SBAudigy\\Surround Mixer\\CTSysVol.exe /r" "AlcWzrd"="ALCWZRD.EXE" "AGRSMMSG"="AGRSMMSG.exe" "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\"" "PrinterAnywhere"="C:\\Program Files\\PrinterAnywhere\\paConsole.exe -minimized" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}" [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E] Shell\AutoRun\command E:\Autorun.exe Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - user.job ******************************************************************** catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-02-04 19:00:32 AVG Anti-Spyware results (I'm not sure if this is the right thing or not?) General properties Report name Complete Test Start time 7/2/2004 17:57 End time 07-02-04 18:52 (total: 55:17.3 Min) Launch method Scanning launched manually Scanning result No threats found Report status Scanning completed successfully Object summary Scanned 90127 Threats Found 0 Cleaned 0 Moved to vault 0 Deleted 0 Errors 0 Test messages Info Exception while scanning C:\Program Files\Valve\Steam\SteamApps\chickennsims2\counter-strike source\cstrike\cache\gg_de_alivemetal.bsp.bz20000 C:\ComboFix.txt "user" - 07-02-05 9:48:15 Service Pack 2 ComboFix 07.02.04 - Running from: "C:\Documents and Settings\user\Desktop" ((((((((((((((((((((((((((((((( Files Created from 2007-01-05 to 2007-02-05 )))))))))))))))))))))))))))))))))) 2007-02-04 19:16 <DIR> d-------- C:\WINDOWS\system32\ActiveScan 2007-02-04 17:56 <DIR> dr-h----- C:\$VAULT$.AVG 2007-02-04 17:05 816,672 --a------ C:\WINDOWS\system32\drivers\avg7core.sys 2007-02-04 17:05 4,960 --a------ C:\WINDOWS\system32\drivers\avgtdi.sys 2007-02-04 17:05 4,224 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys 2007-02-04 17:05 3,968 --a------ C:\WINDOWS\system32\drivers\avgclean.sys 2007-02-04 17:05 28,416 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys 2007-02-04 17:05 18,240 --a------ C:\WINDOWS\system32\drivers\avgmfx86.sys 2007-02-04 17:05 <DIR> d-------- C:\DOCUME~1\user\Application Data\AVG7 2007-02-04 17:05 <DIR> d-------- C:\DOCUME~1\LOCALS~1\Application Data\AVG7 2007-02-04 17:04 <DIR> d-------- C:\Program Files\Grisoft 2007-02-04 17:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Grisoft 2007-02-04 17:04 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\avg7 2007-02-03 16:36 <DIR> d-------- C:\DOCUME~1\user\Application Data\ArcSoft 2007-02-03 16:31 45,056 --a------ C:\WINDOWS\system32\WNASPI32.DLL 2007-02-03 16:31 16,512 --a------ C:\WINDOWS\system32\drivers\ASPI32.SYS 2007-02-03 14:06 8,413 --a------ C:\WINDOWS\system32\drivers\mcstrm.sys 2007-02-03 14:06 <DIR> d-------- C:\DOCUME~1\user\Application Data\Real 2007-02-03 14:05 <DIR> d-------- C:\Program Files\Best Buy Rhapsody 2007-02-03 13:50 10,368 --------- C:\WINDOWS\system32\drivers\iviaspi.sys 2007-02-03 13:49 10,368 --a------ C:\WINDOWS\system32\iviaspi.sys 2007-02-03 13:49 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\InstallShield 2007-02-03 13:48 <DIR> d-------- C:\Program Files\Sandisk 2007-02-03 13:48 <DIR> d-------- C:\Program Files\Common Files\SWF Studio 2007-01-31 15:25 <DIR> d-------- C:\DOCUME~1\user\Application Data\IDS_COMPANY 2007-01-21 08:03 75,512 --a------ C:\WINDOWS\zllsputility.exe 2007-01-21 08:03 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll 2007-01-21 08:03 1,087,216 --a------ C:\WINDOWS\system32\zpeng24.dll 2007-01-21 08:03 <DIR> d-------- C:\WINDOWS\system32\ZoneLabs 2007-01-20 19:40 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll 2007-01-19 18:57 <DIR> d-------- C:\Program Files\balldroppings 2007-01-16 15:44 <DIR> d-------- C:\WINDOWS\pss 2007-01-14 14:30 <DIR> d-------- C:\DOCUME~1\user\Application Data\EPSON 2007-01-14 12:00 <DIR> d-------- C:\Program Files\GameSpy Arcade 2007-01-14 08:44 <DIR> d-------- C:\Program Files\Future Pinball 2007-01-13 16:41 <DIR> d-------- C:\DOCUME~1\user\Application Data\BitTorrent 2007-01-13 16:40 <DIR> d-------- C:\Program Files\BitTorrent 2007-01-13 14:56 <DIR> d-------- C:\Program Files\Disaffected 2007-01-13 12:51 <DIR> d-------- C:\Program Files\De Blob 2007-01-13 09:41 <DIR> d-------- C:\rh 2007-01-11 10:57 <DIR> d-------- C:\DOCUME~1\user\Application Data\Viewpoint 2007-01-06 21:44 <DIR> d-------- C:\WINDOWS\system32\Lang 2007-01-06 21:42 <DIR> d-------- C:\WINDOWS\system32\RTCOM 2007-01-06 21:42 <DIR> d-------- C:\Program Files\Realtek 2007-01-06 21:20 90,112 --a------ C:\WINDOWS\SOUNDMAN.EXE 2007-01-06 21:20 9,698,816 --a------ C:\WINDOWS\RTLCPL.EXE 2007-01-06 21:20 69,632 --a------ C:\WINDOWS\ALCMTR.EXE 2007-01-06 21:20 40,960 -r------- C:\WINDOWS\system32\ChCfg.exe 2007-01-06 21:20 3,160,576 --a------ C:\WINDOWS\system32\drivers\RtkHDAud.sys 2007-01-06 21:20 294,912 --a------ C:\WINDOWS\HideWin.exe 2007-01-06 21:20 2,805,248 --a------ C:\WINDOWS\ALCWZRD.EXE 2007-01-06 21:20 2,087,936 --a------ C:\WINDOWS\MicCal.exe 2007-01-06 21:20 14,565,376 --a------ C:\WINDOWS\RTHDCPL.EXE 2007-01-06 21:19 487,424 -r------- C:\WINDOWS\RtlExUpd.dll 2007-01-06 13:46 127,208 --a------ C:\WINDOWS\system32\mucltui.dll 2007-01-06 10:35 <DIR> d-------- C:\WINDOWS\system32\PreInstall (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-02-05 09:26 -------- d-------- C:\Program Files\symantec 2007-02-05 09:26 -------- d-------- C:\Program Files\sims2pack clean installer 2007-02-05 09:25 -------- d-------- C:\Program Files\quicktime 2007-02-05 09:23 -------- d-------- C:\Program Files\messenger 2007-02-05 09:20 -------- d-------- C:\Program Files\itunes 2007-02-05 09:12 -------- d-------- C:\Program Files\Common Files\symantec shared 2007-02-05 09:10 -------- d-------- C:\Program Files\aim6 2007-02-05 09:09 -------- d-------- C:\Program Files\aim gadgets 2007-02-05 08:59 -------- d-------- C:\DOCUME~1\user\Application Data\symantec 2007-02-05 08:55 -------- d-------- C:\Program Files\mozilla firefox 2007-02-04 17:04 -------- d---s---- C:\DOCUME~1\user\Application Data\microsoft 2007-02-03 14:15 -------- d-------- C:\Program Files\creative 2007-02-03 14:07 -------- d-------- C:\Program Files\Common Files\real 2007-02-03 14:06 -------- d-------- C:\Program Files\real 2007-02-03 13:48 -------- d--h----- C:\Program Files\installshield installation information 2007-01-27 15:13 -------- d-------- C:\DOCUME~1\user\Application Data\u3 2007-01-23 13:26 -------- d-------- C:\Program Files\printeranywhere 2007-01-18 17:22 -------- d-------- C:\Program Files\java 2007-01-14 13:33 -------- d-------- C:\Program Files\sierra 2007-01-01 17:56 -------- d-------- C:\Program Files\movie maker 2007-01-01 14:00 -------- d-------- C:\DOCUME~1\user\Application Data\utorrent 2007-01-01 10:48 -------- d-------- C:\Program Files\abexo 2006-12-27 16:46 -------- d-------- C:\Program Files\playlinc 2006-12-26 13:25 -------- d-------- C:\Program Files\pcpitstop 2006-12-23 21:46 802816 --a------ C:\WINDOWS\feedingfrenzy.scr 2006-12-23 21:45 774144 --a------ C:\Program Files\rnginterstitial.dll 2006-12-23 21:24 -------- d-------- C:\Program Files\microsoft windows vista upgrade advisor 2006-12-23 19:57 27615 --a------ C:\ba.exe 2006-12-21 19:17 -------- d-------- C:\DOCUME~1\user\Application Data\snapfish 2006-12-21 17:07 -------- d-------- C:\Program Files\stormregion 2006-12-17 08:10 -------- d-------- C:\Program Files\Common Files\aol 2006-12-16 10:56 -------- d-------- C:\Program Files\yahoo! 2006-12-16 10:56 -------- d-------- C:\Program Files\nch swift sound 2006-11-27 03:45 60416 --------- C:\WINDOWS\system32\tzchange.exe (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "Aim6"="\"C:\\Program Files\\AIM6\\aim6.exe\" /d locale=en-US ee://aol/imApp" "Steam"="" "LDM"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "Auto EPSON Stylus CX4800 Series on AMYLAPTOP"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIADA.EXE /P44 \"Auto EPSON Stylus CX4800 Series on AMYLAPTOP\" /O17 \"\\\\AMYLAPTOP\\EPSON\" /M \"Stylus CX4800\"" "ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\"" "UpdReg"="C:\\WINDOWS\\UpdReg.EXE" "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\"" "SoundMan"="SOUNDMAN.EXE" "RTHDCPL"="RTHDCPL.EXE" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" "P17Helper"="Rundll32 P17.dll,P17Helper" "nwiz"="nwiz.exe /install" "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" "MediaLifeService"="\"C:\\Program Files\\Logitech\\MediaLife\\MediaLifeService.exe\"" "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\"" "High Definition Audio Property Page Shortcut"="HDAShCut.exe" "EPSON Stylus CX4800 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATIADA.EXE /P26 \"EPSON Stylus CX4800 Series\" /O6 \"USB001\" /M \"Stylus CX4800\"" "CTSysVol"="C:\\Program Files\\Creative\\SBAudigy\\Surround Mixer\\CTSysVol.exe /r" "AlcWzrd"="ALCWZRD.EXE" "AGRSMMSG"="AGRSMMSG.exe" "ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\"" "PrinterAnywhere"="C:\\Program Files\\PrinterAnywhere\\paConsole.exe -minimized" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}" "UPnPMonitor"="{e57ce738-33e8-4c51-8354-bb4de9d215d1}" [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0 [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E] Shell\AutoRun\command E:\Autorun.exe [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{102273d8-f94c-11da-bcef-806d6172696f}] Shell\AutoRun\command E:\Autorun.exe Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - user.job ******************************************************************** catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006 http://www.gmer.net scanning hidden processes ... scanning hidden services ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 ******************************************************************** Completion time: 07-02-05 9:51:22 C:\ComboFix2.txt ... 07-02-04 19:00 New HijackThis Log Logfile of HijackThis v1.99.1 Scan saved at 9:52:49 AM, on 2/5/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\QuickTime\qttask.exe C:\WINDOWS\system32\Rundll32.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Logitech\MediaLife\MediaLifeService.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe C:\Documents and Settings\All Users\Application Data\U3\U3Launcher\LaunchU3.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Logitech\SetPoint\SetPoint.exe C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe C:\Program Files\AIM6\aolsoftware.exe C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\user\Desktop\HijackThis\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [Auto EPSON Stylus CX4800 Series on AMYLAPTOP] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P44 "Auto EPSON Stylus CX4800 Series on AMYLAPTOP" /O17 "\\AMYLAPTOP\EPSON" /M "Stylus CX4800" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe" O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [MediaLifeService] "C:\Program Files\Logitech\MediaLife\MediaLifeService.exe" O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [EPSON Stylus CX4800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE /P26 "EPSON Stylus CX4800 Series" /O6 "USB001" /M "Stylus CX4800" O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [PrinterAnywhere] C:\Program Files\PrinterAnywhere\paConsole.exe -minimized O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Yahoo! Widget Engine\YahooWidgetEngine.exe O4 - Global Startup: WinCinema Manager.lnk = C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: LaunchU3.exe.lnk = ? O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1167957340500 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1168097020812 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramewor...o.cab53083.cab O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab O18 - Protocol: bw+0 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: offline-8876480 - {82FFFEE7-466C-46AB-A1C4-689C5F5D1D17} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Microsoft Workstation Application - Unknown owner - C:\WINDOWS\scvhost.exe (file missing) O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: windows firewall svc - Unknown owner - C:\WINDOWS\navapsvc.exe (file missing) |
|
|
|
|
#7 (permalink) | |
|
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
Join Date: Jan 2005
Location: Ohio
Posts: 19,747
OS: WinXP and Vista
|
Hi,
Please copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions. It is IMPORTANT that you don't miss a step & perform everything in the correct order/sequence. *************************************************** Please copy (Ctrl+C) and paste (Ctrl+V) the following text in the quote to Notepad. Save it as " All Files" and name it FixServices.bat. Please save it on your desktop. Quote:
------------------------------------------------- Unfortunately, you downloaded AVG Free Anti Virus is error. (it is a bit confusing as their products are named so similarly) ![]() It's never a good idea to have more than 1 AV installed, so please uninstall AVG Free Edition via the Add/Remove programs, then delete it's folder if it still exists: C:\Program Files\ Grisoft ------------------------------------------------- Let's try again to download AVG Anti Spyware. ![]() Download AVG Anti Spyware **Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows" ![]()
-------------------------------------------------------------------- Next, please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Use the up arrow key to highlight Safe Mode and press Enter. 5) Login with your usual account. Make sure to close any open browsers. -------------------------------------------------------------------- IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess: Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
-------------------------------------------------------------------- Reboot into Normal Mode. -------------------------------------------------------------------- Were you able to perform the online scan at Panda? If so, please post those results as well. ------------------------------------------------- Please include the following in your next reply: AVG A-S results Panda results What is your E:\ drive? |